I0506 04:58:02.944974 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0506 04:58:02.945152 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0506 04:58:02.945234 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0506 04:58:02.949279 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0506 04:58:02.951814 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0506 04:58:02.953040 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0506 04:58:02.953089 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0506 04:58:02.956400 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0506 04:58:02.972453 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0506 04:58:02.977505 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0506 04:58:02.977553 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0506 04:58:02.977640 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0506 04:58:02.982671 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0506 04:58:02.986191 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0506 04:58:02.991354 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0506 04:58:02.996836 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0506 04:58:03.000902 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0506 04:58:03.003335 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0506 04:58:03.003367 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0506 04:58:03.003412 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0506 04:58:03.005886 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0506 04:58:03.007923 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0506 04:58:03.012209 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0506 04:58:03.018093 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0506 04:58:03.024189 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0506 04:58:03.026554 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0506 04:58:03.029015 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0506 04:58:03.031376 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0506 04:58:03.031400 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0506 04:58:03.031599 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0506 04:58:03.033886 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0506 04:58:03.036364 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0506 04:58:03.039806 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0506 04:58:03.043002 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.043516 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.044821 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.056911 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.076793 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.095288 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.110537 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.127008 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.142022 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:03.146330 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 04:58:16.103653 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-06 04:58:16.103635456 +0000 UTC m=+13.189357558 I0506 04:58:16.819821 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 04:58:16.819807028 +0000 UTC m=+13.905529140 I0506 04:58:16.820415 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 04:58:16.820470 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 04:58:16.820458565 +0000 UTC m=+13.906180677 E0506 04:58:16.840756 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 04:58:16.840921 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-06 04:58:16.840913667 +0000 UTC m=+13.926635749 E0506 04:58:16.841038 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 04:58:16.843769 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:16.843895 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 04:58:16.843960 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 04:58:16.843912555 +0000 UTC m=+13.929634627 E0506 04:58:16.853888 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0506 04:58:16.854014 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 04:58:16.854053 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 04:58:16.854136 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0506 04:58:16.882206 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:16.887246 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-8vbwz" condition "Approved" to 2026-05-06 04:58:16.887232273 +0000 UTC m=+13.972954355 I0506 04:58:16.901517 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-8vbwz" condition "Ready" to 2026-05-06 04:58:16.901505822 +0000 UTC m=+13.987227904 I0506 04:58:16.930397 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 04:58:16.930381443 +0000 UTC m=+14.016103565 I0506 04:58:16.948211 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:21.854487 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 04:58:21.854452304 +0000 UTC m=+18.940174406 I0506 04:58:42.083146 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 04:58:42.083131115 +0000 UTC m=+39.168853197 I0506 04:58:42.087035 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 04:58:42.087132 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 04:58:42.087122661 +0000 UTC m=+39.172844743 I0506 04:58:42.098792 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-06 04:58:42.098778588 +0000 UTC m=+39.184500670 I0506 04:58:42.123052 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:42.123117 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 04:58:42.123134 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 04:58:42.123129055 +0000 UTC m=+39.208851127 I0506 04:58:42.339570 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-sws2x" condition "Approved" to 2026-05-06 04:58:42.339555623 +0000 UTC m=+39.425277725 I0506 04:58:42.368310 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-sws2x" condition "Ready" to 2026-05-06 04:58:42.368302089 +0000 UTC m=+39.454024161 I0506 04:58:42.391610 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 04:58:42.391599183 +0000 UTC m=+39.477321255 I0506 04:58:42.410282 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:42.410549 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 04:58:42.41054238 +0000 UTC m=+39.496264462 I0506 04:58:42.426046 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 04:58:42.446861 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:02:48.531334 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-146.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:02:48.531377 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-146.nip.io-tls" condition "Issuing" to 2026-05-06 05:02:48.531367609 +0000 UTC m=+285.617089711 I0506 05:02:48.531919 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-146.nip.io-tls" condition "Ready" to 2026-05-06 05:02:48.531906433 +0000 UTC m=+285.617628515 I0506 05:02:48.549528 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-146.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-146.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:02:48.549592 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-146.nip.io-tls" condition "Ready" to 2026-05-06 05:02:48.549581857 +0000 UTC m=+285.635303939 I0506 05:02:48.686808 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-146.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-146.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:02:48.720394 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-146.nip.io-tls-vgxwx" condition "Approved" to 2026-05-06 05:02:48.720377455 +0000 UTC m=+285.806099567 I0506 05:02:48.756656 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-146.nip.io-tls-vgxwx" condition "Ready" to 2026-05-06 05:02:48.756638018 +0000 UTC m=+285.842360120 I0506 05:02:48.782751 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-146.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:02:48.782729656 +0000 UTC m=+285.868451738 I0506 05:02:48.809749 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-146.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-146.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:03:47.775723 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 05:03:47.775693842 +0000 UTC m=+344.861415924 I0506 05:03:47.775733 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:03:47.775937 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 05:03:47.775921917 +0000 UTC m=+344.861644029 E0506 05:03:47.790437 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 05:03:47.790489 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-06 05:03:47.790479106 +0000 UTC m=+344.876201198 E0506 05:03:47.790547 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 05:03:47.791387 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:03:47.791434 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:03:47.791450 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 05:03:47.791445427 +0000 UTC m=+344.877167509 E0506 05:03:47.804929 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0506 05:03:47.805031 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 05:03:47.805096 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 05:03:47.805144 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0506 05:03:47.839408 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-28lgf" condition "Approved" to 2026-05-06 05:03:47.83939483 +0000 UTC m=+344.925116922 I0506 05:03:47.850239 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-28lgf" condition "Ready" to 2026-05-06 05:03:47.850228306 +0000 UTC m=+344.935950378 I0506 05:03:47.868177 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:03:47.86815485 +0000 UTC m=+344.953876952 I0506 05:03:47.883087 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:03:52.806106 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:03:52.806092228 +0000 UTC m=+349.891814330 I0506 05:04:31.874247 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-06 05:04:31.87423468 +0000 UTC m=+388.959956752 I0506 05:04:31.874604 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:31.874628 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-06 05:04:31.874624188 +0000 UTC m=+388.960346250 I0506 05:04:31.874811 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:31.874835 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-06 05:04:31.874827931 +0000 UTC m=+388.960550003 I0506 05:04:31.874918 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-06 05:04:31.874904153 +0000 UTC m=+388.960626225 I0506 05:04:31.892629 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-06 05:04:31.892615789 +0000 UTC m=+388.978337871 I0506 05:04:31.892879 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:31.892895 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-06 05:04:31.892892504 +0000 UTC m=+388.978614576 I0506 05:04:31.922020 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:31.922077 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-06 05:04:31.922072408 +0000 UTC m=+389.007794480 I0506 05:04:31.924559 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:31.925545 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-06 05:04:31.925535343 +0000 UTC m=+389.011257455 I0506 05:04:31.925697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:31.925788 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:31.925844 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-06 05:04:31.925837869 +0000 UTC m=+389.011559941 I0506 05:04:32.197533 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.280514 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.288150 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-p9nkz" condition "Approved" to 2026-05-06 05:04:32.288139096 +0000 UTC m=+389.373861178 I0506 05:04:32.298323 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.311440 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-p9nkz" condition "Ready" to 2026-05-06 05:04:32.311431657 +0000 UTC m=+389.397153729 I0506 05:04:32.331641 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-lsrt9" condition "Approved" to 2026-05-06 05:04:32.331632159 +0000 UTC m=+389.417354231 I0506 05:04:32.338764 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:32.338752103 +0000 UTC m=+389.424474185 I0506 05:04:32.376529 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.376890 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:32.376885025 +0000 UTC m=+389.462607087 I0506 05:04:32.378655 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-lsrt9" condition "Ready" to 2026-05-06 05:04:32.378649869 +0000 UTC m=+389.464371941 I0506 05:04:32.411131 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.420999 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.429888 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:32.429882427 +0000 UTC m=+389.515604499 E0506 05:04:32.504221 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-sg5rb\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0506 05:04:32.575932 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.576246 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:32.576240365 +0000 UTC m=+389.661962447 I0506 05:04:32.909524 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:32.958633 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:33.232698 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-g5bct" condition "Approved" to 2026-05-06 05:04:33.2326812 +0000 UTC m=+390.318403302 I0506 05:04:33.617447 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-g5bct" condition "Ready" to 2026-05-06 05:04:33.617436946 +0000 UTC m=+390.703159028 I0506 05:04:33.857201 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" resource_name="grafana-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="grafana-tls-g5bct" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="grafana-tls-dpnpg" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0506 05:04:34.069653 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-tgtx9" condition "Approved" to 2026-05-06 05:04:34.06961112 +0000 UTC m=+391.155333222 I0506 05:04:34.422124 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-tgtx9" condition "Ready" to 2026-05-06 05:04:34.422112198 +0000 UTC m=+391.507834280 I0506 05:04:34.612156 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:34.612138622 +0000 UTC m=+391.697860734 I0506 05:04:34.708903 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:34.709412 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:34.709401841 +0000 UTC m=+391.795123953 I0506 05:04:34.961073 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:35.009929 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:43.978280 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:43.978309 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" condition "Issuing" to 2026-05-06 05:04:43.978302533 +0000 UTC m=+401.064024615 I0506 05:04:43.978639 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" condition "Ready" to 2026-05-06 05:04:43.97862199 +0000 UTC m=+401.064344072 I0506 05:04:43.993461 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:04:43.993561 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:04:43.993593 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" condition "Issuing" to 2026-05-06 05:04:43.993583434 +0000 UTC m=+401.079305546 I0506 05:04:44.223489 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-z2cvh-rrlz6" condition "Approved" to 2026-05-06 05:04:44.223477436 +0000 UTC m=+401.309199508 I0506 05:04:44.247560 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-z2cvh-rrlz6" condition "Ready" to 2026-05-06 05:04:44.247550866 +0000 UTC m=+401.333272938 I0506 05:04:44.281110 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:04:44.281097199 +0000 UTC m=+401.366819271 I0506 05:04:44.302282 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-z2cvh-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:05:00.130475 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:05:00.130533 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-06 05:05:00.130506059 +0000 UTC m=+417.216228151 I0506 05:05:00.131099 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-06 05:05:00.130397627 +0000 UTC m=+417.216119709 I0506 05:05:00.151545 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:05:00.151676 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-06 05:05:00.1516686 +0000 UTC m=+417.237390672 I0506 05:05:00.615980 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:05:00.659668 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-54bdd" condition "Approved" to 2026-05-06 05:05:00.659658683 +0000 UTC m=+417.745380755 I0506 05:05:00.682162 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-54bdd" condition "Ready" to 2026-05-06 05:05:00.682154297 +0000 UTC m=+417.767876359 I0506 05:05:00.726526 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:05:00.726508923 +0000 UTC m=+417.812230995 I0506 05:05:00.748035 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:05:00.748419 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:05:00.748408057 +0000 UTC m=+417.834130139 I0506 05:05:00.792229 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:05:00.792543 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:05:00.79253235 +0000 UTC m=+417.878254422 I0506 05:07:58.380949 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-06 05:07:58.3809358 +0000 UTC m=+595.466657892 I0506 05:07:58.380979 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:07:58.380997 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-06 05:07:58.380993171 +0000 UTC m=+595.466715253 I0506 05:07:58.397781 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.397916 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-06 05:07:58.397907564 +0000 UTC m=+595.483629656 I0506 05:07:58.786827 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.812221 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-ns9dn" condition "Approved" to 2026-05-06 05:07:58.81220891 +0000 UTC m=+595.897931022 I0506 05:07:58.831918 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-ns9dn" condition "Ready" to 2026-05-06 05:07:58.83190756 +0000 UTC m=+595.917629642 I0506 05:07:58.858545 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:07:58.858533651 +0000 UTC m=+595.944255743 I0506 05:07:58.882662 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.886421 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:07:58.886410389 +0000 UTC m=+595.972132471 I0506 05:07:58.888388 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.904012 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.904589 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:07:58.904939 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:07:58.904930083 +0000 UTC m=+595.990652165 I0506 05:08:36.616058 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-06 05:08:36.616039002 +0000 UTC m=+633.701761104 I0506 05:08:36.616120 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:08:36.616168 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-06 05:08:36.616151983 +0000 UTC m=+633.701874055 I0506 05:08:36.633930 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 05:08:36.634063 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 05:08:36.634122 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-06 05:08:36.634112294 +0000 UTC m=+633.719834396 I0506 05:08:36.876626 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-h2vb6" condition "Approved" to 2026-05-06 05:08:36.876613214 +0000 UTC m=+633.962335296 I0506 05:08:36.895982 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-h2vb6" condition "Ready" to 2026-05-06 05:08:36.895970612 +0000 UTC m=+633.981692694 I0506 05:08:36.929441 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 05:08:36.929428512 +0000 UTC m=+634.015150594 I0506 05:08:36.949186 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"