I0402 17:47:12.919857 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0402 17:47:12.919997 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0402 17:47:12.920066 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0402 17:47:12.922687 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0402 17:47:12.923271 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0402 17:47:12.923386 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0402 17:47:12.923470 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0402 17:47:12.925384 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0402 17:47:13.089908 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0402 17:47:13.090206 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0402 17:47:13.098636 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0402 17:47:13.105691 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0402 17:47:13.107969 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0402 17:47:13.108133 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0402 17:47:13.120272 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0402 17:47:13.144012 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0402 17:47:13.147317 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0402 17:47:13.150087 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0402 17:47:13.153567 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0402 17:47:13.154133 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0402 17:47:13.156487 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0402 17:47:13.156508 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0402 17:47:13.156518 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0402 17:47:13.156711 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0402 17:47:13.162756 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0402 17:47:13.172717 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0402 17:47:13.172944 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0402 17:47:13.177245 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0402 17:47:13.182364 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0402 17:47:13.189107 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0402 17:47:13.189192 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0402 17:47:13.192829 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0402 17:47:13.197363 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0402 17:47:13.198224 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.205681 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.206297 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.209080 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.209635 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.209965 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.213093 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.216512 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.232324 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 17:47:13.688438 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 E0402 17:47:44.217799 1 event.go:346] "Server rejected event (will not retry!)" err="etcdserver: request timed out" event="&Event{ObjectMeta:{libvirt-vnc.18a29b5ea00b2e04 openstack 26300 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:Issuer,Namespace:openstack,Name:libvirt-vnc,UID:a9fe88b7-400f-4012-a45c-15db6e8271b2,APIVersion:cert-manager.io/v1,ResourceVersion:15097,FieldPath:,},Reason:KeyPairVerified,Message:Signing CA verified,Source:EventSource{Component:cert-manager-issuers,Host:,},FirstTimestamp:2026-04-02 17:47:13 +0000 UTC,LastTimestamp:2026-04-02 17:47:18.696467027 +0000 UTC m=+5.848947326,Count:2,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:cert-manager-issuers,ReportingInstance:,}" I0402 17:54:11.901043 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-04-02 17:54:11.901025208 +0000 UTC m=+419.053505517 I0402 17:54:11.902520 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 17:54:11.902567 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-04-02 17:54:11.902555726 +0000 UTC m=+419.055036025 I0402 17:54:11.920353 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:11.920474 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 17:54:11.920495 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-04-02 17:54:11.920489584 +0000 UTC m=+419.072969863 I0402 17:54:12.072598 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-kdk2v" condition "Approved" to 2026-04-02 17:54:12.072579127 +0000 UTC m=+419.225059416 I0402 17:54:12.095327 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-kdk2v" condition "Ready" to 2026-04-02 17:54:12.095310815 +0000 UTC m=+419.247791084 I0402 17:54:12.127296 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 17:54:12.127279844 +0000 UTC m=+419.279760113 I0402 17:54:12.152109 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:12.211015 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:53.797064 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-02 17:54:53.79705223 +0000 UTC m=+460.949532509 I0402 17:54:53.797032 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 17:54:53.797360 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-02 17:54:53.797345667 +0000 UTC m=+460.949825966 I0402 17:54:53.827758 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:53.827882 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 17:54:53.828097 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-02 17:54:53.828083925 +0000 UTC m=+460.980564224 I0402 17:54:53.999373 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-75kgx" condition "Approved" to 2026-04-02 17:54:53.999363347 +0000 UTC m=+461.151843616 I0402 17:54:54.020315 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-75kgx" condition "Ready" to 2026-04-02 17:54:54.020303821 +0000 UTC m=+461.172784100 I0402 17:54:54.068169 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 17:54:54.068150707 +0000 UTC m=+461.220630976 I0402 17:54:54.101249 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:54.101609 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 17:54:54.101602224 +0000 UTC m=+461.254082493 I0402 17:54:54.116181 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 17:54:54.121667 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"