Appendix: Konflux mapping

This page maps Konflux and related product names used in client engagements to what this claim actually runs. Quote the table. Do not install Konflux. Do not rename cluster APIs or Task names to Konflux product names.

This page is a term map, not an exercise. Nothing to pass here.

The activity map (what you clicked vs playbook) is Appendix: consultant delivery map. This page is names only.

How to read the table

Column Meaning

Client-engagement name

Word a customer or engagement draft may use. You still say it in the room; you do not install that product here.

What this claim runs

Cluster object under its real OpenShift / Tekton name.

Where you clicked

Gated module, callout, or not on this claim.

Mapping

Client-engagement name What this claim runs Where you clicked

Konflux

OpenShift Pipelines (Tekton) under real Task names. Mapping only.

Track 4. Do not install hosted Konflux. Hands-on hosted Konflux is not this workshop.

Hermeto prefetch

Tekton Task prefetch-dependencies in namespace lightwell-tasks. Maven dependency:go-offline then mvn -o against in-cluster Nexus. Do not pull quay.io/konflux-ci/hermeto. Do not name the cluster object hermeto. Diagram: 4.2.

4.2 (scored)

Buildah

OpenShift BuildConfig started from Tekton (oc start-build --from-dir). No Buildah task on the scored path.

4.4 (scored)

Clair

RHACS pipeline Task acs-image-check. Not a Clair install. Not the 6.1 admission gate.

7.2 (scored; must not stay skipped)

Tekton Chains

RHTAS keyless cosign Task cosign-sign-keyless (5.1). There is no Tekton Chains on this claim and no SLSA L3. 5.2 leaves skip-att-sig-check=true (ignore builtin.attestation.signature_check in the ec report; do not use --ignore-rekor).

5.1 scored (keyless). Chains itself is mapping only.

Conforma

Task conforma-policy in lightwell-tasks plus a ConfigMap you copy into lw-poc-build and tighten. ec validate on the signed app digest.

5.2 (scored)

Release Service

Git commit of the signed digest to the prod GitOps remote (lw-student/gitops-prod-spring-boot-lw-poc). Not a Konflux Release CR.

6.2 (scored)

oc-mirror on bastion

Learner-run oc-mirror v2 in Showroom, dest is the in-cluster registry. Not a physical DMZ host.

1.2 (scored stand-in)

Artifactory

Nexus scored as the enterprise proxy. Artifactory is a callout on the same modules. No Artifactory install.

2.1 callout (remote + virtual + include/exclude). Artifactory is not installed on this claim.

MintMaker / Renovate

Live Renovate CronJob on in-cluster Gitea. You merge a renovate-bot PR. Not hosted Konflux MintMaker.

3.3 (scored)

If a customer asks “do we get Konflux in this cluster?”

Say no. This claim runs OpenShift Pipelines. The controls (hermetic prefetch, BuildConfig image, Conforma, signed promote) are what you sell. Hosted Konflux is a different topology, not this workshop. If you rename Tasks to Konflux names, the Checks fail and you over-claim the platform.

What not to do

  • Do not oc apply a Konflux operator or pull quay.io/konflux-ci/* for scored work.

  • Do not alias prefetch-dependencies, the BuildConfig, or conforma-policy to Hermeto / Buildah / Enterprise Contract object names.

  • Do not claim Tekton Chains or SLSA L3 because 5.1 signed keylessly.

  • Do not treat ACS as Clair-on-the-claim or as the 6.1 ImagePolicy gate.