I0417 00:34:54.826364 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0417 00:34:54.826553 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0417 00:34:54.826666 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0417 00:34:54.831650 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0417 00:34:54.831960 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0417 00:34:54.832073 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0417 00:34:54.832138 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0417 00:34:54.833910 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0417 00:34:54.851651 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0417 00:34:54.856860 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0417 00:34:54.860191 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0417 00:34:54.860236 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0417 00:34:54.860632 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0417 00:34:54.866170 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0417 00:34:54.868746 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0417 00:34:54.871377 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0417 00:34:54.873626 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0417 00:34:54.875486 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0417 00:34:54.877457 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0417 00:34:54.883052 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0417 00:34:54.883099 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0417 00:34:54.883164 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0417 00:34:54.886158 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0417 00:34:54.888537 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0417 00:34:54.888623 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0417 00:34:54.891034 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0417 00:34:54.893409 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0417 00:34:54.895215 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0417 00:34:54.897322 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0417 00:34:54.897395 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0417 00:34:54.899120 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0417 00:34:54.902507 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0417 00:34:54.906856 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0417 00:34:54.909691 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.910522 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.911138 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.911254 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.911794 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.911800 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.911870 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.912505 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.912538 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:34:54.999159 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:35:06.289523 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-17 00:35:06.289506998 +0000 UTC m=+11.496307981 I0417 00:35:07.016523 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-17 00:35:07.016507832 +0000 UTC m=+12.223308825 I0417 00:35:07.016692 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:35:07.016783 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-17 00:35:07.01677121 +0000 UTC m=+12.223572203 E0417 00:35:07.033021 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0417 00:35:07.033112 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-17 00:35:07.033104171 +0000 UTC m=+12.239905144 E0417 00:35:07.033144 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0417 00:35:07.035435 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:07.035525 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:35:07.035548 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-17 00:35:07.035539257 +0000 UTC m=+12.242340250 E0417 00:35:07.043628 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0417 00:35:07.043876 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:35:07.043972 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:35:07.044027 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0417 00:35:07.075944 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6t4h5" condition "Approved" to 2026-04-17 00:35:07.075931407 +0000 UTC m=+12.282732420 I0417 00:35:07.089619 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6t4h5" condition "Ready" to 2026-04-17 00:35:07.089609636 +0000 UTC m=+12.296410599 I0417 00:35:07.118615 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:07.118603529 +0000 UTC m=+12.325404492 I0417 00:35:07.136964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:07.137337 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:07.137327814 +0000 UTC m=+12.344128807 I0417 00:35:07.154223 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:07.154691 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:07.154678213 +0000 UTC m=+12.361479196 I0417 00:35:07.163019 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:12.044874 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:12.044855862 +0000 UTC m=+17.251656845 I0417 00:35:32.976229 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-17 00:35:32.976212752 +0000 UTC m=+38.183013705 I0417 00:35:32.976560 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:35:32.976602 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-17 00:35:32.976598293 +0000 UTC m=+38.183399256 I0417 00:35:32.996466 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-17 00:35:32.996445745 +0000 UTC m=+38.203246768 I0417 00:35:33.000428 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:33.000482 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-17 00:35:33.00047783 +0000 UTC m=+38.207278793 I0417 00:35:33.061177 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:33.094348 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ft54m" condition "Approved" to 2026-04-17 00:35:33.094331797 +0000 UTC m=+38.301132770 I0417 00:35:33.129873 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ft54m" condition "Ready" to 2026-04-17 00:35:33.129854364 +0000 UTC m=+38.336655357 I0417 00:35:33.164800 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:33.164785462 +0000 UTC m=+38.371586435 I0417 00:35:33.185329 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:33.185675 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:35:33.185663184 +0000 UTC m=+38.392464147 I0417 00:35:33.202963 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:35:33.208174 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:21.794157 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:37:21.794204 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-17 00:37:21.794192948 +0000 UTC m=+147.000993931 I0417 00:37:21.794186 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-17 00:37:21.794167977 +0000 UTC m=+147.000968940 E0417 00:37:21.808341 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0417 00:37:21.808542 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-04-17 00:37:21.808531693 +0000 UTC m=+147.015332686 I0417 00:37:21.808625 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0417 00:37:21.811077 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:21.811162 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-17 00:37:21.811154284 +0000 UTC m=+147.017955267 E0417 00:37:21.817994 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0417 00:37:21.818137 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0417 00:37:21.818164 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0417 00:37:21.818195 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0417 00:37:21.822566 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:37:21.822610 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-17 00:37:21.82259876 +0000 UTC m=+147.029399743 I0417 00:37:21.822666 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-17 00:37:21.822649241 +0000 UTC m=+147.029450244 I0417 00:37:21.838814 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:21.838906 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:37:21.838934 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-17 00:37:21.838923898 +0000 UTC m=+147.045724871 I0417 00:37:22.069627 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:22.097414 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-h5kp7" condition "Approved" to 2026-04-17 00:37:22.09740406 +0000 UTC m=+147.304205023 I0417 00:37:22.126839 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-h5kp7" condition "Ready" to 2026-04-17 00:37:22.126820999 +0000 UTC m=+147.333621962 I0417 00:37:22.155842 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:22.155821396 +0000 UTC m=+147.362622389 I0417 00:37:22.177909 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:22.178320 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:22.178311976 +0000 UTC m=+147.385112959 I0417 00:37:22.195603 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:22.364345 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-tc8t5" condition "Approved" to 2026-04-17 00:37:22.364293312 +0000 UTC m=+147.571094305 I0417 00:37:22.382269 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-tc8t5" condition "Ready" to 2026-04-17 00:37:22.382233395 +0000 UTC m=+147.589034378 I0417 00:37:26.818836 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:26.81882405 +0000 UTC m=+152.025625013 I0417 00:37:26.836106 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-tc8t5" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:26.836093091 +0000 UTC m=+152.042894084 I0417 00:37:26.866566 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:26.866547667 +0000 UTC m=+152.073348660 I0417 00:37:26.885068 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:37:26.885587 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:37:26.885577668 +0000 UTC m=+152.092378661 I0417 00:37:26.908193 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:39:59.177795 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-222.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:39:59.177880 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Issuing" to 2026-04-17 00:39:59.17787098 +0000 UTC m=+304.384671973 I0417 00:39:59.178066 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready" to 2026-04-17 00:39:59.178049345 +0000 UTC m=+304.384850358 I0417 00:39:59.192407 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:39:59.192470 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-222.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:39:59.192495 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Issuing" to 2026-04-17 00:39:59.192488793 +0000 UTC m=+304.399289756 I0417 00:39:59.317521 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:39:59.326622 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-222.nip.io-tls-qsn84" condition "Approved" to 2026-04-17 00:39:59.326606769 +0000 UTC m=+304.533407732 I0417 00:39:59.342894 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-222.nip.io-tls-qsn84" condition "Ready" to 2026-04-17 00:39:59.342885141 +0000 UTC m=+304.549686104 I0417 00:39:59.370689 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:39:59.370676906 +0000 UTC m=+304.577477869 I0417 00:39:59.388616 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:39:59.388985 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:39:59.388977185 +0000 UTC m=+304.595778138 I0417 00:39:59.410703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:07.989775 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-17 00:41:07.989714818 +0000 UTC m=+373.196515801 I0417 00:41:07.990340 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:07.990368 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-17 00:41:07.990361627 +0000 UTC m=+373.197162610 I0417 00:41:08.005672 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" E0417 00:41:08.005822 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0417 00:41:08.005826 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-17 00:41:08.005816018 +0000 UTC m=+373.212616981 I0417 00:41:08.005882 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-17 00:41:08.005870979 +0000 UTC m=+373.212671942 E0417 00:41:08.005948 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:41:08.020651 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0417 00:41:08.020734 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:41:08.020766 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:41:08.020806 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0417 00:41:08.023515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:08.044307 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-2qfq6" condition "Approved" to 2026-04-17 00:41:08.04428434 +0000 UTC m=+373.251085323 I0417 00:41:08.056067 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-2qfq6" condition "Ready" to 2026-04-17 00:41:08.056052833 +0000 UTC m=+373.262853816 I0417 00:41:08.078736 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:08.078723325 +0000 UTC m=+373.285524308 I0417 00:41:08.097132 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:13.022093 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:13.022078373 +0000 UTC m=+378.228879356 I0417 00:41:52.547758 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-17 00:41:52.54774281 +0000 UTC m=+417.754543773 I0417 00:41:52.547807 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:52.547835 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-17 00:41:52.547830512 +0000 UTC m=+417.754631495 I0417 00:41:52.553377 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-17 00:41:52.553365596 +0000 UTC m=+417.760166559 I0417 00:41:52.553399 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-17 00:41:52.553393687 +0000 UTC m=+417.760194640 I0417 00:41:52.553451 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:52.553472 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-17 00:41:52.553468629 +0000 UTC m=+417.760269592 I0417 00:41:52.553685 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:52.555823 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-17 00:41:52.555787223 +0000 UTC m=+417.762588266 I0417 00:41:52.582800 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.582922 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:52.582962 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-17 00:41:52.582952898 +0000 UTC m=+417.789753891 I0417 00:41:52.583160 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.583260 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-17 00:41:52.583249677 +0000 UTC m=+417.790050660 I0417 00:41:52.583737 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.584203 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:41:52.584239 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-17 00:41:52.584217743 +0000 UTC m=+417.791018706 I0417 00:41:52.740538 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-5c4v6" condition "Approved" to 2026-04-17 00:41:52.740518946 +0000 UTC m=+417.947319909 I0417 00:41:52.760769 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-5c4v6" condition "Ready" to 2026-04-17 00:41:52.760753398 +0000 UTC m=+417.967554381 I0417 00:41:52.794971 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:52.794955628 +0000 UTC m=+418.001756611 I0417 00:41:52.810518 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.817347 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.817602 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:52.817597147 +0000 UTC m=+418.024398110 I0417 00:41:52.853082 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:52.853690 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:52.85367577 +0000 UTC m=+418.060476783 I0417 00:41:52.853926 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-2dltf" condition "Approved" to 2026-04-17 00:41:52.853881276 +0000 UTC m=+418.060682259 I0417 00:41:52.870741 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-2dltf" condition "Ready" to 2026-04-17 00:41:52.870735274 +0000 UTC m=+418.077536227 I0417 00:41:52.900731 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:52.900714827 +0000 UTC m=+418.107515810 I0417 00:41:52.943898 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:53.397028 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:53.455961 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-228rl" condition "Approved" to 2026-04-17 00:41:53.455943204 +0000 UTC m=+418.662744167 I0417 00:41:53.556559 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-228rl" condition "Ready" to 2026-04-17 00:41:53.556546439 +0000 UTC m=+418.763347402 I0417 00:41:53.997068 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:53.997047748 +0000 UTC m=+419.203848761 I0417 00:41:54.096444 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:41:54.096987 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:41:54.096977075 +0000 UTC m=+419.303778088 I0417 00:41:54.297494 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:00.434059 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-csrds-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:42:00.434090 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Ready" to 2026-04-17 00:42:00.434072952 +0000 UTC m=+425.640873945 I0417 00:42:00.434116 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Issuing" to 2026-04-17 00:42:00.434104813 +0000 UTC m=+425.640905836 I0417 00:42:00.453439 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-csrds-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-csrds-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:00.453605 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-csrds-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:42:00.453641 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Issuing" to 2026-04-17 00:42:00.453631555 +0000 UTC m=+425.660432548 I0417 00:42:00.729777 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-csrds-4x2xm" condition "Approved" to 2026-04-17 00:42:00.729755958 +0000 UTC m=+425.936556951 I0417 00:42:00.750823 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-csrds-4x2xm" condition "Ready" to 2026-04-17 00:42:00.750809333 +0000 UTC m=+425.957610296 I0417 00:42:00.783865 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:42:00.783849781 +0000 UTC m=+425.990650734 I0417 00:42:00.805336 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-csrds-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-csrds-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:00.805843 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:42:00.805828391 +0000 UTC m=+426.012629354 I0417 00:42:00.832547 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-csrds-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-csrds-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:00.833507 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-csrds-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:42:00.833496591 +0000 UTC m=+426.040297554 I0417 00:42:26.498876 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:42:26.498923 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-17 00:42:26.498912137 +0000 UTC m=+451.705713130 I0417 00:42:26.498927 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-17 00:42:26.498902346 +0000 UTC m=+451.705703329 I0417 00:42:26.513556 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:26.513615 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-17 00:42:26.513610166 +0000 UTC m=+451.720411129 I0417 00:42:26.954631 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:26.987065 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-xwzc6" condition "Approved" to 2026-04-17 00:42:26.98704472 +0000 UTC m=+452.193845703 I0417 00:42:27.008070 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-xwzc6" condition "Ready" to 2026-04-17 00:42:27.008054523 +0000 UTC m=+452.214855476 I0417 00:42:27.036534 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:42:27.036517454 +0000 UTC m=+452.243318417 I0417 00:42:27.052734 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:42:27.053324 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:42:27.053312281 +0000 UTC m=+452.260113264 I0417 00:42:27.067899 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:45:46.107290 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-17 00:45:46.107247978 +0000 UTC m=+651.314048961 I0417 00:45:46.107523 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:45:46.107639 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-17 00:45:46.107629158 +0000 UTC m=+651.314430151 I0417 00:45:46.128375 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:45:46.128467 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:45:46.128495 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-17 00:45:46.128488877 +0000 UTC m=+651.335289860 I0417 00:45:46.384453 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-xx4sf" condition "Approved" to 2026-04-17 00:45:46.384442348 +0000 UTC m=+651.591243301 I0417 00:45:46.405011 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-xx4sf" condition "Ready" to 2026-04-17 00:45:46.405000459 +0000 UTC m=+651.611801422 I0417 00:45:46.433314 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:45:46.433302374 +0000 UTC m=+651.640103337 I0417 00:45:46.453465 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:48:13.529353 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:48:13.529427 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-04-17 00:48:13.529419527 +0000 UTC m=+798.736220480 I0417 00:48:13.529775 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-04-17 00:48:13.529753906 +0000 UTC m=+798.736554889 I0417 00:48:13.547794 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:48:13.547866 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-04-17 00:48:13.547856409 +0000 UTC m=+798.754657362 I0417 00:48:13.810669 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:48:13.840447 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-9hj8l" condition "Approved" to 2026-04-17 00:48:13.840428801 +0000 UTC m=+799.047229764 I0417 00:48:13.866692 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-9hj8l" condition "Ready" to 2026-04-17 00:48:13.866676376 +0000 UTC m=+799.073477329 I0417 00:48:13.895772 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:48:13.895756708 +0000 UTC m=+799.102557701 I0417 00:48:13.922727 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:48:13.923301 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:48:13.923292799 +0000 UTC m=+799.130093782 I0417 00:48:13.956973 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:49:20.042049 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:49:20.042046 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-04-17 00:49:20.041521484 +0000 UTC m=+865.248322437 I0417 00:49:20.042180 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-04-17 00:49:20.0421128 +0000 UTC m=+865.248913763 I0417 00:49:20.058949 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:49:20.059103 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-04-17 00:49:20.059089263 +0000 UTC m=+865.265890246 I0417 00:49:20.258515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:49:20.301850 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-67thc" condition "Approved" to 2026-04-17 00:49:20.301827977 +0000 UTC m=+865.508628940 I0417 00:49:20.327176 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-67thc" condition "Ready" to 2026-04-17 00:49:20.327161247 +0000 UTC m=+865.533962210 I0417 00:49:20.358503 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:49:20.358483881 +0000 UTC m=+865.565284864 I0417 00:49:20.388247 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:49:20.389231 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:49:20.389224868 +0000 UTC m=+865.596025821 I0417 00:49:20.427420 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:52:22.017187 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:52:22.017178 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-04-17 00:52:22.017133593 +0000 UTC m=+1047.223934546 I0417 00:52:22.017244 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-04-17 00:52:22.017230366 +0000 UTC m=+1047.224031359 I0417 00:52:22.035799 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:52:22.035889 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-04-17 00:52:22.03587957 +0000 UTC m=+1047.242680553 I0417 00:52:22.434022 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:52:22.474963 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-76jjk" condition "Approved" to 2026-04-17 00:52:22.474944432 +0000 UTC m=+1047.681745435 I0417 00:52:22.494754 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-76jjk" condition "Ready" to 2026-04-17 00:52:22.494738256 +0000 UTC m=+1047.701539209 I0417 00:52:22.524858 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:52:22.5248475 +0000 UTC m=+1047.731648483 I0417 00:52:22.554321 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:52:22.614136 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"