I0325 07:26:43.881748 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0325 07:26:43.881902 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0325 07:26:43.881963 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0325 07:26:43.882056 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0325 07:26:43.884084 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0325 07:26:43.884629 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0325 07:26:43.885541 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0325 07:26:43.886175 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0325 07:26:43.898585 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0325 07:26:43.899865 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0325 07:26:43.900386 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0325 07:26:43.901593 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0325 07:26:43.901990 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0325 07:26:43.902465 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0325 07:26:43.902900 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0325 07:26:43.902945 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0325 07:26:43.903511 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0325 07:26:43.904002 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0325 07:26:43.904064 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0325 07:26:43.904477 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0325 07:26:43.904960 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0325 07:26:43.905644 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0325 07:26:43.905669 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0325 07:26:43.905735 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0325 07:26:43.906020 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0325 07:26:43.906045 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0325 07:26:43.906114 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0325 07:26:43.906863 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0325 07:26:43.907046 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0325 07:26:43.907454 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0325 07:26:43.908217 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0325 07:26:43.910100 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0325 07:26:43.910659 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0325 07:27:03.805902 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-03-25 07:27:03.805849981 +0000 UTC m=+19.963731685 I0325 07:27:03.819151 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-25 07:27:03.819139232 +0000 UTC m=+19.977020926 I0325 07:27:03.819098 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:03.819292 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-03-25 07:27:03.819286725 +0000 UTC m=+19.977168399 E0325 07:27:03.835316 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a004e273a7a90d", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"b980a2c6-ac3d-4059-9bd1-b0f1e8dc341a", APIVersion:"cert-manager.io/v1", ResourceVersion:"1226", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.March, 25, 7, 27, 3, 833463053, time.Local), LastTimestamp:time.Date(2026, time.March, 25, 7, 27, 3, 833463053, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a004e273a7a90d" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) E0325 07:27:03.838655 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0325 07:27:03.839145 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0325 07:27:03.839182 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-25 07:27:03.839178319 +0000 UTC m=+19.997059993 E0325 07:27:03.850795 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0325 07:27:03.873523 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-25 07:27:03.873510537 +0000 UTC m=+20.031392221 I0325 07:27:03.888631 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:03.888650 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-03-25 07:27:03.888648166 +0000 UTC m=+20.046529840 I0325 07:27:03.888578 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-25 07:27:03.888570184 +0000 UTC m=+20.046451858 I0325 07:27:03.905699 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0325 07:27:03.905778 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:03.905802 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-03-25 07:27:03.905797174 +0000 UTC m=+20.063678848 E0325 07:27:04.113531 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0325 07:27:04.446475 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-f9mdj" condition "Approved" to 2026-03-25 07:27:04.446464509 +0000 UTC m=+20.604346193 I0325 07:27:04.466424 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-25 07:27:04.466409151 +0000 UTC m=+20.624290835 I0325 07:27:04.482699 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-f9mdj" condition "Ready" to 2026-03-25 07:27:04.48268164 +0000 UTC m=+20.640563334 I0325 07:27:04.484287 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-25 07:27:04.484278052 +0000 UTC m=+20.642159736 I0325 07:27:04.485275 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:04.485334 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-25 07:27:04.485297494 +0000 UTC m=+20.643179178 I0325 07:27:04.509003 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0325 07:27:04.509059 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:04.509072 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-25 07:27:04.509068683 +0000 UTC m=+20.666950357 I0325 07:27:04.521590 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:04.521582086 +0000 UTC m=+20.679463750 I0325 07:27:04.556702 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0325 07:27:04.557007 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:04.557000221 +0000 UTC m=+20.714881885 I0325 07:27:04.566562 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0325 07:27:04.587439 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0325 07:27:04.603135 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:04.603120914 +0000 UTC m=+20.761002588 I0325 07:27:04.860091 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-25 07:27:04.860078234 +0000 UTC m=+21.017959938 I0325 07:27:04.883980 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:04.883989 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-25 07:27:04.883975777 +0000 UTC m=+21.041857461 I0325 07:27:04.884014 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-25 07:27:04.884007247 +0000 UTC m=+21.041888911 I0325 07:27:04.901948 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0325 07:27:04.902002 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:04.902016 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-25 07:27:04.902012362 +0000 UTC m=+21.059894036 I0325 07:27:05.015679 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-hck7f" condition "Approved" to 2026-03-25 07:27:05.015669716 +0000 UTC m=+21.173551390 I0325 07:27:05.087218 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-hck7f" condition "Ready" to 2026-03-25 07:27:05.087207972 +0000 UTC m=+21.245089636 I0325 07:27:05.163452 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:05.163440852 +0000 UTC m=+21.321322516 I0325 07:27:05.212559 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0325 07:27:05.241845 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-25 07:27:05.241832235 +0000 UTC m=+21.399713909 I0325 07:27:05.260618 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:05.260652 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-25 07:27:05.260642763 +0000 UTC m=+21.418524447 I0325 07:27:05.261080 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-25 07:27:05.261069411 +0000 UTC m=+21.418951095 I0325 07:27:05.280739 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0325 07:27:05.282130 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0325 07:27:05.282168 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-25 07:27:05.282159544 +0000 UTC m=+21.440041258 I0325 07:27:05.389672 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0325 07:27:05.394481 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7vn9f" condition "Approved" to 2026-03-25 07:27:05.394465008 +0000 UTC m=+21.552346722 I0325 07:27:05.562224 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7vn9f" condition "Ready" to 2026-03-25 07:27:05.562208213 +0000 UTC m=+21.720089877 I0325 07:27:05.903385 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:05.903371159 +0000 UTC m=+22.061252853 I0325 07:27:05.943937 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0325 07:27:06.005171 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-vcqqw" condition "Approved" to 2026-03-25 07:27:06.00514948 +0000 UTC m=+22.163031224 I0325 07:27:06.093906 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0325 07:27:06.094608 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:06.094593513 +0000 UTC m=+22.252475217 I0325 07:27:06.299827 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-vcqqw" condition "Ready" to 2026-03-25 07:27:06.299814964 +0000 UTC m=+22.457696658 I0325 07:27:06.794562 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0325 07:27:06.848217 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:06.848202813 +0000 UTC m=+23.006084497 I0325 07:27:07.061818 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0325 07:27:07.062139 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-25 07:27:07.0621291 +0000 UTC m=+23.220010784 I0325 07:27:07.302696 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0325 07:27:07.343248 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0325 07:28:20.538872 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0325 07:28:20.577143 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-25 07:28:20.577130276 +0000 UTC m=+96.735011950 I0325 07:28:20.597706 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-25 07:28:20.597671887 +0000 UTC m=+96.755553571 E0325 07:28:22.663472 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0325 07:28:22.714494 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-25 07:28:22.714482516 +0000 UTC m=+98.872364200 I0325 07:28:22.738719 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-25 07:28:22.738706527 +0000 UTC m=+98.896588211 E0325 07:28:24.265508 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0325 07:28:24.308530 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-25 07:28:24.308513685 +0000 UTC m=+100.466395369 I0325 07:28:24.331467 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-25 07:28:24.331454667 +0000 UTC m=+100.489336351 E0325 07:28:26.195392 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0325 07:28:26.234918 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-25 07:28:26.234905019 +0000 UTC m=+102.392786693 I0325 07:28:26.262978 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-25 07:28:26.262962209 +0000 UTC m=+102.420843913