I0415 17:55:24.516757 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0415 17:55:24.516961 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0415 17:55:24.517011 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0415 17:55:24.517171 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0415 17:55:24.519094 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0415 17:55:24.519683 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0415 17:55:24.519853 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0415 17:55:24.520714 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0415 17:55:24.539765 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0415 17:55:24.541107 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0415 17:55:24.541630 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0415 17:55:24.543807 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0415 17:55:24.544642 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0415 17:55:24.545652 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0415 17:55:24.546775 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0415 17:55:24.547482 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0415 17:55:24.548225 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0415 17:55:24.548945 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0415 17:55:24.550626 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0415 17:55:24.551669 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0415 17:55:24.552320 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0415 17:55:24.552475 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0415 17:55:24.552920 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0415 17:55:24.553415 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0415 17:55:24.553871 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0415 17:55:24.554438 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0415 17:55:24.554764 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0415 17:55:24.554787 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0415 17:55:24.554854 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0415 17:55:24.555306 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0415 17:55:24.555470 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0415 17:55:24.556049 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0415 17:55:24.556107 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0415 17:55:42.855892 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-15 17:55:42.855848061 +0000 UTC m=+18.377224338 I0415 17:55:42.869881 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:42.869901 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-15 17:55:42.869889587 +0000 UTC m=+18.391265864 I0415 17:55:42.869924 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-15 17:55:42.869916577 +0000 UTC m=+18.391292874 I0415 17:55:42.887346 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0415 17:55:42.887434 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:42.887455 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-15 17:55:42.887450352 +0000 UTC m=+18.408826609 E0415 17:55:42.890137 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0415 17:55:42.909617 1 controller.go:167] cert-manager/certificates-trigger "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0415 17:55:42.924649 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-15 17:55:42.924636928 +0000 UTC m=+18.446013215 I0415 17:55:42.939037 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:42.939077 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-15 17:55:42.939071993 +0000 UTC m=+18.460448270 I0415 17:55:42.939019 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-15 17:55:42.938998991 +0000 UTC m=+18.460375278 I0415 17:55:42.954252 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0415 17:55:42.954341 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-15 17:55:42.954331426 +0000 UTC m=+18.475707693 I0415 17:55:43.180098 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0415 17:55:43.227114 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-9rcgm" condition "Approved" to 2026-04-15 17:55:43.22710072 +0000 UTC m=+18.748477007 I0415 17:55:43.264587 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-9rcgm" condition "Ready" to 2026-04-15 17:55:43.264572862 +0000 UTC m=+18.785949119 I0415 17:55:43.308191 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:43.308173653 +0000 UTC m=+18.829549910 I0415 17:55:43.367374 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0415 17:55:43.447917 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0415 17:55:43.559838 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-15 17:55:43.559823112 +0000 UTC m=+19.081199409 I0415 17:55:43.582610 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:43.582646 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-15 17:55:43.582638445 +0000 UTC m=+19.104014742 I0415 17:55:43.582807 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-15 17:55:43.582795029 +0000 UTC m=+19.104171296 I0415 17:55:43.605064 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0415 17:55:43.605126 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-15 17:55:43.605120631 +0000 UTC m=+19.126496898 I0415 17:55:43.714056 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0415 17:55:43.764638 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-9j477" condition "Approved" to 2026-04-15 17:55:43.764628548 +0000 UTC m=+19.286004815 I0415 17:55:43.811761 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-9j477" condition "Ready" to 2026-04-15 17:55:43.811751558 +0000 UTC m=+19.333127825 I0415 17:55:43.864483 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:43.864471053 +0000 UTC m=+19.385847320 I0415 17:55:43.911732 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0415 17:55:43.950765 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-15 17:55:43.950746813 +0000 UTC m=+19.472123110 I0415 17:55:43.977641 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-15 17:55:43.977622567 +0000 UTC m=+19.498998814 I0415 17:55:43.978616 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:43.978650 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-15 17:55:43.9786428 +0000 UTC m=+19.500019077 I0415 17:55:43.995067 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0415 17:55:43.995115 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-15 17:55:43.995109221 +0000 UTC m=+19.516485488 I0415 17:55:44.020285 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0415 17:55:44.376323 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-15 17:55:44.376311774 +0000 UTC m=+19.897688031 I0415 17:55:44.394391 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:44.394420 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-15 17:55:44.394413951 +0000 UTC m=+19.915790218 I0415 17:55:44.394430 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-15 17:55:44.394418751 +0000 UTC m=+19.915795018 I0415 17:55:44.404424 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0415 17:55:44.404464 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0415 17:55:44.404475 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-15 17:55:44.404471367 +0000 UTC m=+19.925847634 I0415 17:55:44.530008 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0415 17:55:44.546464 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-vjhsx" condition "Approved" to 2026-04-15 17:55:44.546453161 +0000 UTC m=+20.067829418 I0415 17:55:44.594782 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-vjhsx" condition "Ready" to 2026-04-15 17:55:44.594773807 +0000 UTC m=+20.116150064 I0415 17:55:44.767813 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:44.767798629 +0000 UTC m=+20.289174906 I0415 17:55:44.965931 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0415 17:55:44.966198 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:44.96619379 +0000 UTC m=+20.487570047 I0415 17:55:45.016495 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0415 17:55:45.323078 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0415 17:55:45.376458 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-9lgbw" condition "Approved" to 2026-04-15 17:55:45.376445738 +0000 UTC m=+20.897822005 I0415 17:55:45.528151 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-9lgbw" condition "Ready" to 2026-04-15 17:55:45.528138999 +0000 UTC m=+21.049515246 I0415 17:55:45.975445 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:45.975431659 +0000 UTC m=+21.496807916 I0415 17:55:46.067053 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0415 17:55:46.067370 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 17:55:46.067363527 +0000 UTC m=+21.588739794 I0415 17:55:46.318135 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0415 17:55:46.367580 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" E0415 17:57:05.659523 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0415 17:57:05.710710 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-15 17:57:05.710658606 +0000 UTC m=+101.232034893 I0415 17:57:05.737630 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-15 17:57:05.737612413 +0000 UTC m=+101.258988710 E0415 17:57:07.991406 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0415 17:57:08.037086 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-15 17:57:08.037064714 +0000 UTC m=+103.558440981 I0415 17:57:08.063805 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-15 17:57:08.063778246 +0000 UTC m=+103.585154533 E0415 17:57:09.755439 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0415 17:57:09.804643 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-15 17:57:09.80463136 +0000 UTC m=+105.326007627 I0415 17:57:09.830730 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-15 17:57:09.83071024 +0000 UTC m=+105.352086497 E0415 17:57:11.582474 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0415 17:57:11.622517 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-15 17:57:11.622504806 +0000 UTC m=+107.143881073 I0415 17:57:11.650563 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-15 17:57:11.650551757 +0000 UTC m=+107.171928014