I0424 13:58:18.781048 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0424 13:58:18.781254 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0424 13:58:18.781384 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0424 13:58:18.789357 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0424 13:58:18.789913 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0424 13:58:18.790587 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0424 13:58:18.790598 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0424 13:58:18.793379 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0424 13:58:18.831812 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0424 13:58:18.837655 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0424 13:58:18.840365 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0424 13:58:18.846690 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0424 13:58:18.853694 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0424 13:58:18.854692 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0424 13:58:18.857697 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0424 13:58:18.860541 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0424 13:58:18.863110 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0424 13:58:18.869090 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0424 13:58:18.869136 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0424 13:58:18.869184 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0424 13:58:18.872815 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0424 13:58:18.876040 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0424 13:58:18.879732 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0424 13:58:18.884926 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0424 13:58:18.887352 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0424 13:58:18.887385 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0424 13:58:18.887397 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0424 13:58:18.887437 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0424 13:58:18.890148 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0424 13:58:18.890195 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0424 13:58:18.893372 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0424 13:58:18.897944 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0424 13:58:18.905386 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0424 13:58:18.914731 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.914976 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.915232 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.915293 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.915339 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.915397 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.915828 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.916036 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:18.917488 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:58:19.037692 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0424 13:59:21.182060 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-24 13:59:21.18201437 +0000 UTC m=+62.445883869 I0424 13:59:22.162321 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-24 13:59:22.162303908 +0000 UTC m=+63.426173407 I0424 13:59:22.162383 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 13:59:22.162441 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-24 13:59:22.162426841 +0000 UTC m=+63.426296330 I0424 13:59:22.182608 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:22.182900 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-24 13:59:22.182889726 +0000 UTC m=+63.446759215 E0424 13:59:22.192615 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0424 13:59:22.193285 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-24 13:59:22.193258887 +0000 UTC m=+63.457128376 E0424 13:59:22.193925 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0424 13:59:22.404611 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" E0424 13:59:22.446316 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0424 13:59:22.446398 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0424 13:59:22.446419 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0424 13:59:22.446447 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0424 13:59:22.536252 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:22.767654 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6k2qj" condition "Approved" to 2026-04-24 13:59:22.767635192 +0000 UTC m=+64.031504691 I0424 13:59:22.810982 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6k2qj" condition "Ready" to 2026-04-24 13:59:22.810955265 +0000 UTC m=+64.074824754 I0424 13:59:22.863859 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 13:59:22.863838893 +0000 UTC m=+64.127708382 I0424 13:59:22.894577 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:27.449661 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 13:59:27.44964306 +0000 UTC m=+68.713512539 I0424 13:59:28.800865 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 13:59:28.800925 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-24 13:59:28.800910655 +0000 UTC m=+70.064780164 I0424 13:59:28.805645 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-24 13:59:28.805636121 +0000 UTC m=+70.069505600 I0424 13:59:28.824449 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-24 13:59:28.824431559 +0000 UTC m=+70.088301038 I0424 13:59:28.828475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:28.828647 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-24 13:59:28.828636722 +0000 UTC m=+70.092506211 I0424 13:59:29.013807 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:29.061502 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-kxcl4" condition "Approved" to 2026-04-24 13:59:29.061487245 +0000 UTC m=+70.325356724 I0424 13:59:29.098717 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-kxcl4" condition "Ready" to 2026-04-24 13:59:29.098692134 +0000 UTC m=+70.362561643 I0424 13:59:29.132247 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 13:59:29.13221975 +0000 UTC m=+70.396089259 I0424 13:59:29.157635 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:33.669135 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-vnc-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 13:59:33.669181 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Issuing" to 2026-04-24 13:59:33.66917037 +0000 UTC m=+74.933039849 I0424 13:59:33.669540 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-04-24 13:59:33.669534638 +0000 UTC m=+74.933404107 I0424 13:59:33.810172 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:33.810273 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-04-24 13:59:33.810254359 +0000 UTC m=+75.074123828 I0424 13:59:33.840431 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:33.874318 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-pjvxc" condition "Approved" to 2026-04-24 13:59:33.874292065 +0000 UTC m=+75.138161574 I0424 13:59:33.912337 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-pjvxc" condition "Ready" to 2026-04-24 13:59:33.912323852 +0000 UTC m=+75.176193331 I0424 13:59:33.942423 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 13:59:33.942401992 +0000 UTC m=+75.206271501 I0424 13:59:33.964650 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:34.534087 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Ready" to 2026-04-24 13:59:34.53406503 +0000 UTC m=+75.797934529 I0424 13:59:34.534618 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 13:59:34.534648 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-04-24 13:59:34.534642583 +0000 UTC m=+75.798512082 I0424 13:59:34.552529 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:34.552621 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 13:59:34.552644 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-04-24 13:59:34.552633633 +0000 UTC m=+75.816503132 I0424 13:59:34.619574 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-jbvnj" condition "Approved" to 2026-04-24 13:59:34.619561273 +0000 UTC m=+75.883430752 I0424 13:59:34.647201 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-jbvnj" condition "Ready" to 2026-04-24 13:59:34.647189178 +0000 UTC m=+75.911058647 I0424 13:59:34.695410 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 13:59:34.695348739 +0000 UTC m=+75.959218218 I0424 13:59:34.722972 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 13:59:35.370630 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-vnc" condition "Ready" to 2026-04-24 13:59:35.370613879 +0000 UTC m=+76.634483378 I0424 13:59:36.192788 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-api" condition "Ready" to 2026-04-24 13:59:36.192768308 +0000 UTC m=+77.456637817 I0424 14:03:09.032043 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 14:03:09.032194 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-24 14:03:09.032093011 +0000 UTC m=+290.295962490 I0424 14:03:09.032212 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-24 14:03:09.032196883 +0000 UTC m=+290.296066352 E0424 14:03:09.992032 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0424 14:03:09.992129 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-04-24 14:03:09.992093752 +0000 UTC m=+291.255963251 I0424 14:03:09.992215 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0424 14:03:09.998165 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:09.998348 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-24 14:03:09.99825155 +0000 UTC m=+291.262121019 E0424 14:03:10.121067 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0424 14:03:10.121274 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0424 14:03:10.121322 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0424 14:03:10.121375 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0424 14:03:10.123370 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-24 14:03:10.123346483 +0000 UTC m=+291.387215962 I0424 14:03:10.123956 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 14:03:10.124013 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-24 14:03:10.124001518 +0000 UTC m=+291.387870997 I0424 14:03:10.127547 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:10.127768 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-24 14:03:10.127751971 +0000 UTC m=+291.391621480 I0424 14:03:10.167116 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:10.175826 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-xh5gw" condition "Approved" to 2026-04-24 14:03:10.17580789 +0000 UTC m=+291.439677379 I0424 14:03:10.178689 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:10.178915 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 14:03:10.179036 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-24 14:03:10.179020722 +0000 UTC m=+291.442890231 I0424 14:03:10.270817 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-xh5gw" condition "Ready" to 2026-04-24 14:03:10.270801675 +0000 UTC m=+291.534671134 I0424 14:03:10.437343 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:03:10.43732146 +0000 UTC m=+291.701190959 I0424 14:03:10.462436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:10.860712 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:11.033841 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-8w66d" condition "Approved" to 2026-04-24 14:03:11.033817303 +0000 UTC m=+292.297686812 I0424 14:03:11.154145 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-8w66d" condition "Ready" to 2026-04-24 14:03:11.15412558 +0000 UTC m=+292.417995059 I0424 14:03:15.122457 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:03:15.122440872 +0000 UTC m=+296.386310351 I0424 14:03:15.466148 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-8w66d" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:03:15.46612757 +0000 UTC m=+296.729997049 I0424 14:03:15.735939 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:03:15.73591384 +0000 UTC m=+296.999783349 I0424 14:03:15.771521 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:03:15.772010 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:03:15.772000606 +0000 UTC m=+297.035870075 I0424 14:03:15.815902 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:10:23.893094 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready" to 2026-04-24 14:10:23.893057761 +0000 UTC m=+725.156927240 I0424 14:10:23.893736 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-53.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 14:10:23.893762 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Issuing" to 2026-04-24 14:10:23.893757016 +0000 UTC m=+725.157626495 I0424 14:10:23.919425 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:10:23.919503 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-53.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0424 14:10:23.919524 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Issuing" to 2026-04-24 14:10:23.919516285 +0000 UTC m=+725.183385774 I0424 14:10:24.322001 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:10:24.324918 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-53.nip.io-tls-s2vjr" condition "Approved" to 2026-04-24 14:10:24.32489927 +0000 UTC m=+725.588768779 I0424 14:10:24.351805 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-53.nip.io-tls-s2vjr" condition "Ready" to 2026-04-24 14:10:24.351789275 +0000 UTC m=+725.615658754 I0424 14:10:24.388214 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:10:24.388192152 +0000 UTC m=+725.652061621 I0424 14:10:24.412623 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:10:24.413118 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-24 14:10:24.413110272 +0000 UTC m=+725.676979751 I0424 14:10:24.436569 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0424 14:10:24.454836 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again"