I0506 17:59:53.715229 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0506 17:59:53.715322 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0506 17:59:53.715402 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0506 17:59:53.720789 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0506 17:59:53.721139 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0506 17:59:53.721179 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0506 17:59:53.721198 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0506 17:59:53.725884 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0506 17:59:53.739967 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0506 17:59:53.743576 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0506 17:59:53.743603 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0506 17:59:53.743660 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0506 17:59:53.747102 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0506 17:59:53.753137 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0506 17:59:53.756511 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0506 17:59:53.759368 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0506 17:59:53.762613 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0506 17:59:53.765870 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0506 17:59:53.768600 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0506 17:59:53.768632 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0506 17:59:53.768642 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0506 17:59:53.768732 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0506 17:59:53.774410 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0506 17:59:53.778344 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0506 17:59:53.780961 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0506 17:59:53.783443 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0506 17:59:53.786178 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0506 17:59:53.788939 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0506 17:59:53.791007 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0506 17:59:53.792834 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0506 17:59:53.794448 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0506 17:59:53.794525 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0506 17:59:53.801929 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0506 17:59:53.804825 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.804844 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.805035 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.805492 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.821848 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.837623 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.856332 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.873709 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.889563 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:59:53.897642 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 18:00:03.666138 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-06 18:00:03.666114231 +0000 UTC m=+9.979826461 I0506 18:00:04.457143 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:00:04.457190 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 18:00:04.457181511 +0000 UTC m=+10.770893771 I0506 18:00:04.457712 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 18:00:04.457698436 +0000 UTC m=+10.771410666 E0506 18:00:04.476670 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:00:04.476821 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-06 18:00:04.476813316 +0000 UTC m=+10.790525546 E0506 18:00:04.477039 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:00:04.479264 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:04.479425 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 18:00:04.479416377 +0000 UTC m=+10.793128597 E0506 18:00:04.493529 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0506 18:00:04.493707 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:00:04.493748 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:00:04.493856 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0506 18:00:04.499278 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:04.499391 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 18:00:04.499381829 +0000 UTC m=+10.813094049 I0506 18:00:04.501272 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-kl7kr" condition "Approved" to 2026-05-06 18:00:04.501264561 +0000 UTC m=+10.814976781 I0506 18:00:04.516870 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-kl7kr" condition "Ready" to 2026-05-06 18:00:04.516857945 +0000 UTC m=+10.830570175 I0506 18:00:04.541813 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:00:04.541790343 +0000 UTC m=+10.855502603 I0506 18:00:04.558509 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:04.558898 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:00:04.558890538 +0000 UTC m=+10.872602768 I0506 18:00:04.579227 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:04.580094 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:09.493917 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:00:09.493890014 +0000 UTC m=+15.807602264 I0506 18:00:30.858293 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 18:00:30.858277975 +0000 UTC m=+37.171990195 I0506 18:00:30.858413 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:00:30.858525 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 18:00:30.858492861 +0000 UTC m=+37.172205091 I0506 18:00:30.870074 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-06 18:00:30.870052383 +0000 UTC m=+37.183764613 I0506 18:00:30.890065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:30.890162 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 18:00:30.890155357 +0000 UTC m=+37.203867567 I0506 18:00:31.207805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:31.248779 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-5vxnx" condition "Approved" to 2026-05-06 18:00:31.248768937 +0000 UTC m=+37.562481157 I0506 18:00:31.277391 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-5vxnx" condition "Ready" to 2026-05-06 18:00:31.277377731 +0000 UTC m=+37.591089961 I0506 18:00:31.344748 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:00:31.344735563 +0000 UTC m=+37.658447783 I0506 18:00:31.363040 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:00:31.364055 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:00:31.364043345 +0000 UTC m=+37.677755585 I0506 18:00:31.387630 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:14.884135 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-05-06 18:02:14.884122325 +0000 UTC m=+141.197834545 I0506 18:02:14.884863 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:02:14.884906 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-05-06 18:02:14.884898535 +0000 UTC m=+141.198610805 I0506 18:02:14.904756 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" E0506 18:02:14.904810 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0506 18:02:14.904852 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:02:14.904894 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-05-06 18:02:14.904885667 +0000 UTC m=+141.218597917 I0506 18:02:14.904966 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-05-06 18:02:14.904958628 +0000 UTC m=+141.218670848 I0506 18:02:14.905018 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0506 18:02:14.920270 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0506 18:02:14.920387 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0506 18:02:14.920420 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0506 18:02:14.920455 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0506 18:02:14.920838 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-05-06 18:02:14.920829949 +0000 UTC m=+141.234542179 I0506 18:02:14.921019 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:02:14.921128 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-05-06 18:02:14.921086366 +0000 UTC m=+141.234798596 I0506 18:02:14.936138 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:14.936322 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:02:14.936382 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-05-06 18:02:14.93636963 +0000 UTC m=+141.250081890 I0506 18:02:15.065013 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-sz7qp" condition "Approved" to 2026-05-06 18:02:15.064997653 +0000 UTC m=+141.378709883 I0506 18:02:15.117467 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-sz7qp" condition "Ready" to 2026-05-06 18:02:15.117450744 +0000 UTC m=+141.431163004 I0506 18:02:15.148251 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:15.148237128 +0000 UTC m=+141.461949358 I0506 18:02:15.169181 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:15.170039 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:15.170030309 +0000 UTC m=+141.483742539 I0506 18:02:15.178738 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:15.194646 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:15.194876 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:15.194868621 +0000 UTC m=+141.508580851 I0506 18:02:15.274443 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:15.281957 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-2rl22" condition "Approved" to 2026-05-06 18:02:15.28194156 +0000 UTC m=+141.595653790 I0506 18:02:15.301446 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-2rl22" condition "Ready" to 2026-05-06 18:02:15.301431628 +0000 UTC m=+141.615143878 I0506 18:02:19.920856 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:19.920843336 +0000 UTC m=+146.234555596 I0506 18:02:19.939524 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-2rl22" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:19.939501772 +0000 UTC m=+146.253214002 I0506 18:02:19.972382 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:19.972360982 +0000 UTC m=+146.286073232 I0506 18:02:19.995101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:52.968659 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-222.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:04:52.968694 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Issuing" to 2026-05-06 18:04:52.968686295 +0000 UTC m=+299.282398525 I0506 18:04:52.968720 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready" to 2026-05-06 18:04:52.968701785 +0000 UTC m=+299.282414015 I0506 18:04:52.986485 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:52.986579 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready" to 2026-05-06 18:04:52.986569977 +0000 UTC m=+299.300282207 I0506 18:04:53.427330 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:53.456491 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-222.nip.io-tls-fr6z2" condition "Approved" to 2026-05-06 18:04:53.456474838 +0000 UTC m=+299.770187098 I0506 18:04:53.477459 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-222.nip.io-tls-fr6z2" condition "Ready" to 2026-05-06 18:04:53.477448426 +0000 UTC m=+299.791160646 I0506 18:04:53.504367 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:04:53.504355976 +0000 UTC m=+299.818068216 I0506 18:04:53.526907 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:53.527292 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:04:53.527285178 +0000 UTC m=+299.840997408 I0506 18:04:53.540733 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-222.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-222.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:53.540994 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-222.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:04:53.540986324 +0000 UTC m=+299.854698554 I0506 18:06:05.316917 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:06:05.316959 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 18:06:05.316947214 +0000 UTC m=+371.630659464 I0506 18:06:05.317115 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:06:05.317093549 +0000 UTC m=+371.630805799 E0506 18:06:05.332062 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:06:05.332136 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-06 18:06:05.332127378 +0000 UTC m=+371.645839608 E0506 18:06:05.332198 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:06:05.333486 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:06:05.333596 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:06:05.333582239 +0000 UTC m=+371.647294499 E0506 18:06:05.345220 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0506 18:06:05.345304 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:06:05.345336 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:06:05.345369 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0506 18:06:05.347937 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:06:05.348027 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:06:05.348016132 +0000 UTC m=+371.661728382 I0506 18:06:05.351702 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:06:05.356093 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-4sbkx" condition "Approved" to 2026-05-06 18:06:05.356076387 +0000 UTC m=+371.669788617 I0506 18:06:05.358668 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:06:05.358659159 +0000 UTC m=+371.672371389 I0506 18:06:05.365377 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:06:05.366513 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-4sbkx" condition "Ready" to 2026-05-06 18:06:05.366502678 +0000 UTC m=+371.680214908 I0506 18:06:05.387298 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:06:05.387282438 +0000 UTC m=+371.700994698 I0506 18:06:05.406266 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:06:10.346556 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:06:10.346541627 +0000 UTC m=+376.660253877