I0425 01:11:32.623957 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0425 01:11:32.624051 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0425 01:11:32.624127 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0425 01:11:32.628835 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0425 01:11:32.629340 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0425 01:11:32.629441 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0425 01:11:32.629494 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0425 01:11:32.639426 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0425 01:11:32.664836 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0425 01:11:32.670141 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0425 01:11:32.673371 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0425 01:11:32.675280 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0425 01:11:32.681498 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0425 01:11:32.683547 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0425 01:11:32.683576 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0425 01:11:32.685788 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0425 01:11:32.687646 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0425 01:11:32.693495 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0425 01:11:32.693609 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0425 01:11:32.693663 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0425 01:11:32.693733 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0425 01:11:32.693884 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0425 01:11:32.695678 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0425 01:11:32.697285 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0425 01:11:32.700127 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0425 01:11:32.700923 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0425 01:11:32.703171 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0425 01:11:32.704612 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0425 01:11:32.704689 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0425 01:11:32.706732 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0425 01:11:32.708472 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0425 01:11:32.710606 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0425 01:11:32.712018 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0425 01:11:32.715468 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.716187 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.717947 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.718178 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.718715 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.719504 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.728195 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.729198 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.736123 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:11:32.971324 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0425 01:12:53.716940 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-h4qkp-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:12:53.717029 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-vnc" condition "Issuing" to 2026-04-25 01:12:53.717011473 +0000 UTC m=+81.242673879 I0425 01:12:53.716927 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-vnc" condition "Ready" to 2026-04-25 01:12:53.7169119 +0000 UTC m=+81.242574286 I0425 01:12:53.746111 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-h4qkp-api" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:12:53.746175 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-api" condition "Issuing" to 2026-04-25 01:12:53.746158027 +0000 UTC m=+81.271820433 I0425 01:12:53.746214 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-api" condition "Ready" to 2026-04-25 01:12:53.746157947 +0000 UTC m=+81.271820363 I0425 01:12:53.767838 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-h4qkp-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:53.767944 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-h4qkp-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:12:53.767970 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-vnc" condition "Issuing" to 2026-04-25 01:12:53.767961399 +0000 UTC m=+81.293623785 I0425 01:12:54.292637 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-libvirt-default-h4qkp-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-api\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:54.292739 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-h4qkp-api" condition "Ready" to 2026-04-25 01:12:54.292730967 +0000 UTC m=+81.818393353 I0425 01:12:54.524314 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-h4qkp-vnc-7xlrh" condition "Approved" to 2026-04-25 01:12:54.524300072 +0000 UTC m=+82.049962458 I0425 01:12:54.545350 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-h4qkp-vnc-7xlrh" condition "Ready" to 2026-04-25 01:12:54.545336086 +0000 UTC m=+82.070998472 I0425 01:12:54.582246 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-h4qkp-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-api\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:54.583306 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-h4qkp-vnc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:12:54.583292237 +0000 UTC m=+82.108954623 I0425 01:12:54.606129 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-libvirt-default-h4qkp-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:54.606446 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-h4qkp-vnc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:12:54.60643829 +0000 UTC m=+82.132100676 I0425 01:12:54.626934 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-h4qkp-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:54.627872 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-h4qkp-api-ttkx9" condition "Approved" to 2026-04-25 01:12:54.627849953 +0000 UTC m=+82.153512409 I0425 01:12:54.644196 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-h4qkp-api-ttkx9" condition "Ready" to 2026-04-25 01:12:54.644182156 +0000 UTC m=+82.169844532 I0425 01:12:54.683898 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-h4qkp-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:12:54.683877538 +0000 UTC m=+82.209539924 I0425 01:12:54.706607 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-libvirt-default-h4qkp-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-api\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:12:54.763324 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-h4qkp-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-h4qkp-api\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:13:30.358983 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Ready" to 2026-04-25 01:13:30.358960809 +0000 UTC m=+117.884623195 I0425 01:13:30.359315 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/neutron-server-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:13:30.359347 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Issuing" to 2026-04-25 01:13:30.359339208 +0000 UTC m=+117.885001584 I0425 01:13:30.375080 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:13:30.375400 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Ready" to 2026-04-25 01:13:30.375383024 +0000 UTC m=+117.901045450 I0425 01:13:30.461856 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:13:30.493358 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "neutron-server-certs-hfhpm" condition "Approved" to 2026-04-25 01:13:30.493340523 +0000 UTC m=+118.019002929 I0425 01:13:30.511929 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "neutron-server-certs-hfhpm" condition "Ready" to 2026-04-25 01:13:30.511893218 +0000 UTC m=+118.037555594 I0425 01:13:30.558444 1 conditions.go:192] Found status change for Certificate "neutron-server-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:13:30.558428741 +0000 UTC m=+118.084091127 I0425 01:13:30.582283 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:13:30.582674 1 conditions.go:192] Found status change for Certificate "neutron-server-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:13:30.58266458 +0000 UTC m=+118.108326956 I0425 01:13:30.605153 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:13:30.605517 1 conditions.go:192] Found status change for Certificate "neutron-server-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:13:30.605508896 +0000 UTC m=+118.131171282 I0425 01:14:16.806989 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-04-25 01:14:16.806971654 +0000 UTC m=+164.332634070 I0425 01:14:16.807563 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:14:16.807596 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-04-25 01:14:16.807587199 +0000 UTC m=+164.333249605 E0425 01:14:16.836395 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:16.836434 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-client" condition "Ready" to 2026-04-25 01:14:16.836426825 +0000 UTC m=+164.362089241 I0425 01:14:16.836487 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:16.839653 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:16.839712 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:14:16.839724 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-04-25 01:14:16.839720103 +0000 UTC m=+164.365382489 E0425 01:14:16.847970 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" E0425 01:14:16.848017 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:16.848036 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0425 01:14:16.848059 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" I0425 01:14:16.886162 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-jnjzq" condition "Approved" to 2026-04-25 01:14:16.886147412 +0000 UTC m=+164.411809818 I0425 01:14:16.902810 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-jnjzq" condition "Ready" to 2026-04-25 01:14:16.902798043 +0000 UTC m=+164.428460429 I0425 01:14:16.926858 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:16.926844398 +0000 UTC m=+164.452506784 I0425 01:14:16.948838 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:16.949365 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:16.949352726 +0000 UTC m=+164.475015132 I0425 01:14:16.969657 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:16.969931 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:16.969922399 +0000 UTC m=+164.495584785 I0425 01:14:17.631012 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-04-25 01:14:17.630990455 +0000 UTC m=+165.156652861 I0425 01:14:17.631478 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:14:17.631533 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-04-25 01:14:17.631521357 +0000 UTC m=+165.157183773 E0425 01:14:17.650247 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:17.650285 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-server" condition "Ready" to 2026-04-25 01:14:17.650276567 +0000 UTC m=+165.175938953 I0425 01:14:17.650324 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:17.652660 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.652719 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-04-25 01:14:17.652713875 +0000 UTC m=+165.178376261 E0425 01:14:17.669004 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" E0425 01:14:17.669130 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0425 01:14:17.671741 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0425 01:14:17.671899 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" I0425 01:14:17.672434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.672615 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-04-25 01:14:17.672601262 +0000 UTC m=+165.198263688 I0425 01:14:17.674996 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-76dgz" condition "Approved" to 2026-04-25 01:14:17.674978328 +0000 UTC m=+165.200640734 I0425 01:14:17.675718 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.689930 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-04-25 01:14:17.689917658 +0000 UTC m=+165.215580034 I0425 01:14:17.695951 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-76dgz" condition "Ready" to 2026-04-25 01:14:17.695939709 +0000 UTC m=+165.221602075 I0425 01:14:17.698492 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.722634 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:17.722601935 +0000 UTC m=+165.248264321 I0425 01:14:17.743109 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.743375 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:17.743366103 +0000 UTC m=+165.269028499 I0425 01:14:17.753596 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:17.766594 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:18.430196 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-04-25 01:14:18.430167334 +0000 UTC m=+165.955829760 I0425 01:14:18.430247 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:14:18.430327 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-04-25 01:14:18.430309097 +0000 UTC m=+165.955971513 I0425 01:14:18.450262 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:18.450359 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-04-25 01:14:18.450349517 +0000 UTC m=+165.976011913 I0425 01:14:18.474102 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:18.502092 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-fdghm" condition "Approved" to 2026-04-25 01:14:18.502076451 +0000 UTC m=+166.027738857 I0425 01:14:18.631490 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-fdghm" condition "Ready" to 2026-04-25 01:14:18.63111273 +0000 UTC m=+166.156775146 I0425 01:14:21.849487 1 conditions.go:85] Found status change for Issuer "octavia-client" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:21.849470202 +0000 UTC m=+169.375132588 I0425 01:14:21.865540 1 conditions.go:252] Found status change for CertificateRequest "octavia-client-certs-fdghm" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:21.865527189 +0000 UTC m=+169.391189575 I0425 01:14:21.896814 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:21.896780902 +0000 UTC m=+169.422443278 I0425 01:14:21.921553 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:21.921871 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:21.921863521 +0000 UTC m=+169.447525907 I0425 01:14:21.950089 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:14:22.669884 1 conditions.go:85] Found status change for Issuer "octavia-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:14:22.669870469 +0000 UTC m=+170.195532885 I0425 01:18:09.324637 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:18:09.324688 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-04-25 01:18:09.324676479 +0000 UTC m=+396.850338855 I0425 01:18:09.324888 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-04-25 01:18:09.324881364 +0000 UTC m=+396.850543750 I0425 01:18:09.355896 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:18:09.356009 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-04-25 01:18:09.355996552 +0000 UTC m=+396.881658958 I0425 01:18:09.659284 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:18:09.696774 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-bd6vn" condition "Approved" to 2026-04-25 01:18:09.69676342 +0000 UTC m=+397.222425806 I0425 01:18:09.720987 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-bd6vn" condition "Ready" to 2026-04-25 01:18:09.720971437 +0000 UTC m=+397.246633853 I0425 01:18:09.753708 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:18:09.753694873 +0000 UTC m=+397.279357249 I0425 01:18:09.779305 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:18:09.838517 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:20:27.610083 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-04-25 01:20:27.610067554 +0000 UTC m=+535.135729940 I0425 01:20:27.610552 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:20:27.610572 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-04-25 01:20:27.610568176 +0000 UTC m=+535.136230562 I0425 01:20:27.629289 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:20:27.629362 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0425 01:20:27.629378 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-04-25 01:20:27.629372036 +0000 UTC m=+535.155034422 I0425 01:20:27.857466 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-ffrgf" condition "Approved" to 2026-04-25 01:20:27.857452509 +0000 UTC m=+535.383114915 I0425 01:20:27.877787 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-ffrgf" condition "Ready" to 2026-04-25 01:20:27.877772764 +0000 UTC m=+535.403435170 I0425 01:20:27.907701 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:20:27.907685783 +0000 UTC m=+535.433348159 I0425 01:20:27.928980 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:20:27.929893 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:20:27.929883052 +0000 UTC m=+535.455545438 I0425 01:20:27.950158 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0425 01:20:27.950653 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-25 01:20:27.950641388 +0000 UTC m=+535.476303804