I0528 08:49:30.554715 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0528 08:49:30.554808 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0528 08:49:30.554881 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0528 08:49:30.560053 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0528 08:49:30.560517 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0528 08:49:30.560548 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0528 08:49:30.560647 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0528 08:49:30.562916 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0528 08:49:30.591468 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0528 08:49:30.597350 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0528 08:49:30.597498 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0528 08:49:30.605092 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0528 08:49:30.610711 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0528 08:49:30.613415 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0528 08:49:30.615125 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0528 08:49:30.617023 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0528 08:49:30.619041 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0528 08:49:30.624215 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0528 08:49:30.624423 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0528 08:49:30.628666 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0528 08:49:30.630572 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0528 08:49:30.632662 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0528 08:49:30.632721 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0528 08:49:30.634713 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0528 08:49:30.637191 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0528 08:49:30.639092 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0528 08:49:30.640730 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0528 08:49:30.640751 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0528 08:49:30.640781 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0528 08:49:30.642813 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0528 08:49:30.645319 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0528 08:49:30.645378 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0528 08:49:30.645480 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0528 08:49:30.651724 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.652872 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.653513 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.667452 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.688567 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.729045 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.751709 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.753875 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.776532 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:30.795417 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0528 08:49:43.621122 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-28 08:49:43.621109964 +0000 UTC m=+13.100880862 I0528 08:49:44.388726 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:49:44.388896 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-28 08:49:44.388881157 +0000 UTC m=+13.868652095 I0528 08:49:44.388728 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-28 08:49:44.388712742 +0000 UTC m=+13.868483680 I0528 08:49:44.402867 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:49:44.403065 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:49:44.403180 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-28 08:49:44.403112485 +0000 UTC m=+13.882883403 E0528 08:49:44.403548 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0528 08:49:44.403785 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-28 08:49:44.403775793 +0000 UTC m=+13.883546701 E0528 08:49:44.403884 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0528 08:49:44.419141 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0528 08:49:44.419483 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0528 08:49:44.419620 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0528 08:49:44.419718 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0528 08:49:44.449232 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:49:44.456292 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-whksl" condition "Approved" to 2026-05-28 08:49:44.456278743 +0000 UTC m=+13.936049681 I0528 08:49:44.469836 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-whksl" condition "Ready" to 2026-05-28 08:49:44.469823922 +0000 UTC m=+13.949594820 I0528 08:49:44.495941 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:49:44.495928684 +0000 UTC m=+13.975699582 I0528 08:49:44.513657 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:49:49.419982 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:49:49.419963929 +0000 UTC m=+18.899734867 I0528 08:50:12.650271 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:50:12.650338 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-28 08:50:12.650329827 +0000 UTC m=+42.130100735 I0528 08:50:12.650323 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-28 08:50:12.650303087 +0000 UTC m=+42.130074005 I0528 08:50:12.664135 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-28 08:50:12.664122858 +0000 UTC m=+42.143893766 I0528 08:50:12.689737 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:50:12.691381 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-28 08:50:12.691362621 +0000 UTC m=+42.171133549 I0528 08:50:13.041237 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:50:13.168703 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hbpk7" condition "Approved" to 2026-05-28 08:50:13.168693873 +0000 UTC m=+42.648464771 I0528 08:50:13.246074 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hbpk7" condition "Ready" to 2026-05-28 08:50:13.246055516 +0000 UTC m=+42.725826424 I0528 08:50:13.291967 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:50:13.291955568 +0000 UTC m=+42.771726486 I0528 08:50:13.318138 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:50:13.324251 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:50:13.324622 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:50:13.324614984 +0000 UTC m=+42.804385892 I0528 08:50:13.340386 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:50:13.340681 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:50:13.340674712 +0000 UTC m=+42.820445610 I0528 08:54:19.428307 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready" to 2026-05-28 08:54:19.428275606 +0000 UTC m=+288.908046534 I0528 08:54:19.428940 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:54:19.429037 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Issuing" to 2026-05-28 08:54:19.429029317 +0000 UTC m=+288.908800255 I0528 08:54:19.460932 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:54:19.461145 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:54:19.461231 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Issuing" to 2026-05-28 08:54:19.461168453 +0000 UTC m=+288.940939391 I0528 08:54:19.639931 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-156.nip.io-tls-6n8sx" condition "Approved" to 2026-05-28 08:54:19.639921584 +0000 UTC m=+289.119692492 I0528 08:54:19.660120 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-156.nip.io-tls-6n8sx" condition "Ready" to 2026-05-28 08:54:19.660110507 +0000 UTC m=+289.139881415 I0528 08:54:19.686181 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:54:19.686167293 +0000 UTC m=+289.165938201 I0528 08:54:19.703069 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:54:19.703586 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:54:19.703578639 +0000 UTC m=+289.183349547 I0528 08:54:19.710562 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:54:19.722095 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:54:19.722659 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:54:19.72264653 +0000 UTC m=+289.202417458 I0528 08:54:19.724528 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:55:23.712794 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:55:23.712835 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-28 08:55:23.712823911 +0000 UTC m=+353.192594819 I0528 08:55:23.712869 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-28 08:55:23.712862982 +0000 UTC m=+353.192633900 E0528 08:55:23.726494 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0528 08:55:23.726525 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-28 08:55:23.726518343 +0000 UTC m=+353.206289241 E0528 08:55:23.726562 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0528 08:55:23.729440 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:55:23.729602 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-28 08:55:23.729595703 +0000 UTC m=+353.209366631 E0528 08:55:23.737316 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0528 08:55:23.737564 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0528 08:55:23.737597 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0528 08:55:23.737668 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0528 08:55:23.743064 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:55:23.760750 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-qcp9p" condition "Approved" to 2026-05-28 08:55:23.760731303 +0000 UTC m=+353.240502241 I0528 08:55:23.772898 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-qcp9p" condition "Ready" to 2026-05-28 08:55:23.772886271 +0000 UTC m=+353.252657179 I0528 08:55:23.794806 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:55:23.79479145 +0000 UTC m=+353.274562388 I0528 08:55:23.812615 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:55:28.738053 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:55:28.738025565 +0000 UTC m=+358.217796503 I0528 08:56:08.382399 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-28 08:56:08.382389851 +0000 UTC m=+397.862160749 I0528 08:56:08.382614 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:08.382630 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-28 08:56:08.382628036 +0000 UTC m=+397.862398924 I0528 08:56:08.392880 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-28 08:56:08.392867816 +0000 UTC m=+397.872638714 I0528 08:56:08.394534 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:08.394554 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-28 08:56:08.39455072 +0000 UTC m=+397.874321618 I0528 08:56:08.394974 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-28 08:56:08.394970289 +0000 UTC m=+397.874741187 I0528 08:56:08.395247 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:08.395262 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-28 08:56:08.395259725 +0000 UTC m=+397.875030623 I0528 08:56:08.427481 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.427530 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-28 08:56:08.427524656 +0000 UTC m=+397.907295554 I0528 08:56:08.444424 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.444575 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:08.444600 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-28 08:56:08.444594506 +0000 UTC m=+397.924365414 I0528 08:56:08.450037 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.450086 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:08.450107 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-28 08:56:08.450101909 +0000 UTC m=+397.929872807 I0528 08:56:08.607311 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.650305 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-trv5w" condition "Approved" to 2026-05-28 08:56:08.650296372 +0000 UTC m=+398.130067270 I0528 08:56:08.679907 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-trv5w" condition "Ready" to 2026-05-28 08:56:08.679896298 +0000 UTC m=+398.159667196 I0528 08:56:08.729320 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:08.729306191 +0000 UTC m=+398.209077089 I0528 08:56:08.740247 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-s7bjf" condition "Approved" to 2026-05-28 08:56:08.740242055 +0000 UTC m=+398.220012953 I0528 08:56:08.754651 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.758754 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-s7bjf" condition "Ready" to 2026-05-28 08:56:08.758749344 +0000 UTC m=+398.238520242 I0528 08:56:08.796882 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:08.796871066 +0000 UTC m=+398.276641964 I0528 08:56:08.912506 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:08.912862 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:08.912855313 +0000 UTC m=+398.392626211 I0528 08:56:08.962444 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:09.062769 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-gt9lt" condition "Approved" to 2026-05-28 08:56:09.062760903 +0000 UTC m=+398.542531801 I0528 08:56:09.167044 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-gt9lt" condition "Ready" to 2026-05-28 08:56:09.167031986 +0000 UTC m=+398.646802894 E0528 08:56:09.505355 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"alertmanager-tls-9kzkt\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" I0528 08:56:09.798017 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:09.7980004 +0000 UTC m=+399.277771308 I0528 08:56:09.907085 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:09.907664 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:09.907630752 +0000 UTC m=+399.387401680 I0528 08:56:09.960925 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:10.208754 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:10.258081 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:14.954108 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" condition "Ready" to 2026-05-28 08:56:14.954090105 +0000 UTC m=+404.433861043 I0528 08:56:14.954173 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:14.954207 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" condition "Issuing" to 2026-05-28 08:56:14.954198597 +0000 UTC m=+404.433969505 I0528 08:56:14.967880 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:14.967965 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:14.967989 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" condition "Issuing" to 2026-05-28 08:56:14.967982816 +0000 UTC m=+404.447753724 I0528 08:56:15.204168 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-9f2f9-bnz8n" condition "Approved" to 2026-05-28 08:56:15.204153919 +0000 UTC m=+404.683924817 I0528 08:56:15.231811 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-9f2f9-bnz8n" condition "Ready" to 2026-05-28 08:56:15.231803208 +0000 UTC m=+404.711574096 I0528 08:56:15.274785 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:15.274771775 +0000 UTC m=+404.754542673 I0528 08:56:15.295726 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-9f2f9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:29.790380 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-28 08:56:29.79035764 +0000 UTC m=+419.270128548 I0528 08:56:29.790744 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:56:29.790761 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-28 08:56:29.790757378 +0000 UTC m=+419.270528286 I0528 08:56:29.817151 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:29.817227 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-28 08:56:29.817218198 +0000 UTC m=+419.296989096 I0528 08:56:30.414675 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:30.445967 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hqc6z" condition "Approved" to 2026-05-28 08:56:30.445947987 +0000 UTC m=+419.925718885 I0528 08:56:30.465751 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hqc6z" condition "Ready" to 2026-05-28 08:56:30.465740035 +0000 UTC m=+419.945510943 I0528 08:56:30.495507 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:30.49549601 +0000 UTC m=+419.975266918 I0528 08:56:30.521557 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:30.522087 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:30.522079792 +0000 UTC m=+420.001850700 I0528 08:56:30.543349 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:56:30.543649 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:56:30.543642295 +0000 UTC m=+420.023413203 I0528 08:59:44.046971 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-28 08:59:44.046948939 +0000 UTC m=+613.526719867 I0528 08:59:44.047545 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 08:59:44.047657 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-28 08:59:44.04764645 +0000 UTC m=+613.527417388 I0528 08:59:44.060693 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:59:44.060762 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-28 08:59:44.06075514 +0000 UTC m=+613.540526048 I0528 08:59:44.180878 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0528 08:59:44.212946 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-jb784" condition "Approved" to 2026-05-28 08:59:44.212933341 +0000 UTC m=+613.692704239 I0528 08:59:44.231913 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-jb784" condition "Ready" to 2026-05-28 08:59:44.231017851 +0000 UTC m=+613.710788749 I0528 08:59:44.262263 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 08:59:44.262246442 +0000 UTC m=+613.742017360 I0528 08:59:44.286090 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0528 09:00:33.382920 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-28 09:00:33.382909497 +0000 UTC m=+662.862680405 I0528 09:00:33.383184 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 09:00:33.383240 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-28 09:00:33.383235832 +0000 UTC m=+662.863006740 I0528 09:00:33.411988 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0528 09:00:33.412532 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0528 09:00:33.412563 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-28 09:00:33.412554823 +0000 UTC m=+662.892325741 I0528 09:00:33.697217 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-blvgq" condition "Approved" to 2026-05-28 09:00:33.697203618 +0000 UTC m=+663.176974556 I0528 09:00:33.715904 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-blvgq" condition "Ready" to 2026-05-28 09:00:33.715894751 +0000 UTC m=+663.195665649 I0528 09:00:33.741245 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 09:00:33.7412323 +0000 UTC m=+663.221003208 I0528 09:00:33.762073 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0528 09:00:33.762457 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 09:00:33.762447613 +0000 UTC m=+663.242218531 I0528 09:00:33.782512 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"