Created
September 10, 2026 21:37
-
-
Save dhellmann/8c4a9ddd9e2c2b963838eea95e4cccb2 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| { | |
| "_type": "https://in-toto.io/Statement/v0.1", | |
| "subject": [ | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b" | |
| } | |
| }, | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75" | |
| } | |
| }, | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f" | |
| } | |
| }, | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| } | |
| }, | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532" | |
| } | |
| }, | |
| { | |
| "name": "quay.io/rhoai/odh-kserve-agent-rhel9", | |
| "digest": { | |
| "sha256": "3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e" | |
| } | |
| } | |
| ], | |
| "predicateType": "https://slsa.dev/provenance/v0.2", | |
| "predicate": { | |
| "buildConfig": { | |
| "tasks": [ | |
| { | |
| "finishedOn": "2026-09-08T21:21:16Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha1": "c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b" | |
| }, | |
| "entryPoint": "konflux-tekton-tasks/rhoai-init/0.1/rhoai-init.yaml", | |
| "uri": "git+https://github.com/red-hat-data-services/rhoai-konflux-tasks.git" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/761d776f-7312-419c-ae4c-7a37b7f1a316", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-adf7ef40e18f1aa2-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "rhoai-init", | |
| "tekton.dev/task": "rhoai-init" | |
| } | |
| }, | |
| "parameters": { | |
| "build-type": "", | |
| "expected-cluster": "", | |
| "image-output": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "rhoai-version": "2.25.11" | |
| } | |
| }, | |
| "name": "rhoai-init", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "url", | |
| "value": "https://github.com/red-hat-data-services/rhoai-konflux-tasks.git" | |
| }, | |
| { | |
| "name": "revision", | |
| "value": "c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b" | |
| }, | |
| { | |
| "name": "pathInRepo", | |
| "value": "konflux-tekton-tasks/rhoai-init/0.1/rhoai-init.yaml" | |
| } | |
| ], | |
| "resolver": "git" | |
| }, | |
| "results": [ | |
| { | |
| "name": "cpe-id", | |
| "type": "string", | |
| "value": "" | |
| }, | |
| { | |
| "name": "display-name", | |
| "type": "string", | |
| "value": "ODH Kserve Agent" | |
| }, | |
| { | |
| "name": "image-name", | |
| "type": "string", | |
| "value": "odh-kserve-agent-rhel9" | |
| }, | |
| { | |
| "name": "image-name-without-rhel-suffix", | |
| "type": "string", | |
| "value": "odh-kserve-agent" | |
| }, | |
| { | |
| "name": "image-namespace", | |
| "type": "string", | |
| "value": "rhoai" | |
| }, | |
| { | |
| "name": "image-registry", | |
| "type": "string", | |
| "value": "quay.io" | |
| }, | |
| { | |
| "name": "image-tag", | |
| "type": "string", | |
| "value": "rhoai-2.25" | |
| }, | |
| { | |
| "name": "konflux-component-name", | |
| "type": "string", | |
| "value": "odh-kserve-agent-v2-25" | |
| }, | |
| { | |
| "name": "skip-slack-message", | |
| "type": "string", | |
| "value": "true" | |
| }, | |
| { | |
| "name": "slack-message-failure-text", | |
| "type": "string", | |
| "value": ":alert: <https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp|odh-kserve-agent-v2-25-on-push-xwfsp> - 2026-09-08T21:21:16\nStatus: Failed :failed: (cluster: stone-prod-p02)\nCC - <!subteam^S0ABFF86BNE|openshift-ai-devops-build-guardian>" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:11Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"----- DEBUG INFORMATION -----\"\necho \"Build URL: $BUILD_URL\"\necho \"SHA URL: $SHA_URL\"\necho \"Target Branch: $target_branch\"\necho \"Summary Annotations: $SUMMARY_ANNOTATIONS\"\necho \"Build Type: $BUILD_TYPE\"\necho \"RHOAI Version: $RHOAI_VERSION\"\necho \"Image Output: $IMAGE_OUTPUT\"\necho \"Expected Cluster: $EXPECTED_CLUSTER\"\necho \"Konflux Component Name: $KONFLUX_COMPONENT_NAME\"\n\n# Check if this is a pull request pipeline\nis_pull_request=false\nif [[ \"$SUMMARY_ANNOTATIONS\" =~ '\"eventType\":\"pull_request\"' || \"$SUMMARY_ANNOTATIONS\" =~ '\"eventType\":\"pull_request_labeled\"' || \"$SUMMARY_ANNOTATIONS\" =~ \"pull_request-id\" ]]; then\n is_pull_request=true\n echo \"Pull request pipeline detected\"\nfi\n\n# Fail if required parameters are not provided\n# rhoai-version is optional for PR pipelines\nif [[ -z \"$RHOAI_VERSION\" && \"$is_pull_request\" == \"false\" ]]; then\n echo \"ERROR: RHOAI version is required but was not provided\"\n exit 1\nfi\n\nif [[ -z \"$IMAGE_OUTPUT\" ]]; then\n echo \"ERROR: Image output is required but was not provided\"\n exit 1\nfi\n\npipelinerun_name=$(echo $BUILD_URL | sed 's|http.*/||')\necho \"Pipelinerun Name: $pipelinerun_name\"\n\n# Function to compare semantic versions\n# returns true (0) if $1 >= $2\nsemver_ge() {\n # Strip pre-release suffix (e.g., \"3.4.0-ea.1\" becomes \"3.4.0\")\n local v1=\"${1%%-*}\"\n local v2=\"${2%%-*}\"\n\n # We append \".0.0\" to ensure at least three components (x.y.z) exist.\n # This normalizes both versions ($1 and $2) to x.y.z format for comparison.\n # We read four variables (x1, y1, z1, extra) to ensure x1, y1 and z1 only captures the x, y and z,\n # and the dummy variable (extra) captures the extra trailing \".0\" parts.\n IFS='.' read -r x1 y1 z1 extra <<< \"${v1}.0.0\"\n IFS='.' read -r x2 y2 z2 extra <<< \"${v2}.0.0\"\n\n echo \"Comparing versions: $1 (normalized to x1=$x1, y1=$y1, z1=$z1) and $2 (normalized to x2=$x2, y2=$y2, z2=$z2)\"\n\n if (( x1 > x2 )); then return 0; fi\n if (( x1 < x2 )); then return 1; fi\n\n if (( y1 > y2 )); then return 0; fi\n if (( y1 < y2 )); then return 1; fi\n\n if (( z1 >= z2 )); then return 0; fi\n\n return 1\n}\n\n# No need to set CPE ID for pull request builds\nif [[ \"$is_pull_request\" == \"false\" ]]; then\n\n # All RHOAI versions 2.20 and above use RHEL 9\n # Determine rhel_version based on semantic comparison with 2.20\n if semver_ge \"$RHOAI_VERSION\" \"2.20\"; then\n rhel_version=9\n else\n rhel_version=8\n fi\n\n # Parse RHOAI version into x, y, z components for CPE ID\n # Strip pre-release suffix first (e.g., \"3.4.0-ea.1\" becomes \"3.4.0\")\n clean_version=\"${RHOAI_VERSION%%-*}\"\n IFS='.' read -r x y z extra <<< \"${clean_version}.0.0\"\n\n # Form the CPE identifier\n cpe_id=\"cpe:/a:redhat:openshift_ai:${x}.${y}::el${rhel_version}\"\nelse\n cpe_id=\"\"\nfi\n\necho \"CPE ID: $cpe_id\"\necho -n \"${cpe_id}\" > \"/tekton/results/cpe-id\"\n\n# Extract image registry, namespace, name and tag from the image-output parameter\n# Supports both 2-level and 3-level paths:\n# quay.io/rhoai/image-name:tag -> registry=quay.io, namespace=rhoai, name=image-name\n# quay.io/redhat-user-workloads/rhoai-tenant/image-name:tag -> registry=quay.io, namespace=redhat-user-workloads/rhoai-tenant, name=image-name\necho \"----- PARSING IMAGE OUTPUT -----\"\n\n# Extract registry (first part before the first /)\nimage_registry=$(echo \"$IMAGE_OUTPUT\" | cut -d'/' -f1)\n\n# Remove registry to get the rest (namespace/path/image:tag)\nimage_path_with_tag=\"${IMAGE_OUTPUT#*/}\"\n\n# Split off the tag first (everything after the last :)\nif [[ \"$image_path_with_tag\" == *\":\"* ]]; then\n image_path=$(echo \"$image_path_with_tag\" | rev | cut -d':' -f2- | rev)\n image_tag=$(echo \"$image_path_with_tag\" | rev | cut -d':' -f1 | rev)\nelse\n image_path=\"$image_path_with_tag\"\n image_tag=\"\"\nfi\n\n# Extract image name (last component of the path)\nimage_name=$(echo \"$image_path\" | rev | cut -d'/' -f1 | rev)\n\n# Extract namespace (everything before the image name)\nimage_namespace=$(echo \"$image_path\" | rev | cut -d'/' -f2- | rev)\n\necho \"Image Registry: $image_registry\"\necho \"Image Namespace: $image_namespace\"\necho \"Image Name: $image_name\"\necho \"Image Tag: $image_tag\"\n\n# Derive additional values from image_name\n# image_name_without_rhel_suffix: Remove -rhel{N} suffix from anywhere in image_name\nimage_name_without_rhel_suffix=$(echo \"$image_name\" | sed 's/-rhel[0-9]*//g')\n\n# display_name: Convert image_name_without_rhel_suffix to human-readable display name\n# Replace hyphens with spaces, capitalize first letter of each word, keep ODH uppercase\ndisplay_name=$(echo \"$image_name_without_rhel_suffix\" | tr '-' ' ' | awk '{for(i=1;i<=NF;i++) $i=toupper(substr($i,1,1)) tolower(substr($i,2)); print}' | sed 's/\\bOdh\\b/ODH/g')\n\necho \"Image Name Without RHEL Suffix: $image_name_without_rhel_suffix\"\necho \"Display Name: $display_name\"\n\necho -n \"${image_registry}\" > \"/tekton/results/image-registry\"\necho -n \"${image_namespace}\" > \"/tekton/results/image-namespace\"\necho -n \"${image_name}\" > \"/tekton/results/image-name\"\necho -n \"${image_tag}\" > \"/tekton/results/image-tag\"\necho -n \"${image_name_without_rhel_suffix}\" > \"/tekton/results/image-name-without-rhel-suffix\"\necho -n \"${KONFLUX_COMPONENT_NAME}\" > \"/tekton/results/konflux-component-name\"\necho -n \"${display_name}\" > \"/tekton/results/display-name\"\n\n# Skip slack message if expected cluster does not match\nCLUSTER=$( echo \"$BUILD_URL\" | grep -oE 'stone-pro?d-[a-z0-9]+')\necho \"Expected Cluster: $EXPECTED_CLUSTER\"\necho \"Actual Cluster: $CLUSTER\"\nif [[ -n \"$EXPECTED_CLUSTER\" && \"$EXPECTED_CLUSTER\" != \"$CLUSTER\" ]]; then\n echo \"Build URL does not match expected cluster $CLUSTER.\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\nelse\n echo -n \"false\" > \"/tekton/results/skip-slack-message\"\nfi\n\nbuild_time=\"$(date +%Y-%m-%dT%H:%M:%S)\"\n\nslack_message=${slack_message/__BUILD__URL__/$BUILD_URL}\nslack_message=${slack_message/__PIPELINERUN__NAME__/$pipelinerun_name}\nslack_message=${slack_message/__BUILD__TIME__/$build_time}\n\n# Don't send a slack message for pull request pipelines\nif [[ \"$is_pull_request\" == \"true\" ]]; then\n echo \"pull request pipeline detected, skipping slack message\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\nfi\n\n# Tag @rhoai-releng for stage FBCF build failures\nif [[ \"$BUILD_TYPE\" == \"stage\" ]]; then\n alertEmoji=\":actual_rotating_light:\"\n slack_message=${slack_message/:alert:/$alertEmoji}\n # The \"!\" in <!subteam^S09SZP9J34M|rhoai-releng> causes Bash history expansion errors\n set +H # disable history expansion\n slack_message=$(echo -e \"${slack_message}\\nCC - <!subteam^S09SZP9J34M|rhoai-releng>\")\n set -H # re-enable history expansion\nfi\n\nif [[ \"$image_namespace\" == \"rhoai-private\" ]]; then\n echo \"Embargoed build target detected. Not sending slack message\"\n # Prod delivery repo is \"rhoai\" for both embargoed and non-embargoed builds\n echo -n \"rhoai\" > \"/tekton/results/image-namespace\"\n echo -n \"true\" > \"/tekton/results/skip-slack-message\"\n exit 0\nfi\n\necho -en \"${slack_message}\" > \"/tekton/results/slack-message-failure-text\"\necho \"Slack Message: ${slack_message}\"\n", | |
| "environment": { | |
| "container": "rhoai-init", | |
| "image": "oci://registry.access.redhat.com/ubi9/ubi@sha256:25a147defd01e19674714f55d17538c8dbe55d8c305fa157ecc3f9c8977b05b6" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "rhoai-init" | |
| ], | |
| "finishedOn": "2026-09-08T21:21:21Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900" | |
| }, | |
| "entryPoint": "init", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-init" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/8bd92c5d-9fdc-4098-8218-7d2605697743", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b156e251d6b8c497-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "init", | |
| "tekton.dev/task": "init" | |
| } | |
| }, | |
| "parameters": { | |
| "enable-cache-proxy": "true" | |
| } | |
| }, | |
| "name": "init", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "init" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-init:0.4.3@sha256:4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "http-proxy", | |
| "type": "string", | |
| "value": "squid.caching.svc.cluster.local:3128" | |
| }, | |
| { | |
| "name": "no-proxy", | |
| "type": "string", | |
| "value": "" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:17Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--enable", | |
| "true" | |
| ], | |
| "entryPoint": "konflux-build-cli config cache-proxy", | |
| "environment": { | |
| "container": "init", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "init" | |
| ], | |
| "finishedOn": "2026-09-08T21:21:40Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544" | |
| }, | |
| "entryPoint": "git-clone-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/4a7736e0-ad0b-4ade-81e1-5fafc8dc7866", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/categories": "Git", | |
| "tekton.dev/displayName": "git clone oci trusted artifacts", | |
| "tekton.dev/pipelines.minVersion": "0.21.0", | |
| "tekton.dev/platforms": "linux/amd64,linux/s390x,linux/ppc64le,linux/arm64", | |
| "tekton.dev/tags": "git", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-784110e1636ca9cd-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clone-repository", | |
| "tekton.dev/task": "git-clone-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca", | |
| "depth": "1", | |
| "enableSymlinkCheck": "true", | |
| "fetchTags": "false", | |
| "httpProxy": "", | |
| "httpsProxy": "", | |
| "logLevel": "info", | |
| "mergeSourceDepth": "", | |
| "mergeSourceRepoUrl": "", | |
| "mergeTargetBranch": "false", | |
| "noProxy": "", | |
| "ociArtifactExpiresAfter": "", | |
| "ociStorage": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.git", | |
| "refspec": "", | |
| "revision": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "shortCommitLength": "7", | |
| "sparseCheckoutDirectories": "", | |
| "sslVerify": "true", | |
| "submodulePaths": "", | |
| "submodules": "true", | |
| "symlinkCheckIgnorePattern": "", | |
| "targetBranch": "main", | |
| "url": "https://github.com/red-hat-data-services/kserve" | |
| } | |
| }, | |
| "name": "clone-repository", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "git-clone-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta:0.2.6@sha256:2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "CHAINS-GIT_COMMIT", | |
| "type": "string", | |
| "value": "58e7f0f6d889933345394152903c95c62e6bd9c3" | |
| }, | |
| { | |
| "name": "CHAINS-GIT_URL", | |
| "type": "string", | |
| "value": "https://github.com/red-hat-data-services/kserve" | |
| }, | |
| { | |
| "name": "commit", | |
| "type": "string", | |
| "value": "58e7f0f6d889933345394152903c95c62e6bd9c3" | |
| }, | |
| { | |
| "name": "commit-timestamp", | |
| "type": "string", | |
| "value": "1788902446" | |
| }, | |
| { | |
| "name": "short-commit", | |
| "type": "string", | |
| "value": "58e7f0f" | |
| }, | |
| { | |
| "name": "url", | |
| "type": "string", | |
| "value": "https://github.com/red-hat-data-services/kserve" | |
| }, | |
| { | |
| "name": "SOURCE_ARTIFACT", | |
| "type": "string", | |
| "value": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:23Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf \"$ca_bundle\" /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\ntest -z \"${PARAM_HTTP_PROXY}\" || export HTTP_PROXY=\"${PARAM_HTTP_PROXY}\"\ntest -z \"${PARAM_HTTPS_PROXY}\" || export HTTPS_PROXY=\"${PARAM_HTTPS_PROXY}\"\ntest -z \"${PARAM_NO_PROXY}\" || export NO_PROXY=\"${PARAM_NO_PROXY}\"\n\nRESULT_FILE=\"$(mktemp)\"\nkonflux-build-cli git-clone >\"${RESULT_FILE}\"\n\nprintf \"%s\" \"$(jq -r '.commit' \"${RESULT_FILE}\")\" >\"/tekton/results/commit\"\nprintf \"%s\" \"$(jq -r '.shortCommit' \"${RESULT_FILE}\")\" >\"/tekton/results/short-commit\"\nprintf \"%s\" \"$(jq -r '.url' \"${RESULT_FILE}\")\" >\"/tekton/results/url\"\nprintf \"%s\" \"$(jq -r '.commitTimestamp' \"${RESULT_FILE}\")\" >\"/tekton/results/commit-timestamp\"\nprintf \"%s\" \"$(jq -r '.\"CHAINS-GIT_URL\"' \"${RESULT_FILE}\")\" >\"/tekton/results/CHAINS-GIT_URL\"\nprintf \"%s\" \"$(jq -r '.\"CHAINS-GIT_COMMIT\"' \"${RESULT_FILE}\")\" >\"/tekton/results/CHAINS-GIT_COMMIT\"\n\nMERGED_SHA=$(jq -r '.mergedSha // empty' \"${RESULT_FILE}\")\nif [ -n \"${MERGED_SHA}\" ]; then\n printf \"%s\" \"${MERGED_SHA}\" >\"/tekton/results/merged_sha\"\nfi\n", | |
| "environment": { | |
| "container": "clone", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "create", | |
| "--store", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.git", | |
| "/tekton/results/SOURCE_ARTIFACT=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "create-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "clone-repository" | |
| ], | |
| "finishedOn": "2026-09-08T21:21:48Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da" | |
| }, | |
| "entryPoint": "prefetch-dependencies-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/648b0bdf-9cf1-4148-bc06-ecdcddf7881a", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-737a60358dade829-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "prefetch-dependencies", | |
| "tekton.dev/task": "prefetch-dependencies-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ACTIVATION_KEY": "custom-activation-key", | |
| "SERVICE_CA_TRUST_CONFIG_MAP_KEY": "service-ca.crt", | |
| "SERVICE_CA_TRUST_CONFIG_MAP_NAME": "openshift-service-ca.crt", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca", | |
| "config-file-content": "", | |
| "enable-package-registry-proxy": "true", | |
| "input": "", | |
| "log-level": "info", | |
| "mode": "strict", | |
| "ociArtifactExpiresAfter": "", | |
| "ociStorage": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.prefetch", | |
| "pip-index-url": "", | |
| "sbom-type": "spdx" | |
| } | |
| }, | |
| "name": "prefetch-dependencies", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "prefetch-dependencies-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta:0.10.2@sha256:374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "CACHI2_ARTIFACT", | |
| "type": "string", | |
| "value": "" | |
| }, | |
| { | |
| "name": "SOURCE_ARTIFACT", | |
| "type": "string", | |
| "value": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:41Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\n\necho -n \"${SOURCE_ARTIFACT}\" >\"/tekton/results/SOURCE_ARTIFACT\"\necho -n \"\" >\"/tekton/results/CACHI2_ARTIFACT\"\n", | |
| "environment": { | |
| "container": "skip-ta", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\n\nif [ -n \"${WORKSPACE_NETRC_PATH}\" ]; then\n export NETRC=\"${WORKSPACE_NETRC_PATH}/.netrc\"\nfi\n\nCA_BUNDLE_PATH=/mnt/trusted-ca/ca-bundle.crt\nSERVICE_CA_BUNDLE_PATH=/mnt/service-ca/ca-bundle.crt\nUPDATE_CA_TRUST=false\n\nif [ -f \"$CA_BUNDLE_PATH\" ]; then\n echo \"Using mounted CA bundle: $CA_BUNDLE_PATH\"\n cp -vf \"$CA_BUNDLE_PATH\" /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n UPDATE_CA_TRUST=true\nfi\n\nif [ -f \"$SERVICE_CA_BUNDLE_PATH\" ]; then\n echo \"Using mounted service CA bundle: $SERVICE_CA_BUNDLE_PATH\"\n cp -vf \"$SERVICE_CA_BUNDLE_PATH\" /etc/pki/ca-trust/source/anchors/service-ca.crt\n UPDATE_CA_TRUST=true\nfi\n\nif [ \"$UPDATE_CA_TRUST\" = \"true\" ]; then\n update-ca-trust\n # requests ignores the system CA store. Set REQUESTS_CA_BUNDLE explicitly.\n export REQUESTS_CA_BUNDLE=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem\nfi\n\nif [ -e /activation-key/org ] && [ -e /activation-key/activationkey ]; then\n export KBC_PD_RHSM_ORG=/activation-key/org\n export KBC_PD_RHSM_ACTIVATION_KEY=/activation-key/activationkey\nfi\n\nif [ -n \"${CONFIG_FILE_CONTENT}\" ]; then\n echo \"${CONFIG_FILE_CONTENT}\" >/mnt/config/config.yaml\n export KBC_PD_CONFIG_FILE=/mnt/config/config.yaml\nfi\n\nif [ -z \"${PIP_INDEX_URL}\" ]; then\n unset PIP_INDEX_URL\nfi\n\nkonflux-build-cli prefetch-dependencies\n", | |
| "environment": { | |
| "container": "prefetch-dependencies", | |
| "image": "oci://quay.io/konflux-ci/hermeto@sha256:887e4fabf1707fc4018275b53fe89c0962ccb61d80d695cce49127096792edae" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "create", | |
| "--store", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25.prefetch", | |
| "/tekton/results/SOURCE_ARTIFACT=/var/workdir/source", | |
| "/tekton/results/CACHI2_ARTIFACT=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "create-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "prefetch-dependencies", | |
| "clone-repository", | |
| "rhoai-init" | |
| ], | |
| "finishedOn": "2026-09-08T21:24:50Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| "entryPoint": "buildah-remote-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/80cee560-7c4c-49f4-9ea2-ee43519e59e7", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-eb4ab01f52fcc444-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "build.appstudio.redhat.com/build_type": "docker", | |
| "build.appstudio.redhat.com/target-platform": "linux-x86_64", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-images", | |
| "tekton.dev/task": "buildah-remote-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ACTIVATION_KEY": "custom-activation-key", | |
| "ADDITIONAL_BASE_IMAGES": [], | |
| "ADDITIONAL_SECRET": "does-not-exist", | |
| "ADD_CAPABILITIES": "", | |
| "ALLOW_CROSS_PLATFORM_IMAGES": "false", | |
| "ANNOTATIONS": [], | |
| "ANNOTATIONS_FILE": "", | |
| "BUILDAH_FORMAT": "docker", | |
| "BUILD_ARGS": [], | |
| "BUILD_ARGS_FILE": "", | |
| "BUILD_TIMESTAMP": "", | |
| "CACHI2_ARTIFACT": "", | |
| "COMMIT_SHA": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "CONTEXT": ".", | |
| "CONTEXTUALIZE_SBOM": "false", | |
| "DOCKERFILE": "Dockerfiles/agent.Dockerfile.konflux", | |
| "ENTITLEMENT_SECRET": "etc-pki-entitlement", | |
| "ENV_VARS": [], | |
| "HERMETIC": "false", | |
| "HTTP_PROXY": "", | |
| "ICM_KEEP_COMPAT_LOCATION": "true", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGE_APPEND_PLATFORM": "true", | |
| "IMAGE_EXPIRES_AFTER": "", | |
| "INHERIT_BASE_IMAGE_LABELS": "true", | |
| "LABELS": [ | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]" | |
| ], | |
| "LOG_LEVEL": "info", | |
| "NO_PROXY": "", | |
| "OMIT_HISTORY": "false", | |
| "PLATFORM": "linux/x86_64", | |
| "PREFETCH_INPUT": "", | |
| "PRIVILEGED_NESTED": "false", | |
| "PROXY_CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "PROXY_CA_TRUST_CONFIG_MAP_NAME": "caching-ca-bundle", | |
| "REWRITE_TIMESTAMP": "false", | |
| "RHSM_MOUNT_CA_CERTS": "auto", | |
| "SBOM_SKIP_VALIDATION": "true", | |
| "SBOM_SOURCE_SCAN_ENABLED": "true", | |
| "SBOM_SYFT_SELECT_CATALOGERS": "", | |
| "SBOM_TYPE": "spdx", | |
| "SKIP_INJECTIONS": "false", | |
| "SKIP_SBOM_GENERATION": "false", | |
| "SKIP_UNUSED_STAGES": "true", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "SOURCE_DATE_EPOCH": "", | |
| "SOURCE_URL": "", | |
| "SQUASH": "false", | |
| "STORAGE_DRIVER": "overlay", | |
| "TARGET_STAGE": "", | |
| "TLSVERIFY": "true", | |
| "WORKINGDIR_MOUNT": "", | |
| "YUM_REPOS_D_FETCHED": "fetched.repos.d", | |
| "YUM_REPOS_D_SRC": "repos.d", | |
| "YUM_REPOS_D_TARGET": "/etc/yum.repos.d", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-images", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "buildah-remote-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b" | |
| }, | |
| { | |
| "name": "IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64" | |
| }, | |
| { | |
| "name": "SBOM_BLOB_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:e388c05e79f53dc430eba6a7676e8cbff0b9ce15edcd6986559f04a84fadf8f9" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:49Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source", | |
| "=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--build-args", | |
| "--envs", | |
| "--labels", | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]", | |
| "--annotations" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--additional-base-images" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n", | |
| "environment": { | |
| "container": "prepare-sboms", | |
| "image": "oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n", | |
| "environment": { | |
| "container": "upload-sbom", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "prefetch-dependencies", | |
| "clone-repository", | |
| "rhoai-init" | |
| ], | |
| "finishedOn": "2026-09-08T21:26:07Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| "entryPoint": "buildah-remote-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ad5f5889-c13a-481e-8ab5-b8fdd0e29042", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-569f583cd9c685eb-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "build.appstudio.redhat.com/build_type": "docker", | |
| "build.appstudio.redhat.com/target-platform": "linux-ppc64le", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-images", | |
| "tekton.dev/task": "buildah-remote-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ACTIVATION_KEY": "custom-activation-key", | |
| "ADDITIONAL_BASE_IMAGES": [], | |
| "ADDITIONAL_SECRET": "does-not-exist", | |
| "ADD_CAPABILITIES": "", | |
| "ALLOW_CROSS_PLATFORM_IMAGES": "false", | |
| "ANNOTATIONS": [], | |
| "ANNOTATIONS_FILE": "", | |
| "BUILDAH_FORMAT": "docker", | |
| "BUILD_ARGS": [], | |
| "BUILD_ARGS_FILE": "", | |
| "BUILD_TIMESTAMP": "", | |
| "CACHI2_ARTIFACT": "", | |
| "COMMIT_SHA": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "CONTEXT": ".", | |
| "CONTEXTUALIZE_SBOM": "false", | |
| "DOCKERFILE": "Dockerfiles/agent.Dockerfile.konflux", | |
| "ENTITLEMENT_SECRET": "etc-pki-entitlement", | |
| "ENV_VARS": [], | |
| "HERMETIC": "false", | |
| "HTTP_PROXY": "", | |
| "ICM_KEEP_COMPAT_LOCATION": "true", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGE_APPEND_PLATFORM": "true", | |
| "IMAGE_EXPIRES_AFTER": "", | |
| "INHERIT_BASE_IMAGE_LABELS": "true", | |
| "LABELS": [ | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]" | |
| ], | |
| "LOG_LEVEL": "info", | |
| "NO_PROXY": "", | |
| "OMIT_HISTORY": "false", | |
| "PLATFORM": "linux/ppc64le", | |
| "PREFETCH_INPUT": "", | |
| "PRIVILEGED_NESTED": "false", | |
| "PROXY_CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "PROXY_CA_TRUST_CONFIG_MAP_NAME": "caching-ca-bundle", | |
| "REWRITE_TIMESTAMP": "false", | |
| "RHSM_MOUNT_CA_CERTS": "auto", | |
| "SBOM_SKIP_VALIDATION": "true", | |
| "SBOM_SOURCE_SCAN_ENABLED": "true", | |
| "SBOM_SYFT_SELECT_CATALOGERS": "", | |
| "SBOM_TYPE": "spdx", | |
| "SKIP_INJECTIONS": "false", | |
| "SKIP_SBOM_GENERATION": "false", | |
| "SKIP_UNUSED_STAGES": "true", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "SOURCE_DATE_EPOCH": "", | |
| "SOURCE_URL": "", | |
| "SQUASH": "false", | |
| "STORAGE_DRIVER": "overlay", | |
| "TARGET_STAGE": "", | |
| "TLSVERIFY": "true", | |
| "WORKINGDIR_MOUNT": "", | |
| "YUM_REPOS_D_FETCHED": "fetched.repos.d", | |
| "YUM_REPOS_D_SRC": "repos.d", | |
| "YUM_REPOS_D_TARGET": "/etc/yum.repos.d", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-images", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "buildah-remote-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75" | |
| }, | |
| { | |
| "name": "IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le" | |
| }, | |
| { | |
| "name": "SBOM_BLOB_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:c51e531b2d7512e3b085484bab77b06c07d3b40fbbb7fee1a562a7166e841b0b" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:49Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source", | |
| "=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--build-args", | |
| "--envs", | |
| "--labels", | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]", | |
| "--annotations" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--additional-base-images" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n", | |
| "environment": { | |
| "container": "prepare-sboms", | |
| "image": "oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n", | |
| "environment": { | |
| "container": "upload-sbom", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "prefetch-dependencies", | |
| "clone-repository", | |
| "rhoai-init" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:04Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| "entryPoint": "buildah-remote-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/7bac666d-84dc-4f8f-839f-86e62cefb9d3", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-3ca78b5f78e8886d-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "build.appstudio.redhat.com/build_type": "docker", | |
| "build.appstudio.redhat.com/target-platform": "linux-s390x", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-images", | |
| "tekton.dev/task": "buildah-remote-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ACTIVATION_KEY": "custom-activation-key", | |
| "ADDITIONAL_BASE_IMAGES": [], | |
| "ADDITIONAL_SECRET": "does-not-exist", | |
| "ADD_CAPABILITIES": "", | |
| "ALLOW_CROSS_PLATFORM_IMAGES": "false", | |
| "ANNOTATIONS": [], | |
| "ANNOTATIONS_FILE": "", | |
| "BUILDAH_FORMAT": "docker", | |
| "BUILD_ARGS": [], | |
| "BUILD_ARGS_FILE": "", | |
| "BUILD_TIMESTAMP": "", | |
| "CACHI2_ARTIFACT": "", | |
| "COMMIT_SHA": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "CONTEXT": ".", | |
| "CONTEXTUALIZE_SBOM": "false", | |
| "DOCKERFILE": "Dockerfiles/agent.Dockerfile.konflux", | |
| "ENTITLEMENT_SECRET": "etc-pki-entitlement", | |
| "ENV_VARS": [], | |
| "HERMETIC": "false", | |
| "HTTP_PROXY": "", | |
| "ICM_KEEP_COMPAT_LOCATION": "true", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGE_APPEND_PLATFORM": "true", | |
| "IMAGE_EXPIRES_AFTER": "", | |
| "INHERIT_BASE_IMAGE_LABELS": "true", | |
| "LABELS": [ | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]" | |
| ], | |
| "LOG_LEVEL": "info", | |
| "NO_PROXY": "", | |
| "OMIT_HISTORY": "false", | |
| "PLATFORM": "linux/s390x", | |
| "PREFETCH_INPUT": "", | |
| "PRIVILEGED_NESTED": "false", | |
| "PROXY_CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "PROXY_CA_TRUST_CONFIG_MAP_NAME": "caching-ca-bundle", | |
| "REWRITE_TIMESTAMP": "false", | |
| "RHSM_MOUNT_CA_CERTS": "auto", | |
| "SBOM_SKIP_VALIDATION": "true", | |
| "SBOM_SOURCE_SCAN_ENABLED": "true", | |
| "SBOM_SYFT_SELECT_CATALOGERS": "", | |
| "SBOM_TYPE": "spdx", | |
| "SKIP_INJECTIONS": "false", | |
| "SKIP_SBOM_GENERATION": "false", | |
| "SKIP_UNUSED_STAGES": "true", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "SOURCE_DATE_EPOCH": "", | |
| "SOURCE_URL": "", | |
| "SQUASH": "false", | |
| "STORAGE_DRIVER": "overlay", | |
| "TARGET_STAGE": "", | |
| "TLSVERIFY": "true", | |
| "WORKINGDIR_MOUNT": "", | |
| "YUM_REPOS_D_FETCHED": "fetched.repos.d", | |
| "YUM_REPOS_D_SRC": "repos.d", | |
| "YUM_REPOS_D_TARGET": "/etc/yum.repos.d", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-images", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "buildah-remote-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f" | |
| }, | |
| { | |
| "name": "IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x" | |
| }, | |
| { | |
| "name": "SBOM_BLOB_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:381d10a089a3dcfb625f58c3ff6f2a98bb4a3bca37f3fcd5800ae730d075ec7b" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:49Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source", | |
| "=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--build-args", | |
| "--envs", | |
| "--labels", | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]", | |
| "--annotations" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--additional-base-images" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n", | |
| "environment": { | |
| "container": "prepare-sboms", | |
| "image": "oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n", | |
| "environment": { | |
| "container": "upload-sbom", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "prefetch-dependencies", | |
| "clone-repository", | |
| "rhoai-init" | |
| ], | |
| "finishedOn": "2026-09-08T21:25:59Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| "entryPoint": "buildah-remote-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/allocation-start-time": "1788902512", | |
| "build.appstudio.redhat.com/cloud-address": "10.29.77.101", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/52195ac0-10ef-431f-b492-c48b518ad346", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-1bf796cedfd19738-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "build.appstudio.redhat.com/build_type": "docker", | |
| "build.appstudio.redhat.com/cloud-dynamic-platform": "linux-m2xlarge-arm64", | |
| "build.appstudio.redhat.com/target-platform": "linux-m2xlarge-arm64", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-images", | |
| "tekton.dev/task": "buildah-remote-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ACTIVATION_KEY": "custom-activation-key", | |
| "ADDITIONAL_BASE_IMAGES": [], | |
| "ADDITIONAL_SECRET": "does-not-exist", | |
| "ADD_CAPABILITIES": "", | |
| "ALLOW_CROSS_PLATFORM_IMAGES": "false", | |
| "ANNOTATIONS": [], | |
| "ANNOTATIONS_FILE": "", | |
| "BUILDAH_FORMAT": "docker", | |
| "BUILD_ARGS": [], | |
| "BUILD_ARGS_FILE": "", | |
| "BUILD_TIMESTAMP": "", | |
| "CACHI2_ARTIFACT": "", | |
| "COMMIT_SHA": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "CONTEXT": ".", | |
| "CONTEXTUALIZE_SBOM": "false", | |
| "DOCKERFILE": "Dockerfiles/agent.Dockerfile.konflux", | |
| "ENTITLEMENT_SECRET": "etc-pki-entitlement", | |
| "ENV_VARS": [], | |
| "HERMETIC": "false", | |
| "HTTP_PROXY": "", | |
| "ICM_KEEP_COMPAT_LOCATION": "true", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGE_APPEND_PLATFORM": "true", | |
| "IMAGE_EXPIRES_AFTER": "", | |
| "INHERIT_BASE_IMAGE_LABELS": "true", | |
| "LABELS": [ | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]" | |
| ], | |
| "LOG_LEVEL": "info", | |
| "NO_PROXY": "", | |
| "OMIT_HISTORY": "false", | |
| "PLATFORM": "linux-m2xlarge/arm64", | |
| "PREFETCH_INPUT": "", | |
| "PRIVILEGED_NESTED": "false", | |
| "PROXY_CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "PROXY_CA_TRUST_CONFIG_MAP_NAME": "caching-ca-bundle", | |
| "REWRITE_TIMESTAMP": "false", | |
| "RHSM_MOUNT_CA_CERTS": "auto", | |
| "SBOM_SKIP_VALIDATION": "true", | |
| "SBOM_SOURCE_SCAN_ENABLED": "true", | |
| "SBOM_SYFT_SELECT_CATALOGERS": "", | |
| "SBOM_TYPE": "spdx", | |
| "SKIP_INJECTIONS": "false", | |
| "SKIP_SBOM_GENERATION": "false", | |
| "SKIP_UNUSED_STAGES": "true", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "SOURCE_DATE_EPOCH": "", | |
| "SOURCE_URL": "", | |
| "SQUASH": "false", | |
| "STORAGE_DRIVER": "overlay", | |
| "TARGET_STAGE": "", | |
| "TLSVERIFY": "true", | |
| "WORKINGDIR_MOUNT": "", | |
| "YUM_REPOS_D_FETCHED": "fetched.repos.d", | |
| "YUM_REPOS_D_SRC": "repos.d", | |
| "YUM_REPOS_D_TARGET": "/etc/yum.repos.d", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-images", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "buildah-remote-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta:0.12.1@sha256:ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| }, | |
| { | |
| "name": "IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64" | |
| }, | |
| { | |
| "name": "SBOM_BLOB_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:bc3679d864ec2aa6153470406486c4eed14351b4dc6e5c6931a19a6c8607c4eb" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:21:50Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source", | |
| "=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--build-args", | |
| "--envs", | |
| "--labels", | |
| "version=v2.25.11", | |
| "url=https://github.com/red-hat-data-services/kserve", | |
| "release=1788902446", | |
| "git.url=https://github.com/red-hat-data-services/kserve", | |
| "git.commit=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "cpe=", | |
| "name=rhoai/odh-kserve-agent-rhel9", | |
| "io.openshift.tags=odh-kserve-agent", | |
| "com.redhat.component=odh-kserve-agent-rhel9", | |
| "summary=ODH Kserve Agent", | |
| "description=ODH Kserve Agent", | |
| "io.k8s.display-name=ODH Kserve Agent", | |
| "io.k8s.description=ODH Kserve Agent", | |
| "vendor=Red Hat, Inc.", | |
| "maintainer=RHOAI DevTestOps Team [openshift-ai-devtestops@redhat.com]", | |
| "--annotations" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -e\nset -o verbose\n\necho \"[$(date --utc -Ins)] Prepare connection\"\n\nmkdir -p ~/.ssh\nif [ -e \"/ssh/error\" ]; then\n #no server could be provisioned\n cat /ssh/error\n exit 1\nfi\n\nSSH_HOST=$(cat /ssh/host)\nexport SSH_HOST\n\nif [ \"$SSH_HOST\" == \"localhost\" ] ; then\n IS_LOCALHOST=true\n echo \"Localhost detected; running build in cluster\"\nelif [ -e \"/ssh/otp\" ]; then\n if ! curl --fail --cacert /ssh/otp-ca -XPOST -d @/ssh/otp \"$(cat /ssh/otp-server)\" >~/.ssh/id_rsa; then\n echo \"Failed to retrieve SSH key from the OTP server. This can happen when the PipelineRun retry option re-runs a task whose one-time credential was already consumed. Please, start a new build, and if problem persists, please report it as an MPC bug.\" >&2\n exit 1\n fi\n echo \"\" >> ~/.ssh/id_rsa\nelse\n cp /ssh/id_rsa ~/.ssh\nfi\n\nmkdir -p scripts\n\nif ! [[ $IS_LOCALHOST ]]; then\n echo \"[$(date --utc -Ins)] Setup VM\"\n\n if [[ \"$BUILDAH_HTTP_PROXY\" =~ .+\\.cluster\\.local ]]; then\n echo \"[$(date --utc -Ins)] Ignoring cluster local proxy for remote build\"\n unset BUILDAH_HTTP_PROXY BUILDAH_NO_PROXY\n fi\n\n chmod 0400 ~/.ssh/id_rsa\n BUILD_DIR=$(cat /ssh/user-dir)\n export BUILD_DIR\n export SSH_ARGS=\"-o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=10\"\n echo \"$BUILD_DIR\"\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/workspaces\" \"${BUILD_DIR@Q}/scripts\" \"${BUILD_DIR@Q}/volumes\"\n\n PORT_FORWARD=\"\"\n PODMAN_PORT_FORWARD=\"\"\n if [ -n \"$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR\" ] ; then\n PORT_FORWARD=\" -L 80:$JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR:80\"\n PODMAN_PORT_FORWARD=\" -e JVM_BUILD_WORKSPACE_ARTIFACT_CACHE_PORT_80_TCP_ADDR=localhost\"\n fi\n\n echo \"[$(date --utc -Ins)] Rsync data\"\n\n rsync --timeout=300 -razW /shared/ \"$SSH_HOST:$BUILD_DIR/volumes/shared/\"\n rsync --timeout=300 -razW /var/workdir/ \"$SSH_HOST:$BUILD_DIR/volumes/workdir/\"\n rsync --timeout=300 -razW /entitlement/ \"$SSH_HOST:$BUILD_DIR/volumes/etc-pki-entitlement/\"\n rsync --timeout=300 -razW /activation-key/ \"$SSH_HOST:$BUILD_DIR/volumes/activation-key/\"\n rsync --timeout=300 -razW /additional-secret/ \"$SSH_HOST:$BUILD_DIR/volumes/additional-secret/\"\n rsync --timeout=300 -razW /mnt/trusted-ca/ \"$SSH_HOST:$BUILD_DIR/volumes/trusted-ca/\"\n rsync --timeout=300 -razW /mnt/proxy-ca-bundle/ \"$SSH_HOST:$BUILD_DIR/volumes/proxy-ca-bundle/\"\n rsync --timeout=300 -razW \"$HOME/.docker/\" \"$SSH_HOST:$BUILD_DIR/.docker/\"\n rsync --timeout=300 -razW \"/tekton/results/\" \"$SSH_HOST:$BUILD_DIR/results/\"\nfi\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\ncat >scripts/script-build.sh <<'REMOTESSHEOF'\n#!/bin/bash\nset -euo pipefail\ncd /var/workdir\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nproxy_ca_bundle=/mnt/proxy-ca-bundle/ca-bundle.crt\nupdate_ca_trust=false\n\nif [ -f \"$ca_bundle\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors/ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ -f \"$proxy_ca_bundle\" ] && [ -n \"${BUILDAH_HTTP_PROXY}\" ]; then\n echo \"[$(date --utc -Ins)] Using mounted proxy CA bundle: $proxy_ca_bundle\"\n cp -vf $proxy_ca_bundle /etc/pki/ca-trust/source/anchors/proxy-ca-bundle.crt\n update_ca_trust=true\nfi\n\nif [ \"$update_ca_trust\" = \"true\" ]; then\n echo \"[$(date --utc -Ins)] Update CA trust\"\n update-ca-trust\nfi\n\necho \"[$(date --utc -Ins)] Prepare system (architecture: $(uname -m))\"\n\n# Fixing group permission on /var/lib/containers\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\n# Delete policy settings for Red Hat registries to disable signature verification.\n# TODO: don't do this?\ncontainer_policy=$(\n jq '.transports |= (\n del(.docker.[\"registry.access.redhat.com\"]) |\n del(.docker.[\"registry.redhat.io\"]) |\n if (.docker == {}) then del(.docker) else . end\n )' /etc/containers/policy.json\n)\necho \"Effective container policy:\"\nprintf '%s\\n' \"$container_policy\" | tee /etc/containers/policy.json\n\n# Setting new namespace to run buildah - 2^32-2\necho 'root:1:4294967294' | tee -a /etc/subuid >>/etc/subgid\n\necho \"[$(date --utc -Ins)] Run the build\"\n\nif [ -e \"$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$CONTEXT/$DOCKERFILE\"\nelif [ -e \"$SOURCE_CODE_DIR/$DOCKERFILE\" ]; then\n dockerfile_path=\"$(pwd)/$SOURCE_CODE_DIR/$DOCKERFILE\"\nelse\n echo \"Cannot find Dockerfile $DOCKERFILE\"\n exit 1\nfi\n\nif [ -n \"${ANNOTATIONS_FILE}\" ] && [ -f \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\" ]; then\n ANNOTATIONS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${ANNOTATIONS_FILE}\")\nfi\n\nif [ -n \"${BUILD_ARGS_FILE}\" ]; then\n BUILD_ARGS_FILE=$(realpath \"${SOURCE_CODE_DIR}/${BUILD_ARGS_FILE}\")\nfi\n\n# Necessary for newer version of buildah if the host system does not contain up to date version of container-selinux\n# TODO remove the option once all hosts were updated\nsecurity_args=(--security-opts unmask=/proc/interrupts)\n\nif [ \"${PRIVILEGED_NESTED}\" == \"true\" ]; then\n security_args+=(--security-opts label=disable)\n security_args+=(--cap-add all)\n security_args+=(--devices /dev/fuse)\nfi\nif [ -n \"${ADD_CAPABILITIES}\" ]; then\n security_args+=(--cap-add \"${ADD_CAPABILITIES}\")\nfi\n\nif [ -f \"/var/workdir/cachi2/cachi2.env\" ]; then\n prefetch_dir=\"/var/workdir/cachi2\"\n # KBC defaults to ${prefetch_dir}/copy-*\n # Copy to a sibling dir instead in case we don't have write permissions to the prefetch_dir.\n # It's still on the same filesystem, so copying via reflinks should be possible.\n prefetch_dir_copy=\"/var/workdir/prefetch-copy\"\n # Save the build machine's architecture to pass to Mobster later\n uname -m >/shared/prefetch-arch\nelse\n prefetch_dir=\"\"\n prefetch_dir_copy=\"\"\nfi\n\nyum_repos_d_sources=()\nif [ -d \"${YUM_REPOS_D_FETCHED}\" ]; then\n yum_repos_d_sources+=(\"${YUM_REPOS_D_FETCHED}\")\nfi\nif [ -d \"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\" ]; then\n yum_repos_d_sources+=(\"${SOURCE_CODE_DIR}/${YUM_REPOS_D_SRC}\")\nfi\n\n# 0. if hermetic=true, skip all subscription related stuff\n# 1. do not enable activation key and entitlement at same time. If both are provided, prefer activation key.\n# 2. Activation-keys will be used when the key 'org' exists in the activation key secret.\n# 3. try to pre-register and mount files to the correct location so that users do no need to modify Dockerfiles.\n# 4. If the Dockerfile contains the string \"subcription-manager register\", add the activation-keys volume\n# to buildah but don't pre-register for backwards compatibility. Mount an empty directory on\n# to \"/etc/pki/entitlement\" to prevent certificates from being included\nrhsm_args=()\nif [ \"${HERMETIC}\" != \"true\" ]; then\n if [ -e /activation-key/org ]; then\n rhsm_args+=(--rhsm-activation-key=/activation-key/activationkey\n --rhsm-org=/activation-key/org\n --rhsm-activation-mount=/activation-key)\n\n if ! grep -E \"^[^#]*subscription-manager.[^#]*register\" \"$dockerfile_path\"; then\n # user is not running registration in the Containerfile: pre-register.\n rhsm_args+=(--rhsm-activation-preregister)\n fi\n elif find /entitlement -name \"*.pem\" >/dev/null; then\n rhsm_args+=(--rhsm-entitlements=/entitlement)\n fi\nfi\nif [ \"${RHSM_MOUNT_CA_CERTS}\" != \"auto\" ]; then\n rhsm_args+=(--rhsm-mount-ca-certs=\"$RHSM_MOUNT_CA_CERTS\")\nfi\n\nsbom_args=()\nif [[ \"$SKIP_SBOM_GENERATION\" != true ]]; then\n sbom_args+=(\n --sbom-format \"$SBOM_TYPE\"\n --syft-select-catalogers \"$SBOM_SYFT_SELECT_CATALOGERS\"\n --syft-image-output /shared/sbom-image.json\n )\n if [[ \"${HERMETIC}\" == \"false\" && \"${SBOM_SOURCE_SCAN_ENABLED}\" == \"true\" ]]; then\n sbom_args+=(--syft-source-output /shared/sbom-source.json)\n fi\n if [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ]; then\n sbom_args+=(\n --builder-metadata-output=/shared/builder-metadata.json\n --buildprobe-output=/shared/buildprobe-metadata.yaml\n )\n fi\nfi\n\n# Prevent ShellCheck from giving a warning because 'image' is defined and 'IMAGE' is not.\ndeclare IMAGE\n\ncmd=(\n konflux-build-cli image build\n -f \"$dockerfile_path\" -t \"$IMAGE\" --source \"$SOURCE_CODE_DIR\" --context \"$CONTEXT\"\n # use the taskRun name as a unique tag to prevent the $IMAGE from being garbage collected\n # if another build pushes to the same $IMAGE output ref\n --additional-tags \"$TASKRUN_NAME\"\n --push\n --push-format \"$PUSH_FORMAT\"\n --secret-dirs \"src=/additional-secret,name=$ADDITIONAL_SECRET,optional=true\"\n --workdir-mount \"$WORKINGDIR_MOUNT\"\n --target \"$TARGET_STAGE\"\n --inherit-labels=\"$INHERIT_BASE_IMAGE_LABELS\"\n --source-date-epoch \"$BUILDAH_SOURCE_DATE_EPOCH\"\n --rewrite-timestamp=\"$BUILDAH_REWRITE_TIMESTAMP\"\n --squash=\"$SQUASH\"\n --omit-history=\"$BUILDAH_OMIT_HISTORY\"\n --image-source \"$SOURCE_URL\"\n --image-revision \"$COMMIT_SHA\"\n --quay-image-expires-after \"$IMAGE_EXPIRES_AFTER\"\n --build-args-file \"$BUILD_ARGS_FILE\"\n --annotations-file \"$ANNOTATIONS_FILE\"\n --legacy-build-timestamp \"$BUILD_TIMESTAMP\"\n --add-legacy-labels\n --include-legacy-buildinfo-path=\"$ICM_KEEP_COMPAT_LOCATION\"\n --skip-injections=\"$SKIP_INJECTIONS\"\n --skip-unused-stages=\"$SKIP_UNUSED_STAGES\"\n --hermetic=\"$HERMETIC\"\n --image-pull-proxy \"$BUILDAH_HTTP_PROXY\"\n --image-pull-noproxy \"$BUILDAH_NO_PROXY\"\n --yum-repos-d-sources \"${yum_repos_d_sources[@]}\"\n --yum-repos-d-target \"$YUM_REPOS_D_TARGET\"\n --prefetch-dir \"$prefetch_dir\"\n --prefetch-dir-copy \"$prefetch_dir_copy\"\n --prefetch-env-mount /cachi2/cachi2.env\n --prefetch-output-mount /cachi2/output\n \"${security_args[@]}\"\n \"${rhsm_args[@]}\"\n \"${sbom_args[@]}\"\n --containerfile-json-output /shared/parsed_dockerfile.json\n --resolved-base-images-output /shared/base_images_digests\n --no-cache\n --ulimits nofile=4096:4096\n --src-tls-verify=\"$TLSVERIFY\"\n --dest-tls-verify=\"$TLSVERIFY\"\n --allow-cross-platform-images=\"$ALLOW_CROSS_PLATFORM_IMAGES\"\n \"$@\" # --annotations, --labels, --envs, --build-args\n)\n\necho \"[$(date --utc -Ins)] $(printf '%q ' \"${cmd[@]}\")\"\n\n\"${cmd[@]}\" | tee /tmp/results.json\n\njq -j .image_url /tmp/results.json >\"/tekton/results/IMAGE_URL\"\njq -j .digest /tmp/results.json >\"/tekton/results/IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.digest)\"' /tmp/results.json >\"/tekton/results/IMAGE_REF\"\n\necho\necho \"[$(date --utc -Ins)] Add metadata\"\n\n# Save the SBOM produced in prefetch so it can be merged into the final SBOM later\nif [ -f \"${prefetch_dir}/output/bom.json\" ]; then\n echo \"Making copy of sbom-prefetch.json\"\n cp \"${prefetch_dir}/output/bom.json\" /shared/sbom-prefetch.json\nfi\n\necho \"[$(date --utc -Ins)] End build\"\n\nREMOTESSHEOF\nchmod +x scripts/script-build.sh\n\nPODMAN_NVIDIA_ARGS=()\nif [[ \"$PLATFORM\" == \"linux-g\"* ]]; then\n PODMAN_NVIDIA_ARGS+=(\"--device=nvidia.com/gpu=all\" \"--security-opt=label=disable\")\nfi\n\nif ! [[ $IS_LOCALHOST ]]; then\n PRIVILEGED_NESTED_FLAGS=()\n if [[ \"${PRIVILEGED_NESTED}\" == \"true\" ]]; then\n # This is a workaround for building bootc images because the cache filesystem (/var/tmp/ on the host) must be a real filesystem that supports setting SELinux security attributes.\n # https://github.com/coreos/rpm-ostree/discussions/4648\n # shellcheck disable=SC2086\n ssh $SSH_ARGS \"$SSH_HOST\" mkdir -p \"${BUILD_DIR@Q}/var/tmp\"\n PRIVILEGED_NESTED_FLAGS=(--privileged --mount \"type=bind,source=$BUILD_DIR/var/tmp,target=/var/tmp,relabel=shared\")\n fi\n rsync --timeout=300 -ra scripts \"$SSH_HOST:$BUILD_DIR\"\n echo \"[$(date --utc -Ins)] Build via ssh\"\n # shellcheck disable=SC2086\n # Please note: all variables below the first ssh line must be quoted with ${var@Q}!\n # See https://stackoverflow.com/questions/6592376/prevent-ssh-from-breaking-up-shell-script-parameters\n ssh $SSH_ARGS \"$SSH_HOST\" $PORT_FORWARD podman run $PODMAN_PORT_FORWARD \\\n --tmpfs /run/secrets \\\n -e ADDITIONAL_SECRET=\"${ADDITIONAL_SECRET@Q}\" \\\n -e ADD_CAPABILITIES=\"${ADD_CAPABILITIES@Q}\" \\\n -e ALLOW_CROSS_PLATFORM_IMAGES=\"${ALLOW_CROSS_PLATFORM_IMAGES@Q}\" \\\n -e ANNOTATIONS_FILE=\"${ANNOTATIONS_FILE@Q}\" \\\n -e BUILD_ARGS_FILE=\"${BUILD_ARGS_FILE@Q}\" \\\n -e BUILD_TIMESTAMP=\"${BUILD_TIMESTAMP@Q}\" \\\n -e CONTEXT=\"${CONTEXT@Q}\" \\\n -e CONTEXTUALIZE_SBOM=\"${CONTEXTUALIZE_SBOM@Q}\" \\\n -e HERMETIC=\"${HERMETIC@Q}\" \\\n -e IMAGE=\"${IMAGE@Q}\" \\\n -e IMAGE_EXPIRES_AFTER=\"${IMAGE_EXPIRES_AFTER@Q}\" \\\n -e INHERIT_BASE_IMAGE_LABELS=\"${INHERIT_BASE_IMAGE_LABELS@Q}\" \\\n -e KBC_LOG_LEVEL=\"${KBC_LOG_LEVEL@Q}\" \\\n -e PRIVILEGED_NESTED=\"${PRIVILEGED_NESTED@Q}\" \\\n -e PUSH_FORMAT=\"${PUSH_FORMAT@Q}\" \\\n -e RHSM_MOUNT_CA_CERTS=\"${RHSM_MOUNT_CA_CERTS@Q}\" \\\n -e SBOM_SKIP_VALIDATION=\"${SBOM_SKIP_VALIDATION@Q}\" \\\n -e SBOM_SOURCE_SCAN_ENABLED=\"${SBOM_SOURCE_SCAN_ENABLED@Q}\" \\\n -e SBOM_SYFT_SELECT_CATALOGERS=\"${SBOM_SYFT_SELECT_CATALOGERS@Q}\" \\\n -e SBOM_TYPE=\"${SBOM_TYPE@Q}\" \\\n -e SKIP_INJECTIONS=\"${SKIP_INJECTIONS@Q}\" \\\n -e SKIP_SBOM_GENERATION=\"${SKIP_SBOM_GENERATION@Q}\" \\\n -e SKIP_UNUSED_STAGES=\"${SKIP_UNUSED_STAGES@Q}\" \\\n -e SOURCE_CODE_DIR=\"${SOURCE_CODE_DIR@Q}\" \\\n -e SQUASH=\"${SQUASH@Q}\" \\\n -e STORAGE_DRIVER=\"${STORAGE_DRIVER@Q}\" \\\n -e TARGET_STAGE=\"${TARGET_STAGE@Q}\" \\\n -e TASKRUN_NAME=\"${TASKRUN_NAME@Q}\" \\\n -e TLSVERIFY=\"${TLSVERIFY@Q}\" \\\n -e WORKINGDIR_MOUNT=\"${WORKINGDIR_MOUNT@Q}\" \\\n -e YUM_REPOS_D_FETCHED=\"${YUM_REPOS_D_FETCHED@Q}\" \\\n -e YUM_REPOS_D_SRC=\"${YUM_REPOS_D_SRC@Q}\" \\\n -e YUM_REPOS_D_TARGET=\"${YUM_REPOS_D_TARGET@Q}\" \\\n -e HOME=\"${HOME@Q}\" \\\n -e COMMIT_SHA=\"${COMMIT_SHA@Q}\" \\\n -e SOURCE_URL=\"${SOURCE_URL@Q}\" \\\n -e DOCKERFILE=\"${DOCKERFILE@Q}\" \\\n -e BUILDAH_HTTP_PROXY=\"${BUILDAH_HTTP_PROXY@Q}\" \\\n -e BUILDAH_NO_PROXY=\"${BUILDAH_NO_PROXY@Q}\" \\\n -e ICM_KEEP_COMPAT_LOCATION=\"${ICM_KEEP_COMPAT_LOCATION@Q}\" \\\n -e BUILDAH_OMIT_HISTORY=\"${BUILDAH_OMIT_HISTORY@Q}\" \\\n -e BUILDAH_SOURCE_DATE_EPOCH=\"${BUILDAH_SOURCE_DATE_EPOCH@Q}\" \\\n -e BUILDAH_REWRITE_TIMESTAMP=\"${BUILDAH_REWRITE_TIMESTAMP@Q}\" \\\n -v \"${BUILD_DIR@Q}/volumes/shared:/shared:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/workdir:/var/workdir:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/etc-pki-entitlement:/entitlement:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/activation-key:/activation-key:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/additional-secret:/additional-secret:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/trusted-ca:/mnt/trusted-ca:Z\" \\\n -v \"${BUILD_DIR@Q}/volumes/proxy-ca-bundle:/mnt/proxy-ca-bundle:Z\" \\\n -v \"${BUILD_DIR@Q}/.docker/:/root/.docker:Z\" \\\n -v \"${BUILD_DIR@Q}/results/:/tekton/results:Z\" \\\n -v \"${BUILD_DIR@Q}/scripts:/scripts:Z\" \\\n -v /var/lib/containers \\\n \"${PRIVILEGED_NESTED_FLAGS[@]@Q}\" \\\n --user=0 \"${PODMAN_NVIDIA_ARGS[@]@Q}\" --rm --entrypoint='' \"${BUILDER_IMAGE@Q}\" /scripts/script-build.sh \"${@@Q}\"\n echo \"[$(date --utc -Ins)] Rsync back\"\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/volumes/shared/\" /shared/\n rsync --timeout=300 -razW --stats \"$SSH_HOST:$BUILD_DIR/results/\" \"/tekton/results/\"\nelse\n bash scripts/script-build.sh \"$@\"\nfi\necho \"Build on remote host $SSH_HOST finished\"\n\necho \"[$(date --utc -Ins)] Final touches\"\n\nbuildah images\necho \"[$(date --utc -Ins)] End remote\"", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--additional-base-images" | |
| ], | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\necho \"[$(date --utc -Ins)] Prepare SBOM\"\n\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM generation\"\n exit 0\nfi\n\n# Convert Tekton array params into Mobster params\nADDITIONAL_BASE_IMAGES=()\nwhile [[ $# -gt 0 ]]; do\n case $1 in\n --additional-base-images)\n shift\n while [[ $# -gt 0 && $1 != --* ]]; do\n ADDITIONAL_BASE_IMAGES+=(\"$1\")\n shift\n done\n ;;\n *)\n echo \"unexpected argument: $1\" >&2\n exit 2\n ;;\n esac\ndone\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\n\necho \"[$(date --utc -Ins)] Generate SBOM with mobster\"\n\nmobster_args=(\n generate\n --output sbom.json\n)\n\n# Validation is a flag for `generate`, not `oci-image`, so we need to\n# handle it before the oci-image arguments\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-image\n --from-syft /shared/sbom-image.json\n --image-pullspec \"$IMAGE_URL\"\n --image-digest \"$IMAGE_DIGEST\"\n --parsed-dockerfile-path \"/shared/parsed_dockerfile.json\"\n --base-image-digest-file \"/shared/base_images_digests\"\n)\n\n# Add metadata to the Mobster args if provided\nmetadata_path=\"/shared/buildprobe-metadata.yaml\"\nbuilder_metadata_path=\"/shared/builder-metadata.json\"\nif [ -f \"$metadata_path\" ]; then\n mobster_args+=(--metadata-path \"$metadata_path\")\nfi\nif [ -f \"$builder_metadata_path\" ]; then\n mobster_args+=(--build-metadata-path \"$builder_metadata_path\")\nfi\n\nif [ -f /shared/sbom-source.json ]; then\n mobster_args+=(--from-syft /shared/sbom-source.json)\nfi\n\nif [ -f /shared/sbom-prefetch.json ]; then\n mobster_args+=(--from-hermeto /shared/sbom-prefetch.json)\nfi\n\nif [ -n \"${TARGET_STAGE}\" ]; then\n mobster_args+=(--dockerfile-target \"${TARGET_STAGE}\")\nfi\n\nfor ADDITIONAL_BASE_IMAGE in \"${ADDITIONAL_BASE_IMAGES[@]}\"; do\n mobster_args+=(--additional-base-image \"$ADDITIONAL_BASE_IMAGE\")\ndone\n\nif [ \"${CONTEXTUALIZE_SBOM}\" == \"true\" ] && [ \"${HERMETIC}\" == \"false\" ]; then\n mobster_args+=(--contextualize)\nfi\n\nif [ -f \"/shared/prefetch-arch\" ]; then\n mobster_args+=(--arch \"$(cat /shared/prefetch-arch)\")\nfi\n\nmobster \"${mobster_args[@]}\"\n\necho \"[$(date --utc -Ins)] End prepare-sboms\"\n", | |
| "environment": { | |
| "container": "prepare-sboms", | |
| "image": "oci://quay.io/konflux-ci/mobster@sha256:3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -euo pipefail\nif [ \"${IMAGE_APPEND_PLATFORM}\" == \"true\" ]; then\n IMAGE=\"${IMAGE}-${PLATFORM//[^a-zA-Z0-9]/-}\"\n export IMAGE\nfi\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nIMAGE_REF=$(cat \"/tekton/results/IMAGE_REF\")\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_REF\" >/tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\n# --- SBOM upload ---\nif [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM push because SBOM generation is disabled\"\nelse\n echo \"[$(date --utc -Ins)] Upload SBOM\"\n echo \"Pushing sbom to registry\"\n if ! retry cosign attach sbom --sbom sbom.json --type \"$SBOM_TYPE\" \"$IMAGE_REF\"; then\n echo \"Failed to push sbom to registry\"\n exit 1\n fi\n\n # Remove tag from IMAGE while allowing registry to contain a port number.\n sbom_repo=\"${IMAGE%:*}\"\n sbom_digest=\"$(sha256sum sbom.json | cut -d' ' -f1)\"\n # The SBOM_BLOB_URL is created by `cosign attach sbom`.\n echo -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\nfi\n\necho\necho \"[$(date --utc -Ins)] Handle keyless signing if enabled\"\n\n# --- keyless signing ---\n# detect if keyless signing is required\nSIGNING_CONFIG='{}'\nKFLX_CONFIG_PATH='/tmp/konflux_config.json'\nif ! RETRY_STOP_IF_STDERR_MATCHES='configmaps \"cluster-config\" not found' retry kubectl get configmap cluster-config -n konflux-info -o json >\"${KFLX_CONFIG_PATH}\"; then\n echo \"Failed to fetch konflux cluster-config, default values will be used\" >&2\nelse\n SIGNING_CONFIG=\"$(cat ${KFLX_CONFIG_PATH})\"\nfi\n\n# configmap key -> variable name mapping\ndeclare -A SIGNING_KEY_MAP=(\n [defaultOIDCIssuer]=SIGSTORE_OIDC_ISSUER\n [rekorInternalUrl]=REKOR_URL\n [fulcioInternalUrl]=SIGSTORE_FULCIO_URL\n [tufInternalUrl]=TUF_URL\n)\n\n# fallback keys when internal URL is not available\ndeclare -A SIGNING_FALLBACK_MAP=(\n [rekorInternalUrl]=rekorExternalUrl\n [fulcioInternalUrl]=fulcioExternalUrl\n [tufInternalUrl]=tufExternalUrl\n)\n\nmissing=\"\"\nconfigured=0\nfor key in \"${!SIGNING_KEY_MAP[@]}\"; do\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${key} // empty\")\n if [ -z \"${val}\" ] && [ -n \"${SIGNING_FALLBACK_MAP[$key]+x}\" ]; then\n fallback_key=\"${SIGNING_FALLBACK_MAP[$key]}\"\n val=$(echo \"${SIGNING_CONFIG}\" | jq -r \".data.${fallback_key} // empty\")\n if [ -n \"${val}\" ]; then\n echo \"Using fallback ${fallback_key} instead of ${key}\"\n fi\n fi\n if [ -z \"${val}\" ]; then\n missing=\"${missing:+${missing}, }${key}\"\n else\n declare \"${SIGNING_KEY_MAP[$key]}=${val}\"\n configured=$((configured + 1))\n fi\ndone\n\nif [ \"${configured}\" -eq 0 ]; then\n echo \"Keyless signing is disabled (none of ${missing} are configured in the konflux-info/cluster-config configmap)\"\nelif [ \"${configured}\" -ne \"${#SIGNING_KEY_MAP[@]}\" ]; then\n echo \"ERROR: Incomplete keyless signing configuration in konflux-info/cluster-config configmap. Missing: ${missing}\" >&2\n exit 1\nelse\n echo \"Keyless signing is enabled\"\n\n echo \"Using Rekor URL: ${REKOR_URL}\"\n echo \"Using Fulcio URL: ${SIGSTORE_FULCIO_URL}\"\n echo \"Using OIDC issuer: ${SIGSTORE_OIDC_ISSUER}\"\n\n echo \"Initializing TUF root from ${TUF_URL}\"\n if ! retry cosign initialize --root \"${TUF_URL}/root.json\" --mirror \"${TUF_URL}\"; then\n echo \"Failed to initialize TUF root\" >&2\n exit 1\n fi\n\n # env var consumed by cosign\n SIGSTORE_ID_TOKEN=\"$(cat /var/run/sigstore/cosign/oidc-token)\"\n export SIGSTORE_ID_TOKEN\n\n echo \"[$(date --utc -Ins)] Sign image\"\n echo \"Signing image ${IMAGE_REF} using keyless signing\"\n if ! retry cosign sign -y \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign image\" >&2\n exit 1\n fi\n\n if [ \"${SKIP_SBOM_GENERATION}\" = \"true\" ]; then\n echo \"Skipping SBOM signing because SBOM generation is disabled\"\n else\n ATT_SBOM_TYPE=\"${SBOM_TYPE}\"\n if [ \"${ATT_SBOM_TYPE}\" = \"spdx\" ]; then\n # for format cossistency with cyclonedx format, we want to use spdxjson instad of spdx\n # spdx export data as rawstring, we want structured json as cyclonedx\n ATT_SBOM_TYPE=\"spdxjson\"\n fi\n\n echo \"[$(date --utc -Ins)] Sign SBOM\"\n echo \"Signing and attaching SBOM to ${IMAGE_REF} using keyless signing\"\n if ! retry cosign attest -y --type \"${ATT_SBOM_TYPE}\" --predicate sbom.json \\\n --use-signing-config=false \\\n --rekor-url=\"${REKOR_URL}\" \\\n --fulcio-url=\"${SIGSTORE_FULCIO_URL}\" \\\n --oidc-issuer=\"${SIGSTORE_OIDC_ISSUER}\" \\\n \"${IMAGE_REF}\"; then\n echo \"Failed to sign SBOM\" >&2\n exit 1\n fi\n fi\nfi\n\necho\necho \"[$(date --utc -Ins)] End upload-sbom\"\n", | |
| "environment": { | |
| "container": "upload-sbom", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-images" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:27Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071" | |
| }, | |
| "entryPoint": "build-image-index", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-build-image-index" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/e195e5b0-7b0d-4835-856f-e89fd7f2710d", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f0fd55e6fc067488-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-image-index", | |
| "tekton.dev/task": "build-image-index" | |
| } | |
| }, | |
| "parameters": { | |
| "ALWAYS_BUILD_INDEX": "true", | |
| "BUILDAH_FORMAT": "docker", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGES": [ | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| ], | |
| "SBOM_SKIP_VALIDATION": "false", | |
| "STORAGE_DRIVER": "vfs", | |
| "TLSVERIFY": "true", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-image-index", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "build-image-index" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-build-image-index:0.3.1@sha256:290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f,quay.io/rhoai/odh-kserve-agent-rhel9@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| }, | |
| { | |
| "name": "IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532" | |
| }, | |
| { | |
| "name": "IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| }, | |
| { | |
| "name": "SBOM_BLOB_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:72450faa03d74b2804511cadca6f81db14fdd03e747d7643b53d813233fe3198" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:05Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-x86-64@sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-ppc64le@sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-s390x@sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25-linux-m2xlarge-arm64@sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35" | |
| ], | |
| "entryPoint": "#!/bin/bash\n# Fixing group permission on /var/lib/containers\nset -eu\nset -o pipefail\nchown root:root /var/lib/containers\n\nsed -i 's/^\\s*short-name-mode\\s*=\\s*.*/short-name-mode = \"disabled\"/' /etc/containers/registries.conf\n\necho \"[$(date --utc -Ins)] Update CA trust\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nMANIFEST_DATA_FILE=\"/index-build-data/manifest_data.json\"\n\necho \"Running konflux-build-cli\"\nif ! konflux-build-cli image build-image-index \\\n --image \"$IMAGE\" \\\n --tls-verify=\"$TLSVERIFY\" \\\n --buildah-format \"$BUILDAH_FORMAT\" \\\n --always-build-index=\"$ALWAYS_BUILD_INDEX\" \\\n --additional-tags \"odh-kserve-agent-v2-25-on-push-xwfsp-build-image-index\" \\\n --output-manifest-path \"$MANIFEST_DATA_FILE\" \\\n --result-path-image-digest \"/tekton/results/IMAGE_DIGEST\" \\\n --result-path-image-url \"/tekton/results/IMAGE_URL\" \\\n --result-path-image-ref \"/tekton/results/IMAGE_REF\" \\\n --result-path-images \"/tekton/results/IMAGES\" \\\n --images \"$@\"; then\n echo \"Failed to build image index\"\n exit 1\nfi\n", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -e\n\nMANIFEST_DATA_FILE=\"/index-build-data/manifest_data.json\"\nif [ ! -f \"$MANIFEST_DATA_FILE\" ]; then\n echo \"The manifest_data.json file does not exist. Skipping the SBOM creation...\"\n exit 0\nfi\n\nIMAGE_URL=\"$(cat \"/tekton/results/IMAGE_URL\")\"\nIMAGE_DIGEST=\"$(cat \"/tekton/results/IMAGE_DIGEST\")\"\necho \"Creating SBOM result file...\"\nmobster_args=(generate --output /index-build-data/index.spdx.json)\n\nif [ \"${SBOM_SKIP_VALIDATION}\" == \"true\" ]; then\n echo \"Skipping SBOM validation\"\n mobster_args+=(--skip-validation)\nfi\n\nmobster_args+=(\n oci-index\n --index-image-pullspec \"$IMAGE_URL\"\n --index-image-digest \"$IMAGE_DIGEST\"\n --index-manifest-path \"$MANIFEST_DATA_FILE\"\n)\nmobster \"${mobster_args[@]}\"\n", | |
| "environment": { | |
| "container": "create-sbom", | |
| "image": "oci://quay.io/konflux-ci/mobster@sha256:135eec87fe80d0751a1ea5e8e47b240147b25ee9a41973cae365540d2e2ee473" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -e\n\necho \"[$(date --utc -Ins)] Update CA trust\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSBOM_RESULT_FILE=\"/index-build-data/index.spdx.json\"\nif [ ! -f \"$SBOM_RESULT_FILE\" ]; then\n echo \"The index.spdx.json file does not exists. Skipping the SBOM upload...\"\n exit 0\nfi\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$(cat \"/tekton/results/IMAGE_REF\")\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\necho \"Pushing sbom to registry\"\nif ! retry cosign attach sbom --sbom \"$SBOM_RESULT_FILE\" --type spdx \"$(cat \"/tekton/results/IMAGE_REF\")\"\nthen\n echo \"Failed to push sbom to registry\"\n exit 1\nfi\n\n# Remove tag from IMAGE while allowing registry to contain a port number.\nsbom_repo=\"${IMAGE%:*}\"\nsbom_digest=\"$(sha256sum \"$SBOM_RESULT_FILE\" | cut -d' ' -f1)\"\n# The SBOM_BLOB_URL is created by `cosign attach sbom`.\necho -n \"${sbom_repo}@sha256:${sbom_digest}\" | tee \"/tekton/results/SBOM_BLOB_URL\"\n", | |
| "environment": { | |
| "container": "upload-sbom", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index", | |
| "prefetch-dependencies" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:00Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665" | |
| }, | |
| "entryPoint": "source-build-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/0d203381-9564-424e-a3e3-770f537cef63", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f86a145d3ef4374d-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "build-source-image", | |
| "tekton.dev/task": "source-build-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "BASE_IMAGES": "", | |
| "BINARY_IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "BINARY_IMAGE_DIGEST": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "CACHI2_ARTIFACT": "", | |
| "IGNORE_UNSIGNED_IMAGE": "false", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca" | |
| } | |
| }, | |
| "name": "build-source-image", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "source-build-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta:0.3.1@sha256:1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "BUILD_RESULT", | |
| "type": "string", | |
| "value": "{\"status\": \"success\", \"dependencies_included\": false, \"base_image_source_included\": true, \"image_url\": \"quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src\", \"image_digest\": \"sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e\"}" | |
| }, | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src@sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e" | |
| }, | |
| { | |
| "name": "SOURCE_IMAGE_DIGEST", | |
| "type": "string", | |
| "value": "sha256:3ffa8b0b17d1b3849c2beb64d31469bd872c42a05e78385f834b753b71a8eb9e" | |
| }, | |
| { | |
| "name": "SOURCE_IMAGE_URL", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9:sha256-c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532.src" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source", | |
| "=/var/workdir/cachi2" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n\nif [[ ! $BINARY_IMAGE_DIGEST =~ ^sha256:[[:xdigit:]]+$ ]]; then\n echo \"$BINARY_IMAGE_DIGEST is not a valid sha256 digest.\"\n exit 1\nfi\n\nif [[ -n \"$BASE_IMAGES\" ]]; then\n echo \"BASE_IMAGES param received:\"\n printf \"%s\" \"$BASE_IMAGES\" | tee \"$BASE_IMAGES_FILE\"\n exit\nfi\n\necho \"BASE_IMAGES param is empty, inspecting the SBOM instead\"\n\nimage_pinned_by_digest=\"${BINARY_IMAGE%:*}@${BINARY_IMAGE_DIGEST}\"\n\nif raw_inspect=$(skopeo inspect --raw \"docker://${image_pinned_by_digest}\"); then\n echo \"Got manifest of image ${image_pinned_by_digest}\"\nelse\n if [[ $? == 2 ]]; then\n printf \"Binary image %s no longer exists in the registry.\\n\" \"$image_pinned_by_digest\" |\n tee \"$IMAGE_NOT_EXIST_FLAG\"\n exit\n else\n exit 1\n fi\nfi\n\nif manifest_digest=$(jq -e -r '.manifests[0].digest' <<<\"$raw_inspect\"); then\n # The BINARY_IMAGE is an image index, each manifest in the list has its own SBOM.\n # We're gonna assume the base images are the same or similar enough in all the SBOMs.\n echo \"Image (${image_pinned_by_digest}) is a manifest list, picking an arbitrary image from the list\"\n image=${image_pinned_by_digest%@*}@${manifest_digest}\nelse\n # The image is a single manifest\n image=$image_pinned_by_digest\nfi\n\n# Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\nmkdir -p /tmp/auth && select-oci-auth \"$image\" >/tmp/auth/config.json\n\nfor i in {1..5}; do\n echo \"Downloading SBOM for $image (attempt $i)\"\n sbom=$(DOCKER_CONFIG=/tmp/auth cosign download sbom \"$image\") && break\n [[ \"$i\" -lt 5 ]] && sleep 1\ndone\n\nif [[ -z \"$sbom\" ]]; then\n echo \"Failed to download SBOM after 5 attempts. Proceeding anyway.\"\n echo \"WARNING: the source image will not include sources for the base image.\"\n exit 0\nfi\n\necho -n \"Looking for base image in SBOM\"\n\n# Note: the SBOM should contain at most one image with the is_base_image property - the\n# base image for the last FROM instruction. That is the only base image we care about.\nif jq -e '.bomFormat == \"CycloneDX\"' <<<\"$sbom\" >/dev/null; then\n echo \" (.formulation[].components[] with 'konflux:container:is_base_image' property)\"\n jq -r '\n .formulation[]?\n | .components[]?\n | select(any(.properties[]?; .name == \"konflux:container:is_base_image\"))\n | (\n .purl\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url + \"@\" + $matched.digest\n ' <<<\"$sbom\" | tee \"$BASE_IMAGES_FILE\"\nelse\n echo ' (a package with a {\"name\": \"konflux:container:is_base_image\"} JSON-encoded annotation)'\n jq -r '\n .packages[]\n | select(any(.annotations[]?.comment; (fromjson?).name? == \"konflux:container:is_base_image\"))\n | [.externalRefs[]? | select(.referenceType == \"purl\").referenceLocator] as $purls\n | (\n $purls | first\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url + \"@\" + $matched.digest\n\n ' <<<\"$sbom\" | tee \"$BASE_IMAGES_FILE\"\nfi\n", | |
| "environment": { | |
| "container": "get-base-images", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:38bfc93b0eacecd0aa5228225427524441c30e911b282a6b2eff9fdb0fdd021e" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n\nif [ -f \"$IMAGE_NOT_EXIST_FLAG\" ]; then\n echo \"Drop building source container image.\"\n printf \"\" >\"$RESULT_SOURCE_IMAGE_URL\"\n printf \"\" >\"$RESULT_SOURCE_IMAGE_DIGEST\"\n printf \"\" >\"$RESULT_IMAGE_REF\"\n message=$(cat \"$IMAGE_NOT_EXIST_FLAG\")\n printf \"{\\\"status\\\": \\\"drop\\\", \\\"message\\\": \\\"%s\\\"}\" \"$message\" >\"$WS_BUILD_RESULT_FILE\"\n exit\nfi\n\napp_dir=/opt/source_build\nregistry_allowlist=\"\nregistry.access.redhat.com\nregistry.redhat.io\n\"\n\n## This is needed for the builds performed by the rpm-ostree task\n## otherwise, we can see this error:\n## \"fatal: detected dubious ownership in repository at '/var/workdir/source'\"\n##\ngit config --global --add safe.directory \"$SOURCE_DIR\"\n\nbase_images=$(if [[ -f \"$BASE_IMAGES_FILE\" ]]; then cat \"$BASE_IMAGES_FILE\"; fi)\n\nargs=(\n --binary-image-ref \"${BINARY_IMAGE}@${BINARY_IMAGE_DIGEST}\"\n --workspace /var/workdir\n --source-dir \"$SOURCE_DIR\"\n --base-images \"$base_images\"\n --write-result-to \"$RESULT_FILE\"\n --prefetch-artifacts-dir \"$CACHI2_ARTIFACTS_DIR\"\n --registry-allowlist=\"$registry_allowlist\"\n)\nif [ \"$IGNORE_UNSIGNED_IMAGE\" == \"true\" ]; then\n args+=(--ignore-unsigned-image)\nfi\n\n${app_dir}/appenv/bin/python3 ${app_dir}/source_build.py \"${args[@]}\"\n\njq -j \".image_url\" <\"$RESULT_FILE\" >\"$RESULT_SOURCE_IMAGE_URL\"\njq -j \".image_digest\" <\"$RESULT_FILE\" >\"$RESULT_SOURCE_IMAGE_DIGEST\"\njq -j '\"\\(.image_url)@\\(.image_digest)\"' \"${RESULT_FILE}\" >\"$RESULT_IMAGE_REF\"\n\ncp \"$RESULT_FILE\" \"$WS_BUILD_RESULT_FILE\"\n", | |
| "environment": { | |
| "container": "build", | |
| "image": "oci://quay.io/konflux-ci/source-container-build@sha256:a8416f792207e4b9b8bfea1c9b86ad54ae7bc28384d14de0726cced3dee01ae5" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:48Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872" | |
| }, | |
| "entryPoint": "deprecated-image-check", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/74f05ed2-9278-40b4-a6aa-321ab47c245a", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-3e2af06bf99ee472-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "deprecated-base-image-check", | |
| "tekton.dev/task": "deprecated-image-check" | |
| } | |
| }, | |
| "parameters": { | |
| "BASE_IMAGES_DIGESTS": "", | |
| "CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "CA_TRUST_CONFIG_MAP_NAME": "trusted-ca", | |
| "IMAGE_DIGEST": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "IMAGE_URL": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "POLICY_DIR": "/project/repository/", | |
| "POLICY_NAMESPACE": "required_checks" | |
| } | |
| }, | |
| "name": "deprecated-base-image-check", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "deprecated-image-check" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check:0.5@sha256:0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:27:47+00:00\",\"note\":\"Task deprecated-image-check completed: Check result for task result.\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\nsource /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nIMAGES_TO_BE_PROCESSED_PATH=\"/tmp/images_to_be_processed.txt\"\ntouch /tmp/images_to_be_processed.txt\n\nsuccess_counter=0\nfailure_counter=0\nerror_counter=0\nwarnings_counter=0\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n while read -r arch arch_sha; do\n SBOM_FILE_PATH=\"/tmp/sbom-${arch}.json\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n # Pre-select the correct credentials to work around cosign not supporting the containers-auth.json spec\n mkdir -p /tmp/auth && select-oci-auth \"${arch_imageanddigest}\" >/tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n\n # Get base images from SBOM\n if ! cosign download sbom \"$arch_imageanddigest\" > \"${SBOM_FILE_PATH}\"; then\n echo \"Unable to download sbom for arch $arch.\"\n continue\n fi\n\n < \"${SBOM_FILE_PATH}\" jq -r '\n if .bomFormat == \"CycloneDX\" then\n .formulation[]?\n | .components[]?\n | select(any(.properties[]?; .name | test(\"^konflux:container:is_(base|builder)_image\")))\n | (\n .purl\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url\n else\n .packages[]\n | select(any(.annotations[]?.comment; (fromjson?).name? | test(\"^konflux:container:is_(base|builder)_image\")?))\n | [.externalRefs[]? | select(.referenceType == \"purl\").referenceLocator] as $purls\n | (\n $purls | first\n | capture(\"^pkg:oci/.*?@(?<digest>[a-z0-9]+:[a-f0-9]+)(?:\\\\?[^#]*repository_url=(?<repository_url>[^&#]*))?\")\n ) as $matched\n | $matched.repository_url\n end\n ' >> \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n echo \"Detected base images from $arch SBOM:\"\n cat \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n echo \"\"\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task deprecated-image-check failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nif [ -n \"${BASE_IMAGES_DIGESTS}\" ];\nthen\n echo \"Base images passed by param BASE_IMAGES_DIGESTS: $BASE_IMAGES_DIGESTS\"\n # Get images from the parameter\n for IMAGE_WITH_TAG in $(echo -n \"$BASE_IMAGES_DIGESTS\" | sed 's/\\\\n/\\'$'\\n''/g' );\n do\n echo \"$IMAGE_WITH_TAG\" | cut -d \":\" -f1 >> \"${IMAGES_TO_BE_PROCESSED_PATH}\"\n done\nfi\n\n# we want to remove duplicated entries\nBASE_IMAGES=$(sort -u \"${IMAGES_TO_BE_PROCESSED_PATH}\")\n\necho \"Images to be checked:\"\necho \"$BASE_IMAGES\"\necho \"\"\n\nfor BASE_IMAGE in ${BASE_IMAGES};\ndo\n IFS=:'/' read -r IMAGE_REGISTRY IMAGE_REPOSITORY<<< \"$BASE_IMAGE\"\n\n # Red Hat Catalog hack: registry.redhat.io must be queried as registry.access.redhat.com in Red Hat catalog\n IMAGE_REGISTRY_CATALOG=$(echo \"${IMAGE_REGISTRY}\" | sed 's/^registry.redhat.io$/registry.access.redhat.com/')\n\n export IMAGE_REPO_PATH=\"/tmp/${IMAGE_REPOSITORY}\"\n mkdir -p \"${IMAGE_REPO_PATH}\"\n echo \"Querying Red Hat Catalog for $BASE_IMAGE.\"\n http_code=$(curl -s -o \"${IMAGE_REPO_PATH}/repository_data.json\" -w '%{http_code}' \"https://catalog.redhat.com/api/containers/v1/repositories/registry/${IMAGE_REGISTRY_CATALOG}/repository/${IMAGE_REPOSITORY}\")\n\n if [ \"$http_code\" == \"200\" ];\n then\n echo \"Running conftest using $POLICY_DIR policy, $POLICY_NAMESPACE namespace.\"\n /usr/bin/conftest test --no-fail \"${IMAGE_REPO_PATH}/repository_data.json\" \\\n --policy \"$POLICY_DIR\" --namespace \"$POLICY_NAMESPACE\" \\\n --output=json | tee \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\"\n\n failures_num=$(jq -r '.[].failures|length' \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\")\n if [[ \"${failures_num}\" -gt 0 ]]; then\n echo \"[FAILURE] Image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} has been deprecated\"\n fi\n failure_counter=$((failure_counter+failures_num))\n\n successes_num=$(jq -r '.[].successes' \"${IMAGE_REPO_PATH}/deprecated_image_check_output.json\")\n if [[ \"${successes_num}\" -gt 0 ]]; then\n echo \"[SUCCESS] Image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} is valid\"\n fi\n success_counter=$((success_counter+successes_num))\n\n elif [ \"$http_code\" == \"404\" ];\n then\n echo \"[WARNING] Registry/image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY} not found in Red Hat Catalog. Task cannot provide results if image is deprecated.\"\n warnings_counter=$((warnings_counter+1))\n else\n echo \"[ERROR] Unexpected error (HTTP code: ${http_code}) occurred for registry/image ${IMAGE_REGISTRY}/${IMAGE_REPOSITORY}.\"\n error_counter=$((error_counter+1))\n fi\ndone\n\nnote=\"Task deprecated-image-check failed: Command conftest failed. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -n \"$POLICY_NAMESPACE\" -t \"$note\")\n\nnote=\"Task deprecated-image-check completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n elif [[ \"${success_counter}\" -eq 0 ]]; then\n # when all counters are 0, there are no base images to check\n note=\"Task deprecated-image-check success: No base images to check.\"\n RES=\"SUCCESS\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" -n \"$POLICY_NAMESPACE\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n", | |
| "environment": { | |
| "container": "check-images", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:15Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| "entryPoint": "clair-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clair-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/56735d8f-bd4c-42b3-9a62-502f4fe97c89", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f2c49c1938a61c45-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clair-scan", | |
| "tekton.dev/task": "clair-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "docker-auth": "", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/x86_64", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-oci-attach-report": "false" | |
| } | |
| }, | |
| "name": "clair-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clair-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "REPORTS", | |
| "type": "string", | |
| "value": "{\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\":\"sha256:d88ff3dacf3d16651aa77594a46b95137350c3deb60354d8ff41e94190264703\"}\n" | |
| }, | |
| { | |
| "name": "SCAN_OUTPUT", | |
| "type": "string", | |
| "value": "{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n", | |
| "environment": { | |
| "container": "get-image-manifests", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n", | |
| "environment": { | |
| "container": "get-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n", | |
| "environment": { | |
| "container": "oci-attach-report", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "conftest-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:16Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| "entryPoint": "clair-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clair-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ef8501e0-b10c-4a23-aefe-1331729e8346", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-8b940cec21748595-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clair-scan", | |
| "tekton.dev/task": "clair-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "docker-auth": "", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/ppc64le", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-oci-attach-report": "false" | |
| } | |
| }, | |
| "name": "clair-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clair-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "REPORTS", | |
| "type": "string", | |
| "value": "{\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\":\"sha256:26ff675350098968a65ce8ef71470afe3428e78d817955ad22f6551e303ce48c\"}\n" | |
| }, | |
| { | |
| "name": "SCAN_OUTPUT", | |
| "type": "string", | |
| "value": "{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:15+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n", | |
| "environment": { | |
| "container": "get-image-manifests", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n", | |
| "environment": { | |
| "container": "get-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n", | |
| "environment": { | |
| "container": "oci-attach-report", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "conftest-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:15Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| "entryPoint": "clair-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clair-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/52123453-b303-47e1-8de8-61d3053d0dfe", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-5fa12cfc7ee74dd1-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clair-scan", | |
| "tekton.dev/task": "clair-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "docker-auth": "", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/s390x", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-oci-attach-report": "false" | |
| } | |
| }, | |
| "name": "clair-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clair-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "REPORTS", | |
| "type": "string", | |
| "value": "{\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\":\"sha256:4ee1c56ed661708d789dc3aebecccb33dc0716884c4c16d23a1bd0e18b128b66\"}\n" | |
| }, | |
| { | |
| "name": "SCAN_OUTPUT", | |
| "type": "string", | |
| "value": "{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n", | |
| "environment": { | |
| "container": "get-image-manifests", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n", | |
| "environment": { | |
| "container": "get-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n", | |
| "environment": { | |
| "container": "oci-attach-report", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "conftest-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:15Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| "entryPoint": "clair-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clair-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/c9f3725b-9279-45f8-b879-a55b0204f72a", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-9b8cf839b0c121a7-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clair-scan", | |
| "tekton.dev/task": "clair-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "docker-auth": "", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux-m2xlarge/arm64", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-oci-attach-report": "false" | |
| } | |
| }, | |
| "name": "clair-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clair-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3.2@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "REPORTS", | |
| "type": "string", | |
| "value": "{\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\":\"sha256:a05323a823fc519c7d0855b2a6c2572807fc3754d2dd0a822863b3102e568bca\"}\n" | |
| }, | |
| { | |
| "name": "SCAN_OUTPUT", | |
| "type": "string", | |
| "value": "{\"vulnerabilities\":{\"critical\":0,\"high\":0,\"medium\":0,\"low\":0,\"unknown\":0},\"unpatched_vulnerabilities\":{\"critical\":0,\"high\":9,\"medium\":80,\"low\":59,\"unknown\":3}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:14+00:00\",\"note\":\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:27Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\necho \"Inspecting raw image manifest $imageanddigest.\"\n\n# Get the arch and image manifests by inspecting the image. This is mainly for identifying image indexes\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\nimage_manifests=$(get_image_manifests -i \"${imageanddigest}\")\nif [ -n \"$image_manifests\" ]; then\n echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"' | while read -r arch arch_sha; do\n echo \"$arch_sha\" > \"/tekton/home/image-manifest-${arch}.sha\"\n done\nelse\n echo \"Failed to get image manifests from image \\\"$imageanddigest\\\"\"\n note=\"Task clair-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n", | |
| "environment": { | |
| "container": "get-image-manifests", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\n\nmkdir -p /tmp/auth && select-oci-auth \"$IMAGE_URL\" > /tmp/auth/config.json\nexport DOCKER_CONFIG=/tmp/auth\n\nimagewithouttag=$(echo -n \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\")\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\n\n# the quay report format used by the Conftest rules in the\n# conftest-vulnerabilities step doesn't contain the \"issued\" date which\n# we require in the policy rules, so we resort to running clair-action\n# twice to produce both quay and clair formatted output\nclair_report() {\n { retry clair-action report --image-ref=\"$1\" --db-path=/tmp/matcher.db --docker-config-dir=/tmp/auth --format=clair | tee \"clair-report-$2.json\"; } && \\\n { retry clair-action convert --file-path=\"clair-report-$2.json\" --format=quay > \"clair-result-$2.json\"; }\n}\n\nrun_clair_on_arch() {\n local arch=\"$1\"\n local sha_file=\"image-manifest-$arch.sha\"\n\n if [ -e \"$sha_file\" ]; then\n local arch_sha\n arch_sha=$(<\"$sha_file\")\n local digest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Running clair-action on $arch image manifest...\"\n clair_report \"$digest\" \"$arch\" || true\n\n digests_processed+=(\"\\\"$arch_sha\\\"\")\n fi\n}\n\nplatform=\"${IMAGE_PLATFORM}\"\n\n# If a platform is specified, extract the architecture and run clair-action on the corresponding image manifest\nif [ -n \"$platform\" ]; then\n arch=\"${platform#*/}\"\n if [ \"$arch\" = \"x86_64\" ] || [ \"$arch\" = \"local\" ] || [ \"$arch\" = \"localhost\" ]; then\n arch=\"amd64\"\n fi\n # Validate against supported arch list. If it's not a known arch, fallback to amd64\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n echo \"Error: Unsupported or malformed architecture: '$arch' (parsed from platform: '$platform')\"\n exit 0\n ;;\n esac\n\n run_clair_on_arch \"$arch\"\n\n# If no platform is specified, run clair-action on all available image manifests\nelse\n for sha_file in image-manifest-*.sha; do\n if [ -e \"$sha_file\" ]; then\n arch=$(basename \"$sha_file\" | sed 's/image-manifest-//;s/.sha//')\n run_clair_on_arch \"$arch\"\n fi\n done\nfi\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\n\nimages_processed=\"${images_processed_template/\\[%s]/[$digests_processed_string]}\"\necho \"$images_processed\" > images-processed.json\n", | |
| "environment": { | |
| "container": "get-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/clair-in-ci@sha256:6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -o errexit\nset -o nounset\nset -o pipefail\n\nif [ \"$SKIP_OCI_ATTACH_REPORT\" = \"true\" ]; then\n echo 'OCI attach report skipped by parameter.'\n echo '{}' > reports.json\n exit 0\nfi\n\nif ! compgen -G \"clair-report-*.json\" > /dev/null; then\n echo 'No Clair reports generated. Skipping upload.'\n echo '{}' > reports.json\n exit 0\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\n\nrepository=\"${IMAGE_URL/:*/}\"\n\narch() {\n report_file=\"$1\"\n arch=\"${report_file/*-}\"\n echo \"${arch/.json/}\"\n}\n\nMEDIA_TYPE='application/vnd.redhat.clair-report+json'\n\nreports_json=\"\"\nfor f in clair-report-*.json; do\n digest=$(cat \"image-manifest-$(arch \"$f\").sha\")\n image_ref=\"${repository}@${digest}\"\n mkdir -p /tmp/auth && select-oci-auth \"${image_ref}\" > /tmp/auth/config.json\n export DOCKER_CONFIG=/tmp/auth\n echo \"Attaching $f to ${image_ref}\"\n if ! report_digest=\"$(retry oras attach --no-tty --format go-template='{{.digest}}' --registry-config \\\n \"/tmp/auth/config.json\" --artifact-type \"${MEDIA_TYPE}\" \"${image_ref}\" \"$f:${MEDIA_TYPE}\")\"\n then\n echo \"Failed to attach ${f} to ${image_ref}\"\n exit 1\n fi\n # shellcheck disable=SC2016\n reports_json=\"$(yq --output-format json --indent=0 eval-all '. as $i ireduce ({}; . * $i)' <(echo \"${reports_json}\") <(echo \"${digest}: ${report_digest}\"))\"\ndone\necho \"${reports_json}\" > reports.json\n", | |
| "environment": { | |
| "container": "oci-attach-report", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nclair_result_files=$(ls /tekton/home/clair-result-*.json)\nif [ -z \"$clair_result_files\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: No clair-result files found in /tekton/home.\"\nfi\n\nmissing_vulnerabilities_files=\"\"\nfor file in $clair_result_files; do\n file_suffix=$(basename \"$file\" | sed 's/clair-result-//;s/.json//')\n if [ ! -s \"$file\" ]; then\n echo \"Previous step [get-vulnerabilities] failed: $file is empty.\"\n else\n /usr/bin/conftest test --no-fail \"$file\" \\\n --policy /project/clair/vulnerabilities-check.rego --namespace required_checks \\\n --output=json | tee \"/tekton/home/clair-vulnerabilities-${file_suffix}.json\" || true\n fi\n\n #check for missing \"clair-vulnerabilities-<arch>/image-index\" file and create a string\n if [ ! -f \"/tekton/home/clair-vulnerabilities-$file_suffix.json\" ]; then\n missing_vulnerabilities_files+=\"${missing_vulnerabilities_files:+, }/tekton/home/clair-vulnerabilities-$file_suffix.json\"\n fi\ndone\n\nif [ -n \"$missing_vulnerabilities_files\" ]; then\n note=\"Task clair-scan failed: $missing_vulnerabilities_files did not generate. For details, check Tekton task log.\"\n TEST_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"$missing_vulnerabilities_files did not generate correctly. For details, check conftest command in Tekton task log.\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nscan_result='{\"vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}, \"unpatched_vulnerabilities\":{\"critical\":0, \"high\":0, \"medium\":0, \"low\":0, \"unknown\":0}}'\nfor file in /tekton/home/clair-vulnerabilities-*.json; do\n result=$(jq -rce \\\n '{\n vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n },\n unpatched_vulnerabilities:{\n critical: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_critical_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n high: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_high_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n medium: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_medium_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n low: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_low_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0),\n unknown: (.[] | .warnings? // [] | map(select(.metadata.details.name==\"clair_unpatched_unknown_vulnerabilities\").metadata.\"vulnerabilities_number\" // 0)| add // 0)\n }\n }' \"$file\")\n\n scan_result=$(jq -s -rce \\\n '.[0].vulnerabilities.critical += .[1].vulnerabilities.critical |\n .[0].vulnerabilities.high += .[1].vulnerabilities.high |\n .[0].vulnerabilities.medium += .[1].vulnerabilities.medium |\n .[0].vulnerabilities.low += .[1].vulnerabilities.low |\n .[0].vulnerabilities.unknown += .[1].vulnerabilities.unknown |\n .[0].unpatched_vulnerabilities.critical += .[1].unpatched_vulnerabilities.critical |\n .[0].unpatched_vulnerabilities.high += .[1].unpatched_vulnerabilities.high |\n .[0].unpatched_vulnerabilities.medium += .[1].unpatched_vulnerabilities.medium |\n .[0].unpatched_vulnerabilities.low += .[1].unpatched_vulnerabilities.low |\n .[0].unpatched_vulnerabilities.unknown += .[1].unpatched_vulnerabilities.unknown |\n .[0]' <<<\"$scan_result $result\")\ndone\n\necho \"$scan_result\" | tee \"/tekton/results/SCAN_OUTPUT\"\n\ntee \"/tekton/results/IMAGES_PROCESSED\" < /tekton/home/images-processed.json\n# shellcheck disable=SC2154\ncat /tekton/home/reports.json > \"/tekton/results/REPORTS\"\n\nnote=\"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.\"\nTEST_OUTPUT=$(make_result_json -r \"SUCCESS\" -t \"$note\")\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "conftest-vulnerabilities", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index", | |
| "prefetch-dependencies" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:06Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e" | |
| }, | |
| "entryPoint": "sast-snyk-check-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/40e99c4e-f6c4-40c6-99fe-8ab588258fca", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b310c749efc05df4-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "sast-snyk-check", | |
| "tekton.dev/task": "sast-snyk-check-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ARGS": "", | |
| "CACHI2_ARTIFACT": "", | |
| "EXTRA_ARTIFACT_FILTER": "(^|/)(Dockerfile|Containerfile|[^/]+\\.(sh|bash|zsh|ksh|py|rb|pl|js|mjs|cjs|ts|ps1))$", | |
| "FETCH_EXTRA_ARTIFACTS": "false", | |
| "IGNORE_FILE_PATHS": "", | |
| "IMP_FINDINGS_ONLY": "true", | |
| "KFP_GIT_URL": "SITE_DEFAULT", | |
| "PROJECT_NAME": "", | |
| "RECORD_EXCLUDED": "false", | |
| "SNYK_SECRET": "snyk-secret", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "TARGET_DIRS": ".", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "sast-snyk-check", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "sast-snyk-check-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta:0.5@sha256:99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:28:03+00:00\",\"note\":\"For details, check Tekton task log.\",\"namespace\":\"default\",\"successes\":0,\"failures\":1,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n\nif [[ \"${FETCH_EXTRA_ARTIFACTS}\" != \"true\" ]]; then\n exit 0\nfi\n\nif [[ -z \"${IMAGE_URL}\" || -z \"${IMAGE_DIGEST}\" ]]; then\n echo \"INFO: image-url/image-digest missing, cannot fetch extra artifacts\"\n exit 0\nfi\n\ndeclare -a oras_opts=()\n# shellcheck source=/dev/null\nsource /usr/local/bin/oras_opts.sh\n\nIMAGE_REF=\"${IMAGE_URL}@${IMAGE_DIGEST}\"\necho \"INFO: Fetching extra artifacts from OCI reference ${IMAGE_REF}\"\n\nauthfile=\"$(mktemp)\"\ntrap 'rm -f \"${authfile}\"' EXIT\n/usr/local/bin/select-oci-auth.sh \"${IMAGE_URL}\" >\"${authfile}\"\n\nretry oras manifest fetch \"${oras_opts[@]}\" --registry-config \"${authfile}\" \"${IMAGE_REF}\" >\"/tmp/manifest.json\"\n\nconfig_media_type=\"$(jq -r '.config.mediaType // \"\"' /tmp/manifest.json)\"\nif [[ \"${config_media_type}\" == \"application/vnd.oci.image.config.v1+json\" ]] || [[ \"${config_media_type}\" == \"application/vnd.docker.container.image.v1+json\" ]]; then\n echo \"INFO: Reference points to a container image config (${config_media_type}); skipping extra artifact fetch\"\n exit 0\nfi\n\nmkdir -p /var/workdir/source\n\nfetched_count=0\nwhile IFS=$'\\t' read -r digest rel_path; do\n [[ -n \"${rel_path}\" ]] || continue\n if ! printf '%s\\n' \"${rel_path}\" | grep -Eq \"${EXTRA_ARTIFACT_FILTER}\"; then\n continue\n fi\n\n dest_path=\"/var/workdir/source/${rel_path}\"\n resolved_dest=\"$(realpath -m \"${dest_path}\")\"\n if [[ ! \"${resolved_dest}\" == /var/workdir/source/* ]]; then\n echo \"WARN: Skipping path outside source root: ${rel_path}\"\n continue\n fi\n\n mkdir -p \"$(dirname \"${resolved_dest}\")\"\n echo \"INFO: Fetching blob ${digest} -> ${rel_path}\"\n retry oras blob fetch \"${oras_opts[@]}\" --registry-config \"${authfile}\" \"${IMAGE_URL}@${digest}\" --output \"${resolved_dest}\"\n fetched_count=$((fetched_count + 1))\ndone < <(jq -r '.layers[] | [.digest, (.annotations[\"org.opencontainers.image.title\"] // \"\")] | @tsv' /tmp/manifest.json)\n\nif [[ \"${fetched_count}\" -eq 0 ]]; then\n echo \"INFO: No files matched EXTRA_ARTIFACT_FILTER\"\nelse\n echo \"INFO: Fetched ${fetched_count} extra artifact file(s) alongside SOURCE_ARTIFACT\"\nfi\n", | |
| "environment": { | |
| "container": "fetch-extra-artifacts", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nset -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nif [[ \"${ARGS}\" != *\"--project-name\"* ]]; then\n ARGS=\"$ARGS --project-name=${PROJECT_NAME}\"\nfi\n\n# Installation of Red Hat certificates for cloning Red Hat internal repositories\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSNYK_TOKEN_PATH=\"/etc/secrets/snyk_token\"\nif [ -f \"${SNYK_TOKEN_PATH}\" ] && [ -s \"${SNYK_TOKEN_PATH}\" ]; then\n # SNYK token is provided\n SNYK_TOKEN=\"$(cat ${SNYK_TOKEN_PATH})\"\n export SNYK_TOKEN\nelse\n # According to shellcheck documentation, the following error can be ignored as it is ignored through indirection: https://www.shellcheck.net/wiki/SC2034\n # shellcheck disable=SC2034\n to_enable_snyk='[here](https://konflux-ci.dev/docs/testing/build/snyk/)'\n note=\"Task sast-snyk-check-oci-ta skipped: If you wish to use the Snyk code SAST task, please create a secret name snyk-secret with the key 'snyk_token' containing the Snyk token by following the steps given ${to_enable_snyk}\"\n TEST_OUTPUT=$(make_result_json -r SKIPPED -t \"$note\")\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# Wrapper around snyk code test that maps valid non-zero exit codes (1, 3)\n# to 0 so the existing retry function only retries on exit code 2 (error).\n# Exit codes: 0 = success, 1 = vulnerabilities found, 2 = error, 3 = no supported files\n# The real exit code is always preserved in SNYK_EXIT_CODE.\n# Error codes (2+) always override, valid codes (0, 1, 3) only if no previous error.\n_snyk_code_test() {\n snyk code test \"$@\" 1>&2 >>\"${WORK_DIR}/stdout.txt\"\n local ec=$?\n if [[ \"$ec\" -ne 0 ]] && [[ \"$ec\" -ne 1 ]] && [[ \"$ec\" -ne 3 ]]; then\n SNYK_EXIT_CODE=$ec\n fi\n if [[ \"$ec\" -eq 1 ]] || [[ \"$ec\" -eq 3 ]]; then\n return 0\n fi\n return \"$ec\"\n}\n\n_empty_sarif() {\n local snyk_ver\n snyk_ver=$(snyk --version 2>/dev/null | head -1 | tr -d '\\n' || echo \"unknown\")\n jq -n --arg version \"$snyk_ver\" '{\n \"$schema\": \"https://json.schemastore.org/sarif-2.1.0.json\",\n \"version\": \"2.1.0\",\n \"runs\": [{\n \"tool\": {\n \"driver\": {\n \"name\": \"snyk\",\n \"version\": $version,\n \"informationUri\": \"https://snyk.io\"\n }\n },\n \"results\": [],\n \"properties\": {\n \"coverage\": []\n }\n }]\n }'\n}\n\nSNYK_EXIT_CODE=0\nWORK_DIR=\"$(pwd)\"\nSOURCE_CODE_DIR=/var/workdir/source\n\n# We ignore files using snyk ignore if the user set up the IGNORE_FILE_PATHS variable.\n(cd \"${SOURCE_CODE_DIR}\" && IFS=\",\" && for path in $IGNORE_FILE_PATHS; do\n snyk ignore --file-path=\"${path}\"\ndone)\n\nset +e\necho \"INFO: Running 'snyk code test'..\"\n# We do want to expand ARGS (it can be multiple CLI flags, not just one)\n# shellcheck disable=SC2086\n\n# Generate full paths for each directory in TARGET_DIRS\nIFS=\",\" read -ra TARGETS_ARRAY <<<\"$TARGET_DIRS\"\nfor d in \"${TARGETS_ARRAY[@]}\"; do\n potential_path=\"${SOURCE_CODE_DIR}/${d}\"\n resolved_path=$(realpath -m \"$potential_path\")\n\n # Ensure resolved path is still within SOURCE_CODE_DIR\n if [[ ! \"$resolved_path\" == \"$SOURCE_CODE_DIR\"* ]]; then\n echo \"Error: path traversal attempt, '$potential_path' is outside '$SOURCE_CODE_DIR'\"\n exit 1\n fi\n\n # Ensure directory exists\n if [ ! -d \"$resolved_path\" ]; then\n echo \"Warning: Directory $resolved_path does not exist, skipping\"\n continue\n fi\n\n echo \"INFO: Scanning directory: $resolved_path\"\n # We do want to expand ARGS (it can be multiple CLI flags, not just one)\n # shellcheck disable=SC2086\n RETRY_INTERVAL=30 retry _snyk_code_test $ARGS \"$resolved_path\" --max-depth=1 --sarif-file-output=\"${resolved_path}/sast_snyk_check_out_${d//\\//_}.json\"\n\n sarif_out=\"${resolved_path}/sast_snyk_check_out_${d//\\//_}.json\"\n if [[ \"$d\" != \".\" && -f \"$sarif_out\" ]]; then\n prefix=\"${d%/}/\"\n echo \"INFO: Prepending path prefix '${prefix}' to ${sarif_out}\"\n csgrep --mode=sarif --prepend-path-prefix=\"$prefix\" \"$sarif_out\" >\"${sarif_out}.tmp\" && mv \"${sarif_out}.tmp\" \"$sarif_out\"\n fi\n\ndone\n\n# Merge all per-target SARIF outputs into a single valid SARIF file\nshopt -s globstar nullglob\ncd \"${SOURCE_CODE_DIR}\" || exit 1\nsarif_files=(./**/sast_snyk_check_out_*.json)\nif [[ ${#sarif_files[@]} -gt 0 ]]; then\n csgrep --mode=sarif \"${sarif_files[@]}\" >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\" 2>\"${WORK_DIR}/csgrep_merge.err\" || {\n echo \"WARN: Failed to merge SARIF files with csgrep, creating empty SARIF\"\n cat \"${WORK_DIR}/csgrep_merge.err\" >&2\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\n }\nelse\n echo \"WARN: No SARIF output files found, creating empty SARIF\"\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\nfi\nshopt -u globstar nullglob\ncd \"${WORK_DIR}\" || exit 1\nset -e\ntest_not_skipped=0\nSKIP_MSG=\"We found 0 supported files\"\ngrep -q \"$SKIP_MSG\" \"${WORK_DIR}/stdout.txt\" || test_not_skipped=$?\n\nif [[ \"$SNYK_EXIT_CODE\" -eq 0 ]] || [[ \"$SNYK_EXIT_CODE\" -eq 1 ]]; then\n # Check if the merged SARIF file has content - this could happen if the snyk scan found no findings\n if [ ! -s \"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\" ]; then\n echo \"WARN: No JSON output files were generated by snyk scan\"\n _empty_sarif >\"${SOURCE_CODE_DIR}/sast_snyk_check_out.json\"\n fi\n\n # In order to generate csdiff/v1, we need to add the whole path of the source code as Snyk only provides an URI to embed the context\n (cd \"${SOURCE_CODE_DIR}\" && csgrep --mode=json --embed-context=3 \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json) \\\n >sast_snyk_check_out_all_findings.json\n\n echo \"INFO: Initial results:\"\n csgrep --mode=evtstat sast_snyk_check_out_all_findings.json\n csgrep sast_snyk_check_out_all_findings.json\n\n if [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\n fi\n PROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n # create the KFP clone directory regardless\n KFP_DIR=\"known-false-positives\"\n KFP_CLONED=\"0\"\n mkdir -p \"${KFP_DIR}\"\n\n # We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\n if [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\n fi\n\n if [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\n mv sast_snyk_check_out_all_findings.json filtered_sast_snyk_check_out.json\n else\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n CMD=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n if [ \"${RECORD_EXCLUDED}\" == \"true\" ]; then\n CMD+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n set +e\n \"${CMD[@]}\" sast_snyk_check_out_all_findings.json >filtered_sast_snyk_check_out.json\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n else\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\n echo \"INFO: Results after filtering:\"\n (set -x && csgrep --mode=evtstat filtered_sast_snyk_check_out.json)\n csgrep filtered_sast_snyk_check_out.json\n fi\n\n # Generation of scan stats\n\n total_files=$(jq '[(.runs[0].properties.coverage // [])[].files] | add' \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json)\n supported_files=$(jq '[(.runs[0].properties.coverage // [])[] | select(.type == \"SUPPORTED\") | .files] | add' \"${SOURCE_CODE_DIR}\"/sast_snyk_check_out.json)\n\n # We make sure the values are 0 if no supported/total files are found\n if [ \"$total_files\" = \"null\" ] || [ -z \"$total_files\" ]; then\n total_files=0\n fi\n\n if [ \"$supported_files\" = \"null\" ] || [ -z \"$supported_files\" ]; then\n supported_files=0\n fi\n\n coverage_ratio=0\n if ((total_files > 0)); then\n coverage_ratio=$((supported_files * 100 / total_files))\n fi\n\n # embed stats in results file and convert to SARIF\n csgrep --mode=sarif --set-scan-prop snyk-scanned-files-coverage:\"${coverage_ratio}\" \\\n --set-scan-prop snyk-scanned-files-success:\"${supported_files}\" \\\n --set-scan-prop snyk-scanned-files-total:\"${total_files}\" \\\n filtered_sast_snyk_check_out.json >sast_snyk_check_out.sarif\n\n # Create filtered SARIF for Tekton task result based on IMP_FINDINGS_ONLY parameter\n if [ \"${IMP_FINDINGS_ONLY}\" == \"true\" ]; then\n # Filter to only \"error\" level or higher (high/critical severity) for Tekton task result\n # In SARIF, defects are given a level like \"error\" or \"warning\". Snyk maps \"high\" level findings to \"error\".\n # - \"error\" → importance level 1\n # - \"warning\" (or missing level) → importance level 0\n RESULT_SARIF=\"result_sast_snyk_check_out.sarif\"\n csgrep --mode=sarif --imp-level 1 sast_snyk_check_out.sarif >\"$RESULT_SARIF\"\n else\n # Use all findings for Tekton task result\n RESULT_SARIF=\"sast_snyk_check_out.sarif\"\n fi\n\n TEST_OUTPUT=\n parse_test_output \"sast-snyk-check-oci-ta\" sarif \"$RESULT_SARIF\" || true\n\n# When the test is skipped, the \"SNYK_EXIT_CODE\" is 3 and it can also be 3 in some other situation\nelif [[ \"$test_not_skipped\" -eq 0 ]]; then\n note=\"Task sast-snyk-check-oci-ta success: Snyk code test found zero supported files.\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelse\n echo \"sast-snyk-check test failed because of the following issues:\"\n cat \"${WORK_DIR}/stdout.txt\"\n note=\"Task sast-snyk-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "sast-snyk-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nif [ -z \"${IMAGE_URL}\" ]; then\n echo 'No image-url provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"sast_snyk_check_out.sarif excluded-findings.json\"\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n if [ \"${UPLOAD_FILE}\" == \"excluded-findings.json\" ]; then\n MEDIA_TYPE=application/json\n else\n MEDIA_TYPE=application/sarif+json\n fi\n echo \"Selecting auth\"\n select-oci-auth \"${IMAGE_URL}\" >\"${HOME}/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n if ! retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"; then\n echo \"Failed to attach to ${IMAGE_URL}\"\n fi\ndone\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:58Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| "entryPoint": "clamav-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/fccb52f7-3e0b-4594-92b9-830eb0cac21a", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "virus, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-de9669d9fc05ea3e-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clamav-scan", | |
| "tekton.dev/task": "clamav-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "clamd-max-threads": "8", | |
| "docker-auth": "", | |
| "image-arch": "linux/x86_64", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-upload": "false" | |
| } | |
| }, | |
| "name": "clamav-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clamav-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"timestamp\":\"1788902874\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n", | |
| "environment": { | |
| "container": "extract-and-scan-image", | |
| "image": "oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:58Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| "entryPoint": "clamav-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/abbcb159-67ef-4265-8f2e-a547fa899ad7", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "virus, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-e66ae890756fcd77-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clamav-scan", | |
| "tekton.dev/task": "clamav-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "clamd-max-threads": "8", | |
| "docker-auth": "", | |
| "image-arch": "linux/ppc64le", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-upload": "false" | |
| } | |
| }, | |
| "name": "clamav-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clamav-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"timestamp\":\"1788902875\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n", | |
| "environment": { | |
| "container": "extract-and-scan-image", | |
| "image": "oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:00Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| "entryPoint": "clamav-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/dc2be385-3a0d-474c-8b56-32f808581eb4", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "virus, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-93c77cf31f239c13-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clamav-scan", | |
| "tekton.dev/task": "clamav-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "clamd-max-threads": "8", | |
| "docker-auth": "", | |
| "image-arch": "linux/s390x", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-upload": "false" | |
| } | |
| }, | |
| "name": "clamav-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clamav-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"timestamp\":\"1788902876\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n", | |
| "environment": { | |
| "container": "extract-and-scan-image", | |
| "image": "oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:59Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| "entryPoint": "clamav-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/a9e01aea-22db-4eab-945d-bfc0ff017616", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "virus, konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-1ce322344973ba0c-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "clamav-scan", | |
| "tekton.dev/task": "clamav-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "clamd-max-threads": "8", | |
| "docker-auth": "", | |
| "image-arch": "linux-m2xlarge/arm64", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "skip-upload": "false" | |
| } | |
| }, | |
| "name": "clamav-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "clamav-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan:0.3.3@sha256:9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\",\"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\"]}}\n" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"timestamp\":\"1788902875\",\"namespace\":\"required_checks\",\"successes\":2,\"failures\":0,\"warnings\":0,\"result\":\"SUCCESS\",\"note\":\"All checks passed successfully\"}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -euo pipefail\n# shellcheck disable=SC1091 # /utils.sh is only available in the container image at runtime\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Start clamd in background\n/start-clamd.sh\n\n# Bootstrap .docker config in overridden HOME.\n# This prevents 'oc' CLI failures in clean environments where ~/.docker does not exist.\nif [ ! -d ~/.docker ]; then\n mkdir -p ~/.docker\n echo '{}' > ~/.docker/config.json\nfi\n\nimagewithouttag=$(echo \"$IMAGE_URL\" | sed \"s/\\(.*\\):.*/\\1/\" | tr -d '\\n')\n\n# strip new-line escape symbol from parameter and save it to variable\nimageanddigest=\"${imagewithouttag}@${IMAGE_DIGEST}\"\n\n# check if image is attestation one, skip the clamav scan in such case\nif [[ $imageanddigest == *.att ]]\nthen\n echo \"$imageanddigest is an attestation image. Skipping ClamAV scan.\"\n exit 0\nfi\n\nimages_processed_template='{\"image\": {\"pullspec\": \"'\"$IMAGE_URL\"'\", \"digests\": [%s]}}'\ndigests_processed=()\nmkdir logs\nmkdir content\ncd content\necho \"Detecting artifact type for ${imageanddigest}.\"\necho '{\"artifact\":{\"pullspec\":\"'\"${imageanddigest}\"'\",\"type\":\"unknown\",\"mediaType\":\"\"}}' > /work/logs/artifact-meta.json\n\n# Function to scan content and process results with ClamAV and EC\n# Parameters:\n# $1: destination - path to the content to scan\n# $2: suffix - suffix for log file names (e.g., \"oci\", \"amd64\")\n# $3: digest - digest to add to digests_processed array\n# $4: scan_message - optional message describing what is being scanned\nscan_and_process() {\n local destination=\"$1\"\n local suffix=\"$2\"\n local digest=\"$3\"\n local scan_message=\"${4:-Scanning content}\"\n\n db_version=$(clamdscan --version | sed 's|.*/\\(.*\\)/.*|\\1|')\n\n echo \"$scan_message. This operation may take a while.\"\n clamdscan \"${destination}\" -vi --multiscan --fdpass \\\n | tee \"/work/logs/clamscan-result-${suffix}.log\" || true\n\n echo \"Executed-on: Scan was executed on clamsdcan version - $(clamdscan --version) Database version: $db_version\" | tee -a \"/work/logs/clamscan-result-${suffix}.log\"\n\n digests_processed+=(\"\\\"$digest\\\"\")\n\n if [[ -e \"/work/logs/clamscan-result-${suffix}.log\" ]]; then\n # OPA/EC requires structured data input, add clamAV log into json\n jq -Rs '{ output: . }' \"/work/logs/clamscan-result-${suffix}.log\" > \"/work/logs/clamscan-result-log-${suffix}.json\"\n\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o json \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" || true\n\n # workaround: due to a bug in ec-cli, we cannot generate json and appstudio output at the same time, running it again\n EC_EXPERIMENTAL=1 ec test \\\n --namespace required_checks \\\n --policy /project/clamav/virus-check.rego \\\n -o appstudio \\\n \"/work/logs/clamscan-result-log-${suffix}.json\" | tee \"/work/logs/clamscan-ec-test-${suffix}.json\" || true\n\n cat \"/work/logs/clamscan-ec-test-${suffix}.json\"\n fi\n}\n\n# Skip extract only when every real file is a known weight type.\nis_weight_filename() {\n local base=\"$1\"\n case \"$base\" in\n *.safetensors|*.gguf|*.ggml|*.pt|*.pth|*.onnx|*.onnx_data|*.onnx_data_*) return 0 ;;\n *) return 1 ;;\n esac\n}\n\n# 2000MiB: slightly under ClamAV's ~2GiB MaxFileSize (0.2 used --max-filesize=2000M).\nCLAMAV_SKIP_BLOB_BYTES=2097152000\n\n# listing = stdout of: oc image extract --dry-run\nis_weight_only_layer() {\n local listing=\"$1\"\n local mode entry base\n # Fail closed: empty stdout is not evidence the layer is weight-only.\n [[ -z \"${listing}\" ]] && return 1\n while IFS= read -r line; do\n [ -z \"$line\" ] && continue\n mode=$(awk '{print $2}' <<< \"$line\")\n [[ \"$mode\" == d* ]] && continue\n [[ \"$line\" == *\" -> \"* ]] && return 1\n entry=$(awk '{print $NF}' <<< \"$line\")\n base=$(basename \"$entry\")\n [[ \"$base\" == .wh.* ]] && continue\n is_weight_filename \"$base\" || return 1\n done <<< \"$listing\"\n return 0\n}\n\n# title/path from the OCI layer descriptor (olot ModelCars). Empty is not a skip.\nlayer_annotation_is_weight() {\n local title=\"$1\" inpath=\"$2\" base candidate\n for candidate in \"$title\" \"$inpath\"; do\n [ -z \"$candidate\" ] && continue\n base=$(basename \"$candidate\")\n is_weight_filename \"$base\" && return 0\n done\n return 1\n}\n\n# Detect artifact type: container image vs OCI artifact\n# First, try to get image manifests (works for container images)\n# Use subshell to prevent get_image_manifests() from exiting the main script if it fails\n# (get_image_manifests uses exit 1 when Architecture field is missing, which happens for OCI artifacts)\nimage_manifests=$(bash -c '. /utils.sh; get_image_manifests -i \"'\"${imageanddigest}\"'\"' 2>/dev/null || echo \"\")\n\n# If get_image_manifests failed, check if it's an OCI artifact by inspecting manifest media type\nif [ -z \"$image_manifests\" ]; then\n echo \"get_image_manifests returned empty, checking if this is an OCI artifact...\"\n raw_manifest=$(skopeo inspect --raw --authfile ~/.docker/config.json \"docker://${imageanddigest}\" 2>/dev/null || true)\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"inspected\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n\n if [ -n \"$raw_manifest\" ]; then\n media_type=$(echo \"$raw_manifest\" | jq -r '.mediaType // .config.mediaType // empty' 2>/dev/null || echo \"\")\n artifact_type=$(echo \"$raw_manifest\" | jq -r '.artifactType // empty' 2>/dev/null || echo \"\")\n config_media_type=$(echo \"$raw_manifest\" | jq -r '.config.mediaType // empty' 2>/dev/null || echo \"\")\n\n # Determine if this is an OCI artifact (not a container image)\n # OCI artifacts typically have:\n # - An empty/scratch config (config.mediaType contains \"empty\" or \"scratch\")\n # - An explicit artifactType field that is not a container image type\n is_oci_artifact=false\n\n # Check if config is empty/scratch (typical for OCI artifacts like python wheels, helm charts, etc.)\n if echo \"$config_media_type\" | grep -qiE \"(empty|scratch)\"; then\n is_oci_artifact=true\n fi\n\n # Check if artifactType is set and is not a container image type\n if [ -n \"$artifact_type\" ] && ! echo \"$artifact_type\" | grep -qE \"application/vnd\\.(oci|docker)\\.(image|container)\"; then\n is_oci_artifact=true\n fi\n\n if [ \"$is_oci_artifact\" = true ]; then\n # This is an OCI artifact (e.g., python wheels, helm charts, etc.)\n echo \"Detected OCI artifact (artifactType: ${artifact_type:-unset}, config.mediaType: ${config_media_type:-unset}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.artifactType = '\"\\\"${artifact_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n elif echo \"$media_type\" | grep -qE \"(application/vnd\\.(docker|oci)\\.(distribution|image)\\.manifest|application/vnd\\.docker\\.distribution\\.manifest)\"; then\n # This looks like a container image manifest, but get_image_manifests failed\n echo \"Detected container image manifest type: $media_type, but get_image_manifests failed. This may indicate an error.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"$media_type\\\"\"' | .artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n note=\"Task clamav-scan failed: Failed to get image manifests from image \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n else\n # Likely an OCI artifact with non-standard media type\n echo \"Detected OCI artifact (media type: ${media_type:-unknown}). Downloading for scanning...\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.mediaType = '\"\\\"${media_type:-unknown}\\\"\"' | .artifact.type = \"oci\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n destination=\"content-oci\"\n mkdir -p \"$destination\"\n\n # Download OCI artifact using skopeo copy\n echo \"Downloading OCI artifact using skopeo copy\"\n if ! retry skopeo copy --authfile ~/.docker/config.json \"docker://${imageanddigest}\" \"dir:${destination}\" 2>&1; then\n echo \"Failed to download OCI artifact \\\"$imageanddigest\\\". Skipping ClamAV scan!\"\n note=\"Task clamav-scan failed: Failed to download OCI artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n\n # Scan and process OCI artifact\n scan_and_process \"${destination}\" \"oci\" \"$IMAGE_DIGEST\" \"Scanning OCI artifact\"\n\n # Skip the container image processing path\n image_manifests=\"\"\n fi\n else\n echo \"Failed to inspect artifact \\\"$imageanddigest\\\". Unable to determine type.\"\n note=\"Task clamav-scan failed: Failed to inspect artifact \\\"$imageanddigest\\\". For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r \"ERROR\" -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\nfi\n\n# Process container images (existing logic)\nif [ -n \"$image_manifests\" ]; then\n echo \"Detected container image. Processing image manifests.\"\n if [ -s /work/logs/artifact-meta.json ]; then\n tmp=$(mktemp)\n if jq '.artifact.type = \"image\"' /work/logs/artifact-meta.json > \"$tmp\"; then\n mv \"$tmp\" /work/logs/artifact-meta.json || true\n fi\n fi\n # Proceed only if a specific arch is provided.\n # This typically occurs when using Tekton Matrix to launch multiple TaskRuns to scan all architectures of a multi-arch image in parallel.\n if [ -n \"$IMAGE_ARCH\" ]; then\n arch=\"${IMAGE_ARCH#*/}\"\n if [ \"${arch}\" = \"x86_64\" ]; then\n arch=\"amd64\"\n fi\n\n # Check if arch is supported; if not (e.g., it's 'local', see link below), default to amd64.\n # https://github.com/redhat-appstudio/infra-deployments/blob/main/components/multi-platform-controller/production/stone-prd-rh01/host-config.yaml#L9-L14\n case \"$arch\" in\n amd64|ppc64le|arm64|s390x)\n ;;\n *)\n arch=\"amd64\"\n ;;\n esac\n\n image_manifests=$(echo \"$image_manifests\" | jq -c --arg arch \"$arch\" '{($arch): .[$arch]}')\n fi\n\n while read -r arch arch_sha; do\n destination=\"content-${arch}\"\n mkdir -p \"$destination\"\n arch_imageanddigest=\"${imagewithouttag}@${arch_sha}\"\n\n echo \"Inspecting layers for arch $arch\"\n skip_log=\"\"\n layers=$(skopeo inspect --raw --authfile ~/.docker/config.json \\\n \"docker://${arch_imageanddigest}\" | jq -c '\n .layers[]? | {\n digest: (.digest // \"\"),\n size: ((.size // 0) | if type == \"number\" then . else 0 end),\n title: (.annotations[\"org.opencontainers.image.title\"] // \"\"),\n inpath: (.annotations[\"olot.layer.content.inlayerpath\"] // \"\")\n }') || layers=\"\"\n\n if [ -z \"${layers}\" ]; then\n echo \"Could not list layers; extracting full image\"\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \"$arch_imageanddigest\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract image for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n else\n skip_log=\"/work/logs/skipped-layers-${arch}.log\"\n : > \"$skip_log\"\n while IFS= read -r layer_json; do\n [ -z \"$layer_json\" ] && continue\n digest=$(jq -r '.digest' <<< \"$layer_json\")\n size=$(jq -r '.size' <<< \"$layer_json\")\n title=$(jq -r '.title' <<< \"$layer_json\")\n inpath=$(jq -r '.inpath' <<< \"$layer_json\")\n [ -z \"$digest\" ] && continue\n\n if layer_annotation_is_weight \"$title\" \"$inpath\"; then\n echo \"Skipping unscannable weight layer ${digest} (manifest ${title:-$inpath})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if { [ -n \"$title\" ] || [ -n \"$inpath\" ]; } && [ \"${size}\" -ge \"${CLAMAV_SKIP_BLOB_BYTES}\" ]; then\n echo \"Skipping unscannable layer ${digest} (manifest ${title:-$inpath}, size ${size})\" | tee -a \"$skip_log\"\n continue\n fi\n\n if [ -z \"$title\" ] && [ -z \"$inpath\" ]; then\n echo \"Listing layer ${digest}\"\n if listing=$(retry oc image extract --dry-run --confirm \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"); then\n if is_weight_only_layer \"${listing}\"; then\n echo \"Skipping unscannable weight layer ${digest}\" | tee -a \"$skip_log\"\n continue\n fi\n else\n echo \"Failed to list layer ${digest}; extracting it\"\n fi\n fi\n\n if ! retry oc image extract --confirm --only-files=true \\\n --registry-config ~/.docker/config.json \\\n \"${arch_imageanddigest}[~${digest}]\" \\\n --path=\"/:${destination}\" --filter-by-os=\"linux/${arch}\"; then\n echo \"Unable to extract layer ${digest} for arch $arch. Skipping ClamAV scan!\"\n exit 0\n fi\n done <<< \"$layers\"\n fi\n\n # Scan and process container image for this architecture\n scan_and_process \"${destination}\" \"$arch\" \"$arch_sha\" \"Scanning image for arch $arch\"\n\n if [ -s \"${skip_log}\" ]; then\n cat \"$skip_log\" >> \"/work/logs/clamscan-result-${arch}.log\"\n fi\n done < <(echo \"$image_manifests\" | jq -r 'to_entries[] | \"\\(.key) \\(.value)\"')\nfi\n\njq -s -rce '\n reduce .[] as $item ({\"timestamp\":\"0\",\"namespace\":\"\",\"successes\":0,\"failures\":0,\"warnings\":0,\"result\":\"\",\"note\":\"\"};\n {\n \"timestamp\" : (if .timestamp < $item.timestamp then $item.timestamp else .timestamp end),\n \"namespace\" : $item.namespace,\n \"successes\" : (.successes + $item.successes),\n \"failures\" : (.failures + $item.failures),\n \"warnings\" : (.warnings + $item.warnings),\n \"result\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.result else .result end),\n \"note\" : (if .result == \"\" or ($item.result == \"SKIPPED\" and .result == \"SUCCESS\") or ($item.result == \"WARNING\" and (.result == \"SUCCESS\" or .result == \"SKIPPED\")) or ($item.result == \"FAILURE\" and .result != \"ERROR\") or $item.result == \"ERROR\" then $item.note else .note end)\n })' /work/logs/clamscan-ec-test-*.json | tee \"/tekton/results/TEST_OUTPUT\"\n\n# If the image is an Image Index, also add the Image Index digest to the list.\nif [[ \"${digests_processed[*]}\" != *\"$IMAGE_DIGEST\"* ]]; then\n digests_processed+=(\"\\\"$IMAGE_DIGEST\\\"\")\nfi\n\ndigests_processed_string=$(IFS=,; echo \"${digests_processed[*]}\")\necho \"${images_processed_template/\\[%s]/[$digests_processed_string]}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n", | |
| "environment": { | |
| "container": "extract-and-scan-image", | |
| "image": "oci://quay.io/konflux-ci/clamav-db@sha256:60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -e\n\n# Skip upload if requested e.g. read-only CI tests where push access is denied\nif [ \"$SKIP_UPLOAD\" == \"true\" ]; then\n echo \"Upload skipped by parameter.\"\n exit 0\nfi\n\n# Don't return a glob expression when no matches are found\nshopt -s nullglob\n\ncd logs\n\nfor UPLOAD_FILE in clamscan-result*.log; do\n MEDIA_TYPE=text/vnd.clamav\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\nfor UPLOAD_FILE in clamscan-ec-test*.json; do\n MEDIA_TYPE=application/vnd.konflux.test_output+json\n args+=(\"${UPLOAD_FILE}:${MEDIA_TYPE}\")\ndone\n\nif [ ${#args[@]} -eq 0 ]; then\n echo \"No files found. Skipping upload.\"\n exit 0;\nfi\n\necho \"Selecting auth\"\nselect-oci-auth \"$IMAGE_URL\" > \"$HOME/auth.json\"\necho \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type application/vnd.clamav \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${args[@]}\"\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/task-runner@sha256:1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:33Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de" | |
| }, | |
| "entryPoint": "coverity-availability-check", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/83002330-c983-4a8f-96cf-c95f2c69f2f7", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-d63c04970b0dcebb-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "coverity-availability-check", | |
| "tekton.dev/task": "coverity-availability-check" | |
| } | |
| }, | |
| "parameters": { | |
| "AUTH_TOKEN_COVERITY_IMAGE": "auth-token-coverity-image", | |
| "COV_LICENSE": "cov-license" | |
| } | |
| }, | |
| "name": "coverity-availability-check", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "coverity-availability-check" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check:0.2@sha256:8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "STATUS", | |
| "type": "string", | |
| "value": "failed" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:27:33+00:00\",\"note\":\"Task coverity-availability-check failed: Coverity license expired on 2026-Apr-13 08:00:00 UTC\",\"namespace\":\"default\",\"successes\":0,\"failures\":1,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -eo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\n# Checking Coverity license\nCOV_LICENSE_PATH=/etc/secrets/cov/cov-license\nif [ -f \"${COV_LICENSE_PATH}\" ] && [ -s \"${COV_LICENSE_PATH}\" ]; then\n echo \"Coverity license detected!\"\n\n # Check license expiry\n EXPIRY_DATE=$(sed -n 's/.*<valid-until>\\(.*\\)<\\/valid-until>.*/\\1/p' \"${COV_LICENSE_PATH}\" || true)\n if [ -n \"$EXPIRY_DATE\" ]; then\n # Reformat \"2020-Jan-01 08:00:00 UTC\" -> \"01 Jan 2020 08:00:00 UTC\"\n DATE_PART=\"${EXPIRY_DATE%% *}\"\n TIME_PART=\"${EXPIRY_DATE#* }\"\n IFS=- read -r YEAR MON DAY <<< \"$DATE_PART\"\n EXPIRY_EPOCH=$(date -d \"$DAY $MON $YEAR $TIME_PART\" +%s 2>/dev/null || true)\n if [ -n \"$EXPIRY_EPOCH\" ]; then\n NOW_EPOCH=$(date +%s)\n if [ \"$NOW_EPOCH\" -gt \"$EXPIRY_EPOCH\" ]; then\n echo \"Coverity license expired on ${EXPIRY_DATE}\"\n note=\"Task coverity-availability-check failed: Coverity license expired on ${EXPIRY_DATE}\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\n fi\n DAYS_LEFT=$(( (EXPIRY_EPOCH - NOW_EPOCH) / 86400 ))\n if [ \"$DAYS_LEFT\" -lt 14 ]; then\n echo \"WARNING: Coverity license expires in ${DAYS_LEFT} days (${EXPIRY_DATE})\"\n else\n echo \"Coverity license valid until: ${EXPIRY_DATE}\"\n fi\n fi\n fi\nelse\n echo 'No license file for Coverity was detected. Coverity scan will not be executed...'\n echo 'Please, create a secret called 'cov-license' with a key called 'cov-license' and the value containing the Coverity license'\n note=\"Task coverity-availability-check failed: No license file for Coverity was detected. Please, create a secret called 'cov-license' with a key called 'cov-license' and the value containing the Coverity license\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\n# Checking authentication token for downloading coverity image\nAUTH_TOKEN_COVERITY_IMAGE_PATH=/etc/secrets/auth/config.json\nif [ -f \"${AUTH_TOKEN_COVERITY_IMAGE_PATH}\" ] && [ -s \"${AUTH_TOKEN_COVERITY_IMAGE_PATH}\" ]; then\n echo \"Authentication token detected!\"\nelse\n echo 'No authentication token for downloading Coverity image detected. Coverity scan will not be executed...'\n echo 'Please, create an imagePullSecret named 'auth-token-coverity-image' with the authentication token for pulling the Coverity image'\n note=\"Task coverity-availability-check failed: No authentication token for downloading Coverity image detected. Please, create an imagePullSecret named 'auth-token-coverity-image' with the authentication token for pulling the Coverity image\"\n TEST_OUTPUT=$(make_result_json -r FAILURE -t \"$note\" -f 1)\n echo -n \"failed\" | tee \"/tekton/results/STATUS\"\n echo \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 0\nfi\n\nnote=\"Task coverity-availability-check completed: Coverity availability checks finished succesfully.\"\n# shellcheck disable=SC2034\nTEST_OUTPUT=$(make_result_json -r SUCCESS -s 1 -t \"$note\")\necho -n \"success\" | tee \"/tekton/results/STATUS\"\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "coverity-availability-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:3bba1fe5ad96bd3811f34b367487192683aa9b1ba343da4885dda565b0a7207e" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index", | |
| "prefetch-dependencies" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:41Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e" | |
| }, | |
| "entryPoint": "sast-shell-check-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/9e86038e-55f3-4dcf-ba51-f9b430fea229", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-c9e2ddf090055c74-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "sast-shell-check", | |
| "tekton.dev/task": "sast-shell-check-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "CACHI2_ARTIFACT": "", | |
| "IMP_FINDINGS_ONLY": "true", | |
| "KFP_GIT_URL": "SITE_DEFAULT", | |
| "PROJECT_NAME": "", | |
| "RECORD_EXCLUDED": "false", | |
| "SKIP_JINJA": "true", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "TARGET_DIRS": ".", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "sast-shell-check", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "sast-shell-check-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"FAILURE\",\"timestamp\":\"2026-09-08T21:27:39+00:00\",\"note\":\"For details, check Tekton task log.\",\"namespace\":\"default\",\"successes\":0,\"failures\":2,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -x\n# shellcheck source=/dev/null\nsource /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nPACKAGE_VERSION=$(rpm -q --queryformat '%{NAME}-%{VERSION}-%{RELEASE}\\n' ShellCheck)\n\nOUTPUT_FILE=\"shellcheck-results.json\"\nSOURCE_CODE_DIR=/var/workdir/source\n\n# generate full path for each dirname separated by comma\ndeclare -a ALL_TARGETS\nIFS=\",\" read -ra TARGET_ARRAY <<<\"$TARGET_DIRS\"\nfor d in \"${TARGET_ARRAY[@]}\"; do\n potential_path=\"${SOURCE_CODE_DIR}/${d}\"\n\n resolved_path=$(realpath -m \"$potential_path\")\n\n # ensure resolved path is still within SOURCE_CODE_DIR\n if [[ \"$resolved_path\" == \"$SOURCE_CODE_DIR\"* ]]; then\n ALL_TARGETS+=(\"$resolved_path\")\n else\n echo \"Error: path traversal attempt, '$potential_path' is outside '$SOURCE_CODE_DIR'\"\n exit 1\n fi\ndone\n\n# determine number of available CPU cores for shellcheck based on container cgroup v2 CPU limits\n# this calculates the ceiling, so if the cpu limit is 0.5, the number of jobs will be 1.\nif [ -z \"$SC_JOBS\" ] && [ -r \"/sys/fs/cgroup/cpu.max\" ]; then\n read -r quota period </sys/fs/cgroup/cpu.max\n if [ \"$quota\" != \"max\" ] && [ -n \"$period\" ] && [ \"$period\" -gt 0 ]; then\n export SC_JOBS=$(((quota + period - 1) / period))\n echo \"INFO: Setting SC_JOBS=${SC_JOBS} based on cgroups v2 max for run-shellcheck.sh\"\n fi\nfi\n\nif [[ \"${SKIP_JINJA}\" == \"true\" ]]; then\n export SC_SKIP_JINJA=1\nfi\n\n# generate all shellcheck result JSON files to $SC_RESULTS_DIR, which defaults to ./shellcheck-results/\n/usr/share/csmock/scripts/run-shellcheck.sh \"${ALL_TARGETS[@]}\"\n\nCSGREP_OPTS=(\n --mode=json\n --strip-path-prefix=\"$SOURCE_CODE_DIR\"/\n --remove-duplicates\n --embed-context=3\n --set-scan-prop=\"ShellCheck:${PACKAGE_VERSION}\"\n)\nif [[ \"$IMP_FINDINGS_ONLY\" == \"true\" ]]; then\n # predefined list of shellcheck important findings\n CSGREP_EVENT_FILTER='\\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|'\n CSGREP_EVENT_FILTER+='2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|'\n CSGREP_EVENT_FILTER+='2218|2224|2225|2242|2256|2258|2261)\\]$'\n CSGREP_OPTS+=(\n --event=\"$CSGREP_EVENT_FILTER\"\n )\nelse\n CSGREP_OPTS+=(\n --event=\"error|warning\"\n )\nfi\n\nif ! csgrep \"${CSGREP_OPTS[@]}\" ./shellcheck-results/*.json >\"$OUTPUT_FILE\"; then\n echo \"Error occurred while running 'run-shellcheck.sh'\"\n note=\"Task sast-shell-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\nif [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\nfi\nPROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n# create the KFP clone directory regardless\nKFP_DIR=\"known-false-positives\"\nKFP_CLONED=\"0\"\nmkdir \"${KFP_DIR}\"\n\n# We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\nif [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\nfi\n\nif [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\nelse\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n # build initial csfilter-kfp command\n csfilter_kfp_cmd=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n if [[ \"${RECORD_EXCLUDED}\" == \"true\" ]]; then\n csfilter_kfp_cmd+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n # Execute the command and capture any errors\n set +e\n \"${csfilter_kfp_cmd[@]}\" \"${OUTPUT_FILE}\" >\"${OUTPUT_FILE}.filtered\" 2>\"${OUTPUT_FILE}.error\"\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n else\n mv \"${OUTPUT_FILE}.filtered\" \"$OUTPUT_FILE\"\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\nfi\n\necho \"ShellCheck results have been saved to $OUTPUT_FILE\"\n\ncsgrep --mode=evtstat \"$OUTPUT_FILE\"\ncsgrep \"$OUTPUT_FILE\"\ncsgrep --mode=sarif \"$OUTPUT_FILE\" >shellcheck-results.sarif\n\nTEST_OUTPUT=\nparse_test_output \"sast-shell-check-oci-ta\" sarif shellcheck-results.sarif || true\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "sast-shell-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -e\n\nif [ -z \"${IMAGE_URL}\" ] || [ -z \"${IMAGE_DIGEST}\" ]; then\n echo 'No image-url or image-digest param provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"shellcheck-results.sarif excluded-findings.json\"\n\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n\n # Determine the media type based on the file extension\n if [[ \"${UPLOAD_FILE}\" == *.json ]]; then\n MEDIA_TYPE=\"application/json\"\n else\n MEDIA_TYPE=\"application/sarif+json\"\n fi\n\n echo \"Selecting auth\"\n select-oci-auth \"$IMAGE_URL\" >\"$HOME/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n if ! retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"; then\n echo \"Failed to attach ${UPLOAD_FILE} to ${IMAGE_URL}\"\n exit 1\n fi\ndone\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index", | |
| "prefetch-dependencies" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:52Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89" | |
| }, | |
| "entryPoint": "sast-unicode-check-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/6892d670-2189-4461-945f-3b495f84a1de", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-ed77e098fa96e2c2-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "sast-unicode-check", | |
| "tekton.dev/task": "sast-unicode-check-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "CACHI2_ARTIFACT": "", | |
| "FIND_UNICODE_CONTROL_ARGS": "-p bidi -v -d -t", | |
| "KFP_GIT_URL": "SITE_DEFAULT", | |
| "PROJECT_NAME": "", | |
| "RECORD_EXCLUDED": "false", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "TARGET_DIRS": ".", | |
| "caTrustConfigMapKey": "ca-bundle.crt", | |
| "caTrustConfigMapName": "trusted-ca", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "sast-unicode-check", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "sast-unicode-check-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.4@sha256:381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:27:50+00:00\",\"note\":\"Task sast-unicode-check-oci-ta success: No finding was detected\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\nset -exuo pipefail\n\n# shellcheck source=/dev/null\n. /utils.sh\ntrap 'handle_error /tekton/results/TEST_OUTPUT' EXIT\n\nif [[ -z \"${PROJECT_NAME}\" ]]; then\n PROJECT_NAME=${COMPONENT_LABEL}\nfi\n\necho \"INFO: The PROJECT_NAME used is: ${PROJECT_NAME}\"\n\nca_bundle=/mnt/trusted-ca/ca-bundle.crt\nif [ -f \"$ca_bundle\" ]; then\n echo \"INFO: Using mounted CA bundle: $ca_bundle\"\n cp -vf $ca_bundle /etc/pki/ca-trust/source/anchors\n update-ca-trust\nfi\n\nSCAN_PROP=\"https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58\"\nFUC_EXIT_CODE=0\n\n# generate full path for each dirname separated by comma\ndeclare -a ALL_TARGETS\nOLD_IFS=\"$IFS\"\nIFS=\",\"\nfor d in $TARGET_DIRS; do\n ALL_TARGETS+=(\"${SOURCE_CODE_DIR}/source/${d}\")\ndone\nIFS=\"$OLD_IFS\"\n\n# shellcheck disable=SC2086\nLANG=en_US.utf8 find_unicode_control.py ${FIND_UNICODE_CONTROL_ARGS} \"${ALL_TARGETS[@]}\" \\\n >raw_sast_unicode_check_out.txt \\\n 2>raw_sast_unicode_check_out.log ||\n FUC_EXIT_CODE=$?\nif [[ \"${FUC_EXIT_CODE}\" -ne 0 ]] && [[ \"${FUC_EXIT_CODE}\" -ne 1 ]]; then\n echo \"Failed to run find-unicode-control command\" >&2\n cat raw_sast_unicode_check_out.log\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\n# Translate the output format\nif ! sed -i raw_sast_unicode_check_out.txt -E -e 's|(.*:[0-9]+)(.*)|\\1: warning:\\2|' -e 's|^|Error: UNICONTROL_WARNING:\\n|'; then\n echo \"Error: failed to translate the unicontrol output format\" >&2\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\n# Process all results as configured with CSGERP_OPTS\nCSGERP_OPTS=(\n --mode=json\n --remove-duplicates\n --embed-context=3\n --set-scan-prop=\"${SCAN_PROP}\"\n --strip-path-prefix=\"${SOURCE_CODE_DIR}\"/source/\n)\n# In order to generate csdiff/v1, we need to add the whole path of the source code as\n# sast-unicode-check only provides an URI to embed the context\nif ! csgrep \"${CSGERP_OPTS[@]}\" raw_sast_unicode_check_out.txt >processed_sast_unicode_check_out.json 2>processed_sast_unicode_check_out.err; then\n echo \"Error occurred while running csgrep with CSGERP_OPTS:\"\n cat processed_sast_unicode_check_out.err\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n echo \"${ERROR_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\n exit 1\nfi\n\ncsgrep --mode=evtstat processed_sast_unicode_check_out.json\ncsgrep processed_sast_unicode_check_out.json\n\nif [[ \"${KFP_GIT_URL}\" == \"SITE_DEFAULT\" ]]; then\n KFP_GIT_URL=\"https://gitlab.cee.redhat.com/osh/known-false-positives.git\"\nfi\nPROBE_URL=\"${KFP_GIT_URL%.git}\" # trims '.git' suffix\n\n# create the KFP clone directory regardless\nKFP_DIR=\"known-false-positives\"\nKFP_CLONED=\"0\"\nmkdir \"${KFP_DIR}\"\n\n# We check if the KFP_GIT_URL variable is set to clone and apply the filters or not\nif [[ -n \"${KFP_GIT_URL}\" ]]; then\n # Default location only reachable from internal Konflux instances, check reachable first\n echo -n \"INFO: Probing ${PROBE_URL}... \"\n if curl --fail --head --max-time 60 --no-progress-meter \"${PROBE_URL}\" > >(head -1); then\n echo \"INFO: Trying to clone known-false-positives..\"\n git clone \"${KFP_GIT_URL}\" \"${KFP_DIR}\" && KFP_CLONED=\"1\"\n fi\nfi\n\n# If KFP clone failed, use the unfiltered results\nif [[ \"${KFP_CLONED}\" -eq \"0\" ]]; then\n echo \"WARN: Failed to clone known-false-positives at ${KFP_GIT_URL}, scan results will not be filtered\"\n mv processed_sast_unicode_check_out.json sast_unicode_check_out.json\nelse\n echo \"INFO: Filtering false positives in results files using csfilter-kfp...\"\n\n # Build initial csfilter-kfp command\n csfilter_kfp_cmd=(\n csfilter-kfp\n --verbose\n --kfp-dir=\"${KFP_DIR}\"\n --project-nvr=\"${PROJECT_NAME}\"\n )\n\n # Append --record-excluded option if RECORD_EXCLUDED is true\n if [[ \"${RECORD_EXCLUDED}\" == \"true\" ]]; then\n csfilter_kfp_cmd+=(--record-excluded=\"excluded-findings.json\")\n fi\n\n # Execute the command and capture any errors\n set +e\n \"${csfilter_kfp_cmd[@]}\" processed_sast_unicode_check_out.json >sast_unicode_check_out.json 2>sast_unicode_check_out.error\n status=$?\n set -e\n if [ \"$status\" -ne 0 ]; then\n echo \"WARN: failed to filter known false positives\" >&2\n mv processed_sast_unicode_check_out.json sast_unicode_check_out.json\n else\n echo \"INFO: Succeeded filtering known false positives\" >&2\n fi\nfi\n\n# Generate sarif report\ncsgrep --mode=sarif sast_unicode_check_out.json >sast_unicode_check_out.sarif\nif [[ \"${FUC_EXIT_CODE}\" -eq 0 ]]; then\n note=\"Task sast-unicode-check-oci-ta success: No finding was detected\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelif [[ \"${FUC_EXIT_CODE}\" -eq 1 ]] && [[ ! -s sast_unicode_check_out.sarif ]]; then\n note=\"Task sast-unicode-check-oci-ta success: Some findings were detected, but filtered by known false positive\"\n ERROR_OUTPUT=$(make_result_json -r SUCCESS -t \"$note\")\nelse\n echo \"sast-unicode-check test failed because of the following issues:\"\n cat sast_unicode_check_out.json\n TEST_OUTPUT=\n parse_test_output \"sast-unicode-check-oci-ta\" sarif sast_unicode_check_out.sarif || true\n note=\"Task sast-unicode-check-oci-ta failed: For details, check Tekton task log.\"\n ERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/results/TEST_OUTPUT\"\n", | |
| "environment": { | |
| "container": "sast-unicode-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/usr/bin/env bash\n\nif [ -z \"${IMAGE_URL}\" ]; then\n echo 'No image-url param provided. Skipping upload.'\n exit 0\nfi\n\nUPLOAD_FILES=\"sast_unicode_check_out.sarif excluded-findings.json\"\nfor UPLOAD_FILE in ${UPLOAD_FILES}; do\n if [ ! -f \"${UPLOAD_FILE}\" ]; then\n echo \"No ${UPLOAD_FILE} exists. Skipping upload.\"\n continue\n fi\n\n if [ \"${UPLOAD_FILE}\" == \"excluded-findings.json\" ]; then\n MEDIA_TYPE=application/json\n else\n MEDIA_TYPE=application/sarif+json\n fi\n\n echo \"Selecting auth\"\n select-oci-auth \"${IMAGE_URL}\" >\"${HOME}/auth.json\"\n echo \"Attaching to ${IMAGE_URL}\"\n retry oras attach --no-tty --registry-config \"$HOME/auth.json\" --artifact-type \"${MEDIA_TYPE}\" \"${IMAGE_URL}@${IMAGE_DIGEST}\" \"${UPLOAD_FILE}:${MEDIA_TYPE}\"\ndone\n", | |
| "environment": { | |
| "container": "upload", | |
| "image": "oci://quay.io/konflux-ci/oras@sha256:1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:33Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba" | |
| }, | |
| "entryPoint": "apply-tags", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-apply-tags" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/725fcc7c-b3f3-427e-8b1d-82ce14630493", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "konflux", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f5158b6e5a84f4e7-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "apply-tags", | |
| "tekton.dev/task": "apply-tags" | |
| } | |
| }, | |
| "parameters": { | |
| "ADDITIONAL_TAGS": [ | |
| "rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3" | |
| ], | |
| "CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "CA_TRUST_CONFIG_MAP_NAME": "trusted-ca", | |
| "IMAGE_DIGEST": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "IMAGE_URL": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "LOG_LEVEL": "info" | |
| } | |
| }, | |
| "name": "apply-tags", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "apply-tags" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-apply-tags:0.3.1@sha256:ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--image-url", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "--digest", | |
| "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "--tags", | |
| "rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "--tags-from-image-label", | |
| "konflux.additional-tags" | |
| ], | |
| "entryPoint": "konflux-build-cli image apply-tags", | |
| "environment": { | |
| "container": "apply-additional-tags", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index", | |
| "prefetch-dependencies" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:36Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548" | |
| }, | |
| "entryPoint": "push-dockerfile-oci-ta", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/2d97a744-fa45-41d3-b276-5196f162b51f", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/pipelines.minVersion": "0.12.1", | |
| "tekton.dev/tags": "image-build, appstudio", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-cc9c6f3b286a8eef-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "build.appstudio.redhat.com/build_type": "docker", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "push-dockerfile", | |
| "tekton.dev/task": "push-dockerfile-oci-ta" | |
| } | |
| }, | |
| "parameters": { | |
| "ARTIFACT_TYPE": "application/vnd.konflux.dockerfile", | |
| "CA_TRUST_CONFIG_MAP_KEY": "ca-bundle.crt", | |
| "CA_TRUST_CONFIG_MAP_NAME": "trusted-ca", | |
| "CONTEXT": ".", | |
| "DOCKERFILE": "Dockerfiles/agent.Dockerfile.konflux", | |
| "IMAGE": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "IMAGE_DIGEST": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "LOG_LEVEL": "info", | |
| "SOURCE_ARTIFACT": "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735", | |
| "TAG_SUFFIX": ".dockerfile" | |
| } | |
| }, | |
| "name": "push-dockerfile", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "push-dockerfile-oci-ta" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta:0.3.1@sha256:ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGE_REF", | |
| "type": "string", | |
| "value": "quay.io/rhoai/odh-kserve-agent-rhel9@sha256:90de7875a003ab5f8ed0a1aeb49e8b9a34b4416d5a171c2932c34a75f0c44239" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "use", | |
| "oci:quay.io/rhoai/odh-kserve-agent-rhel9@sha256:19f338c16f6217443fd5b7239b809e3c1d05d3e5571ef27eff732be5f2211735=/var/workdir/source" | |
| ], | |
| "entryPoint": "", | |
| "environment": { | |
| "container": "use-trusted-artifact", | |
| "image": "oci://quay.io/konflux-ci/build-trusted-artifacts@sha256:61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "--source", | |
| "source", | |
| "--context", | |
| ".", | |
| "--containerfile", | |
| "Dockerfiles/agent.Dockerfile.konflux", | |
| "--image-url", | |
| "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "--image-digest", | |
| "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "--artifact-type", | |
| "application/vnd.konflux.dockerfile", | |
| "--tag-suffix", | |
| ".dockerfile", | |
| "--result-path-image-ref", | |
| "/tekton/results/IMAGE_REF", | |
| "--alternative-filename", | |
| "Dockerfile" | |
| ], | |
| "entryPoint": "konflux-build-cli image push-containerfile", | |
| "environment": { | |
| "container": "push", | |
| "image": "oci://quay.io/konflux-ci/konflux-build-cli@sha256:85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:33Z", | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha256": "9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8" | |
| }, | |
| "entryPoint": "rpms-signature-scan", | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/998e5fb3-98fd-468f-ba01-3db94e80630e", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-6ba848dd68d4388b-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "rpms-signature-scan", | |
| "tekton.dev/task": "rpms-signature-scan" | |
| } | |
| }, | |
| "parameters": { | |
| "ca-trust-config-map-key": "ca-bundle.crt", | |
| "ca-trust-config-map-name": "trusted-ca", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "workdir": "/tmp" | |
| } | |
| }, | |
| "name": "rpms-signature-scan", | |
| "ref": { | |
| "params": [ | |
| { | |
| "name": "name", | |
| "value": "rpms-signature-scan" | |
| }, | |
| { | |
| "name": "bundle", | |
| "value": "quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan:0.2.2@sha256:9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8" | |
| }, | |
| { | |
| "name": "kind", | |
| "value": "task" | |
| } | |
| ], | |
| "resolver": "bundles" | |
| }, | |
| "results": [ | |
| { | |
| "name": "IMAGES_PROCESSED", | |
| "type": "string", | |
| "value": "{\"image\": {\"pullspec\": \"quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25\", \"digests\": [\"sha256:7aece482d1b41909c6b97bf6e2dbf4279a85f0b683a85e63109a9c4137e8604f\", \"sha256:740b874d1100b1af247da587ae71eaa292dd940f75a77edaede4797fb740f93b\", \"sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532\", \"sha256:cb072ae3a46790ba353edac7f9e08095f204710bf3dbd62faaa9c19ec1534c35\", \"sha256:6009f92c7357c68da61d38022144223751edd3aa082579c91d650b70df5fcb75\"]}}\n" | |
| }, | |
| { | |
| "name": "RPMS_DATA", | |
| "type": "string", | |
| "value": "{\"keys\": {\"199e2f91fd431d51\": 424, \"unsigned\": 0}}\n" | |
| }, | |
| { | |
| "name": "SCAN_LOG", | |
| "type": "string", | |
| "value": "" | |
| }, | |
| { | |
| "name": "TEST_OUTPUT", | |
| "type": "string", | |
| "value": "{\"result\":\"SUCCESS\",\"timestamp\":\"2026-09-08T21:28:31+00:00\",\"note\":\"Task rpms-signature-scan completed successfully\",\"namespace\":\"default\",\"successes\":0,\"failures\":0,\"warnings\":0}\n" | |
| } | |
| ], | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -ex\nset -o pipefail\n\nrpm_verifier \\\n --image-url \"${IMAGE_URL}\" \\\n --image-digest \"${IMAGE_DIGEST}\" \\\n --workdir \"${WORKDIR}\" \\\n 2> >(tee \"${WORKDIR}/stderr\" >&2)\n", | |
| "environment": { | |
| "container": "rpms-signature-scan", | |
| "image": "oci://quay.io/konflux-ci/tools@sha256:69102586287b89a162f7eaf4cded2db44a0df41da17016aacc4fadffa5490b6b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "#!/bin/bash\nset -ex\n\nsource /utils.sh\nstatus=$(cat \"${WORKDIR}\"/status)\nrpms_data=$(cat \"${WORKDIR}\"/results)\nimages_processed=$(cat \"${WORKDIR}\"/images_processed)\n\nif [ \"$status\" == \"ERROR\" ]; then\n note=\"Task rpms-signature-scan failed to scan images. Refer to Tekton task output for details\"\nelse\n note=\"Task rpms-signature-scan completed successfully\"\nfi\n\nTEST_OUTPUT=$(make_result_json -r \"$status\" -t \"$note\")\n\necho \"${TEST_OUTPUT}\" | tee \"/tekton/results/TEST_OUTPUT\"\necho \"${rpms_data}\" | tee \"/tekton/results/RPMS_DATA\"\necho \"${images_processed}\" | tee \"/tekton/results/IMAGES_PROCESSED\"\n\nif [ -f \"${WORKDIR}/stderr\" ]; then\n head -c 4000 \"${WORKDIR}/stderr\" | tee \"/tekton/results/SCAN_LOG\"\nelse\n echo \"\" > \"/tekton/results/SCAN_LOG\"\nfi\n", | |
| "environment": { | |
| "container": "output-results", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:41Z", | |
| "invocation": { | |
| "configSource": {}, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/d16bf159-2c4c-46d6-a636-e756287105c5", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-703b8e79215d52d3-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "fips-check" | |
| } | |
| }, | |
| "parameters": { | |
| "blocking": "true", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/x86_64", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "fips-check", | |
| "ref": {}, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n", | |
| "environment": { | |
| "container": "prepare-image-list", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "-s", | |
| "--", | |
| "bash", | |
| "-c", | |
| "set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-0 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-0 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n" | |
| ], | |
| "entryPoint": "/usr/bin/tini", | |
| "environment": { | |
| "container": "run-fips-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n", | |
| "environment": { | |
| "container": "evaluate-result", | |
| "image": "oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:41Z", | |
| "invocation": { | |
| "configSource": {}, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/e8495340-f9f9-418c-a72a-d02c1044501c", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-546c798d5d232205-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "fips-check" | |
| } | |
| }, | |
| "parameters": { | |
| "blocking": "true", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/ppc64le", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "fips-check", | |
| "ref": {}, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n", | |
| "environment": { | |
| "container": "prepare-image-list", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "-s", | |
| "--", | |
| "bash", | |
| "-c", | |
| "set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-1 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-1 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n" | |
| ], | |
| "entryPoint": "/usr/bin/tini", | |
| "environment": { | |
| "container": "run-fips-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n", | |
| "environment": { | |
| "container": "evaluate-result", | |
| "image": "oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:40Z", | |
| "invocation": { | |
| "configSource": {}, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/100f073d-abce-4d9e-a705-ca29cb130d40", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-c80b1b3d661e34a6-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "fips-check" | |
| } | |
| }, | |
| "parameters": { | |
| "blocking": "true", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux/s390x", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "fips-check", | |
| "ref": {}, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n", | |
| "environment": { | |
| "container": "prepare-image-list", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "-s", | |
| "--", | |
| "bash", | |
| "-c", | |
| "set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-2 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-2 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n" | |
| ], | |
| "entryPoint": "/usr/bin/tini", | |
| "environment": { | |
| "container": "run-fips-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n", | |
| "environment": { | |
| "container": "evaluate-result", | |
| "image": "oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-image-index" | |
| ], | |
| "finishedOn": "2026-09-08T21:27:41Z", | |
| "invocation": { | |
| "configSource": {}, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/f96d4cd3-f1c1-4daa-85bf-a5d6f4128155", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-b8c48302b03ceff6-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "fips-check" | |
| } | |
| }, | |
| "parameters": { | |
| "blocking": "true", | |
| "image-digest": "sha256:c8decae0508655b27aaa8f7a34e13c1650b15f563ede557a1d62f56c753c6532", | |
| "image-platform": "linux-m2xlarge/arm64", | |
| "image-url": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25" | |
| } | |
| }, | |
| "name": "fips-check", | |
| "ref": {}, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:27:28Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "ARCH=\"${IMAGE_PLATFORM#*/}\"\nif [ \"${ARCH}\" = \"x86_64\" ]; then ARCH=\"amd64\"; fi\ncase \"${ARCH}\" in\n amd64|ppc64le|arm64|s390x) ;;\n *) ARCH=\"amd64\" ;;\nesac\nIMAGE_WITHOUT_TAG=$(echo \"${IMAGE_URL}\" | sed 's/\\(.*\\):.*/\\1/')\nPLATFORM_DIGEST=$(skopeo inspect --raw \"docker://${IMAGE_WITHOUT_TAG}@${IMAGE_DIGEST}\" | jq -r \".manifests[] | select(.platform.architecture == \\\"${ARCH}\\\") | .digest\")\nif [ -z \"${PLATFORM_DIGEST}\" ]; then\n echo \"Could not find digest for architecture ${ARCH} in ${IMAGE_URL}@${IMAGE_DIGEST}\"\n exit 1\nfi\nprintf '%s' \"${IMAGE_WITHOUT_TAG}@${PLATFORM_DIGEST}\" > /tekton/home/unique_related_images.txt\n", | |
| "environment": { | |
| "container": "prepare-image-list", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": [ | |
| "-s", | |
| "--", | |
| "bash", | |
| "-c", | |
| "set -euo pipefail\n# shellcheck source=/dev/null\n. /utils.sh\n\nexport RETRY_COUNT=2\nexport RETRY_INTERVAL=5\n\n# Create temporary directory for parallel processing counters\ncounter_dir=$(mktemp -d)\ntrap 'rm -rf \"$counter_dir\"' EXIT\n\n# Function to clean up OCI image and extracted directory\ncleanup_image_artifacts() {\n local image_num=\"$1\"\n local component_label=\"$2\"\n local version_label=\"$3\"\n local release_label=\"$4\"\n # Clean up OCI directory (may already be deleted by inline rm, or may not exist)\n rm -rf \"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n # Clean up extracted directory (may or may not exist depending on failure point)\n rm -rf \"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" 2>/dev/null || true\n}\n\n# Function to process a single related image\nprocess_image() {\n # shellcheck source=/dev/null\n . /utils.sh\n\n local related_image=\"$1\"\n local image_num=\"$2\"\n local total_images=\"$3\"\n local check_payload_version=\"$4\"\n local image_mirror_map=\"$5\"\n\n related_image=\"${related_image//$'\\n'/}\"\n echo \"Processing related image ${image_num} of ${total_images}: ${related_image}\"\n\n image_accessible=0\n if ! image_labels=$(get_image_labels \"$related_image\"); then\n echo \"Could not inspect original pullspec $related_image. Checking if there's a mirror present\"\n if [ -n \"${image_mirror_map}\" ]; then\n reg_and_repo=$(get_image_registry_and_repository \"${related_image}\")\n mapfile -t mirrors < <(get_image_mirror_list \"${reg_and_repo}\" \"${image_mirror_map}\")\n if [[ -z \"${mirrors[0]}\" ]]; then\n echo \"No mirrors found in image mirror map for ${reg_and_repo}\"\n else\n echo \"Mirrors for $reg_and_repo are:\"\n printf \"%s\\n\" \"${mirrors[@]}\"\n\n for mirror in \"${mirrors[@]}\"; do\n echo \"Attempting to use mirror ${mirror}\"\n replaced_image=$(replace_image_pullspec \"$related_image\" \"$mirror\")\n if ! image_labels=$(get_image_labels \"$replaced_image\"); then\n echo \"Mirror $mirror is inaccessible.\"\n continue\n fi\n image_accessible=1\n echo \"Replacing $related_image with $replaced_image\"\n related_image=\"$replaced_image\"\n break\n done\n fi\n fi\n else\n image_accessible=1\n echo \"Successfully inspected $related_image. Mirror not required.\"\n fi\n\n if [[ $image_accessible -eq 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not inspect image ${related_image} for labels\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n component_label=$(echo \"${image_labels}\" | grep 'com.redhat.component=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n version_label=$(echo \"${image_labels}\" | grep '^version=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n release_label=$(echo \"${image_labels}\" | grep 'release=' | cut -d= -f2 | tr -d '\\n\\r' | xargs || true)\n echo \"Component label is ${component_label}\"\n echo \"Version label is ${version_label}\"\n echo \"Release label is ${release_label}\"\n\n # Sanitize component_label to prevent directory path issues\n # Replace problematic characters (/ \\ : * ? \" < > | and whitespace) with hyphens\n sanitized_component_label=$(echo -n \"${component_label}\" | tr '/\\\\:*?\"<>|[:space:]' '-')\n echo \"Sanitized component label for path usage: ${component_label} -> ${sanitized_component_label}\"\n component_label=\"${sanitized_component_label}\"\n\n if [ -z \"${component_label}\" ]; then\n echo -e \"Error: Unable to scan image: Could not get com.redhat.component label for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Sanitize the image reference to handle Docker references with both tag and digest\n sanitized_related_image=$(get_image_registry_repository_digest \"${related_image}\")\n\n # If no digest is present, fallback to using tag-based sanitization\n if [[ \"${sanitized_related_image}\" != *\"@\"* ]]; then\n echo \"No digest found in sanitized image, using tag-based sanitization\"\n sanitized_related_image=$(get_image_registry_repository_tag \"${related_image}\")\n fi\n echo \"Successfully sanitized image reference: ${sanitized_related_image}. Using sanitized image reference for extraction\"\n\n # Fetch the first available architecture so that the skopeo copy does not fail if the default arch is not available\n first_arch=$(get_first_arch \"${sanitized_related_image}\")\n echo \"Detected architecture for ${sanitized_related_image}: ${first_arch}\"\n\n # Create destination directory for extraction\n extract_dir=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\"\n mkdir -p \"${extract_dir}\"\n\n # Extract image filesystem using oc image extract, with fallback to skopeo+umoci\n # oc image extract may fail with large images under high parallelism\n extraction_success=1\n if oc image extract \"${sanitized_related_image}\" \\\n --path=/:\"${extract_dir}\" \\\n --filter-by-os=\".*/${first_arch}\" \\\n --confirm \\\n --preserve-ownership; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using oc image extract\"\n else\n echo \"oc image extract failed for ${related_image}, falling back to skopeo+umoci\"\n # Clean up partial extraction before fallback\n rm -rf \"${extract_dir}\" 2>/dev/null || true\n mkdir -p \"${extract_dir}\"\n\n # Fallback: use skopeo copy + umoci unpack\n oci_dir=\"/tekton/home/${image_num}-${component_label}-${version_label}-${release_label}\"\n if retry skopeo copy --override-arch \"${first_arch}\" --remove-signatures \\\n \"docker://${sanitized_related_image}\" \\\n \"oci://${oci_dir}:latest\"; then\n if retry umoci raw unpack --rootless \\\n --image \"${oci_dir}:latest\" \\\n \"${extract_dir}\"; then\n extraction_success=0\n echo \"Successfully extracted ${related_image} using skopeo+umoci fallback\"\n else\n echo \"umoci unpack failed for ${related_image}\"\n fi\n # Clean up OCI image regardless of umoci success\n rm -rf \"${oci_dir}\" 2>/dev/null || true\n else\n echo \"skopeo copy failed for ${related_image}\"\n fi\n fi\n\n if [[ \"${extraction_success}\" -ne 0 ]]; then\n echo -e \"Error: Unable to scan image: Could not extract filesystem from ${related_image}\\n\"\n # Clean up any partial extracted directory to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/error\"\n return\n fi\n\n # Run check-payload on the extracted image\n # The check-payload command fails with exit 1 when the scan for an image is unsuccessful\n # or when the image is not FIPS compliant. Hence, count those as failures and not errors\n if ! check-payload scan local \\\n --path=\"/tekton/home/unpacked-${image_num}-${component_label}-${version_label}-${release_label}\" \\\n \"${check_payload_version}\" \\\n --components=\"${component_label}\" \\\n --output-format=csv \\\n --output-file=\"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan failed for ${related_image}\\n\"\n # Clean up extracted directory on scan failure to prevent resource accumulation\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n echo \"1\" >> \"${counter_dir}/failure\"\n return\n fi\n\n if [ -f \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\" ]; then\n if grep -q -- \"---- Successful run\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/success\"\n # Clean up extracted directory on successful run to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n elif grep -q -- \"---- Successful run with warnings\" \"/tekton/home/report-${image_num}-${component_label}-${version_label}-${release_label}.csv\"; then\n echo -e \"check-payload scan was successful with warnings for ${related_image}\\n\"\n echo \"1\" >> \"${counter_dir}/warnings\"\n # Clean up extracted directory on successful run with warnings to save space\n cleanup_image_artifacts \"${image_num}\" \"${component_label}\" \"${version_label}\" \"${release_label}\"\n fi\n fi\n}\n\nif [ ! -e \"/tekton/home/unique_related_images.txt\" ]; then\n echo \"No relatedImages to process\"\n exit 0\nfi\n\nmapfile -d ' ' -t related_images < <(cat /tekton/home/unique_related_images.txt)\necho \"Related images are :\"\nprintf \"%s\\n\" \"${related_images[@]}\"\n\n# If target OCP version is found, use it to apply the exception list when running check-payload\ncheck_payload_version=\"\"\nif [ -f \"/tekton/home/target_ocp_version.txt\" ]; then\n version=$(cat \"/tekton/home/target_ocp_version.txt\")\n check_payload_version=\"-V=${version}\"\n echo \"Target OCP version found: ${check_payload_version}\"\nfi\n\n# Check if an image to mirror map is defined for unreleased images\nimage_mirror_map=\"\"\nif [ -f \"/tekton/home/related-images-map.txt\" ]; then\n image_mirror_map=$(cat \"/tekton/home/related-images-map.txt\")\n echo \"Image Mirror Map found:\"\n echo \"${image_mirror_map}\" | jq '.'\nfi\n\n# Process images in parallel with MAX_PARALLEL limit\necho \"Processing ${#related_images[@]} images with MAX_PARALLEL=${MAX_PARALLEL}\"\ndeclare -i count=0\nfor related_image in \"${related_images[@]}\"; do\n count+=1\n # Wait if we've reached the parallel limit\n while [ \"$(jobs -r | wc -l)\" -ge \"${MAX_PARALLEL}\" ]; do\n wait -n\n done\n # Launch background job to process image\n process_image \"$related_image\" \"$count\" \"${#related_images[@]}\" \"$check_payload_version\" \"$image_mirror_map\" &\ndone\n\n# Wait for all background jobs to complete\nwait\n\n# Aggregate results from counter files\nsuccess_counter=0\nwarnings_counter=0\nerror_counter=0\nfailure_counter=0\n\nif [ -f \"${counter_dir}/success\" ]; then\n success_counter=$(wc -l < \"${counter_dir}/success\")\nfi\nif [ -f \"${counter_dir}/warnings\" ]; then\n warnings_counter=$(wc -l < \"${counter_dir}/warnings\")\nfi\nif [ -f \"${counter_dir}/error\" ]; then\n error_counter=$(wc -l < \"${counter_dir}/error\")\nfi\nif [ -f \"${counter_dir}/failure\" ]; then\n failure_counter=$(wc -l < \"${counter_dir}/failure\")\nfi\n\necho \"Results: success=${success_counter}, warnings=${warnings_counter}, errors=${error_counter}, failures=${failure_counter}\"\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-3 failed: Some images could not be scanned. For details, check Tekton task log.\"\nERROR_OUTPUT=$(make_result_json -r ERROR -t \"$note\")\n\nnote=\"Task odh-kserve-agent-v2-25-on-push-xwfsp-fips-check-3 completed: Check result for task result.\"\nif [[ \"$error_counter\" == 0 ]];\nthen\n if [[ \"${failure_counter}\" -gt 0 ]]; then\n RES=\"FAILURE\"\n elif [[ \"${warnings_counter}\" -gt 0 ]]; then\n RES=\"WARNING\"\n else\n RES=\"SUCCESS\"\n fi\n TEST_OUTPUT=$(make_result_json \\\n -r \"${RES}\" \\\n -s \"${success_counter}\" -f \"${failure_counter}\" -w \"${warnings_counter}\" -t \"$note\")\nfi\necho \"${TEST_OUTPUT:-${ERROR_OUTPUT}}\" | tee \"/tekton/steps/step-run-fips-check/results/TEST_OUTPUT\"\n" | |
| ], | |
| "entryPoint": "/usr/bin/tini", | |
| "environment": { | |
| "container": "run-fips-check", | |
| "image": "oci://quay.io/konflux-ci/konflux-test@sha256:dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| } | |
| }, | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"${TEST_OUTPUT}\"\nif echo \"${TEST_OUTPUT}\" | grep -qE '\"result\":\"(FAILURE|ERROR)\"'; then\n if [ \"${BLOCKING}\" = \"true\" ]; then\n echo \"FIPS check failed and blocking is enabled\"\n exit 1\n fi\n echo \"FIPS check failed but blocking is not enabled, continuing\"\nfi\n", | |
| "environment": { | |
| "container": "evaluate-result", | |
| "image": "oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| } | |
| } | |
| ] | |
| }, | |
| { | |
| "after": [ | |
| "build-source-image", | |
| "sast-shell-check", | |
| "sast-unicode-check", | |
| "deprecated-base-image-check", | |
| "clair-scan", | |
| "ecosystem-cert-preflight-checks", | |
| "sast-snyk-check", | |
| "clamav-scan", | |
| "apply-tags", | |
| "push-dockerfile", | |
| "rpms-signature-scan", | |
| "sast-coverity-check", | |
| "coverity-availability-check", | |
| "fips-check" | |
| ], | |
| "finishedOn": "2026-09-08T21:28:38Z", | |
| "invocation": { | |
| "configSource": {}, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipeline.tekton.dev/release": "aa28e09810a679c1282095ae604afb1f5488e162", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/childReadyForDeletion": "true", | |
| "results.tekton.dev/record": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d/records/ce2b6dd4-2175-4f69-b7ba-32166133e7af", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "results.tekton.dev/result": "rhoai-tenant/results/48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "results.tekton.dev/stored": "true", | |
| "tekton.dev/taskrunSpanContext": "{\"traceparent\":\"00-0473cb0063b29b5640d9f0715a84a77f-f8973a1dc1f9363e-01\"}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/memberOf": "tasks", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRun": "odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "tekton.dev/pipelineRunUID": "48d14ba0-ce28-4ff8-a2d2-10f2c712368d", | |
| "tekton.dev/pipelineTask": "pipeline-success-indicator" | |
| } | |
| }, | |
| "parameters": {} | |
| }, | |
| "name": "pipeline-success-indicator", | |
| "ref": {}, | |
| "serviceAccountName": "build-pipeline-odh-kserve-agent-v2-25", | |
| "startedOn": "2026-09-08T21:28:33Z", | |
| "status": "Succeeded", | |
| "steps": [ | |
| { | |
| "annotations": null, | |
| "arguments": null, | |
| "entryPoint": "echo \"Success\"\n", | |
| "environment": { | |
| "container": "noop", | |
| "image": "oci://quay.io/rhoai-konflux/alpine@sha256:149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| } | |
| } | |
| ] | |
| } | |
| ] | |
| }, | |
| "buildType": "tekton.dev/v1/PipelineRun", | |
| "builder": { | |
| "id": "https://tekton.dev/chains/v2" | |
| }, | |
| "invocation": { | |
| "configSource": { | |
| "digest": { | |
| "sha1": "ddcd122efdfbc61998906ef968b2b96f32f991b3" | |
| }, | |
| "entryPoint": "pipelines/multi-arch-container-build.yaml", | |
| "uri": "git+https://github.com/red-hat-data-services/konflux-central.git" | |
| }, | |
| "environment": { | |
| "annotations": { | |
| "build.appstudio.openshift.io/build-nudge-files": "build/operator-nudging.yaml", | |
| "build.appstudio.openshift.io/repo": "https://github.com/red-hat-data-services/kserve?rev=58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/commit_sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "build.appstudio.redhat.com/target_branch": "rhoai-2.25", | |
| "kueue.konflux-ci.dev/requests-aws-ip": "1", | |
| "kueue.konflux-ci.dev/requests-konflux-ci-dev-token": "1", | |
| "kueue.konflux-ci.dev/requests-linux-m2xlarge-arm64": "1", | |
| "kueue.konflux-ci.dev/requests-linux-ppc64le": "1", | |
| "kueue.konflux-ci.dev/requests-linux-s390x": "1", | |
| "kueue.konflux-ci.dev/requests-linux-x86-64": "1", | |
| "pipelinesascode.tekton.dev/branch": "rhoai-2.25", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/controller-info": "{\"name\":\"default\",\"configmap\":\"pipelines-as-code\",\"secret\":\"pipelines-as-code-secret\", \"gRepo\": \"pipelines-as-code\"}", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/git-auth-secret": "pac-gitauth-yvnajm", | |
| "pipelinesascode.tekton.dev/git-provider": "github", | |
| "pipelinesascode.tekton.dev/installation-id": "54743998", | |
| "pipelinesascode.tekton.dev/log-url": "https://konflux-ui.apps.stone-prod-p02.hjvn.p1.openshiftapps.com/ns/rhoai-tenant/pipelinerun/odh-kserve-agent-v2-25-on-push-xwfsp", | |
| "pipelinesascode.tekton.dev/max-keep-runs": "3", | |
| "pipelinesascode.tekton.dev/on-cel-expression": "event == \"push\"\n&& target_branch == \"rhoai-2.25\"\n&& ( files.all.exists(p, !p.matches('^\\\\.tekton/')) || \".tekton/odh-kserve-agent-v2-25-push.yaml\".pathChanged() )\n", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/scm-reporting-plr-started": "true", | |
| "pipelinesascode.tekton.dev/secret-created": "true", | |
| "pipelinesascode.tekton.dev/sender": "maskarb", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/sha-title": "Merge pull request #4575 from maskarb/downstream-2.25-sync\n\nfix: upgrade go to 1.26\n\nhttps://redhat.atlassian.net/browse/RHOAIENG-86113\nhttps://redhat.atlassian.net/browse/RHOAIENG-86112", | |
| "pipelinesascode.tekton.dev/sha-url": "https://github.com/red-hat-data-services/kserve/commit/58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/source-branch": "refs/heads/rhoai-2.25", | |
| "pipelinesascode.tekton.dev/source-repo-url": "https://github.com/red-hat-data-services/kserve", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "results.tekton.dev/recordSummaryAnnotations": "{\"repo\":\"kserve\",\"commit\":\"58e7f0f6d889933345394152903c95c62e6bd9c3\",\"eventType\":\"push\",\"pull_request-id\":4575}", | |
| "test.appstudio.openshift.io/pr-status": "merged" | |
| }, | |
| "labels": { | |
| "app.kubernetes.io/managed-by": "pipelinesascode.tekton.dev", | |
| "app.kubernetes.io/version": "v0.49.0", | |
| "appstudio.openshift.io/application": "rhoai-v2-25", | |
| "appstudio.openshift.io/component": "odh-kserve-agent-v2-25", | |
| "kueue.x-k8s.io/priority-class": "konflux-post-merge-build", | |
| "kueue.x-k8s.io/queue-name": "pipelines-queue", | |
| "pipelines.appstudio.openshift.io/type": "build", | |
| "pipelinesascode.tekton.dev/check-run-id": "102242466639", | |
| "pipelinesascode.tekton.dev/event-type": "push", | |
| "pipelinesascode.tekton.dev/original-prname": "odh-kserve-agent-v2-25-on-push", | |
| "pipelinesascode.tekton.dev/pull-request": "4575", | |
| "pipelinesascode.tekton.dev/repository": "odh-kserve-agent-v2-24", | |
| "pipelinesascode.tekton.dev/sha": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "pipelinesascode.tekton.dev/state": "queued", | |
| "pipelinesascode.tekton.dev/url-org": "red-hat-data-services", | |
| "pipelinesascode.tekton.dev/url-repository": "kserve", | |
| "tekton.dev/pipeline": "odh-kserve-agent-v2-25-on-push-xwfsp" | |
| } | |
| }, | |
| "parameters": { | |
| "additional-build-secret": "does-not-exist", | |
| "additional-labels": [], | |
| "additional-tags": [ | |
| "rhoai-2.25-58e7f0f6d889933345394152903c95c62e6bd9c3" | |
| ], | |
| "build-args": [], | |
| "build-args-file": "", | |
| "build-image-index": "true", | |
| "build-platforms": [ | |
| "linux/x86_64", | |
| "linux/ppc64le", | |
| "linux/s390x", | |
| "linux-m2xlarge/arm64" | |
| ], | |
| "build-source-image": "true", | |
| "buildah-format": "docker", | |
| "clone-depth": "1", | |
| "disable-slack-notifications": "false", | |
| "dockerfile": "Dockerfiles/agent.Dockerfile.konflux", | |
| "enable-cache-proxy": "true", | |
| "enable-package-registry-proxy": "true", | |
| "expected-cluster": "", | |
| "fetch-git-tags": "false", | |
| "fips-check-blocking": "true", | |
| "git-url": "https://github.com/red-hat-data-services/kserve", | |
| "hermetic": "false", | |
| "image-expires-after": "", | |
| "omit-history": "false", | |
| "output-image": "quay.io/rhoai/odh-kserve-agent-rhel9:rhoai-2.25", | |
| "path-context": ".", | |
| "prefetch-config-file-content": "", | |
| "prefetch-input": "", | |
| "prefetch-log-level": "info", | |
| "privileged-nested": "false", | |
| "revision": "58e7f0f6d889933345394152903c95c62e6bd9c3", | |
| "rewrite-timestamp": "false", | |
| "rhel-subscription-activation-key": "custom-activation-key", | |
| "rhoai-version": "2.25.11", | |
| "sast-target-dirs": ".", | |
| "skip-checks": "false", | |
| "source-date-epoch": "", | |
| "synk-secret": "synk-secret" | |
| } | |
| }, | |
| "materials": [ | |
| { | |
| "digest": { | |
| "sha1": "ddcd122efdfbc61998906ef968b2b96f32f991b3" | |
| }, | |
| "uri": "git+https://github.com/red-hat-data-services/konflux-central.git" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "25a147defd01e19674714f55d17538c8dbe55d8c305fa157ecc3f9c8977b05b6" | |
| }, | |
| "uri": "oci://registry.access.redhat.com/ubi9/ubi" | |
| }, | |
| { | |
| "digest": { | |
| "sha1": "c6e2c970f62d8ed9cc3960aa1ad3f6d72dadd68b" | |
| }, | |
| "uri": "git+https://github.com/red-hat-data-services/rhoai-konflux-tasks.git" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "85141954209ee158fe9e559869a0da196ff08c5d4bb15b1a6c2e54d4fcd6b52f" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/konflux-build-cli" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "4be9343579d91c7b501cafe966cff59a601dfeca903c476e3763dd8d7599b900" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-init" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "61c6023c9247cbc74a0153bcebbd97e41bfd71d68579d1c43f504ce2edf9762c" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/build-trusted-artifacts" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "2e8fe30b6d5c8a8a3e6bbc0ea5a55e05b6170d4a399830f25ea43e17881ce544" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "4b01fbf98fa7155f5c21443c285f88853864ae7cc66981cf6b543fc6ba16b81b" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/task-runner" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "887e4fabf1707fc4018275b53fe89c0962ccb61d80d695cce49127096792edae" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/hermeto" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "374f776bcb2048c3adeaf4dbb460c52d001bc6020320df5e878c2d05391302da" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "3eee4ecf87d50cb073318ab96097b9ea2cb6e5e59dd296a212e57017a9059f61" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/mobster" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "ceecb10bc58092c51a104f62ce6fd188a2d3f06fbdc446d81801cab118929344" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-buildah-remote-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "135eec87fe80d0751a1ea5e8e47b240147b25ee9a41973cae365540d2e2ee473" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/mobster" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "290c9ec319423ff9ae7b2cb78fa859e1d333abcdd2ef6c001533377812020071" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-build-image-index" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "38bfc93b0eacecd0aa5228225427524441c30e911b282a6b2eff9fdb0fdd021e" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/task-runner" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "a8416f792207e4b9b8bfea1c9b86ad54ae7bc28384d14de0726cced3dee01ae5" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/source-container-build" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "1808485d95cf77fb7912f6fe69191bead05fc0f2f71e00031941a7ea38a5f665" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-source-build-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "dae74bf0d6fc349d3ae140d9e3a921ad5009fdf8dade3186bfd9b65fbe3a365b" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/konflux-test" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "0ccc688a77e9b7b0b8973c132a1e840844137e77f887be4a0bec8893b0776872" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-deprecated-image-check" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "6ed1dbb16de5a87f42df0d11cfb5b6bb0571a56e793b2c702c03e010846d34d5" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/clair-in-ci" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "1d57720b2d1730ff2bb52b93d458eb14bfed759ec5267c2b532f776ff0bf8fab" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/task-runner" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clair-scan" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "15c5eeb451924ddfc9d8680319130fe277df7850728d5c37f13ae3eb9d607249" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/build-trusted-artifacts" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "04b5f424f6ada156b4c601f90dd3f6186499c695a34f73b43e610914bd250f14" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/konflux-test" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "1cc659b4d30536ec98300ac551739ef36dee345a7dcfe06129fd78abdc3688ac" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/oras" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "99e2263ad98c00b1b44012a325bf0b114684c9f6152fe259ada44e2561a8479e" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "60297bb97fd977731706a64e252d969b81234422b0da065d9b9a57e9b103e74c" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/clamav-db" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "9df272d2180bd67e6a3e04d5cd30ffa7ba27af4e599a1922f7069f5c89888e5b" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-clamav-scan" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "3bba1fe5ad96bd3811f34b367487192683aa9b1ba343da4885dda565b0a7207e" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/konflux-test" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "8b501440a960aec446db2ebc6625a49d0317a9fc7bf0f7bd9b18cb63052db7de" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-coverity-availability-check" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "d9b01530ce3c20287714e64980f154e28c0e94d17e2dbfbaf3c8bf77b1844b9e" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "381750451fbcc86d90fa83579a48e0e6555d7cf374fe2c4af3f9262a17fc3c89" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "ccd3665345d86c6799bc7e2e6ad86b277d9f3a5c40b513e6f2a0af8ad92e7dba" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-apply-tags" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "ef00a86cb22259fcfdefa15a5116b63d0f24ee35c95d05ff9815ee8f84beb548" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-push-dockerfile-oci-ta" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "69102586287b89a162f7eaf4cded2db44a0df41da17016aacc4fadffa5490b6b" | |
| }, | |
| "uri": "oci://quay.io/konflux-ci/tools" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "9ef4dabd53e823e3139b99c8de708be4ee759d63b32982847929df19ab75b2f8" | |
| }, | |
| "uri": "quay.io/konflux-ci/tekton-catalog/task-rpms-signature-scan" | |
| }, | |
| { | |
| "digest": { | |
| "sha256": "149feff81b1fc443edb5eb8351753344abb5aba4a04a5ade4a760fb9efe48c2e" | |
| }, | |
| "uri": "oci://quay.io/rhoai-konflux/alpine" | |
| }, | |
| { | |
| "digest": { | |
| "sha1": "58e7f0f6d889933345394152903c95c62e6bd9c3" | |
| }, | |
| "uri": "git+https://github.com/red-hat-data-services/kserve.git" | |
| } | |
| ], | |
| "metadata": { | |
| "buildFinishedOn": "2026-09-08T21:28:38Z", | |
| "buildStartedOn": "2026-09-08T21:20:56Z", | |
| "completeness": { | |
| "environment": false, | |
| "materials": false, | |
| "parameters": false | |
| }, | |
| "reproducible": false | |
| } | |
| } | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment