I0422 07:20:44.240498 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0422 07:20:44.240680 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0422 07:20:44.240730 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0422 07:20:44.240828 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0422 07:20:44.242078 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0422 07:20:44.242438 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0422 07:20:44.243209 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0422 07:20:44.243654 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0422 07:20:44.262504 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0422 07:20:44.269120 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0422 07:20:44.271011 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0422 07:20:44.272574 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0422 07:20:44.273221 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0422 07:20:44.273280 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0422 07:20:44.273997 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0422 07:20:44.274605 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0422 07:20:44.275046 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0422 07:20:44.275071 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0422 07:20:44.275078 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0422 07:20:44.275089 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0422 07:20:44.275857 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0422 07:20:44.276890 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0422 07:20:44.277604 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0422 07:20:44.277941 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0422 07:20:44.278066 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0422 07:20:44.278454 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0422 07:20:44.278932 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0422 07:20:44.279242 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0422 07:20:44.279634 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0422 07:20:44.280003 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0422 07:20:44.280079 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0422 07:20:44.280887 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0422 07:20:44.281326 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0422 07:21:04.882701 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-22 07:21:04.882676535 +0000 UTC m=+20.679145848 I0422 07:21:04.897871 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:04.897901 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 07:21:04.897895485 +0000 UTC m=+20.694364798 I0422 07:21:04.900417 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 07:21:04.900403711 +0000 UTC m=+20.696873024 E0422 07:21:04.911007 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a89ccec6bf0150", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"3f6051d4-564a-47a5-9e36-cb66bd9b7153", APIVersion:"cert-manager.io/v1", ResourceVersion:"1164", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 22, 7, 21, 4, 909263184, time.Local), LastTimestamp:time.Date(2026, time.April, 22, 7, 21, 4, 909263184, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a89ccec6bf0150" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0422 07:21:04.913143 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0422 07:21:04.913194 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 07:21:04.913188426 +0000 UTC m=+20.709657739 E0422 07:21:04.916659 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0422 07:21:04.955888 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 07:21:04.955878562 +0000 UTC m=+20.752347855 I0422 07:21:04.972303 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:21:04.972288404 +0000 UTC m=+20.768757747 I0422 07:21:04.972730 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:04.972774 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 07:21:04.972768143 +0000 UTC m=+20.769237456 I0422 07:21:05.007586 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 07:21:05.008366 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:21:05.00835405 +0000 UTC m=+20.804823353 I0422 07:21:05.243181 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" E0422 07:21:05.249041 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0422 07:21:05.339697 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-ts2mh" condition "Approved" to 2026-04-22 07:21:05.339685455 +0000 UTC m=+21.136154768 I0422 07:21:05.397374 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-ts2mh" condition "Ready" to 2026-04-22 07:21:05.397352458 +0000 UTC m=+21.193821771 I0422 07:21:05.439097 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:05.438358039 +0000 UTC m=+21.234827352 I0422 07:21:05.475247 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 07:21:05.779048 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 07:21:05.77903258 +0000 UTC m=+21.575501913 I0422 07:21:05.795682 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 07:21:05.795669932 +0000 UTC m=+21.592139275 I0422 07:21:05.796484 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:05.796566 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 07:21:05.796559869 +0000 UTC m=+21.593029162 I0422 07:21:05.811076 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:21:05.811475 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:05.811499 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 07:21:05.81149482 +0000 UTC m=+21.607964133 I0422 07:21:06.153468 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 07:21:06.153454121 +0000 UTC m=+21.949923424 I0422 07:21:06.178870 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:06.178873 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 07:21:06.178858318 +0000 UTC m=+21.975327621 I0422 07:21:06.178911 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 07:21:06.178900028 +0000 UTC m=+21.975369331 I0422 07:21:06.198431 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:21:06.198489 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:06.198504 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 07:21:06.198498874 +0000 UTC m=+21.994968187 I0422 07:21:06.570375 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 07:21:06.570358771 +0000 UTC m=+22.366828094 I0422 07:21:06.584579 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 07:21:06.584566593 +0000 UTC m=+22.381035896 I0422 07:21:06.584673 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:06.584711 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 07:21:06.584705886 +0000 UTC m=+22.381175219 I0422 07:21:06.606772 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 07:21:06.606889 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:21:06.606904 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 07:21:06.606899421 +0000 UTC m=+22.403368724 I0422 07:21:06.760053 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:21:06.791732 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7r9zc" condition "Approved" to 2026-04-22 07:21:06.791714352 +0000 UTC m=+22.588183655 I0422 07:21:06.827499 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-7r9zc" condition "Ready" to 2026-04-22 07:21:06.827481198 +0000 UTC m=+22.623950541 I0422 07:21:06.942303 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 07:21:06.958201 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:06.958185853 +0000 UTC m=+22.754655166 I0422 07:21:06.986831 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-zgfkx" condition "Approved" to 2026-04-22 07:21:06.986811142 +0000 UTC m=+22.783280445 I0422 07:21:07.005795 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:21:07.006136 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-szg5g" condition "Approved" to 2026-04-22 07:21:07.006123122 +0000 UTC m=+22.802592435 I0422 07:21:07.016420 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:07.016409013 +0000 UTC m=+22.812878316 I0422 07:21:07.044440 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-zgfkx" condition "Ready" to 2026-04-22 07:21:07.04441987 +0000 UTC m=+22.840889183 I0422 07:21:07.069515 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:21:07.069812 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:07.069806177 +0000 UTC m=+22.866275490 I0422 07:21:07.070132 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-szg5g" condition "Ready" to 2026-04-22 07:21:07.070119723 +0000 UTC m=+22.866589026 I0422 07:21:07.499879 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:07.499866449 +0000 UTC m=+23.296335762 I0422 07:21:07.577303 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:07.577283871 +0000 UTC m=+23.373753184 I0422 07:21:07.705126 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 07:21:07.795147 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:21:07.796021 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:21:07.796012444 +0000 UTC m=+23.592481757 I0422 07:21:08.101776 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" E0422 07:22:15.182926 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0422 07:22:15.230674 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 07:22:15.230653801 +0000 UTC m=+91.027123144 I0422 07:22:15.257248 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:22:15.257234139 +0000 UTC m=+91.053703442 E0422 07:22:17.467004 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0422 07:22:17.504952 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 07:22:17.504935469 +0000 UTC m=+93.301404782 I0422 07:22:17.525008 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 07:22:17.524994764 +0000 UTC m=+93.321464077 E0422 07:22:19.119230 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0422 07:22:19.161983 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 07:22:19.161968063 +0000 UTC m=+94.958437396 I0422 07:22:19.181349 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 07:22:19.181333749 +0000 UTC m=+94.977803062 E0422 07:22:20.973708 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0422 07:22:21.023180 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 07:22:21.023163926 +0000 UTC m=+96.819633239 I0422 07:22:21.046244 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 07:22:21.046234228 +0000 UTC m=+96.842703541