I0422 09:32:02.721026 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0422 09:32:02.721144 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0422 09:32:02.721208 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0422 09:32:02.721260 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0422 09:32:02.722070 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0422 09:32:02.722341 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0422 09:32:02.722519 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0422 09:32:02.722682 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0422 09:32:02.736877 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0422 09:32:02.739367 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0422 09:32:02.739835 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0422 09:32:02.739859 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0422 09:32:02.739870 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0422 09:32:02.739994 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0422 09:32:02.740654 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0422 09:32:02.741004 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0422 09:32:02.741534 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0422 09:32:02.742418 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0422 09:32:02.743006 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0422 09:32:02.743382 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0422 09:32:02.743861 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0422 09:32:02.746405 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0422 09:32:02.749305 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0422 09:32:02.751752 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0422 09:32:02.752785 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0422 09:32:02.753416 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0422 09:32:02.753448 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0422 09:32:02.753499 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0422 09:32:02.754220 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0422 09:32:02.754837 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0422 09:32:02.755447 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0422 09:32:02.756303 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0422 09:32:02.756367 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0422 09:32:30.624967 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-22 09:32:30.624924709 +0000 UTC m=+27.942602371 I0422 09:32:30.711728 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 09:32:30.711717618 +0000 UTC m=+28.029395240 I0422 09:32:30.711760 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:30.711936 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 09:32:30.711919713 +0000 UTC m=+28.029597375 I0422 09:32:30.916190 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0422 09:32:30.916693 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:30.916727 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 09:32:30.916716204 +0000 UTC m=+28.234393866 E0422 09:32:31.007730 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0422 09:32:31.014251 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a8a3fae713b2ad", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"e3e23aca-9712-4f6d-acb7-53969543eab6", APIVersion:"cert-manager.io/v1", ResourceVersion:"1258", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 22, 9, 32, 31, 11639981, time.Local), LastTimestamp:time.Date(2026, time.April, 22, 9, 32, 31, 11639981, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a8a3fae713b2ad" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0422 09:32:31.044391 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 09:32:31.044379488 +0000 UTC m=+28.362057150 I0422 09:32:31.076264 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 09:32:31.076253973 +0000 UTC m=+28.393931605 I0422 09:32:31.076387 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:31.076412 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 09:32:31.076406147 +0000 UTC m=+28.394083779 E0422 09:32:31.084242 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0422 09:32:31.095503 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 09:32:31.095579 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:31.095596 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 09:32:31.095590814 +0000 UTC m=+28.413268446 I0422 09:32:33.222245 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-2wgcl" condition "Approved" to 2026-04-22 09:32:33.222235203 +0000 UTC m=+30.539912835 I0422 09:32:33.228292 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 09:32:33.638937 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-2wgcl" condition "Ready" to 2026-04-22 09:32:33.638925956 +0000 UTC m=+30.956603588 I0422 09:32:34.691073 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:34.691060895 +0000 UTC m=+32.008738517 I0422 09:32:34.727693 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 09:32:34.728096 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:34.728089096 +0000 UTC m=+32.045766718 I0422 09:32:35.388509 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 09:32:35.390961 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 09:32:35.899602 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 09:32:35.899584099 +0000 UTC m=+33.217261731 I0422 09:32:35.916907 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 09:32:35.916895625 +0000 UTC m=+33.234573257 I0422 09:32:35.917359 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:35.917438 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 09:32:35.917432088 +0000 UTC m=+33.235109720 I0422 09:32:35.932620 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 09:32:35.932683 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 09:32:35.932678463 +0000 UTC m=+33.250356085 I0422 09:32:36.231704 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 09:32:36.237199 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 09:32:36.237186494 +0000 UTC m=+33.554864116 I0422 09:32:36.260866 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:36.260902 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 09:32:36.260895941 +0000 UTC m=+33.578573573 I0422 09:32:36.261134 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 09:32:36.261129746 +0000 UTC m=+33.578807368 I0422 09:32:36.295277 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 09:32:36.295345 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:36.295362 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 09:32:36.295358104 +0000 UTC m=+33.613035736 I0422 09:32:36.299069 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-dgggr" condition "Approved" to 2026-04-22 09:32:36.299062003 +0000 UTC m=+33.616739625 I0422 09:32:36.359391 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-dgggr" condition "Ready" to 2026-04-22 09:32:36.359370324 +0000 UTC m=+33.677047986 I0422 09:32:36.414946 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:36.414935841 +0000 UTC m=+33.732613473 I0422 09:32:36.477424 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 09:32:36.477658 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:36.47765316 +0000 UTC m=+33.795330782 I0422 09:32:36.507104 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 09:32:36.507603 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:36.507596226 +0000 UTC m=+33.825273868 I0422 09:32:36.592763 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 09:32:36.59275175 +0000 UTC m=+33.910429372 I0422 09:32:36.607091 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 09:32:36.607079753 +0000 UTC m=+33.924757385 I0422 09:32:36.607434 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 09:32:36.607462 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 09:32:36.607455651 +0000 UTC m=+33.925133283 I0422 09:32:36.635004 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 09:32:36.635090 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 09:32:36.635084402 +0000 UTC m=+33.952762024 I0422 09:32:37.714668 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 09:32:37.735068 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 09:32:37.754899 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-m67kv" condition "Approved" to 2026-04-22 09:32:37.754887765 +0000 UTC m=+35.072565427 I0422 09:32:37.759510 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-f2l52" condition "Approved" to 2026-04-22 09:32:37.759503255 +0000 UTC m=+35.077180887 I0422 09:32:37.813910 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-m67kv" condition "Ready" to 2026-04-22 09:32:37.81390179 +0000 UTC m=+35.131579412 I0422 09:32:37.873218 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-f2l52" condition "Ready" to 2026-04-22 09:32:37.873206752 +0000 UTC m=+35.190884474 I0422 09:32:37.933676 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:37.933663781 +0000 UTC m=+35.251341413 I0422 09:32:38.005692 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:38.005682516 +0000 UTC m=+35.323360138 I0422 09:32:38.009826 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 09:32:38.010459 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:38.010454079 +0000 UTC m=+35.328131701 I0422 09:32:38.179209 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 09:32:38.183635 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 09:32:38.183919 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 09:32:38.183911905 +0000 UTC m=+35.501589527 I0422 09:32:38.589107 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0422 09:34:38.708669 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0422 09:34:39.368067 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 09:34:39.367965846 +0000 UTC m=+156.685643478 I0422 09:34:40.436117 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 09:34:40.436102488 +0000 UTC m=+157.753780120 E0422 09:34:43.737732 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0422 09:34:43.779748 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 09:34:43.779737198 +0000 UTC m=+161.097414820 I0422 09:34:43.799658 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 09:34:43.799644833 +0000 UTC m=+161.117322455 E0422 09:34:46.216758 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0422 09:34:46.251644 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 09:34:46.251595857 +0000 UTC m=+163.569273499 I0422 09:34:46.270996 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 09:34:46.270986361 +0000 UTC m=+163.588663993 E0422 09:34:47.900108 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0422 09:34:47.956040 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 09:34:47.956028298 +0000 UTC m=+165.273705930 I0422 09:34:47.980069 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 09:34:47.9800548 +0000 UTC m=+165.297732432