I0508 18:18:12.600251 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0508 18:18:12.600417 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0508 18:18:12.600514 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0508 18:18:12.606223 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0508 18:18:12.606579 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0508 18:18:12.606727 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0508 18:18:12.606804 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0508 18:18:12.609206 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0508 18:18:12.629118 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0508 18:18:12.634306 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0508 18:18:12.636148 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0508 18:18:12.638291 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0508 18:18:12.640079 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0508 18:18:12.644099 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0508 18:18:12.646841 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0508 18:18:12.649218 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0508 18:18:12.650932 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0508 18:18:12.650950 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0508 18:18:12.651042 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0508 18:18:12.652795 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0508 18:18:12.654671 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0508 18:18:12.656599 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0508 18:18:12.658799 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0508 18:18:12.663485 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0508 18:18:12.663538 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0508 18:18:12.667589 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0508 18:18:12.667615 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0508 18:18:12.667673 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0508 18:18:12.667754 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0508 18:18:12.670450 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0508 18:18:12.672214 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0508 18:18:12.674085 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0508 18:18:12.676018 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0508 18:18:12.677848 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.679112 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.679579 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.679699 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.679837 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.680037 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.680552 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.681070 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.681169 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:12.765772 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 18:18:22.806706 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-08 18:18:22.806687108 +0000 UTC m=+10.238081898 I0508 18:18:23.502667 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:18:23.502714 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-08 18:18:23.502708483 +0000 UTC m=+10.934103263 I0508 18:18:23.503227 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-08 18:18:23.503210579 +0000 UTC m=+10.934605389 E0508 18:18:23.517722 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 18:18:23.517784 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-08 18:18:23.517776761 +0000 UTC m=+10.949171551 E0508 18:18:23.517817 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 18:18:23.519369 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.519458 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-08 18:18:23.519447573 +0000 UTC m=+10.950842363 E0508 18:18:23.530575 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0508 18:18:23.530908 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 18:18:23.530977 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 18:18:23.531056 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0508 18:18:23.536926 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.562150 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vsthv" condition "Approved" to 2026-05-08 18:18:23.562138208 +0000 UTC m=+10.993532998 I0508 18:18:23.575072 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vsthv" condition "Ready" to 2026-05-08 18:18:23.57506116 +0000 UTC m=+11.006455950 I0508 18:18:23.598904 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:18:23.598884009 +0000 UTC m=+11.030278829 I0508 18:18:23.618374 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.618837 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:18:23.618828219 +0000 UTC m=+11.050223029 I0508 18:18:23.622418 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.631070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.633235 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:23.633527 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:18:23.633516255 +0000 UTC m=+11.064911045 I0508 18:18:28.531894 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:18:28.531882318 +0000 UTC m=+15.963277108 I0508 18:18:50.517109 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:18:50.517311 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-08 18:18:50.517227399 +0000 UTC m=+37.948622189 I0508 18:18:50.517155 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-08 18:18:50.517142227 +0000 UTC m=+37.948537017 I0508 18:18:50.534071 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-08 18:18:50.533807738 +0000 UTC m=+37.965202528 I0508 18:18:50.543162 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:50.543362 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:18:50.543414 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-08 18:18:50.543381789 +0000 UTC m=+37.974776569 I0508 18:18:50.744766 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:50.751053 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-lcb97" condition "Approved" to 2026-05-08 18:18:50.751045526 +0000 UTC m=+38.182440316 I0508 18:18:50.796429 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-lcb97" condition "Ready" to 2026-05-08 18:18:50.796416588 +0000 UTC m=+38.227811378 I0508 18:18:50.835518 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:18:50.835502788 +0000 UTC m=+38.266897588 I0508 18:18:50.913277 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:18:50.956625 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:22:57.172781 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Ready" to 2026-05-08 18:22:57.172742202 +0000 UTC m=+284.604136992 I0508 18:22:57.173458 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-228.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:22:57.173547 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Issuing" to 2026-05-08 18:22:57.173534737 +0000 UTC m=+284.604929587 I0508 18:22:57.202455 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-228.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-228.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:22:57.202558 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-228.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:22:57.202593 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Issuing" to 2026-05-08 18:22:57.202581608 +0000 UTC m=+284.633976428 I0508 18:22:57.487001 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-228.nip.io-tls-slg26" condition "Approved" to 2026-05-08 18:22:57.486987146 +0000 UTC m=+284.918381966 I0508 18:22:57.528521 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-228.nip.io-tls-slg26" condition "Ready" to 2026-05-08 18:22:57.528510411 +0000 UTC m=+284.959905201 I0508 18:22:57.559378 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:22:57.55936838 +0000 UTC m=+284.990763170 I0508 18:22:57.591037 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-228.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-228.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:22:57.591441 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:22:57.591433478 +0000 UTC m=+285.022828268 I0508 18:22:57.615890 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-228.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-228.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:22:57.616228 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-228.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:22:57.61622065 +0000 UTC m=+285.047615440 I0508 18:22:57.616381 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-228.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-228.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:02.225282 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:02.225327 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-08 18:24:02.225317374 +0000 UTC m=+349.656712184 I0508 18:24:02.225718 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-08 18:24:02.225700075 +0000 UTC m=+349.657094865 E0508 18:24:02.259560 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 18:24:02.259597 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-08 18:24:02.259589892 +0000 UTC m=+349.690984682 E0508 18:24:02.259642 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 18:24:02.264843 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:02.265151 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:02.265582 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-08 18:24:02.265206073 +0000 UTC m=+349.696600893 E0508 18:24:02.294305 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0508 18:24:02.294551 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 18:24:02.294622 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 18:24:02.294736 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0508 18:24:02.356884 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-9x2mt" condition "Approved" to 2026-05-08 18:24:02.356867204 +0000 UTC m=+349.788262074 I0508 18:24:02.371511 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-9x2mt" condition "Ready" to 2026-05-08 18:24:02.3715004 +0000 UTC m=+349.802895190 I0508 18:24:02.402419 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:02.402389753 +0000 UTC m=+349.833784563 I0508 18:24:02.414863 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:02.415130 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:02.415120251 +0000 UTC m=+349.846515041 I0508 18:24:02.425449 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:02.434751 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:07.295073 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:07.295056596 +0000 UTC m=+354.726451386 I0508 18:24:47.574607 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:47.574667 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-08 18:24:47.574635854 +0000 UTC m=+395.006030624 I0508 18:24:47.574893 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-08 18:24:47.574889089 +0000 UTC m=+395.006283869 I0508 18:24:47.576008 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:47.576069 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-08 18:24:47.576025454 +0000 UTC m=+395.007420234 I0508 18:24:47.576255 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-08 18:24:47.576251318 +0000 UTC m=+395.007646098 I0508 18:24:47.601921 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:47.601959 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-08 18:24:47.601952646 +0000 UTC m=+395.033347426 I0508 18:24:47.602185 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-08 18:24:47.602176031 +0000 UTC m=+395.033570811 I0508 18:24:47.613129 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:47.613204 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-08 18:24:47.6131985 +0000 UTC m=+395.044593280 I0508 18:24:47.613990 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:47.614148 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:47.614817 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-08 18:24:47.614809756 +0000 UTC m=+395.046204536 I0508 18:24:47.636581 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:47.636633 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:24:47.636653 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-08 18:24:47.6366466 +0000 UTC m=+395.068041390 I0508 18:24:47.860375 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:47.867492 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-bplp4" condition "Approved" to 2026-05-08 18:24:47.86748454 +0000 UTC m=+395.298879330 I0508 18:24:47.881612 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7pb5p" condition "Approved" to 2026-05-08 18:24:47.881600816 +0000 UTC m=+395.312995606 I0508 18:24:47.901123 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-bplp4" condition "Ready" to 2026-05-08 18:24:47.90111306 +0000 UTC m=+395.332507850 I0508 18:24:47.904860 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7pb5p" condition "Ready" to 2026-05-08 18:24:47.904845222 +0000 UTC m=+395.336240002 I0508 18:24:47.935024 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:47.935003575 +0000 UTC m=+395.366398365 I0508 18:24:47.939751 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:47.939740739 +0000 UTC m=+395.371135509 I0508 18:24:47.969615 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:47.969649 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:48.164999 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:48.473613 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-p665w" condition "Approved" to 2026-05-08 18:24:48.473592198 +0000 UTC m=+395.904986988 I0508 18:24:48.581500 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-p665w" condition "Ready" to 2026-05-08 18:24:48.581486693 +0000 UTC m=+396.012881483 I0508 18:24:49.051247 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:49.051227299 +0000 UTC m=+396.482622119 I0508 18:24:49.117707 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:24:49.118543 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:24:49.118531292 +0000 UTC m=+396.549926102 I0508 18:24:49.317174 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:02.672010 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:25:02.672055 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" condition "Issuing" to 2026-05-08 18:25:02.672036077 +0000 UTC m=+410.103430867 I0508 18:25:02.672517 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" condition "Ready" to 2026-05-08 18:25:02.672510227 +0000 UTC m=+410.103905017 I0508 18:25:02.702241 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:02.702325 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:25:02.702361 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" condition "Issuing" to 2026-05-08 18:25:02.702350449 +0000 UTC m=+410.133745259 I0508 18:25:02.821680 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:02.830117 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-xvb2f-6khj8" condition "Approved" to 2026-05-08 18:25:02.830108201 +0000 UTC m=+410.261502981 I0508 18:25:02.852557 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-xvb2f-6khj8" condition "Ready" to 2026-05-08 18:25:02.852544799 +0000 UTC m=+410.283939589 I0508 18:25:02.880509 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:25:02.880494381 +0000 UTC m=+410.311889171 I0508 18:25:02.910835 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xvb2f-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:24.357271 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:25:24.357320 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-08 18:25:24.357309341 +0000 UTC m=+431.788704151 I0508 18:25:24.357313 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-08 18:25:24.357290051 +0000 UTC m=+431.788684861 I0508 18:25:24.372496 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:24.372587 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:25:24.372631 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-08 18:25:24.372621973 +0000 UTC m=+431.804016763 I0508 18:25:24.700713 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-t6s5d" condition "Approved" to 2026-05-08 18:25:24.700702432 +0000 UTC m=+432.132097212 I0508 18:25:24.723360 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-t6s5d" condition "Ready" to 2026-05-08 18:25:24.723349649 +0000 UTC m=+432.154744439 I0508 18:25:24.743778 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:25:24.743767451 +0000 UTC m=+432.175162231 I0508 18:25:24.768938 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:25:24.817373 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:28:40.275549 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:28:40.275638 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-08 18:28:40.275628209 +0000 UTC m=+627.707023009 I0508 18:28:40.275755 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-08 18:28:40.275738591 +0000 UTC m=+627.707133401 I0508 18:28:40.292592 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:28:40.292675 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:28:40.292725 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-08 18:28:40.292718848 +0000 UTC m=+627.724113658 I0508 18:28:40.486943 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:28:40.488606 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6g9bv" condition "Approved" to 2026-05-08 18:28:40.488597919 +0000 UTC m=+627.919992709 I0508 18:28:40.509344 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6g9bv" condition "Ready" to 2026-05-08 18:28:40.509331014 +0000 UTC m=+627.940725814 I0508 18:28:40.534233 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:28:40.534224701 +0000 UTC m=+627.965619491 I0508 18:28:40.556078 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:28:40.608613 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.578068 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 18:29:20.578097 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-08 18:29:20.578091113 +0000 UTC m=+668.009485883 I0508 18:29:20.578428 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-08 18:29:20.578423207 +0000 UTC m=+668.009817977 I0508 18:29:20.604076 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.604156 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-08 18:29:20.604147369 +0000 UTC m=+668.035542149 I0508 18:29:20.705056 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.737034 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-bbqwt" condition "Approved" to 2026-05-08 18:29:20.737022119 +0000 UTC m=+668.168416889 I0508 18:29:20.759599 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-bbqwt" condition "Ready" to 2026-05-08 18:29:20.759592153 +0000 UTC m=+668.190986923 I0508 18:29:20.788208 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:29:20.788193778 +0000 UTC m=+668.219588558 I0508 18:29:20.808996 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.809300 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:29:20.809293621 +0000 UTC m=+668.240688401 I0508 18:29:20.817003 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.831872 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 18:29:20.832405 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 18:29:20.832393423 +0000 UTC m=+668.263788223