I0510 03:57:27.042682 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0510 03:57:27.042761 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0510 03:57:27.042822 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0510 03:57:27.047375 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0510 03:57:27.047768 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0510 03:57:27.047894 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0510 03:57:27.047963 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0510 03:57:27.053453 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0510 03:57:27.065998 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0510 03:57:27.071043 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0510 03:57:27.075597 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0510 03:57:27.078293 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0510 03:57:27.078170 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0510 03:57:27.079162 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0510 03:57:27.079205 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0510 03:57:27.079224 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0510 03:57:27.083178 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0510 03:57:27.088680 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0510 03:57:27.092222 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0510 03:57:27.095840 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0510 03:57:27.099499 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0510 03:57:27.104260 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0510 03:57:27.106572 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0510 03:57:27.108796 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0510 03:57:27.111371 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0510 03:57:27.113994 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0510 03:57:27.119108 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0510 03:57:27.119299 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0510 03:57:27.123594 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0510 03:57:27.126096 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0510 03:57:27.126229 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0510 03:57:27.128767 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0510 03:57:27.131741 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0510 03:57:27.135508 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.135813 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.136500 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.136827 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.148544 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.171576 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.182969 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.196587 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.215771 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:27.225905 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0510 03:57:44.688286 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-10 03:57:44.68826746 +0000 UTC m=+17.675125762 I0510 03:57:45.393708 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 03:57:45.393862 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-10 03:57:45.393819543 +0000 UTC m=+18.380677875 I0510 03:57:45.393878 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-10 03:57:45.393812552 +0000 UTC m=+18.380670854 I0510 03:57:45.408501 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:57:45.408588 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-10 03:57:45.408579078 +0000 UTC m=+18.395437340 E0510 03:57:45.414502 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0510 03:57:45.414587 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-10 03:57:45.414579222 +0000 UTC m=+18.401437494 E0510 03:57:45.414613 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0510 03:57:45.430420 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0510 03:57:45.430509 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0510 03:57:45.430553 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0510 03:57:45.430589 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0510 03:57:45.434858 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:57:45.455295 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-8xmst" condition "Approved" to 2026-05-10 03:57:45.455284972 +0000 UTC m=+18.442143244 I0510 03:57:45.466670 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-8xmst" condition "Ready" to 2026-05-10 03:57:45.466654167 +0000 UTC m=+18.453512469 I0510 03:57:45.497023 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 03:57:45.497009577 +0000 UTC m=+18.483867849 I0510 03:57:45.560929 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:57:45.602869 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:57:50.433401 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 03:57:50.433393706 +0000 UTC m=+23.420251968 I0510 03:58:14.423098 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 03:58:14.423246 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-10 03:58:14.423236486 +0000 UTC m=+47.410094758 I0510 03:58:14.423429 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-10 03:58:14.42339437 +0000 UTC m=+47.410252642 I0510 03:58:14.458515 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-10 03:58:14.458497587 +0000 UTC m=+47.445355849 I0510 03:58:14.458648 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:58:14.458859 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-10 03:58:14.458850917 +0000 UTC m=+47.445709189 I0510 03:58:14.639443 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:58:14.673744 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-chmmz" condition "Approved" to 2026-05-10 03:58:14.673731554 +0000 UTC m=+47.660589826 I0510 03:58:14.718503 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-chmmz" condition "Ready" to 2026-05-10 03:58:14.718490504 +0000 UTC m=+47.705348776 I0510 03:58:14.755993 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 03:58:14.755980425 +0000 UTC m=+47.742838687 I0510 03:58:14.793674 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:58:14.794192 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 03:58:14.794184507 +0000 UTC m=+47.781042779 I0510 03:58:14.805000 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0510 03:58:14.820176 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:03:07.181486 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-238.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:03:07.181722 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-238.nip.io-tls" condition "Issuing" to 2026-05-10 04:03:07.181547594 +0000 UTC m=+340.168405896 I0510 04:03:07.181713 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-238.nip.io-tls" condition "Ready" to 2026-05-10 04:03:07.181706338 +0000 UTC m=+340.168564630 I0510 04:03:07.195566 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-238.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-238.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:03:07.195615 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-238.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:03:07.195629 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-238.nip.io-tls" condition "Issuing" to 2026-05-10 04:03:07.195624948 +0000 UTC m=+340.182483210 I0510 04:03:07.466565 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-238.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-238.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:03:07.476611 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-238.nip.io-tls-mq4jf" condition "Approved" to 2026-05-10 04:03:07.476597526 +0000 UTC m=+340.463455798 I0510 04:03:07.507086 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-238.nip.io-tls-mq4jf" condition "Ready" to 2026-05-10 04:03:07.507041303 +0000 UTC m=+340.493899565 I0510 04:03:07.531786 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-238.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:03:07.53177494 +0000 UTC m=+340.518633212 I0510 04:03:07.554767 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-238.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-238.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.459938 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:04:12.460307 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-10 04:04:12.46029834 +0000 UTC m=+405.447156602 I0510 04:04:12.460380 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-10 04:04:12.46031772 +0000 UTC m=+405.447176012 E0510 04:04:12.477097 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0510 04:04:12.477141 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-10 04:04:12.477132694 +0000 UTC m=+405.463990966 E0510 04:04:12.477187 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0510 04:04:12.480018 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.480903 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-10 04:04:12.480892037 +0000 UTC m=+405.467750329 E0510 04:04:12.494440 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0510 04:04:12.494756 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0510 04:04:12.494793 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0510 04:04:12.494868 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0510 04:04:12.501488 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.529088 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-ws4r8" condition "Approved" to 2026-05-10 04:04:12.52907842 +0000 UTC m=+405.515936682 I0510 04:04:12.542086 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-ws4r8" condition "Ready" to 2026-05-10 04:04:12.542076219 +0000 UTC m=+405.528934491 I0510 04:04:12.563899 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:12.563886184 +0000 UTC m=+405.550744456 I0510 04:04:12.609159 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.609441 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:12.609435457 +0000 UTC m=+405.596293719 I0510 04:04:12.613016 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.620260 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:12.620489 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:12.620483383 +0000 UTC m=+405.607341645 I0510 04:04:12.623670 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:17.496044 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:17.49600662 +0000 UTC m=+410.482864912 I0510 04:04:57.842090 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:04:57.842116 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-10 04:04:57.842111132 +0000 UTC m=+450.828969394 I0510 04:04:57.850635 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-10 04:04:57.850621825 +0000 UTC m=+450.837480077 I0510 04:04:57.866581 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:04:57.866620 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-10 04:04:57.86661512 +0000 UTC m=+450.853473382 I0510 04:04:57.867016 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-10 04:04:57.867007227 +0000 UTC m=+450.853865529 I0510 04:04:57.867289 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-10 04:04:57.866965136 +0000 UTC m=+450.853823438 I0510 04:04:57.866277 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:04:57.877194 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:57.879096 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-10 04:04:57.874873638 +0000 UTC m=+450.861731990 I0510 04:04:57.879894 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-10 04:04:57.87988544 +0000 UTC m=+450.866743702 I0510 04:04:57.903040 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:57.903124 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:04:57.903142 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-10 04:04:57.903137142 +0000 UTC m=+450.889995404 I0510 04:04:57.927682 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:57.927749 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-10 04:04:57.927743902 +0000 UTC m=+450.914602164 I0510 04:04:58.021058 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.054736 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-2dd5l" condition "Approved" to 2026-05-10 04:04:58.054728381 +0000 UTC m=+451.041586643 I0510 04:04:58.125272 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-2dd5l" condition "Ready" to 2026-05-10 04:04:58.125264642 +0000 UTC m=+451.112122904 I0510 04:04:58.215549 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.215614 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:58.215604105 +0000 UTC m=+451.202462377 I0510 04:04:58.236151 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.237396 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:58.237385477 +0000 UTC m=+451.224243739 I0510 04:04:58.252645 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.259374 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-dfm2l" condition "Approved" to 2026-05-10 04:04:58.259365633 +0000 UTC m=+451.246223895 I0510 04:04:58.265221 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.284327 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-dfm2l" condition "Ready" to 2026-05-10 04:04:58.284255938 +0000 UTC m=+451.271114200 I0510 04:04:58.362673 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:58.362659919 +0000 UTC m=+451.349518221 I0510 04:04:58.512307 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.512800 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:58.512794855 +0000 UTC m=+451.499653117 I0510 04:04:58.883512 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:58.884038 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rmcxv" condition "Approved" to 2026-05-10 04:04:58.884028857 +0000 UTC m=+451.870887119 I0510 04:04:59.329722 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rmcxv" condition "Ready" to 2026-05-10 04:04:59.329712398 +0000 UTC m=+452.316570670 I0510 04:04:59.491140 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:59.491122857 +0000 UTC m=+452.477981159 I0510 04:04:59.562512 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:59.562842 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:04:59.562836439 +0000 UTC m=+452.549694711 I0510 04:04:59.810721 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:04:59.859396 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:11.063561 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:05:11.063595 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" condition "Issuing" to 2026-05-10 04:05:11.063587845 +0000 UTC m=+464.050446117 I0510 04:05:11.064005 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" condition "Ready" to 2026-05-10 04:05:11.063997254 +0000 UTC m=+464.050855546 I0510 04:05:11.080827 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-d54x9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:11.080871 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:05:11.080888 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" condition "Issuing" to 2026-05-10 04:05:11.080877719 +0000 UTC m=+464.067735981 I0510 04:05:11.264434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-d54x9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:11.271171 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-d54x9-cqzjd" condition "Approved" to 2026-05-10 04:05:11.271161486 +0000 UTC m=+464.258019768 I0510 04:05:11.289360 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-d54x9-cqzjd" condition "Ready" to 2026-05-10 04:05:11.289350458 +0000 UTC m=+464.276208740 I0510 04:05:11.317486 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:05:11.317459306 +0000 UTC m=+464.304317578 I0510 04:05:11.359616 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-d54x9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:11.359887 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:05:11.359882387 +0000 UTC m=+464.346740649 I0510 04:05:11.378824 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-d54x9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-d54x9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:29.291025 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:05:29.291052 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-10 04:05:29.291045588 +0000 UTC m=+482.277903850 I0510 04:05:29.291073 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-10 04:05:29.291057328 +0000 UTC m=+482.277915600 I0510 04:05:29.314017 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:29.314124 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-10 04:05:29.314113944 +0000 UTC m=+482.300972246 I0510 04:05:29.507864 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:05:29.540346 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-v92r9" condition "Approved" to 2026-05-10 04:05:29.540335524 +0000 UTC m=+482.527193786 I0510 04:05:29.562332 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-v92r9" condition "Ready" to 2026-05-10 04:05:29.562319209 +0000 UTC m=+482.549177491 I0510 04:05:29.600097 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:05:29.600088067 +0000 UTC m=+482.586946319 I0510 04:05:29.627978 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:08:29.522688 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-10 04:08:29.522665948 +0000 UTC m=+662.509524240 I0510 04:08:29.522745 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:08:29.523015 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-10 04:08:29.522998484 +0000 UTC m=+662.509856866 I0510 04:08:29.538819 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:08:29.538963 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:08:29.539051 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-10 04:08:29.539043511 +0000 UTC m=+662.525901813 I0510 04:08:29.720559 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-srtf7" condition "Approved" to 2026-05-10 04:08:29.720543342 +0000 UTC m=+662.707401614 I0510 04:08:29.740522 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-srtf7" condition "Ready" to 2026-05-10 04:08:29.740506364 +0000 UTC m=+662.727364656 I0510 04:08:29.818212 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:08:29.818201907 +0000 UTC m=+662.805060169 I0510 04:08:29.841774 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:08:29.842085 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:08:29.842079275 +0000 UTC m=+662.828937547 I0510 04:08:29.848808 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:08:29.863115 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:09:10.885663 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0510 04:09:10.885696 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-10 04:09:10.885689131 +0000 UTC m=+703.872547403 I0510 04:09:10.886111 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-10 04:09:10.886084397 +0000 UTC m=+703.872942699 I0510 04:09:10.910116 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:09:10.910175 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-10 04:09:10.910169812 +0000 UTC m=+703.897028064 I0510 04:09:11.153562 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0510 04:09:11.186873 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-kpmbs" condition "Approved" to 2026-05-10 04:09:11.186865042 +0000 UTC m=+704.173723304 I0510 04:09:11.206554 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-kpmbs" condition "Ready" to 2026-05-10 04:09:11.206543565 +0000 UTC m=+704.193401837 I0510 04:09:11.236499 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-10 04:09:11.236483716 +0000 UTC m=+704.223341988 I0510 04:09:11.265288 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"