I0513 16:52:02.719498 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0513 16:52:02.719685 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0513 16:52:02.719748 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0513 16:52:02.730848 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0513 16:52:02.731270 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0513 16:52:02.733856 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0513 16:52:02.734321 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0513 16:52:02.734372 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0513 16:52:02.794876 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0513 16:52:02.797286 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0513 16:52:02.797305 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0513 16:52:02.797312 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0513 16:52:02.800093 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0513 16:52:02.809122 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0513 16:52:02.815708 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0513 16:52:02.824320 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0513 16:52:02.824356 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0513 16:52:02.824945 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0513 16:52:02.826471 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0513 16:52:02.829468 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0513 16:52:02.829848 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0513 16:52:02.831737 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0513 16:52:02.833435 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0513 16:52:02.838643 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0513 16:52:02.842310 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0513 16:52:02.847758 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0513 16:52:02.851487 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0513 16:52:02.853270 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0513 16:52:02.853837 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0513 16:52:02.855138 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0513 16:52:02.857680 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0513 16:52:02.860908 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0513 16:52:02.864005 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.864424 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0513 16:52:02.869913 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.872346 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.873125 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.873380 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.873565 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.873905 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.876151 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:02.897104 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:03.153385 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:52:29.426882 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:52:29.426915 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-vnc" condition "Issuing" to 2026-05-13 16:52:29.426907977 +0000 UTC m=+26.774832360 I0513 16:52:29.427128 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-vnc" condition "Ready" to 2026-05-13 16:52:29.427111684 +0000 UTC m=+26.775036067 I0513 16:52:29.431118 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-api" condition "Ready" to 2026-05-13 16:52:29.431110679 +0000 UTC m=+26.779035062 I0513 16:52:29.432981 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-api" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:52:29.433033 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-api" condition "Issuing" to 2026-05-13 16:52:29.433024619 +0000 UTC m=+26.780949002 I0513 16:52:29.446754 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.446870 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:52:29.446904 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-vnc" condition "Issuing" to 2026-05-13 16:52:29.446897905 +0000 UTC m=+26.794822278 I0513 16:52:29.448023 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-api\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.448089 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-libvirt-default-6fj9s-api" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:52:29.448116 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-6fj9s-api" condition "Issuing" to 2026-05-13 16:52:29.448112443 +0000 UTC m=+26.796036806 I0513 16:52:29.668960 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-6fj9s-api-74rfq" condition "Approved" to 2026-05-13 16:52:29.668944666 +0000 UTC m=+27.016869069 I0513 16:52:29.776592 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-6fj9s-api-74rfq" condition "Ready" to 2026-05-13 16:52:29.776576305 +0000 UTC m=+27.124500708 I0513 16:52:29.809603 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-6fj9s-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.816231 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-6fj9s-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:52:29.816221279 +0000 UTC m=+27.164145642 I0513 16:52:29.823685 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-6fj9s-vnc-6cpf4" condition "Approved" to 2026-05-13 16:52:29.823673093 +0000 UTC m=+27.171597476 I0513 16:52:29.835037 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-libvirt-default-6fj9s-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-api\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.835470 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-6fj9s-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:52:29.835462703 +0000 UTC m=+27.183387076 I0513 16:52:29.843384 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-6fj9s-vnc-6cpf4" condition "Ready" to 2026-05-13 16:52:29.843374432 +0000 UTC m=+27.191298795 I0513 16:52:29.857799 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-6fj9s-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-api\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.871990 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-6fj9s-vnc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:52:29.87197852 +0000 UTC m=+27.219902903 I0513 16:52:29.887600 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-libvirt-default-6fj9s-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:52:29.935122 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-libvirt-default-6fj9s-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-6fj9s-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:36.873122 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Ready" to 2026-05-13 16:56:36.873086966 +0000 UTC m=+274.221011379 I0513 16:56:36.873291 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/heat-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:56:36.873376 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Issuing" to 2026-05-13 16:56:36.873367354 +0000 UTC m=+274.221291767 I0513 16:56:36.891699 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:36.891793 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/heat-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:56:36.891815 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Issuing" to 2026-05-13 16:56:36.891809364 +0000 UTC m=+274.239733747 I0513 16:56:37.175140 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:37.182592 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-api-certs-zs8k9" condition "Approved" to 2026-05-13 16:56:37.182581281 +0000 UTC m=+274.530505664 I0513 16:56:37.201939 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-api-certs-zs8k9" condition "Ready" to 2026-05-13 16:56:37.201925198 +0000 UTC m=+274.549849571 I0513 16:56:37.235878 1 conditions.go:192] Found status change for Certificate "heat-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:56:37.235865114 +0000 UTC m=+274.583789497 I0513 16:56:37.252316 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:37.300029 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:38.475356 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/heat-cfn-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:56:38.475409 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Issuing" to 2026-05-13 16:56:38.475400658 +0000 UTC m=+275.823325041 I0513 16:56:38.475854 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Ready" to 2026-05-13 16:56:38.475833741 +0000 UTC m=+275.823758144 I0513 16:56:38.490010 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:38.490096 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/heat-cfn-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:56:38.490113 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Issuing" to 2026-05-13 16:56:38.49010732 +0000 UTC m=+275.838031693 I0513 16:56:38.684182 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:38.693646 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-cfn-certs-hds4w" condition "Approved" to 2026-05-13 16:56:38.693627969 +0000 UTC m=+276.041552352 I0513 16:56:38.714223 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-cfn-certs-hds4w" condition "Ready" to 2026-05-13 16:56:38.714212825 +0000 UTC m=+276.062137208 I0513 16:56:38.744128 1 conditions.go:192] Found status change for Certificate "heat-cfn-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:56:38.744111614 +0000 UTC m=+276.092036027 I0513 16:56:38.771545 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:56:38.838101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:25.969928 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-05-13 16:59:25.969889979 +0000 UTC m=+443.317814382 I0513 16:59:25.970032 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:59:25.970148 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-05-13 16:59:25.970079375 +0000 UTC m=+443.318003778 E0513 16:59:25.984690 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:25.984782 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-client" condition "Ready" to 2026-05-13 16:59:25.984774378 +0000 UTC m=+443.332698761 I0513 16:59:25.984803 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:25.990297 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:25.990450 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:59:25.990483 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-05-13 16:59:25.990477008 +0000 UTC m=+443.338401391 E0513 16:59:25.998329 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" E0513 16:59:25.998627 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:25.998763 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0513 16:59:25.998813 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" I0513 16:59:26.046462 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-dk4q8" condition "Approved" to 2026-05-13 16:59:26.046444461 +0000 UTC m=+443.394368844 I0513 16:59:26.065054 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-dk4q8" condition "Ready" to 2026-05-13 16:59:26.065039227 +0000 UTC m=+443.412963610 I0513 16:59:26.099032 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:26.099009437 +0000 UTC m=+443.446933810 I0513 16:59:26.120037 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:26.120407 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:26.120401911 +0000 UTC m=+443.468326284 I0513 16:59:26.127657 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:26.143434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:26.691454 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-05-13 16:59:26.691434453 +0000 UTC m=+444.039358866 I0513 16:59:26.692072 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:59:26.692107 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-05-13 16:59:26.692100314 +0000 UTC m=+444.040024727 E0513 16:59:26.705647 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:26.706352 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-server" condition "Ready" to 2026-05-13 16:59:26.706332782 +0000 UTC m=+444.054257165 I0513 16:59:26.706426 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:26.709959 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:26.710567 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-05-13 16:59:26.710558485 +0000 UTC m=+444.058482858 E0513 16:59:26.716732 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" E0513 16:59:26.716831 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0513 16:59:26.716860 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0513 16:59:26.716945 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" I0513 16:59:26.724318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:26.756085 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-kpwnx" condition "Approved" to 2026-05-13 16:59:26.756069339 +0000 UTC m=+444.103993702 I0513 16:59:26.879704 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-kpwnx" condition "Ready" to 2026-05-13 16:59:26.879691054 +0000 UTC m=+444.227615437 I0513 16:59:26.926328 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:26.926314293 +0000 UTC m=+444.274238676 I0513 16:59:27.015273 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:27.015587 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:27.015578456 +0000 UTC m=+444.363502849 I0513 16:59:27.026638 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:27.038333 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:27.470390 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 16:59:27.470777 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-05-13 16:59:27.470765327 +0000 UTC m=+444.818689710 I0513 16:59:27.470805 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-13 16:59:27.470790948 +0000 UTC m=+444.818715321 I0513 16:59:27.484720 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:27.484778 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-13 16:59:27.484771609 +0000 UTC m=+444.832695982 I0513 16:59:27.503305 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:27.530898 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-vltvb" condition "Approved" to 2026-05-13 16:59:27.530886171 +0000 UTC m=+444.878810554 I0513 16:59:27.553207 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-vltvb" condition "Ready" to 2026-05-13 16:59:27.553194164 +0000 UTC m=+444.901118557 I0513 16:59:30.999606 1 conditions.go:85] Found status change for Issuer "octavia-client" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:30.999591689 +0000 UTC m=+448.347516072 I0513 16:59:31.058871 1 conditions.go:252] Found status change for CertificateRequest "octavia-client-certs-vltvb" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:31.058856387 +0000 UTC m=+448.406780760 I0513 16:59:31.086828 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:31.086813457 +0000 UTC m=+448.434737840 I0513 16:59:31.105922 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:31.160231 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 16:59:31.717924 1 conditions.go:85] Found status change for Issuer "octavia-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 16:59:31.717903771 +0000 UTC m=+449.065828184 I0513 17:02:15.799620 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-13 17:02:15.799605669 +0000 UTC m=+613.147530082 I0513 17:02:15.800151 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:02:15.800178 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-05-13 17:02:15.800171777 +0000 UTC m=+613.148096180 I0513 17:02:15.822568 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:02:15.822728 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-13 17:02:15.822704336 +0000 UTC m=+613.170628729 I0513 17:02:15.909243 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:02:15.948122 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-px7fj" condition "Approved" to 2026-05-13 17:02:15.948106918 +0000 UTC m=+613.296031301 I0513 17:02:15.981342 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-px7fj" condition "Ready" to 2026-05-13 17:02:15.981327664 +0000 UTC m=+613.329252047 I0513 17:02:16.009731 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:02:16.009711239 +0000 UTC m=+613.357635652 I0513 17:02:16.041465 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:02:16.041784 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:02:16.041776109 +0000 UTC m=+613.389700482 I0513 17:02:16.047805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:02:16.071048 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:02:16.071533 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:02:16.071522836 +0000 UTC m=+613.419447219 I0513 17:03:01.976522 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-13 17:03:01.976477955 +0000 UTC m=+659.324402318 I0513 17:03:01.999979 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:02.000021 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-13 17:03:02.000005137 +0000 UTC m=+659.347929570 I0513 17:03:02.000063 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-13 17:03:02.000053708 +0000 UTC m=+659.347978151 I0513 17:03:02.015285 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager-test/selfsigned-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.015372 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:02.015396 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-13 17:03:02.015389701 +0000 UTC m=+659.363314084 E0513 17:03:02.032322 1 controller.go:134] "issuer in work queue no longer exists" err="issuer.cert-manager.io \"test-selfsigned\" not found" logger="cert-manager.issuers" I0513 17:03:02.086673 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-13 17:03:02.086651637 +0000 UTC m=+659.434576060 I0513 17:03:02.108859 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-13 17:03:02.108844836 +0000 UTC m=+659.456769249 I0513 17:03:02.108953 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-system/capi-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:02.109013 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-13 17:03:02.109001531 +0000 UTC m=+659.456925944 I0513 17:03:02.127484 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.127555 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-13 17:03:02.127544285 +0000 UTC m=+659.475468668 E0513 17:03:02.282404 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" logger="cert-manager.certificates-key-manager" key="cert-manager-test/selfsigned-cert" I0513 17:03:02.580019 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.619585 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-xb2rb" condition "Approved" to 2026-05-13 17:03:02.619575868 +0000 UTC m=+659.967500241 I0513 17:03:02.654335 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-xb2rb" condition "Ready" to 2026-05-13 17:03:02.654324662 +0000 UTC m=+660.002249045 I0513 17:03:02.687479 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:02.687462367 +0000 UTC m=+660.035386750 I0513 17:03:02.704828 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.705110 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:02.705103102 +0000 UTC m=+660.053027475 I0513 17:03:02.715260 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.724852 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.900327 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-13 17:03:02.900312753 +0000 UTC m=+660.248237136 I0513 17:03:02.925651 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-13 17:03:02.925636401 +0000 UTC m=+660.273560774 I0513 17:03:02.925709 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:02.925856 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-13 17:03:02.925848457 +0000 UTC m=+660.273772830 I0513 17:03:02.953116 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:02.953186 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:02.953207 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-13 17:03:02.953199999 +0000 UTC m=+660.301124392 I0513 17:03:03.293020 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-djgrl" condition "Approved" to 2026-05-13 17:03:03.293009286 +0000 UTC m=+660.640933669 I0513 17:03:03.330933 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-djgrl" condition "Ready" to 2026-05-13 17:03:03.33092408 +0000 UTC m=+660.678848453 I0513 17:03:03.379356 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-13 17:03:03.379347866 +0000 UTC m=+660.727272239 I0513 17:03:03.406954 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:03.406941695 +0000 UTC m=+660.754866068 I0513 17:03:03.427999 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-13 17:03:03.427981808 +0000 UTC m=+660.775906211 I0513 17:03:03.428524 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:03.428546 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-13 17:03:03.428539416 +0000 UTC m=+660.776463819 I0513 17:03:03.441899 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:03.442211 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:03.442202016 +0000 UTC m=+660.790126409 I0513 17:03:03.447602 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:03.449070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:03.449114 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:03.449130 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-13 17:03:03.449126064 +0000 UTC m=+660.797050437 I0513 17:03:03.462916 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:03.700060 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-s5xws" condition "Approved" to 2026-05-13 17:03:03.700045559 +0000 UTC m=+661.047969962 I0513 17:03:03.729720 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-s5xws" condition "Ready" to 2026-05-13 17:03:03.729710634 +0000 UTC m=+661.077635007 I0513 17:03:03.778203 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:03.778182921 +0000 UTC m=+661.126107334 I0513 17:03:03.869762 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-13 17:03:03.869745856 +0000 UTC m=+661.217670239 I0513 17:03:03.870126 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:03.871184 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:03.871174991 +0000 UTC m=+661.219099384 I0513 17:03:03.893066 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-13 17:03:03.89304924 +0000 UTC m=+661.240973623 I0513 17:03:03.893384 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capo-system/capo-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:03.893406 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-13 17:03:03.893402721 +0000 UTC m=+661.241327094 I0513 17:03:04.226993 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:04.227078 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capo-system/capo-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:03:04.227104 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-13 17:03:04.227097865 +0000 UTC m=+661.575022248 I0513 17:03:04.290504 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:04.319045 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:04.698680 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:04.727259 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-rdssh" condition "Approved" to 2026-05-13 17:03:04.727248784 +0000 UTC m=+662.075173157 I0513 17:03:04.782791 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-rdssh" condition "Ready" to 2026-05-13 17:03:04.782777673 +0000 UTC m=+662.130702046 I0513 17:03:05.284206 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:05.28416374 +0000 UTC m=+662.632088123 I0513 17:03:05.420619 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:05.421074 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:03:05.421063243 +0000 UTC m=+662.768987646 I0513 17:03:05.674480 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:03:05.724006 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:28.719784 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Ready" to 2026-05-13 17:06:28.719751667 +0000 UTC m=+866.067676050 I0513 17:06:28.719896 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:06:28.719959 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-13 17:06:28.719949993 +0000 UTC m=+866.067874366 I0513 17:06:28.735400 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:28.735706 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:06:28.735744 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-13 17:06:28.735723875 +0000 UTC m=+866.083648248 I0513 17:06:29.127311 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-qw9pg" condition "Approved" to 2026-05-13 17:06:29.127300323 +0000 UTC m=+866.475224706 I0513 17:06:29.144463 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-qw9pg" condition "Ready" to 2026-05-13 17:06:29.144454124 +0000 UTC m=+866.492378507 I0513 17:06:29.178207 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:06:29.178195622 +0000 UTC m=+866.526120005 I0513 17:06:29.199366 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:29.199896 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:06:29.199887224 +0000 UTC m=+866.547811627 I0513 17:06:29.232603 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.273733 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:06:31.273772 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-05-13 17:06:31.273763966 +0000 UTC m=+868.621688349 I0513 17:06:31.273867 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Ready" to 2026-05-13 17:06:31.273844028 +0000 UTC m=+868.621768411 I0513 17:06:31.297762 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.297901 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Ready" to 2026-05-13 17:06:31.297889997 +0000 UTC m=+868.645814400 I0513 17:06:31.365282 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.417050 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-tccfg" condition "Approved" to 2026-05-13 17:06:31.417022903 +0000 UTC m=+868.764947276 I0513 17:06:31.432819 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-tccfg" condition "Ready" to 2026-05-13 17:06:31.432807746 +0000 UTC m=+868.780732129 I0513 17:06:31.465422 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:06:31.46541049 +0000 UTC m=+868.813334873 I0513 17:06:31.492574 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.492825 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:06:31.492819006 +0000 UTC m=+868.840743379 I0513 17:06:31.506250 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.512067 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:06:31.512529 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:06:31.512518131 +0000 UTC m=+868.860442524 I0513 17:12:38.993639 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:12:38.993707 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-05-13 17:12:38.993698646 +0000 UTC m=+1236.341623029 I0513 17:12:38.993921 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-05-13 17:12:38.993906152 +0000 UTC m=+1236.341830535 I0513 17:12:39.014172 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:12:39.014350 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-05-13 17:12:39.014339086 +0000 UTC m=+1236.362263499 I0513 17:12:39.071217 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:12:39.103558 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-2j9xn" condition "Approved" to 2026-05-13 17:12:39.103544715 +0000 UTC m=+1236.451469098 I0513 17:12:39.122719 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-2j9xn" condition "Ready" to 2026-05-13 17:12:39.122705358 +0000 UTC m=+1236.470629741 I0513 17:12:39.150036 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:12:39.150022168 +0000 UTC m=+1236.497946551 I0513 17:12:39.168257 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:12:39.168679 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:12:39.168672805 +0000 UTC m=+1236.516597178 I0513 17:12:39.191176 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:13:58.515917 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-13 17:13:58.515900491 +0000 UTC m=+1315.863824894 I0513 17:13:58.516129 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:13:58.516207 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-13 17:13:58.516199481 +0000 UTC m=+1315.864123864 I0513 17:13:58.533890 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:13:58.534010 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 17:13:58.534030 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-13 17:13:58.534024101 +0000 UTC m=+1315.881948474 I0513 17:13:58.812161 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:13:58.820757 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-tp8vm" condition "Approved" to 2026-05-13 17:13:58.820745948 +0000 UTC m=+1316.168670341 I0513 17:13:58.843988 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-tp8vm" condition "Ready" to 2026-05-13 17:13:58.843966899 +0000 UTC m=+1316.191891282 I0513 17:13:58.878485 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:13:58.878469626 +0000 UTC m=+1316.226394019 I0513 17:13:58.897871 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:13:58.898226 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 17:13:58.898219078 +0000 UTC m=+1316.246143451 I0513 17:13:58.913466 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 17:13:58.916745 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"