I0513 16:13:14.431112 1 start.go:191] "starting" version="v1.12.17" revision="37b853ff34a6c093e946c657c189f40413c0f628" I0513 16:13:14.448720 1 setup.go:119] "Registering a reconciler for injectable" logger="cert-manager" kind="mutatingwebhookconfiguration" I0513 16:13:14.450432 1 setup.go:119] "Registering a reconciler for injectable" logger="cert-manager" kind="validatingwebhookconfiguration" I0513 16:13:14.450508 1 setup.go:119] "Registering a reconciler for injectable" logger="cert-manager" kind="apiservice" I0513 16:13:14.451693 1 setup.go:119] "Registering a reconciler for injectable" logger="cert-manager" kind="customresourcedefinition" I0513 16:13:14.453803 1 reflector.go:351] Caches populated for *v1.ValidatingWebhookConfiguration from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.453935 1 reflector.go:351] Caches populated for *v1.MutatingWebhookConfiguration from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.457055 1 reflector.go:351] Caches populated for *v1.APIService from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.666076 1 reflector.go:351] Caches populated for *v1.CustomResourceDefinition from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.752594 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-cainjector-leader-election... I0513 16:13:14.761807 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-cainjector-leader-election I0513 16:13:14.762082 1 recorder.go:104] "cert-manager-cainjector-64b59ddb75-gctl9_d299f279-696a-4645-9d0e-476ca3394866 became leader" logger="cert-manager.events" type="Normal" object={"kind":"Lease","namespace":"cert-manager","name":"cert-manager-cainjector-leader-election","uid":"ed79a060-556c-4af2-ab8e-ebf458bb492a","apiVersion":"coordination.k8s.io/v1","resourceVersion":"1128"} reason="LeaderElection" I0513 16:13:14.762300 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" source="kind source: *v1.MutatingWebhookConfiguration" I0513 16:13:14.762367 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" source="kind source: *v1.Secret" I0513 16:13:14.762389 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" source="kind source: *v1.Secret" I0513 16:13:14.762413 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" source="kind source: *v1.Certificate" I0513 16:13:14.762441 1 controller.go:185] "Starting Controller" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" I0513 16:13:14.762505 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" source="kind source: *v1.ValidatingWebhookConfiguration" I0513 16:13:14.762554 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" source="kind source: *v1.Secret" I0513 16:13:14.762537 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" source="kind source: *v1.APIService" I0513 16:13:14.762586 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" source="kind source: *v1.Secret" I0513 16:13:14.762614 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" source="kind source: *v1.Secret" I0513 16:13:14.762617 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" source="kind source: *v1.Certificate" I0513 16:13:14.762642 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" source="kind source: *v1.Secret" I0513 16:13:14.762660 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" source="kind source: *v1.Certificate" I0513 16:13:14.762684 1 controller.go:185] "Starting Controller" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" I0513 16:13:14.762725 1 controller.go:185] "Starting Controller" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" I0513 16:13:14.762737 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" source="kind source: *v1.CustomResourceDefinition" I0513 16:13:14.762909 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" source="kind source: *v1.Secret" I0513 16:13:14.762929 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" source="kind source: *v1.Secret" I0513 16:13:14.762944 1 controller.go:177] "Starting EventSource" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" source="kind source: *v1.Certificate" I0513 16:13:14.762951 1 controller.go:185] "Starting Controller" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" I0513 16:13:14.784386 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.814608 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 16:13:14.871262 1 controller.go:219] "Starting workers" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" worker count=1 I0513 16:13:14.871439 1 controller.go:219] "Starting workers" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" worker count=1 I0513 16:13:14.872733 1 controller.go:219] "Starting workers" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" worker count=1 I0513 16:13:14.872852 1 controller.go:219] "Starting workers" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" worker count=1 E0513 16:13:14.872863 1 sources.go:176] "unable to fetch associated secret" err="Secret \"cert-manager-webhook-ca\" not found" logger="cert-manager" kind="mutatingwebhookconfiguration" kind="mutatingwebhookconfiguration" name="cert-manager-webhook" secret="cert-manager/cert-manager-webhook-ca" I0513 16:13:14.872901 1 reconciler.go:118] "could not find any ca data in data source for target" logger="cert-manager" kind="mutatingwebhookconfiguration" kind="mutatingwebhookconfiguration" name="cert-manager-webhook" E0513 16:13:14.873090 1 sources.go:176] "unable to fetch associated secret" err="Secret \"cert-manager-webhook-ca\" not found" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="cert-manager-webhook" secret="cert-manager/cert-manager-webhook-ca" I0513 16:13:14.873135 1 reconciler.go:118] "could not find any ca data in data source for target" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="cert-manager-webhook" I0513 16:13:16.994701 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="cert-manager-webhook" I0513 16:13:16.997624 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="mutatingwebhookconfiguration" kind="mutatingwebhookconfiguration" name="cert-manager-webhook" I0513 16:13:16.999511 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="cert-manager-webhook" I0513 16:13:17.001191 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="mutatingwebhookconfiguration" kind="mutatingwebhookconfiguration" name="cert-manager-webhook" E0513 16:14:09.173497 1 sources.go:116] "unable to fetch associated secret" err="Secret \"rabbitmq-messaging-topology-operator-webhook\" not found" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" certificate="openstack/rabbitmq-messaging-topology-operator-webhook" secret="openstack/rabbitmq-messaging-topology-operator-webhook" I0513 16:14:09.173533 1 reconciler.go:118] "could not find any ca data in data source for target" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" E0513 16:14:09.193424 1 sources.go:116] "unable to fetch associated secret" err="Secret \"rabbitmq-messaging-topology-operator-webhook\" not found" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" certificate="openstack/rabbitmq-messaging-topology-operator-webhook" secret="openstack/rabbitmq-messaging-topology-operator-webhook" I0513 16:14:09.193479 1 reconciler.go:118] "could not find any ca data in data source for target" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" E0513 16:14:09.468511 1 sources.go:116] "unable to fetch associated secret" err="Secret \"rabbitmq-messaging-topology-operator-webhook\" not found" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" certificate="openstack/rabbitmq-messaging-topology-operator-webhook" secret="openstack/rabbitmq-messaging-topology-operator-webhook" I0513 16:14:09.468558 1 reconciler.go:118] "could not find any ca data in data source for target" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" I0513 16:14:09.565697 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" I0513 16:14:09.573506 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" I0513 16:14:09.583017 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" I0513 16:14:09.599034 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" I0513 16:14:09.621890 1 reconciler.go:142] "Updated object" logger="cert-manager" kind="validatingwebhookconfiguration" kind="validatingwebhookconfiguration" name="rabbitmq-messaging-topology-operator-webhook-openstack" E0513 16:51:30.701828 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-cainjector-leader-election: etcdserver: request timed out E0513 16:51:57.921562 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-cainjector-leader-election: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-cainjector-leader-election": context deadline exceeded I0513 16:51:57.921633 1 leaderelection.go:285] failed to renew lease cert-manager/cert-manager-cainjector-leader-election: timed out waiting for the condition Error: error running manager: leader election lost I0513 16:52:01.626619 1 recorder.go:104] "cert-manager-cainjector-64b59ddb75-gctl9_d299f279-696a-4645-9d0e-476ca3394866 stopped leading" logger="cert-manager.events" type="Normal" object={"kind":"Lease","namespace":"cert-manager","name":"cert-manager-cainjector-leader-election","uid":"ed79a060-556c-4af2-ab8e-ebf458bb492a","apiVersion":"coordination.k8s.io/v1","resourceVersion":"18823"} reason="LeaderElection" I0513 16:52:01.626698 1 internal.go:581] "Stopping and waiting for non leader election runnables" logger="cert-manager" I0513 16:52:01.626770 1 internal.go:585] "Stopping and waiting for leader election runnables" logger="cert-manager" I0513 16:52:01.626821 1 internal.go:591] "Stopping and waiting for caches" logger="cert-manager" I0513 16:52:01.626859 1 internal.go:595] "Stopping and waiting for webhooks" logger="cert-manager" I0513 16:52:01.626877 1 internal.go:599] "Wait completed, proceeding to shutdown the manager" logger="cert-manager" I0513 16:52:01.626915 1 controller.go:239] "Shutdown signal received, waiting for all workers to finish" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" I0513 16:52:01.626948 1 controller.go:239] "Shutdown signal received, waiting for all workers to finish" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" I0513 16:52:01.626979 1 controller.go:239] "Shutdown signal received, waiting for all workers to finish" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" I0513 16:52:01.627009 1 controller.go:239] "Shutdown signal received, waiting for all workers to finish" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" I0513 16:52:01.627329 1 controller.go:241] "All workers finished" logger="cert-manager" controller="mutatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="MutatingWebhookConfiguration" I0513 16:52:01.627525 1 controller.go:241] "All workers finished" logger="cert-manager" controller="customresourcedefinition" controllerGroup="apiextensions.k8s.io" controllerKind="CustomResourceDefinition" I0513 16:52:01.627587 1 controller.go:241] "All workers finished" logger="cert-manager" controller="apiservice" controllerGroup="apiregistration.k8s.io" controllerKind="APIService" Usage: cainjector [flags] Flags: --add_dir_header If true, adds the file directory to the header of the log messages --alsologtostderr log to standard error as well as files (no effect when -logtostderr=true) --enable-apiservices-injectable Inject CA data to annotated APIServices. This functionality is not required if cainjector is only used as cert-manager's internal component and setting it to false might reduce memory consumption (default true) --enable-certificates-data-source Enable configuring cert-manager.io Certificate resources as potential sources for CA data. Requires cert-manager.io Certificate CRD to be installed. This data source can be disabled to reduce memory consumption if you only use cainjector as part of cert-manager's installation (default true) --enable-customresourcedefinitions-injectable Inject CA data to annotated CustomResourceDefinitions. This functionality is not required if cainjecor is only used as cert-manager's internal component and setting it to false might slightly reduce memory consumption (default true) --enable-mutatingwebhookconfigurations-injectable Inject CA data to annotated MutatingWebhookConfigurations. This functionality is required for cainjector to work correctly as cert-manager's internal component (default true) --enable-profiling Enable profiling for cainjector --enable-validatingwebhookconfigurations-injectable Inject CA data to annotated ValidatingWebhookConfigurations. This functionality is required for cainjector to correctly function as cert-manager's internal component (default true) --feature-gates mapStringBool A set of key=value pairs that describe feature gates for alpha/experimental features. Options are: AllAlpha=true|false (ALPHA - default=false) AllBeta=true|false (BETA - default=false) ServerSideApply=true|false (ALPHA - default=false) -h, --help help for cainjector --kubeconfig string Paths to a kubeconfig. Only required if out-of-cluster. --leader-elect If true, cainjector will perform leader election between instances to ensure no more than one instance of cainjector operates at a time (default true) --leader-election-lease-duration duration The duration that non-leader candidates will wait after observing a leadership renewal until attempting to acquire leadership of a led but unrenewed leader slot. This is effectively the maximum duration that a leader can be stopped before it is replaced by another candidate. This is only applicable if leader election is enabled. (default 1m0s) --leader-election-namespace string Namespace used to perform leader election. Only used if leader election is enabled (default "kube-system") --leader-election-renew-deadline duration The interval between attempts by the acting master to renew a leadership slot before it stops leading. This must be less than or equal to the lease duration. This is only applicable if leader election is enabled. (default 40s) --leader-election-retry-period duration The duration the clients should wait between attempting acquisition and renewal of a leadership. This is only applicable if leader election is enabled. (default 15s) --log-flush-frequency duration Maximum number of seconds between log flushes (default 5s) --log_backtrace_at traceLocation when logging hits line file:N, emit a stack trace (default :0) --log_dir string If non-empty, write log files in this directory (no effect when -logtostderr=true) --log_file string If non-empty, use this log file (no effect when -logtostderr=true) --log_file_max_size uint Defines the maximum size a log file can grow to (no effect when -logtostderr=true). Unit is megabytes. If the value is 0, the maximum file size is unlimited. (default 1800) --logging-format string Sets the log format. Permitted formats: "json" (gated by LoggingBetaOptions), "text". (default "text") --logtostderr log to standard error instead of files (default true) --namespace string If set, this limits the scope of cainjector to a single namespace. If set, cainjector will not update resources with certificates outside of the configured namespace. --one_output If true, only write logs to their native severity level (vs also writing to each lower severity level; no effect when -logtostderr=true) --profiler-address string Address of the Go profiler (pprof) if enabled. This should never be exposed on a public interface. (default "localhost:6060") --skip_headers If true, avoid header prefixes in the log messages --skip_log_headers If true, avoid headers when opening log files (no effect when -logtostderr=true) --stderrthreshold severity logs at or above this threshold go to stderr when writing to files and stderr (no effect when -logtostderr=true or -alsologtostderr=true) (default 2) -v, --v Level number for the log level verbosity (default 0) --vmodule pattern=N,... comma-separated list of pattern=N settings for file-filtered logging (only works for text log format) I0513 16:52:01.627694 1 controller.go:241] "All workers finished" logger="cert-manager" controller="validatingwebhookconfiguration" controllerGroup="admissionregistration.k8s.io" controllerKind="ValidatingWebhookConfiguration" E0513 16:52:01.631603 1 main.go:45] "error executing command" err="error running manager: leader election lost" logger="cert-manager"