I0512 01:41:31.242212 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0512 01:41:31.242303 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0512 01:41:31.242343 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0512 01:41:31.244796 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0512 01:41:31.245094 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0512 01:41:31.245217 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0512 01:41:31.245334 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0512 01:41:31.247566 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0512 01:41:31.260985 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0512 01:41:31.261236 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0512 01:41:31.261306 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0512 01:41:31.261329 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0512 01:41:31.269257 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0512 01:41:31.272273 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0512 01:41:31.274547 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0512 01:41:31.276774 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0512 01:41:31.276893 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0512 01:41:31.279219 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0512 01:41:31.280981 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0512 01:41:31.285668 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0512 01:41:31.287661 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0512 01:41:31.289406 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0512 01:41:31.291135 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0512 01:41:31.292973 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0512 01:41:31.294668 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0512 01:41:31.294710 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0512 01:41:31.296745 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0512 01:41:31.298444 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0512 01:41:31.304555 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0512 01:41:31.308731 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0512 01:41:31.311099 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0512 01:41:31.313874 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0512 01:41:31.313911 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0512 01:41:31.316841 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.318492 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.318576 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.372320 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.376550 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.391232 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.401375 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.417025 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.437974 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:31.454178 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:41:44.078517 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-12 01:41:44.078501315 +0000 UTC m=+12.867225644 I0512 01:41:44.817666 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-12 01:41:44.817650379 +0000 UTC m=+13.606374718 I0512 01:41:44.817874 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:41:44.817929 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-12 01:41:44.817921713 +0000 UTC m=+13.606646042 I0512 01:41:44.828740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:41:44.828806 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:41:44.828824 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-12 01:41:44.828818694 +0000 UTC m=+13.617543013 E0512 01:41:44.830596 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:41:44.830651 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-12 01:41:44.830644696 +0000 UTC m=+13.619369025 E0512 01:41:44.830777 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:41:44.844272 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0512 01:41:44.844340 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:41:44.844365 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:41:44.844392 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0512 01:41:44.863964 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-l6bgm" condition "Approved" to 2026-05-12 01:41:44.863938657 +0000 UTC m=+13.652662986 I0512 01:41:44.887404 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-l6bgm" condition "Ready" to 2026-05-12 01:41:44.88739077 +0000 UTC m=+13.676115099 I0512 01:41:44.907945 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:41:44.907931477 +0000 UTC m=+13.696655806 I0512 01:41:44.932210 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:41:44.932693 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:41:44.932686025 +0000 UTC m=+13.721410344 I0512 01:41:44.945218 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:41:44.945606 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:41:44.945598051 +0000 UTC m=+13.734322370 I0512 01:41:49.845175 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:41:49.845165258 +0000 UTC m=+18.633889587 I0512 01:42:14.194233 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-12 01:42:14.194199099 +0000 UTC m=+42.982923428 I0512 01:42:14.194277 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:42:14.194332 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-12 01:42:14.19431904 +0000 UTC m=+42.983043369 I0512 01:42:14.201972 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-12 01:42:14.201955695 +0000 UTC m=+42.990680014 I0512 01:42:14.236861 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:42:14.236934 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:42:14.236952 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-12 01:42:14.236947363 +0000 UTC m=+43.025671672 I0512 01:42:14.731329 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-9h29t" condition "Approved" to 2026-05-12 01:42:14.731316538 +0000 UTC m=+43.520040867 I0512 01:42:14.762732 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-9h29t" condition "Ready" to 2026-05-12 01:42:14.762721955 +0000 UTC m=+43.551446274 I0512 01:42:14.797550 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:42:14.797527671 +0000 UTC m=+43.586252010 I0512 01:42:14.819891 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:42:14.820238 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:42:14.820230852 +0000 UTC m=+43.608955171 I0512 01:42:14.842749 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:42:14.843185 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:42:14.843178966 +0000 UTC m=+43.631903285 I0512 01:47:10.760168 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-167.nip.io-tls" condition "Ready" to 2026-05-12 01:47:10.76011656 +0000 UTC m=+339.548840909 I0512 01:47:10.760245 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-167.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:47:10.760286 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-167.nip.io-tls" condition "Issuing" to 2026-05-12 01:47:10.760275042 +0000 UTC m=+339.548999401 I0512 01:47:10.778163 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-167.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-167.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:47:10.778244 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-167.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:47:10.778263 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-167.nip.io-tls" condition "Issuing" to 2026-05-12 01:47:10.778256109 +0000 UTC m=+339.566980438 I0512 01:47:10.917964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-214-167.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-167.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:47:10.925795 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-214-167.nip.io-tls-nbj7h" condition "Approved" to 2026-05-12 01:47:10.925783905 +0000 UTC m=+339.714508234 I0512 01:47:10.950242 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-214-167.nip.io-tls-nbj7h" condition "Ready" to 2026-05-12 01:47:10.950231849 +0000 UTC m=+339.738956168 I0512 01:47:10.975475 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-214-167.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:47:10.975462496 +0000 UTC m=+339.764186825 I0512 01:47:10.998787 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-214-167.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-167.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:47:10.999163 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-214-167.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:47:10.999156197 +0000 UTC m=+339.787880526 I0512 01:47:11.015491 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-214-167.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-167.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:48:16.454672 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-12 01:48:16.454640034 +0000 UTC m=+405.243364363 I0512 01:48:16.454907 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:48:16.455025 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-12 01:48:16.45501049 +0000 UTC m=+405.243734839 E0512 01:48:16.471582 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:48:16.471698 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-12 01:48:16.471690009 +0000 UTC m=+405.260414338 E0512 01:48:16.471740 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:48:16.472509 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:48:16.472614 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:48:16.472648 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-12 01:48:16.472643743 +0000 UTC m=+405.261368072 E0512 01:48:16.484065 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0512 01:48:16.484747 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:48:16.484970 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:48:16.485387 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0512 01:48:16.510639 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-9jqjp" condition "Approved" to 2026-05-12 01:48:16.510626408 +0000 UTC m=+405.299350737 I0512 01:48:16.525171 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-9jqjp" condition "Ready" to 2026-05-12 01:48:16.525151135 +0000 UTC m=+405.313875484 I0512 01:48:16.546835 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:48:16.546824408 +0000 UTC m=+405.335548727 I0512 01:48:16.565845 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:48:16.566208 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:48:16.566199676 +0000 UTC m=+405.354924015 I0512 01:48:16.588703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:48:21.484834 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:48:21.484821784 +0000 UTC m=+410.273546113 I0512 01:49:07.990321 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:07.990410 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-12 01:49:07.990351624 +0000 UTC m=+456.779075943 I0512 01:49:07.992195 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-12 01:49:07.990359835 +0000 UTC m=+456.779084144 I0512 01:49:07.998802 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-12 01:49:07.998790113 +0000 UTC m=+456.787514432 I0512 01:49:07.999042 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:07.999056 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-12 01:49:07.999053817 +0000 UTC m=+456.787778136 I0512 01:49:08.005656 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-12 01:49:08.00564422 +0000 UTC m=+456.794368549 I0512 01:49:08.005917 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:08.005936 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-12 01:49:08.005933284 +0000 UTC m=+456.794657603 I0512 01:49:08.031449 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:08.031535 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:08.031561 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-12 01:49:08.031554725 +0000 UTC m=+456.820279054 I0512 01:49:08.047721 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:08.047793 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:08.047812 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-12 01:49:08.047807574 +0000 UTC m=+456.836531893 I0512 01:49:08.071235 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:08.071342 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:08.071378 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-12 01:49:08.071370486 +0000 UTC m=+456.860094825 I0512 01:49:08.330993 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-zx89d" condition "Approved" to 2026-05-12 01:49:08.330982145 +0000 UTC m=+457.119706464 I0512 01:49:08.354938 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-zx89d" condition "Ready" to 2026-05-12 01:49:08.354930093 +0000 UTC m=+457.143654412 I0512 01:49:08.376760 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-msp52" condition "Approved" to 2026-05-12 01:49:08.376751809 +0000 UTC m=+457.165476128 I0512 01:49:08.395380 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:08.395368832 +0000 UTC m=+457.184093151 I0512 01:49:08.397498 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-msp52" condition "Ready" to 2026-05-12 01:49:08.397490862 +0000 UTC m=+457.186215191 I0512 01:49:08.429120 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:08.431088 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:08.431082075 +0000 UTC m=+457.219806394 I0512 01:49:08.461172 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" E0512 01:49:08.558121 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-l68gg\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" E0512 01:49:08.580184 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"grafana-tls-4678c\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" I0512 01:49:08.888293 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-bkfsx" condition "Approved" to 2026-05-12 01:49:08.888278489 +0000 UTC m=+457.677002818 I0512 01:49:09.140129 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-bkfsx" condition "Ready" to 2026-05-12 01:49:09.140118847 +0000 UTC m=+457.928843176 I0512 01:49:09.433801 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:09.433785252 +0000 UTC m=+458.222509621 I0512 01:49:09.556104 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:16.735771 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" condition "Ready" to 2026-05-12 01:49:16.735745456 +0000 UTC m=+465.524469775 I0512 01:49:16.736143 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:16.736159 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" condition "Issuing" to 2026-05-12 01:49:16.736154982 +0000 UTC m=+465.524879331 I0512 01:49:16.757685 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-pthsf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:16.757834 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" condition "Ready" to 2026-05-12 01:49:16.757825925 +0000 UTC m=+465.546550254 I0512 01:49:17.200283 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-pthsf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:17.586917 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-pthsf-crkhn" condition "Approved" to 2026-05-12 01:49:17.586904593 +0000 UTC m=+466.375628922 I0512 01:49:17.635836 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-pthsf-crkhn" condition "Ready" to 2026-05-12 01:49:17.635813168 +0000 UTC m=+466.424537527 I0512 01:49:17.676022 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:17.67600975 +0000 UTC m=+466.464734079 I0512 01:49:17.695554 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-pthsf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-pthsf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:30.808323 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-12 01:49:30.808287099 +0000 UTC m=+479.597011418 I0512 01:49:30.808769 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:30.808825 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-12 01:49:30.808819526 +0000 UTC m=+479.597543845 I0512 01:49:30.835500 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:30.835670 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:49:30.835689 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-12 01:49:30.835684488 +0000 UTC m=+479.624408807 I0512 01:49:31.080991 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-htqn5" condition "Approved" to 2026-05-12 01:49:31.080978272 +0000 UTC m=+479.869702591 I0512 01:49:31.101293 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-htqn5" condition "Ready" to 2026-05-12 01:49:31.101280903 +0000 UTC m=+479.890005242 I0512 01:49:31.128433 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:31.128422779 +0000 UTC m=+479.917147098 I0512 01:49:31.151134 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:31.151501 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:31.151495308 +0000 UTC m=+479.940219627 I0512 01:49:31.167412 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:49:31.167670 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:49:31.167664652 +0000 UTC m=+479.956388971 I0512 01:52:53.862788 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-12 01:52:53.862764381 +0000 UTC m=+682.651488730 I0512 01:52:53.862992 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:52:53.863098 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-12 01:52:53.863078141 +0000 UTC m=+682.651802480 I0512 01:52:53.884755 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:53.884941 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-12 01:52:53.884929697 +0000 UTC m=+682.673654026 I0512 01:52:54.226566 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:54.263843 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-m9n6t" condition "Approved" to 2026-05-12 01:52:54.263833404 +0000 UTC m=+683.052557733 I0512 01:52:54.290648 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-m9n6t" condition "Ready" to 2026-05-12 01:52:54.290637449 +0000 UTC m=+683.079361778 I0512 01:52:54.317931 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:52:54.317908098 +0000 UTC m=+683.106632417 I0512 01:52:54.345430 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:54.352969 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:52:54.352957878 +0000 UTC m=+683.141682197 I0512 01:52:54.368556 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:54.374627 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:54.374965 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:54.375244 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:52:54.375236967 +0000 UTC m=+683.163961296 I0512 01:53:39.278152 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-12 01:53:39.278140663 +0000 UTC m=+728.066865102 I0512 01:53:39.278521 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:53:39.278563 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-12 01:53:39.278558956 +0000 UTC m=+728.067283275 I0512 01:53:39.299387 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.299441 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:53:39.299452 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-12 01:53:39.299446882 +0000 UTC m=+728.088171201 I0512 01:53:39.531323 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.546377 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-8stvj" condition "Approved" to 2026-05-12 01:53:39.546367176 +0000 UTC m=+728.335091495 I0512 01:53:39.572350 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-8stvj" condition "Ready" to 2026-05-12 01:53:39.572339842 +0000 UTC m=+728.361064171 I0512 01:53:39.620368 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:39.620358468 +0000 UTC m=+728.409082787 I0512 01:53:39.651200 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.651674 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:39.651667852 +0000 UTC m=+728.440392181 I0512 01:53:39.666475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.675530 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.677419 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:39.677943 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:39.677933447 +0000 UTC m=+728.466657776