I0521 22:48:14.317756 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0521 22:48:14.317912 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0521 22:48:14.317951 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0521 22:48:14.318031 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0521 22:48:14.319788 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0521 22:48:14.320401 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0521 22:48:14.321119 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0521 22:48:14.321835 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0521 22:48:14.334559 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0521 22:48:14.334800 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0521 22:48:14.336371 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0521 22:48:14.338668 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0521 22:48:14.338823 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0521 22:48:14.339320 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0521 22:48:14.339944 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0521 22:48:14.340607 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0521 22:48:14.341322 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0521 22:48:14.342222 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0521 22:48:14.343054 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0521 22:48:14.343556 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0521 22:48:14.343836 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0521 22:48:14.343923 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0521 22:48:14.344421 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0521 22:48:14.344669 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0521 22:48:14.344962 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0521 22:48:14.344982 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0521 22:48:14.345180 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0521 22:48:14.345468 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0521 22:48:14.345978 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0521 22:48:14.346196 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0521 22:48:14.349701 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0521 22:48:14.351033 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0521 22:48:14.351132 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0521 22:48:38.770722 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-21 22:48:38.770697748 +0000 UTC m=+24.485953580 I0521 22:48:38.783297 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-21 22:48:38.783284014 +0000 UTC m=+24.498539866 I0521 22:48:38.783430 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:38.783456 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-21 22:48:38.783448407 +0000 UTC m=+24.498704239 E0521 22:48:38.796669 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18b1b6412aca7123", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"f7cbaecd-0956-4268-9fd1-f8340c55a817", APIVersion:"cert-manager.io/v1", ResourceVersion:"1300", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 21, 22, 48, 38, 795096355, time.Local), LastTimestamp:time.Date(2026, time.May, 21, 22, 48, 38, 795096355, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18b1b6412aca7123" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0521 22:48:38.797681 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0521 22:48:38.797728 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-21 22:48:38.797722331 +0000 UTC m=+24.512978163 E0521 22:48:38.802178 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0521 22:48:38.835946 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-21 22:48:38.835936755 +0000 UTC m=+24.551192587 I0521 22:48:38.848214 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:38.848242 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-21 22:48:38.848233847 +0000 UTC m=+24.563489679 I0521 22:48:38.848696 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-21 22:48:38.848692165 +0000 UTC m=+24.563947997 I0521 22:48:38.863290 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0521 22:48:38.863351 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:38.863366 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-21 22:48:38.863361942 +0000 UTC m=+24.578617774 E0521 22:48:39.150711 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0521 22:48:39.165677 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0521 22:48:39.170528 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-nrmj9" condition "Approved" to 2026-05-21 22:48:39.170521854 +0000 UTC m=+24.885777676 I0521 22:48:39.208119 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-nrmj9" condition "Ready" to 2026-05-21 22:48:39.208107679 +0000 UTC m=+24.923363501 I0521 22:48:39.249137 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:39.249126617 +0000 UTC m=+24.964382439 I0521 22:48:39.267079 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0521 22:48:39.373218 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-21 22:48:39.373204085 +0000 UTC m=+25.088459907 I0521 22:48:39.387017 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:39.387051 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-21 22:48:39.387040944 +0000 UTC m=+25.102296766 I0521 22:48:39.387012 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-21 22:48:39.387001771 +0000 UTC m=+25.102257603 I0521 22:48:39.401161 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0521 22:48:39.401377 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:39.401461 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-21 22:48:39.401453191 +0000 UTC m=+25.116709033 I0521 22:48:39.722871 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-21 22:48:39.722857918 +0000 UTC m=+25.438113750 I0521 22:48:39.750219 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-21 22:48:39.750209431 +0000 UTC m=+25.465465253 I0521 22:48:39.750553 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:39.750586 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-21 22:48:39.750583422 +0000 UTC m=+25.465839244 I0521 22:48:39.773906 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0521 22:48:39.774061 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-21 22:48:39.774055084 +0000 UTC m=+25.489310916 I0521 22:48:40.038785 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-21 22:48:40.038774387 +0000 UTC m=+25.754030209 I0521 22:48:40.053337 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-21 22:48:40.053325846 +0000 UTC m=+25.768581668 I0521 22:48:40.054222 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:40.054249 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-21 22:48:40.054243852 +0000 UTC m=+25.769499664 I0521 22:48:40.070287 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0521 22:48:40.071453 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0521 22:48:40.071474 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-21 22:48:40.071470292 +0000 UTC m=+25.786726114 I0521 22:48:40.402279 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-b92mt" condition "Approved" to 2026-05-21 22:48:40.402268549 +0000 UTC m=+26.117524381 I0521 22:48:40.434269 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-b92mt" condition "Ready" to 2026-05-21 22:48:40.434254265 +0000 UTC m=+26.149510087 I0521 22:48:40.477809 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:40.477794954 +0000 UTC m=+26.193050816 I0521 22:48:40.497864 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0521 22:48:40.499204 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:40.499165696 +0000 UTC m=+26.214421538 I0521 22:48:40.515294 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0521 22:48:40.518682 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0521 22:48:40.525425 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0521 22:48:40.534493 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0521 22:48:40.572459 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-sn52h" condition "Approved" to 2026-05-21 22:48:40.572449267 +0000 UTC m=+26.287705089 I0521 22:48:40.595153 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-sn52h" condition "Ready" to 2026-05-21 22:48:40.595144927 +0000 UTC m=+26.310400739 I0521 22:48:40.785654 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:40.78564509 +0000 UTC m=+26.500900912 I0521 22:48:40.928845 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0521 22:48:40.929240 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:40.929231925 +0000 UTC m=+26.644487777 I0521 22:48:41.282546 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0521 22:48:41.342454 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-2xfxl" condition "Approved" to 2026-05-21 22:48:41.342443912 +0000 UTC m=+27.057699744 I0521 22:48:41.380961 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0521 22:48:41.428997 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0521 22:48:41.802551 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-2xfxl" condition "Ready" to 2026-05-21 22:48:41.802539823 +0000 UTC m=+27.517795655 I0521 22:48:42.088201 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:42.08690115 +0000 UTC m=+27.802157012 I0521 22:48:42.182929 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0521 22:48:42.183220 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-21 22:48:42.183213414 +0000 UTC m=+27.898469246 I0521 22:48:42.432905 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0521 22:48:42.484945 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0521 22:49:46.700254 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0521 22:49:46.729531 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-21 22:49:46.729400221 +0000 UTC m=+92.444656073 I0521 22:49:46.753525 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-21 22:49:46.753518731 +0000 UTC m=+92.468774563 E0521 22:49:48.708045 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0521 22:49:48.755823 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-21 22:49:48.755807199 +0000 UTC m=+94.471063051 I0521 22:49:48.775126 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-21 22:49:48.775114926 +0000 UTC m=+94.490370758 E0521 22:49:50.205759 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0521 22:49:50.242638 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-21 22:49:50.242619837 +0000 UTC m=+95.957875699 I0521 22:49:50.261205 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-21 22:49:50.261196286 +0000 UTC m=+95.976452118 E0521 22:49:51.818034 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0521 22:49:51.860766 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-21 22:49:51.860753296 +0000 UTC m=+97.576009118 I0521 22:49:51.883464 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-21 22:49:51.883451841 +0000 UTC m=+97.598707703