I0519 17:13:22.921240 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0519 17:13:22.921346 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0519 17:13:22.921404 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0519 17:13:22.924765 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0519 17:13:22.925689 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0519 17:13:22.926348 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0519 17:13:22.926358 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0519 17:13:22.941529 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0519 17:13:23.477691 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0519 17:13:23.492046 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0519 17:13:23.492158 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0519 17:13:23.492201 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0519 17:13:23.493467 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0519 17:13:23.493530 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0519 17:13:23.493539 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0519 17:13:23.495108 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0519 17:13:23.495989 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0519 17:13:23.512990 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0519 17:13:23.515059 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0519 17:13:23.518774 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0519 17:13:23.519325 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0519 17:13:23.520355 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0519 17:13:23.522613 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0519 17:13:23.524792 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0519 17:13:23.526682 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0519 17:13:23.528351 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0519 17:13:23.528382 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0519 17:13:23.528427 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0519 17:13:23.535298 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0519 17:13:23.535525 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0519 17:13:23.538879 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0519 17:13:23.541058 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0519 17:13:23.543286 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0519 17:13:23.549340 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.551843 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.551881 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.552509 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.553179 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.553839 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.557414 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.569213 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.570660 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0519 17:13:23.851893 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 E0519 17:13:50.982667 1 event.go:346] "Server rejected event (will not retry!)" err="etcdserver: request timed out" event="&Event{ObjectMeta:{libvirt-api.18b106ccad41f4da openstack 32297 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:Issuer,Namespace:openstack,Name:libvirt-api,UID:4649d0cc-a4ba-4ff3-bf42-40dd34817db0,APIVersion:cert-manager.io/v1,ResourceVersion:17975,FieldPath:,},Reason:KeyPairVerified,Message:Signing CA verified,Source:EventSource{Component:cert-manager-issuers,Host:,},FirstTimestamp:2026-05-19 17:13:23 +0000 UTC,LastTimestamp:2026-05-19 17:13:28.858289492 +0000 UTC m=+5.981831258,Count:2,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:cert-manager-issuers,ReportingInstance:,}" E0519 17:13:50.984056 1 event.go:346] "Server rejected event (will not retry!)" err="etcdserver: request timed out" event="&Event{ObjectMeta:{atmosphere.18b106ccac4bf3e0 default 32295 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:ClusterIssuer,Namespace:,Name:atmosphere,UID:e8af141b-9a69-456d-8afa-9538a836a579,APIVersion:cert-manager.io/v1,ResourceVersion:1668,FieldPath:,},Reason:KeyPairVerified,Message:Signing CA verified,Source:EventSource{Component:cert-manager-clusterissuers,Host:,},FirstTimestamp:2026-05-19 17:13:23 +0000 UTC,LastTimestamp:2026-05-19 17:13:28.854336772 +0000 UTC m=+5.977878578,Count:2,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:cert-manager-clusterissuers,ReportingInstance:,}" E0519 17:14:10.759085 1 event.go:346] "Server rejected event (will not retry!)" err="etcdserver: request timed out" event="&Event{ObjectMeta:{octavia-client.18b106ccad441867 openstack 32307 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:Issuer,Namespace:openstack,Name:octavia-client,UID:335f7dfb-f2e6-4435-bdfd-6d907291feb5,APIVersion:cert-manager.io/v1,ResourceVersion:27405,FieldPath:,},Reason:KeyPairVerified,Message:Signing CA verified,Source:EventSource{Component:cert-manager-issuers,Host:,},FirstTimestamp:2026-05-19 17:13:23 +0000 UTC,LastTimestamp:2026-05-19 17:13:28.861604287 +0000 UTC m=+5.985146093,Count:2,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:cert-manager-issuers,ReportingInstance:,}" I0519 17:19:36.618949 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:19:36.619011 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-05-19 17:19:36.619000791 +0000 UTC m=+373.742542557 I0519 17:19:36.619104 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-05-19 17:19:36.619080293 +0000 UTC m=+373.742622089 I0519 17:19:36.640629 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:19:36.640715 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:19:36.640734 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-05-19 17:19:36.640725996 +0000 UTC m=+373.764267762 I0519 17:19:36.802703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:19:36.820279 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-wkvq6" condition "Approved" to 2026-05-19 17:19:36.820256034 +0000 UTC m=+373.943797810 I0519 17:19:36.847277 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-wkvq6" condition "Ready" to 2026-05-19 17:19:36.84725915 +0000 UTC m=+373.970800926 I0519 17:19:36.897188 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:19:36.897169636 +0000 UTC m=+374.020711412 I0519 17:19:36.937112 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:19:36.937686 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:19:36.937674308 +0000 UTC m=+374.061216114 I0519 17:19:36.963994 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:20:15.107352 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:20:15.107404 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-19 17:20:15.107392654 +0000 UTC m=+412.230934450 I0519 17:20:15.107447 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-19 17:20:15.107425204 +0000 UTC m=+412.230966990 I0519 17:20:15.126438 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:20:15.126525 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:20:15.126543 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-19 17:20:15.126535669 +0000 UTC m=+412.250077445 I0519 17:20:15.467688 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:20:15.479313 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ld9kr" condition "Approved" to 2026-05-19 17:20:15.479298362 +0000 UTC m=+412.602840138 I0519 17:20:15.502722 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ld9kr" condition "Ready" to 2026-05-19 17:20:15.502709537 +0000 UTC m=+412.626251313 I0519 17:20:15.535624 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:20:15.535609475 +0000 UTC m=+412.659151241 I0519 17:20:15.559500 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:20:15.560036 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:20:15.560023521 +0000 UTC m=+412.683565327 I0519 17:20:15.582377 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"