[konflux-ci/agent-plugins]: describe the PipelineRun to find the failed TaskRun (kubectl get taskruns with the pipelineRun label), then get the step logs with kubectl logs on the pod with -c step plus the failed step name, then kubectl get events in the namespace. For ImagePullBackOff, verify the image name and tag and check the ServiceAccount imagePullSecrets. For stuck pipelines, list TaskRuns and check whether the running one is making progress in its logs; only raise the timeout if the slowness is legitimate. Watch out: onError continue masks step failures, so a TaskRun can show Succeeded while buildctl failed; read step logs directly.

Context: A PipelineRun failed and you need the standard triage sequence.