I0330 23:47:04.205462 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0330 23:47:04.205637 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0330 23:47:04.205679 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0330 23:47:04.205763 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0330 23:47:04.207307 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0330 23:47:04.207665 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0330 23:47:04.208679 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0330 23:47:04.208798 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0330 23:47:04.225164 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0330 23:47:04.227156 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0330 23:47:04.227814 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0330 23:47:04.228068 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0330 23:47:04.228709 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0330 23:47:04.229412 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0330 23:47:04.229850 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0330 23:47:04.230413 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0330 23:47:04.230534 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0330 23:47:04.231199 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0330 23:47:04.231664 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0330 23:47:04.231963 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0330 23:47:04.232564 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0330 23:47:04.232763 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0330 23:47:04.232785 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0330 23:47:04.233179 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0330 23:47:04.233475 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0330 23:47:04.233775 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0330 23:47:04.234116 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0330 23:47:04.234441 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0330 23:47:04.234535 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0330 23:47:04.235014 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0330 23:47:04.235197 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0330 23:47:04.235653 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0330 23:47:04.238109 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0330 23:47:29.115740 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-03-30 23:47:29.11570969 +0000 UTC m=+24.944453447 I0330 23:47:29.128646 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:29.128669 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-03-30 23:47:29.128663617 +0000 UTC m=+24.957407354 I0330 23:47:29.129325 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-30 23:47:29.129321022 +0000 UTC m=+24.958064759 E0330 23:47:29.158938 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a1c349a03a6da2", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"c5d1cca2-1e2f-4112-831a-7923341e8a8d", APIVersion:"cert-manager.io/v1", ResourceVersion:"1235", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.March, 30, 23, 47, 29, 148898722, time.Local), LastTimestamp:time.Date(2026, time.March, 30, 23, 47, 29, 148898722, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a1c349a03a6da2" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) E0330 23:47:29.169968 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0330 23:47:29.195612 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0330 23:47:29.206487 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-30 23:47:29.206476945 +0000 UTC m=+25.035220662 I0330 23:47:29.222809 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:29.222836 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-03-30 23:47:29.222831911 +0000 UTC m=+25.051575638 I0330 23:47:29.223123 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-30 23:47:29.223114698 +0000 UTC m=+25.051858425 I0330 23:47:29.240722 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0330 23:47:29.240983 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-30 23:47:29.240886886 +0000 UTC m=+25.069630613 E0330 23:47:29.281425 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0330 23:47:29.482502 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0330 23:47:29.543778 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-8q92v" condition "Approved" to 2026-03-30 23:47:29.543769897 +0000 UTC m=+25.372513624 I0330 23:47:29.606693 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-8q92v" condition "Ready" to 2026-03-30 23:47:29.606684614 +0000 UTC m=+25.435428341 I0330 23:47:29.642488 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-30 23:47:29.642478286 +0000 UTC m=+25.471222013 I0330 23:47:29.680630 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0330 23:47:29.815620 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-30 23:47:29.815608895 +0000 UTC m=+25.644352632 I0330 23:47:29.832978 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-30 23:47:29.832966775 +0000 UTC m=+25.661710542 I0330 23:47:29.833315 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:29.833380 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-30 23:47:29.833342813 +0000 UTC m=+25.662086550 I0330 23:47:29.855783 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0330 23:47:29.855847 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:29.855859 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-30 23:47:29.85585499 +0000 UTC m=+25.684598717 I0330 23:47:30.195590 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-30 23:47:30.195576438 +0000 UTC m=+26.024320165 I0330 23:47:30.223742 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-30 23:47:30.223733129 +0000 UTC m=+26.052476856 I0330 23:47:30.224055 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:30.224069 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-30 23:47:30.224066537 +0000 UTC m=+26.052810264 I0330 23:47:30.266582 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0330 23:47:30.266696 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-30 23:47:30.266691177 +0000 UTC m=+26.095434904 I0330 23:47:30.351418 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0330 23:47:30.362062 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-8jpgt" condition "Approved" to 2026-03-30 23:47:30.36205278 +0000 UTC m=+26.190796527 I0330 23:47:30.423296 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-8jpgt" condition "Ready" to 2026-03-30 23:47:30.423284473 +0000 UTC m=+26.252028200 I0330 23:47:30.471960 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0330 23:47:30.485974 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-30 23:47:30.485965361 +0000 UTC m=+26.314709088 I0330 23:47:30.544654 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0330 23:47:30.546152 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-k2hqj" condition "Approved" to 2026-03-30 23:47:30.546145071 +0000 UTC m=+26.374888788 I0330 23:47:30.580386 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-30 23:47:30.58037245 +0000 UTC m=+26.409116217 I0330 23:47:30.606455 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:30.606492 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-30 23:47:30.606489495 +0000 UTC m=+26.435233222 I0330 23:47:30.606452 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-30 23:47:30.606437444 +0000 UTC m=+26.435181171 I0330 23:47:30.625930 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-k2hqj" condition "Ready" to 2026-03-30 23:47:30.625916418 +0000 UTC m=+26.454660145 I0330 23:47:30.626284 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0330 23:47:30.626581 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0330 23:47:30.626623 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-30 23:47:30.626616904 +0000 UTC m=+26.455360631 I0330 23:47:30.952311 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-30 23:47:30.9522995 +0000 UTC m=+26.781043237 I0330 23:47:31.035705 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0330 23:47:31.126061 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0330 23:47:31.590887 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-9dj5m" condition "Approved" to 2026-03-30 23:47:31.590873519 +0000 UTC m=+27.419617256 I0330 23:47:31.846230 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-9dj5m" condition "Ready" to 2026-03-30 23:47:31.84621459 +0000 UTC m=+27.674958327 I0330 23:47:32.179646 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-30 23:47:32.179629947 +0000 UTC m=+28.008373694 I0330 23:47:32.293695 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0330 23:47:32.293948 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-30 23:47:32.293943523 +0000 UTC m=+28.122687250 I0330 23:47:32.477361 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0330 23:48:33.308770 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0330 23:48:33.369198 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-30 23:48:33.36917257 +0000 UTC m=+89.197916337 I0330 23:48:33.390986 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-30 23:48:33.390970173 +0000 UTC m=+89.219713910 E0330 23:48:35.603959 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0330 23:48:35.638240 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-30 23:48:35.638231263 +0000 UTC m=+91.466975000 I0330 23:48:35.663562 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-30 23:48:35.663556194 +0000 UTC m=+91.492299931 E0330 23:48:37.328533 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0330 23:48:37.377717 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-30 23:48:37.377703687 +0000 UTC m=+93.206447414 I0330 23:48:37.396391 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-30 23:48:37.39638021 +0000 UTC m=+93.225123957 E0330 23:48:38.988596 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0330 23:48:39.016953 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-30 23:48:39.016942346 +0000 UTC m=+94.845686073 I0330 23:48:39.037932 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-30 23:48:39.037921308 +0000 UTC m=+94.866665045