I0413 15:09:27.055163 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0413 15:09:27.055411 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0413 15:09:27.055479 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0413 15:09:27.055594 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0413 15:09:27.057284 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0413 15:09:27.058768 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0413 15:09:27.059215 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0413 15:09:27.060949 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0413 15:09:27.074970 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0413 15:09:27.075271 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0413 15:09:27.077325 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0413 15:09:27.077381 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0413 15:09:27.077623 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0413 15:09:27.078289 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0413 15:09:27.078866 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0413 15:09:27.078898 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0413 15:09:27.078918 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0413 15:09:27.079048 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0413 15:09:27.079657 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0413 15:09:27.080259 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0413 15:09:27.081383 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0413 15:09:27.081870 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0413 15:09:27.082370 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0413 15:09:27.082816 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0413 15:09:27.083187 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0413 15:09:27.083544 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0413 15:09:27.084111 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0413 15:09:27.085201 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0413 15:09:27.085368 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0413 15:09:27.086516 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0413 15:09:27.086885 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0413 15:09:27.087037 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0413 15:09:27.087682 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0413 15:09:48.280841 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-13 15:09:48.280794918 +0000 UTC m=+21.266042713 I0413 15:09:48.295418 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:48.295449 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-13 15:09:48.295443101 +0000 UTC m=+21.280690876 I0413 15:09:48.295549 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-13 15:09:48.295538273 +0000 UTC m=+21.280786058 E0413 15:09:48.314718 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a5f329a864d959", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"2123389f-e615-400b-9fc9-a930bcb80f8b", APIVersion:"cert-manager.io/v1", ResourceVersion:"1208", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 13, 15, 9, 48, 311918937, time.Local), LastTimestamp:time.Date(2026, time.April, 13, 15, 9, 48, 311918937, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a5f329a864d959" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0413 15:09:48.315516 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0413 15:09:48.315649 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-13 15:09:48.315639164 +0000 UTC m=+21.300886929 E0413 15:09:48.315839 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0413 15:09:48.327876 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0413 15:09:48.345822 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-13 15:09:48.3458098 +0000 UTC m=+21.331057575 I0413 15:09:48.358075 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:48.358153 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-13 15:09:48.358141538 +0000 UTC m=+21.343389323 I0413 15:09:48.358449 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-13 15:09:48.358437925 +0000 UTC m=+21.343685730 I0413 15:09:48.378859 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0413 15:09:48.378936 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:48.378957 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-13 15:09:48.378950876 +0000 UTC m=+21.364198671 E0413 15:09:48.639304 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0413 15:09:48.867469 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-13 15:09:48.867448473 +0000 UTC m=+21.852696248 I0413 15:09:48.881900 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-13 15:09:48.881888071 +0000 UTC m=+21.867135846 I0413 15:09:48.883543 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:48.886305 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-13 15:09:48.886295895 +0000 UTC m=+21.871543680 I0413 15:09:48.902291 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0413 15:09:48.902359 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-13 15:09:48.90235097 +0000 UTC m=+21.887598745 I0413 15:09:49.222023 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-13 15:09:49.222014868 +0000 UTC m=+22.207262633 I0413 15:09:49.235934 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:49.235969 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-13 15:09:49.235959283 +0000 UTC m=+22.221207058 I0413 15:09:49.236570 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-gn2wg" condition "Approved" to 2026-04-13 15:09:49.236561338 +0000 UTC m=+22.221809103 I0413 15:09:49.236594 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-13 15:09:49.236588858 +0000 UTC m=+22.221836633 I0413 15:09:49.257710 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0413 15:09:49.257845 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-13 15:09:49.257838295 +0000 UTC m=+22.243086070 I0413 15:09:49.273327 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-gn2wg" condition "Ready" to 2026-04-13 15:09:49.273311837 +0000 UTC m=+22.258559602 I0413 15:09:49.320683 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:49.320671474 +0000 UTC m=+22.305919249 I0413 15:09:49.347395 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0413 15:09:49.353514 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:49.353507771 +0000 UTC m=+22.338755536 I0413 15:09:49.399629 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0413 15:09:49.409635 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0413 15:09:49.410172 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:49.410166427 +0000 UTC m=+22.395414192 I0413 15:09:49.486632 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0413 15:09:49.562180 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-7fplt" condition "Approved" to 2026-04-13 15:09:49.56216668 +0000 UTC m=+22.547414445 I0413 15:09:49.612787 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-13 15:09:49.612775064 +0000 UTC m=+22.598022819 I0413 15:09:49.612907 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0413 15:09:49.613581 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-13 15:09:49.613576532 +0000 UTC m=+22.598824317 I0413 15:09:49.612813 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-13 15:09:49.612795154 +0000 UTC m=+22.598042919 I0413 15:09:49.616378 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-7fplt" condition "Ready" to 2026-04-13 15:09:49.616373827 +0000 UTC m=+22.601621582 I0413 15:09:49.636742 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:49.636845 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-13 15:09:49.636838687 +0000 UTC m=+22.622086452 I0413 15:09:49.657374 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:49.657356436 +0000 UTC m=+22.642604201 I0413 15:09:49.694190 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0413 15:09:49.866055 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:50.032182 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-jnbms" condition "Approved" to 2026-04-13 15:09:50.032173288 +0000 UTC m=+23.017421053 I0413 15:09:50.065816 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-jnbms" condition "Ready" to 2026-04-13 15:09:50.065802684 +0000 UTC m=+23.051050459 I0413 15:09:50.315809 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:50.31579917 +0000 UTC m=+23.301046935 I0413 15:09:50.413066 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0413 15:09:50.561948 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:50.562511 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:50.56250132 +0000 UTC m=+23.547749115 I0413 15:09:50.817792 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:50.8177825 +0000 UTC m=+23.803030265 I0413 15:09:50.883053 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7wwjr" condition "Approved" to 2026-04-13 15:09:50.883043143 +0000 UTC m=+23.868290908 I0413 15:09:50.943267 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:50.960930 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:51.014219 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0413 15:09:51.081508 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7wwjr" condition "Ready" to 2026-04-13 15:09:51.081500235 +0000 UTC m=+24.066748000 I0413 15:09:51.622812 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:51.622795157 +0000 UTC m=+24.608042922 I0413 15:09:51.711272 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0413 15:09:51.711753 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 15:09:51.71174489 +0000 UTC m=+24.696992665 I0413 15:09:51.911698 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" E0413 15:10:57.944729 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0413 15:10:57.978649 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-13 15:10:57.978337682 +0000 UTC m=+90.963585487 I0413 15:10:58.000786 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-13 15:10:58.000769498 +0000 UTC m=+90.986017323 E0413 15:11:00.083134 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0413 15:11:00.121949 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-13 15:11:00.121936405 +0000 UTC m=+93.107184180 I0413 15:11:00.145462 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-13 15:11:00.145450183 +0000 UTC m=+93.130697958 E0413 15:11:01.719763 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0413 15:11:01.759296 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-13 15:11:01.759282533 +0000 UTC m=+94.744530308 I0413 15:11:01.777024 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-13 15:11:01.777013095 +0000 UTC m=+94.762260860 E0413 15:11:03.468491 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0413 15:11:03.497357 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-13 15:11:03.497340642 +0000 UTC m=+96.482588447 I0413 15:11:03.518889 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-13 15:11:03.518873837 +0000 UTC m=+96.504121622