I0402 00:45:36.610219 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0402 00:45:36.610346 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0402 00:45:36.610424 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0402 00:45:36.615020 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0402 00:45:36.615434 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0402 00:45:36.615475 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0402 00:45:36.615545 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0402 00:45:36.618329 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0402 00:45:36.629963 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0402 00:45:36.630286 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0402 00:45:36.630374 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0402 00:45:36.636131 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0402 00:45:36.642428 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0402 00:45:36.644822 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0402 00:45:36.647424 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0402 00:45:36.647522 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0402 00:45:36.649955 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0402 00:45:36.652018 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0402 00:45:36.653746 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0402 00:45:36.657520 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0402 00:45:36.660564 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0402 00:45:36.663053 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0402 00:45:36.665561 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0402 00:45:36.665593 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0402 00:45:36.665667 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0402 00:45:36.668088 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0402 00:45:36.670709 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0402 00:45:36.672845 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0402 00:45:36.674638 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0402 00:45:36.676438 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0402 00:45:36.682084 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0402 00:45:36.682245 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0402 00:45:36.685768 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0402 00:45:36.688830 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.689559 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.690202 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.705217 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.729962 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.770177 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.783044 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.787056 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.802813 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:36.820600 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0402 00:45:49.456066 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-02 00:45:49.456041889 +0000 UTC m=+12.884563802 I0402 00:45:50.148008 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-02 00:45:50.147993731 +0000 UTC m=+13.576515634 I0402 00:45:50.148044 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:45:50.148521 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-02 00:45:50.148490602 +0000 UTC m=+13.577012515 E0402 00:45:50.163265 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0402 00:45:50.163327 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-02 00:45:50.16331778 +0000 UTC m=+13.591839673 E0402 00:45:50.163356 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0402 00:45:50.164804 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:45:50.164869 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-02 00:45:50.164860967 +0000 UTC m=+13.593382860 E0402 00:45:50.178002 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0402 00:45:50.178466 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0402 00:45:50.178586 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0402 00:45:50.178946 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0402 00:45:50.185246 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:45:50.203675 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-nbd6h" condition "Approved" to 2026-04-02 00:45:50.203664251 +0000 UTC m=+13.632186134 I0402 00:45:50.215655 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-nbd6h" condition "Ready" to 2026-04-02 00:45:50.215644203 +0000 UTC m=+13.644166096 I0402 00:45:50.242277 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:45:50.242267525 +0000 UTC m=+13.670789408 I0402 00:45:50.257343 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:45:50.257805 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:45:50.257797303 +0000 UTC m=+13.686319186 I0402 00:45:50.277253 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:45:55.179195 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:45:55.179184869 +0000 UTC m=+18.607706742 I0402 00:46:20.882067 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-02 00:46:20.882052403 +0000 UTC m=+44.310574286 I0402 00:46:20.888052 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:46:20.888181 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-02 00:46:20.8881716 +0000 UTC m=+44.316693473 I0402 00:46:20.901952 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-02 00:46:20.901940864 +0000 UTC m=+44.330462747 I0402 00:46:20.920022 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:46:20.920089 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:46:20.920112 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-02 00:46:20.92010621 +0000 UTC m=+44.348628093 I0402 00:46:21.380927 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ssjhk" condition "Approved" to 2026-04-02 00:46:21.380919256 +0000 UTC m=+44.809441119 I0402 00:46:21.413209 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ssjhk" condition "Ready" to 2026-04-02 00:46:21.413198947 +0000 UTC m=+44.841720820 I0402 00:46:21.448551 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:46:21.448538485 +0000 UTC m=+44.877060378 I0402 00:46:21.474873 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:46:21.475331 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:46:21.475322221 +0000 UTC m=+44.903844134 I0402 00:46:21.491183 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:46:21.498752 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:46:21.499098 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:46:21.49909019 +0000 UTC m=+44.927612073 I0402 00:51:39.574830 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-3.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:51:39.574883 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-3.nip.io-tls" condition "Issuing" to 2026-04-02 00:51:39.57487664 +0000 UTC m=+363.003398533 I0402 00:51:39.575418 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-3.nip.io-tls" condition "Ready" to 2026-04-02 00:51:39.575411965 +0000 UTC m=+363.003933848 I0402 00:51:39.591370 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-3.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-3.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:51:39.591432 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-3.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:51:39.591562 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-3.nip.io-tls" condition "Issuing" to 2026-04-02 00:51:39.591440124 +0000 UTC m=+363.019962007 I0402 00:51:39.942605 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-3.nip.io-tls-ncw6s" condition "Approved" to 2026-04-02 00:51:39.942590605 +0000 UTC m=+363.371112508 I0402 00:51:39.970427 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-3.nip.io-tls-ncw6s" condition "Ready" to 2026-04-02 00:51:39.970417188 +0000 UTC m=+363.398939071 I0402 00:51:39.995649 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-3.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:51:39.995636088 +0000 UTC m=+363.424157961 I0402 00:51:40.010142 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-3.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-3.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:51:40.010544 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-3.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:51:40.010537177 +0000 UTC m=+363.439059060 I0402 00:51:40.026572 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-3.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-3.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:51:40.028102 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-3.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-3.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:52:48.701620 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:52:48.701640 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-02 00:52:48.701617503 +0000 UTC m=+432.130139416 I0402 00:52:48.701672 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-02 00:52:48.701658544 +0000 UTC m=+432.130180457 E0402 00:52:48.794803 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0402 00:52:48.794949 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-02 00:52:48.794941 +0000 UTC m=+432.223462883 E0402 00:52:48.794992 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0402 00:52:48.814521 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:52:48.814744 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:52:48.814772 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-02 00:52:48.814765986 +0000 UTC m=+432.243287869 E0402 00:52:48.879012 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0402 00:52:48.879095 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0402 00:52:48.879267 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0402 00:52:48.879374 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0402 00:52:49.346410 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-zwpql" condition "Approved" to 2026-04-02 00:52:49.346398485 +0000 UTC m=+432.774920398 I0402 00:52:49.523457 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-zwpql" condition "Ready" to 2026-04-02 00:52:49.523448502 +0000 UTC m=+432.951970385 I0402 00:52:49.658400 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:52:49.658381221 +0000 UTC m=+433.086903134 I0402 00:52:49.729755 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:52:53.880227 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:52:53.880208909 +0000 UTC m=+437.308730832 I0402 00:53:37.881551 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-02 00:53:37.881541161 +0000 UTC m=+481.310063034 I0402 00:53:37.882253 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:53:37.882366 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-02 00:53:37.882349628 +0000 UTC m=+481.310871521 I0402 00:53:37.882711 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:53:37.882741 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-02 00:53:37.882734896 +0000 UTC m=+481.311256769 I0402 00:53:37.882961 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-02 00:53:37.882956081 +0000 UTC m=+481.311477954 I0402 00:53:37.891567 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-02 00:53:37.891553192 +0000 UTC m=+481.320075075 I0402 00:53:37.892196 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:53:37.892248 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-02 00:53:37.892242427 +0000 UTC m=+481.320764300 I0402 00:53:37.943787 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:37.943846 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-02 00:53:37.943841174 +0000 UTC m=+481.372363047 I0402 00:53:37.955348 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:37.955664 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:37.955777 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-02 00:53:37.955767555 +0000 UTC m=+481.384289458 I0402 00:53:37.956152 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-02 00:53:37.955415747 +0000 UTC m=+481.383937650 I0402 00:53:38.137920 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:38.219979 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:38.222575 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-68p2m" condition "Approved" to 2026-04-02 00:53:38.222565959 +0000 UTC m=+481.651087842 I0402 00:53:38.250424 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:38.251611 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-68p2m" condition "Ready" to 2026-04-02 00:53:38.251599779 +0000 UTC m=+481.680121652 I0402 00:53:38.280443 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-5d4jn" condition "Approved" to 2026-04-02 00:53:38.280431226 +0000 UTC m=+481.708953099 I0402 00:53:38.282020 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:38.282014109 +0000 UTC m=+481.710535982 I0402 00:53:38.315015 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-5d4jn" condition "Ready" to 2026-04-02 00:53:38.315002133 +0000 UTC m=+481.743524036 I0402 00:53:38.322167 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:38.364087 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:38.364073315 +0000 UTC m=+481.792595218 I0402 00:53:38.419838 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:38.420083 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:38.420076923 +0000 UTC m=+481.848598796 I0402 00:53:38.720794 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:39.101174 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6qz9c" condition "Approved" to 2026-04-02 00:53:39.101156395 +0000 UTC m=+482.529678308 I0402 00:53:39.379468 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6qz9c" condition "Ready" to 2026-04-02 00:53:39.37945787 +0000 UTC m=+482.807979753 E0402 00:53:39.420707 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"grafana-tls-69hbt\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" I0402 00:53:39.648949 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" resource_name="grafana-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="grafana-tls-6qz9c" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="grafana-tls-vpvxh" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0402 00:53:39.775501 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-r6frp" condition "Approved" to 2026-04-02 00:53:39.775486378 +0000 UTC m=+483.204008261 I0402 00:53:39.833022 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-r6frp" condition "Ready" to 2026-04-02 00:53:39.833010526 +0000 UTC m=+483.261532409 I0402 00:53:40.375444 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:40.375432016 +0000 UTC m=+483.803953899 I0402 00:53:40.521660 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:40.522161 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:40.522153803 +0000 UTC m=+483.950675686 I0402 00:53:40.892083 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:40.892083 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:54.612056 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" condition "Ready" to 2026-04-02 00:53:54.612020022 +0000 UTC m=+498.040541935 I0402 00:53:54.613041 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:53:54.613073 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" condition "Issuing" to 2026-04-02 00:53:54.613064203 +0000 UTC m=+498.041586116 I0402 00:53:54.626030 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-cddc6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:54.626104 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" condition "Ready" to 2026-04-02 00:53:54.626099462 +0000 UTC m=+498.054621345 I0402 00:53:54.848964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-cddc6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:53:54.890663 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-cddc6-mtmdg" condition "Approved" to 2026-04-02 00:53:54.890650477 +0000 UTC m=+498.319172350 I0402 00:53:54.919880 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-cddc6-mtmdg" condition "Ready" to 2026-04-02 00:53:54.919871868 +0000 UTC m=+498.348393741 I0402 00:53:54.950850 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:53:54.950840184 +0000 UTC m=+498.379362057 I0402 00:53:54.969669 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-cddc6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-cddc6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:54:16.466615 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-02 00:54:16.46660266 +0000 UTC m=+519.895124533 I0402 00:54:16.466716 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:54:16.466744 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-02 00:54:16.466737783 +0000 UTC m=+519.895259656 I0402 00:54:16.482532 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:54:16.482699 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:54:16.482724 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-02 00:54:16.482717552 +0000 UTC m=+519.911239435 I0402 00:54:16.632697 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-988pj" condition "Approved" to 2026-04-02 00:54:16.632686597 +0000 UTC m=+520.061208470 I0402 00:54:16.657146 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-988pj" condition "Ready" to 2026-04-02 00:54:16.657132475 +0000 UTC m=+520.085654358 I0402 00:54:16.682715 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:54:16.682699146 +0000 UTC m=+520.111221039 I0402 00:54:16.701708 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:57:46.593065 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:57:46.593150 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-02 00:57:46.593140709 +0000 UTC m=+730.021662612 I0402 00:57:46.593170 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-02 00:57:46.59315107 +0000 UTC m=+730.021672943 I0402 00:57:46.612221 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:57:46.612315 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-02 00:57:46.612307255 +0000 UTC m=+730.040829128 I0402 00:57:46.796835 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:57:46.833643 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6ppp8" condition "Approved" to 2026-04-02 00:57:46.833619988 +0000 UTC m=+730.262141871 I0402 00:57:46.850371 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6ppp8" condition "Ready" to 2026-04-02 00:57:46.850358361 +0000 UTC m=+730.278880234 I0402 00:57:46.880139 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:57:46.880118801 +0000 UTC m=+730.308640694 I0402 00:57:46.911971 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:57:46.962120 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:58:30.906303 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-02 00:58:30.906287728 +0000 UTC m=+774.334809601 I0402 00:58:30.906314 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0402 00:58:30.906355 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-02 00:58:30.90635067 +0000 UTC m=+774.334872533 I0402 00:58:30.923567 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:58:30.923641 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-02 00:58:30.923633872 +0000 UTC m=+774.352155755 I0402 00:58:31.472032 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:58:31.529241 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-6xb4z" condition "Approved" to 2026-04-02 00:58:31.529231686 +0000 UTC m=+774.957753559 I0402 00:58:31.566811 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-6xb4z" condition "Ready" to 2026-04-02 00:58:31.566798515 +0000 UTC m=+774.995320408 I0402 00:58:31.599679 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:58:31.599671006 +0000 UTC m=+775.028192879 I0402 00:58:31.617856 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0402 00:58:31.618282 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-02 00:58:31.618274854 +0000 UTC m=+775.046796737 I0402 00:58:31.646594 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"