Appendix: Konflux mapping
This page maps Konflux and related product names used in client engagements to what this claim actually runs. Quote the table. Do not install Konflux. Do not rename cluster APIs or Task names to Konflux product names.
This page is a term map, not an exercise. Nothing to pass here.
The activity map (what you clicked vs playbook) is Appendix: consultant delivery map. This page is names only.
How to read the table
| Column | Meaning |
|---|---|
Client-engagement name |
Word a customer or engagement draft may use. You still say it in the room; you do not install that product here. |
What this claim runs |
Cluster object under its real OpenShift / Tekton name. |
Where you clicked |
Gated module, callout, or not on this claim. |
Mapping
| Client-engagement name | What this claim runs | Where you clicked |
|---|---|---|
Konflux |
OpenShift Pipelines (Tekton) under real Task names. Mapping only. |
Track 4. Do not install hosted Konflux. Hands-on hosted Konflux is not this workshop. |
Hermeto prefetch |
Tekton Task |
4.2 (scored) |
Buildah |
OpenShift BuildConfig started from Tekton ( |
4.4 (scored) |
Clair |
RHACS pipeline Task |
7.2 (scored; must not stay skipped) |
Tekton Chains |
RHTAS keyless cosign Task |
5.1 scored (keyless). Chains itself is mapping only. |
Conforma |
Task |
5.2 (scored) |
Release Service |
Git commit of the signed digest to the prod GitOps remote ( |
6.2 (scored) |
oc-mirror on bastion |
Learner-run |
1.2 (scored stand-in) |
Artifactory |
Nexus scored as the enterprise proxy. Artifactory is a callout on the same modules. No Artifactory install. |
2.1 callout (remote + virtual + include/exclude). Artifactory is not installed on this claim. |
MintMaker / Renovate |
Live Renovate CronJob on in-cluster Gitea. You merge a |
3.3 (scored) |
If a customer asks “do we get Konflux in this cluster?”
Say no. This claim runs OpenShift Pipelines. The controls (hermetic prefetch, BuildConfig image, Conforma, signed promote) are what you sell. Hosted Konflux is a different topology, not this workshop. If you rename Tasks to Konflux names, the Checks fail and you over-claim the platform.
What not to do
-
Do not
oc applya Konflux operator or pullquay.io/konflux-ci/*for scored work. -
Do not alias
prefetch-dependencies, the BuildConfig, orconforma-policyto Hermeto / Buildah / Enterprise Contract object names. -
Do not claim Tekton Chains or SLSA L3 because 5.1 signed keylessly.
-
Do not treat ACS as Clair-on-the-claim or as the 6.1 ImagePolicy gate.
Related
-
Consultant delivery map — activities, not product names
-
Internal enablement checklist — after the workshop; do not over-claim Konflux
-
4.2 Prefetch — Hermeto callout and diagram
-
4.4 Build and SBOM — Buildah → BuildConfig
-
3.3 Live Renovate — MintMaker → this bot