I0420 08:06:38.935849 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0420 08:06:38.936053 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0420 08:06:38.936233 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 08:06:38.941413 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0420 08:06:38.941844 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0420 08:06:38.941902 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0420 08:06:38.941962 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0420 08:06:38.943755 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 08:06:38.963537 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0420 08:06:38.968974 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0420 08:06:38.976633 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0420 08:06:38.980859 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0420 08:06:38.982950 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0420 08:06:38.984819 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0420 08:06:38.986614 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0420 08:06:38.988418 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0420 08:06:38.990297 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0420 08:06:38.990331 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0420 08:06:38.990425 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0420 08:06:38.995357 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0420 08:06:38.995433 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0420 08:06:38.998644 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0420 08:06:39.001384 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0420 08:06:39.004210 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0420 08:06:39.004328 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0420 08:06:39.006415 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0420 08:06:39.008514 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0420 08:06:39.010415 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0420 08:06:39.010441 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0420 08:06:39.010616 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0420 08:06:39.012502 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0420 08:06:39.014428 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0420 08:06:39.021268 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0420 08:06:39.025706 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.025708 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.028022 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.047265 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.065971 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.082050 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.100087 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.120257 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.122528 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:39.144662 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 08:06:51.900112 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-20 08:06:51.900093689 +0000 UTC m=+13.008949341 I0420 08:06:52.709797 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:06:52.709861 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 08:06:52.709850759 +0000 UTC m=+13.818706401 I0420 08:06:52.710199 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-20 08:06:52.710189974 +0000 UTC m=+13.819045616 E0420 08:06:52.726373 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 08:06:52.726572 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-20 08:06:52.72656046 +0000 UTC m=+13.835416072 E0420 08:06:52.726698 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 08:06:52.730386 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:06:52.730457 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:06:52.730478 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 08:06:52.730472088 +0000 UTC m=+13.839327700 E0420 08:06:52.738802 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0420 08:06:52.738991 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 08:06:52.739071 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 08:06:52.739150 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0420 08:06:52.768924 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-84q4g" condition "Approved" to 2026-04-20 08:06:52.76891122 +0000 UTC m=+13.877766842 I0420 08:06:52.781954 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-84q4g" condition "Ready" to 2026-04-20 08:06:52.781942277 +0000 UTC m=+13.890797899 I0420 08:06:52.804647 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:06:52.804630713 +0000 UTC m=+13.913486335 I0420 08:06:52.824950 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:06:52.825971 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:06:52.825958916 +0000 UTC m=+13.934814528 I0420 08:06:52.834829 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:06:52.848035 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:06:52.848292 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:06:52.848285966 +0000 UTC m=+13.957141578 I0420 08:06:57.740136 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:06:57.7401148 +0000 UTC m=+18.848970442 I0420 08:07:19.258615 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:07:19.258790 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 08:07:19.258775949 +0000 UTC m=+40.367631571 I0420 08:07:19.258612 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 08:07:19.258540805 +0000 UTC m=+40.367396447 I0420 08:07:19.284686 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-20 08:07:19.284653267 +0000 UTC m=+40.393508879 I0420 08:07:19.291182 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:07:19.291400 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 08:07:19.291391518 +0000 UTC m=+40.400247140 I0420 08:07:19.581885 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:07:19.620150 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-59h8c" condition "Approved" to 2026-04-20 08:07:19.620136637 +0000 UTC m=+40.728992259 I0420 08:07:19.667562 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-59h8c" condition "Ready" to 2026-04-20 08:07:19.667547137 +0000 UTC m=+40.776402749 I0420 08:07:19.705748 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:07:19.70572942 +0000 UTC m=+40.814585052 I0420 08:07:19.730977 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:07:19.731284 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:07:19.731276173 +0000 UTC m=+40.840131795 I0420 08:07:19.760044 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:12:05.701954 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-176.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:12:05.702044 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-176.nip.io-tls" condition "Issuing" to 2026-04-20 08:12:05.702033677 +0000 UTC m=+326.810889359 I0420 08:12:05.702423 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-176.nip.io-tls" condition "Ready" to 2026-04-20 08:12:05.702405284 +0000 UTC m=+326.811260926 I0420 08:12:05.719084 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-176.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-176.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:12:05.719236 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-176.nip.io-tls" condition "Ready" to 2026-04-20 08:12:05.719225854 +0000 UTC m=+326.828081476 I0420 08:12:05.891700 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-176.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-176.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:12:05.922386 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-176.nip.io-tls-sfctr" condition "Approved" to 2026-04-20 08:12:05.922372188 +0000 UTC m=+327.031227830 I0420 08:12:05.951450 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-176.nip.io-tls-sfctr" condition "Ready" to 2026-04-20 08:12:05.951437096 +0000 UTC m=+327.060292708 I0420 08:12:05.978959 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-176.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:12:05.978946271 +0000 UTC m=+327.087801893 I0420 08:12:06.002508 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-176.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-176.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:12:06.002997 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-176.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:12:06.002988177 +0000 UTC m=+327.111843809 I0420 08:12:06.024643 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-176.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-176.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:08.538937 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-20 08:13:08.538881686 +0000 UTC m=+389.647737308 I0420 08:13:08.538967 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:08.539068 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 08:13:08.539057099 +0000 UTC m=+389.647912751 I0420 08:13:08.566186 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:08.566298 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:08.566319 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 08:13:08.566312268 +0000 UTC m=+389.675167890 E0420 08:13:08.567486 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 08:13:08.567529 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-20 08:13:08.567523359 +0000 UTC m=+389.676378981 E0420 08:13:08.567577 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 08:13:08.646233 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0420 08:13:08.646312 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 08:13:08.646340 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 08:13:08.646364 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0420 08:13:08.685191 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:08.698497 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-x7ctl" condition "Approved" to 2026-04-20 08:13:08.698480389 +0000 UTC m=+389.807336031 I0420 08:13:08.734544 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-x7ctl" condition "Ready" to 2026-04-20 08:13:08.734516601 +0000 UTC m=+389.843372223 I0420 08:13:08.839746 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:08.839729268 +0000 UTC m=+389.948584910 I0420 08:13:08.857143 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:08.857539 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:08.857531121 +0000 UTC m=+389.966386743 I0420 08:13:08.866857 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:08.879225 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:13.647131 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:13.64711189 +0000 UTC m=+394.755967532 I0420 08:13:58.195870 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:58.195904 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-20 08:13:58.195898404 +0000 UTC m=+439.304754006 I0420 08:13:58.196175 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 08:13:58.196172239 +0000 UTC m=+439.305027851 I0420 08:13:58.196772 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 08:13:58.196768399 +0000 UTC m=+439.305624011 I0420 08:13:58.196961 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:58.196976 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 08:13:58.196974442 +0000 UTC m=+439.305830054 I0420 08:13:58.197073 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:58.197086 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 08:13:58.197084304 +0000 UTC m=+439.305939916 I0420 08:13:58.197206 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-20 08:13:58.197204266 +0000 UTC m=+439.306059868 I0420 08:13:58.385542 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.386008 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:13:58.386282 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 08:13:58.386274282 +0000 UTC m=+439.495129894 I0420 08:13:58.422721 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.422833 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-20 08:13:58.422821625 +0000 UTC m=+439.531677267 I0420 08:13:58.423841 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.424095 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 08:13:58.424082466 +0000 UTC m=+439.532938078 I0420 08:13:58.494431 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.560043 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6df58" condition "Approved" to 2026-04-20 08:13:58.560029371 +0000 UTC m=+439.668885003 I0420 08:13:58.585143 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6df58" condition "Ready" to 2026-04-20 08:13:58.585132588 +0000 UTC m=+439.693988200 I0420 08:13:58.621371 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.631145 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:58.631135374 +0000 UTC m=+439.739990996 I0420 08:13:58.663963 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.664468 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:58.664461525 +0000 UTC m=+439.773317137 I0420 08:13:58.684743 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-5ll9f" condition "Approved" to 2026-04-20 08:13:58.684732254 +0000 UTC m=+439.793587866 I0420 08:13:58.710600 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.719746 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-5ll9f" condition "Ready" to 2026-04-20 08:13:58.719734042 +0000 UTC m=+439.828589654 I0420 08:13:58.755082 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:58.755061875 +0000 UTC m=+439.863917497 I0420 08:13:58.787197 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:58.787747 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:58.787722274 +0000 UTC m=+439.896577886 I0420 08:13:58.957724 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:59.054751 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:59.112215 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6428x" condition "Approved" to 2026-04-20 08:13:59.112182954 +0000 UTC m=+440.221038576 I0420 08:13:59.251466 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6428x" condition "Ready" to 2026-04-20 08:13:59.25144799 +0000 UTC m=+440.360303592 I0420 08:13:59.708392 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:59.708359211 +0000 UTC m=+440.817214813 I0420 08:13:59.806174 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:13:59.806626 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:13:59.806615603 +0000 UTC m=+440.915471235 I0420 08:14:00.012840 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:06.941567 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:14:06.941604 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" condition "Issuing" to 2026-04-20 08:14:06.941595125 +0000 UTC m=+448.050450747 I0420 08:14:06.942183 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" condition "Ready" to 2026-04-20 08:14:06.942148814 +0000 UTC m=+448.051004416 I0420 08:14:06.958107 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:06.958264 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:14:06.958310 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" condition "Issuing" to 2026-04-20 08:14:06.958300293 +0000 UTC m=+448.067155915 I0420 08:14:07.227969 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-kbrzl-w7w48" condition "Approved" to 2026-04-20 08:14:07.227956297 +0000 UTC m=+448.336811919 I0420 08:14:07.258016 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-kbrzl-w7w48" condition "Ready" to 2026-04-20 08:14:07.258003388 +0000 UTC m=+448.366859010 I0420 08:14:07.290705 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:14:07.290688422 +0000 UTC m=+448.399544044 I0420 08:14:07.321607 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-kbrzl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:20.005516 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 08:14:20.005491825 +0000 UTC m=+461.114347447 I0420 08:14:20.006030 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:14:20.006041 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 08:14:20.006038183 +0000 UTC m=+461.114893805 I0420 08:14:20.048579 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:20.048715 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:14:20.048747 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 08:14:20.048738217 +0000 UTC m=+461.157593839 I0420 08:14:20.288148 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-sccfs" condition "Approved" to 2026-04-20 08:14:20.288128934 +0000 UTC m=+461.396984556 I0420 08:14:20.306584 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-sccfs" condition "Ready" to 2026-04-20 08:14:20.306571186 +0000 UTC m=+461.415426798 I0420 08:14:20.337116 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:14:20.337093167 +0000 UTC m=+461.445948789 I0420 08:14:20.363106 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:20.363461 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:14:20.363453932 +0000 UTC m=+461.472309544 I0420 08:14:20.387476 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:14:20.387955 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:14:20.387944508 +0000 UTC m=+461.496800120 I0420 08:17:27.026542 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:17:27.026586 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 08:17:27.026576864 +0000 UTC m=+648.135432486 I0420 08:17:27.026866 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-20 08:17:27.026843188 +0000 UTC m=+648.135698810 I0420 08:17:27.043576 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:17:27.043653 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-20 08:17:27.043646123 +0000 UTC m=+648.152501745 I0420 08:17:27.170982 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:17:27.209359 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-nz49j" condition "Approved" to 2026-04-20 08:17:27.209343458 +0000 UTC m=+648.318199080 I0420 08:17:27.238552 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-nz49j" condition "Ready" to 2026-04-20 08:17:27.238538885 +0000 UTC m=+648.347394507 I0420 08:17:27.278106 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:17:27.278082488 +0000 UTC m=+648.386938120 I0420 08:17:27.302953 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:17:27.351989 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:18:08.258088 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:18:08.258173 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-20 08:18:08.258166353 +0000 UTC m=+689.367021965 I0420 08:18:08.258457 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-20 08:18:08.258442012 +0000 UTC m=+689.367297624 I0420 08:18:08.278008 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:18:08.278102 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 08:18:08.278129 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-20 08:18:08.278118851 +0000 UTC m=+689.386974493 I0420 08:18:08.595987 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 08:18:08.607315 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-pbzmc" condition "Approved" to 2026-04-20 08:18:08.607299335 +0000 UTC m=+689.716154947 I0420 08:18:08.625807 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-pbzmc" condition "Ready" to 2026-04-20 08:18:08.625784105 +0000 UTC m=+689.734639757 I0420 08:18:08.658597 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 08:18:08.658577696 +0000 UTC m=+689.767433298 I0420 08:18:08.685965 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"