Name: capo-controller-manager-65565fdb7f-8m2gr Namespace: capo-system Priority: 0 Service Account: capo-manager Node: instance/199.19.213.183 Start Time: Wed, 20 May 2026 13:55:14 +0000 Labels: cluster.x-k8s.io/provider=infrastructure-openstack control-plane=capo-controller-manager pod-template-hash=65565fdb7f Annotations: Status: Running SeccompProfile: RuntimeDefault IP: 10.0.0.81 IPs: IP: 10.0.0.81 Controlled By: ReplicaSet/capo-controller-manager-65565fdb7f Containers: manager: Container ID: containerd://33b2c465cbd413df180cbd8ef7d1426713bfebd9e38ecaf77f7922fe0dec6a93 Image: harbor.atmosphere.dev/registry.k8s.io/capi-openstack/capi-openstack-controller:v0.12.7 Image ID: harbor.atmosphere.dev/registry.k8s.io/capi-openstack/capi-openstack-controller@sha256:b964c2f374ad4f26a593749d3c737492d5c1821db143b26596c9285b9055a8b4 Ports: 9443/TCP, 9440/TCP Host Ports: 0/TCP, 0/TCP Command: /manager Args: --leader-elect --v=2 --diagnostics-address=127.0.0.1:8080 --insecure-diagnostics=true State: Running Started: Wed, 20 May 2026 14:01:35 +0000 Last State: Terminated Reason: Error Message: E0520 14:01:18.757800 1 main.go:328] "unable to create controller" err="failed to get API group resources: unable to retrieve the complete list of server APIs: ipam.cluster.x-k8s.io/v1beta1: forbidden: User \"system:serviceaccount:capo-system:capo-manager\" cannot get path \"/apis/ipam.cluster.x-k8s.io/v1beta1\"" logger="setup" controller="FloatingIPPool" Exit Code: 1 Started: Wed, 20 May 2026 14:01:16 +0000 Finished: Wed, 20 May 2026 14:01:18 +0000 Ready: True Restart Count: 3 Liveness: http-get http://:healthz/healthz delay=0s timeout=1s period=10s #success=1 #failure=3 Readiness: http-get http://:healthz/readyz delay=0s timeout=1s period=10s #success=1 #failure=3 Environment: CLUSTER_API_OPENSTACK_INSTANCE_CREATE_TIMEOUT: 10 Mounts: /tmp/k8s-webhook-server/serving-certs from cert (ro) /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-lbh5c (ro) Conditions: Type Status Initialized True Ready True ContainersReady True PodScheduled True Volumes: cert: Type: Secret (a volume populated by a Secret) SecretName: capo-webhook-service-cert Optional: false kube-api-access-lbh5c: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: DownwardAPI: true QoS Class: BestEffort Node-Selectors: openstack-control-plane=enabled Tolerations: node-role.kubernetes.io/control-plane:NoSchedule node-role.kubernetes.io/master:NoSchedule node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 37m default-scheduler Successfully assigned capo-system/capo-controller-manager-65565fdb7f-8m2gr to instance Warning Unhealthy 33m (x3 over 34m) kubelet Liveness probe failed: Get "http://10.0.0.81:9440/healthz": dial tcp 10.0.0.81:9440: connect: connection refused Normal Killing 33m kubelet Container manager failed liveness probe, will be restarted Normal Pulled 33m (x2 over 37m) kubelet Container image "harbor.atmosphere.dev/registry.k8s.io/capi-openstack/capi-openstack-controller:v0.12.7" already present on machine Normal Created 32m (x2 over 37m) kubelet Created container manager Normal Started 32m (x2 over 37m) kubelet Started container manager Warning Unhealthy 31m (x16 over 34m) kubelet Readiness probe failed: Get "http://10.0.0.81:9440/readyz": dial tcp 10.0.0.81:9440: connect: connection refused