I0317 20:50:15.507655 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0317 20:50:15.507819 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0317 20:50:15.507856 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0317 20:50:15.507947 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0317 20:50:15.510333 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0317 20:50:15.510897 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0317 20:50:15.511062 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0317 20:50:15.511655 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0317 20:50:15.528228 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0317 20:50:15.528452 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0317 20:50:15.530212 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0317 20:50:15.531168 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0317 20:50:15.531628 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0317 20:50:15.533284 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0317 20:50:15.533969 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0317 20:50:15.534224 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0317 20:50:15.534250 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0317 20:50:15.534792 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0317 20:50:15.535270 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0317 20:50:15.535293 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0317 20:50:15.535592 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0317 20:50:15.535836 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0317 20:50:15.537733 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0317 20:50:15.537989 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0317 20:50:15.538084 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0317 20:50:15.538827 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0317 20:50:15.539157 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0317 20:50:15.540396 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0317 20:50:15.540740 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0317 20:50:15.540894 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0317 20:50:15.541269 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0317 20:50:15.541680 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0317 20:50:15.542479 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0317 20:50:55.000173 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-03-17 20:50:55.000150686 +0000 UTC m=+39.532890081 I0317 20:50:55.146372 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-17 20:50:55.146361413 +0000 UTC m=+39.679100798 I0317 20:50:55.146797 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:55.146914 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-03-17 20:50:55.146903558 +0000 UTC m=+39.679642943 E0317 20:50:55.162911 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.189dbc1ba457c829", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"014ec317-43d4-4a13-9804-20fb915ed232", APIVersion:"cert-manager.io/v1", ResourceVersion:"1127", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.March, 17, 20, 50, 55, 161198633, time.Local), LastTimestamp:time.Date(2026, time.March, 17, 20, 50, 55, 161198633, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.189dbc1ba457c829" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0317 20:50:55.170771 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0317 20:50:55.171521 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-17 20:50:55.171506313 +0000 UTC m=+39.704245698 E0317 20:50:55.173014 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0317 20:50:55.193058 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0317 20:50:55.238912 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-17 20:50:55.23890167 +0000 UTC m=+39.771641055 I0317 20:50:55.255146 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:55.255124 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-17 20:50:55.255113172 +0000 UTC m=+39.787852557 I0317 20:50:55.255176 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-03-17 20:50:55.255169333 +0000 UTC m=+39.787908708 I0317 20:50:55.306891 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0317 20:50:55.309725 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-17 20:50:55.309711597 +0000 UTC m=+39.842451022 E0317 20:50:55.337569 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0317 20:50:55.581809 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0317 20:50:55.838811 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-h57sg" condition "Approved" to 2026-03-17 20:50:55.838799276 +0000 UTC m=+40.371538651 I0317 20:50:56.228249 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-h57sg" condition "Ready" to 2026-03-17 20:50:56.22823067 +0000 UTC m=+40.760970065 I0317 20:50:56.340419 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-17 20:50:56.340407445 +0000 UTC m=+40.873146840 I0317 20:50:56.378336 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0317 20:50:56.378778 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-17 20:50:56.378767585 +0000 UTC m=+40.911506980 I0317 20:50:56.405907 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0317 20:50:56.414119 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0317 20:50:56.651946 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-17 20:50:56.651930126 +0000 UTC m=+41.184669531 I0317 20:50:56.822369 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-17 20:50:56.822359656 +0000 UTC m=+41.355099031 I0317 20:50:56.822664 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:56.822677 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-17 20:50:56.822675005 +0000 UTC m=+41.355414380 I0317 20:50:56.868881 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0317 20:50:56.868952 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-17 20:50:56.868946824 +0000 UTC m=+41.401686209 I0317 20:50:56.996256 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0317 20:50:57.059587 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-gqpxc" condition "Approved" to 2026-03-17 20:50:57.059577851 +0000 UTC m=+41.592317226 I0317 20:50:57.149382 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-gqpxc" condition "Ready" to 2026-03-17 20:50:57.149369287 +0000 UTC m=+41.682108662 I0317 20:50:57.191199 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-17 20:50:57.191188312 +0000 UTC m=+41.723927687 I0317 20:50:57.233957 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0317 20:50:57.274763 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-17 20:50:57.274749769 +0000 UTC m=+41.807489154 I0317 20:50:57.292054 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-17 20:50:57.292045718 +0000 UTC m=+41.824785103 I0317 20:50:57.292544 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:57.292587 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-17 20:50:57.292582913 +0000 UTC m=+41.825322298 I0317 20:50:57.303097 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0317 20:50:57.317362 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0317 20:50:57.317428 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:57.317461 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-17 20:50:57.31745537 +0000 UTC m=+41.850194745 I0317 20:50:57.509403 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-jqb78" condition "Approved" to 2026-03-17 20:50:57.509395248 +0000 UTC m=+42.042134623 I0317 20:50:57.550384 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-jqb78" condition "Ready" to 2026-03-17 20:50:57.550377049 +0000 UTC m=+42.083116414 I0317 20:50:57.641971 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-17 20:50:57.641957227 +0000 UTC m=+42.174696602 I0317 20:50:57.660944 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-17 20:50:57.660930393 +0000 UTC m=+42.193669768 I0317 20:50:57.977512 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-17 20:50:57.977496962 +0000 UTC m=+42.510236347 I0317 20:50:57.977545 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:57.977603 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-17 20:50:57.977570315 +0000 UTC m=+42.510309690 I0317 20:50:57.987154 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0317 20:50:58.011480 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0317 20:50:58.011547 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0317 20:50:58.011566 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-17 20:50:58.011560873 +0000 UTC m=+42.544300258 I0317 20:50:58.605643 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0317 20:50:58.648008 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-fvng5" condition "Approved" to 2026-03-17 20:50:58.643359497 +0000 UTC m=+43.176098902 I0317 20:50:58.697884 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-fvng5" condition "Ready" to 2026-03-17 20:50:58.697870361 +0000 UTC m=+43.230609756 I0317 20:50:58.747217 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-17 20:50:58.747117103 +0000 UTC m=+43.279856488 I0317 20:50:58.775107 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0317 20:50:58.837071 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0317 20:52:10.486035 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0317 20:52:10.520197 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-17 20:52:10.520185682 +0000 UTC m=+115.052925057 I0317 20:52:10.538260 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-17 20:52:10.538249962 +0000 UTC m=+115.070989357 E0317 20:52:12.460108 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0317 20:52:12.507234 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-17 20:52:12.507219684 +0000 UTC m=+117.039959099 I0317 20:52:12.527395 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-17 20:52:12.527384758 +0000 UTC m=+117.060124143 E0317 20:52:13.867453 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0317 20:52:13.912487 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-17 20:52:13.912474557 +0000 UTC m=+118.445213942 I0317 20:52:13.931653 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-17 20:52:13.931618987 +0000 UTC m=+118.464358382 E0317 20:52:15.685522 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0317 20:52:15.719480 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-17 20:52:15.719467692 +0000 UTC m=+120.252207067 I0317 20:52:15.739099 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-17 20:52:15.73908494 +0000 UTC m=+120.271824355