I0528 21:42:32.869975 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0528 21:42:32.870111 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0528 21:42:32.870156 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0528 21:42:32.870246 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0528 21:42:32.871507 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0528 21:42:32.871850 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0528 21:42:32.872064 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0528 21:42:32.872927 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0528 21:42:32.888430 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0528 21:42:32.888772 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0528 21:42:32.889756 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0528 21:42:32.890601 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0528 21:42:32.891154 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0528 21:42:32.893076 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0528 21:42:32.894061 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0528 21:42:32.894640 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0528 21:42:32.895248 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0528 21:42:32.896415 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0528 21:42:32.897122 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0528 21:42:32.897647 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0528 21:42:32.898169 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0528 21:42:32.898198 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0528 21:42:32.898239 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0528 21:42:32.898874 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0528 21:42:32.900874 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0528 21:42:32.901954 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0528 21:42:32.902733 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0528 21:42:32.903579 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0528 21:42:32.904079 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0528 21:42:32.904203 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0528 21:42:32.904774 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0528 21:42:32.904794 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0528 21:42:32.905056 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0528 21:42:58.286033 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-28 21:42:58.286013814 +0000 UTC m=+25.447048527 I0528 21:42:58.298356 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-28 21:42:58.298347453 +0000 UTC m=+25.459382156 I0528 21:42:58.298614 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.298738 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-28 21:42:58.298730511 +0000 UTC m=+25.459765224 I0528 21:42:58.311070 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0528 21:42:58.311191 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.311288 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-28 21:42:58.311282494 +0000 UTC m=+25.472317207 E0528 21:42:58.315484 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0528 21:42:58.327381 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18b3d8bbada0d115", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"5dfac792-45b0-4df3-af0d-6c7b3bbd0ffe", APIVersion:"cert-manager.io/v1", ResourceVersion:"1337", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 28, 21, 42, 58, 324959509, time.Local), LastTimestamp:time.Date(2026, time.May, 28, 21, 42, 58, 324959509, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18b3d8bbada0d115" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0528 21:42:58.350865 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-28 21:42:58.350854132 +0000 UTC m=+25.511888835 I0528 21:42:58.364122 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-28 21:42:58.364112929 +0000 UTC m=+25.525147652 I0528 21:42:58.364258 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.364310 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-28 21:42:58.364307593 +0000 UTC m=+25.525342296 I0528 21:42:58.381399 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0528 21:42:58.381445 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.381459 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-28 21:42:58.381453708 +0000 UTC m=+25.542488431 E0528 21:42:58.385165 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0528 21:42:58.695479 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0528 21:42:58.703546 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-gtqp6" condition "Approved" to 2026-05-28 21:42:58.703538331 +0000 UTC m=+25.864573034 I0528 21:42:58.738015 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-gtqp6" condition "Ready" to 2026-05-28 21:42:58.738006576 +0000 UTC m=+25.899041279 I0528 21:42:58.779084 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:42:58.779069974 +0000 UTC m=+25.940104717 I0528 21:42:58.799983 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0528 21:42:58.800221 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:42:58.800215231 +0000 UTC m=+25.961249934 I0528 21:42:58.816750 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0528 21:42:58.872154 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-28 21:42:58.871961067 +0000 UTC m=+26.032995780 I0528 21:42:58.892043 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-28 21:42:58.892035752 +0000 UTC m=+26.053070465 I0528 21:42:58.891783 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.892394 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-28 21:42:58.892389309 +0000 UTC m=+26.053424022 I0528 21:42:58.907319 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0528 21:42:58.907360 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:58.907369 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-28 21:42:58.907365811 +0000 UTC m=+26.068400514 I0528 21:42:59.168872 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-28 21:42:59.168864343 +0000 UTC m=+26.329899046 I0528 21:42:59.191291 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:59.191318 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-28 21:42:59.191312432 +0000 UTC m=+26.352347145 I0528 21:42:59.191911 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-28 21:42:59.191902184 +0000 UTC m=+26.352936887 I0528 21:42:59.223538 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0528 21:42:59.223616 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:59.223628 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-28 21:42:59.22362495 +0000 UTC m=+26.384659653 I0528 21:42:59.473872 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-8hxlw" condition "Approved" to 2026-05-28 21:42:59.473862735 +0000 UTC m=+26.634897448 I0528 21:42:59.475569 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-28 21:42:59.475558019 +0000 UTC m=+26.636592712 I0528 21:42:59.499211 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-28 21:42:59.499200143 +0000 UTC m=+26.660234846 I0528 21:42:59.499303 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:59.499875 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-28 21:42:59.499814655 +0000 UTC m=+26.660849378 I0528 21:42:59.520380 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0528 21:42:59.520437 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0528 21:42:59.520453 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-28 21:42:59.520449399 +0000 UTC m=+26.681484102 I0528 21:42:59.524973 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-8hxlw" condition "Ready" to 2026-05-28 21:42:59.524967559 +0000 UTC m=+26.686002262 I0528 21:42:59.568744 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:42:59.568736606 +0000 UTC m=+26.729771309 I0528 21:42:59.605829 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0528 21:42:59.606052 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:42:59.606047214 +0000 UTC m=+26.767081917 I0528 21:42:59.631946 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0528 21:42:59.634335 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:42:59.634329791 +0000 UTC m=+26.795364494 I0528 21:42:59.813810 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-fbfpf" condition "Approved" to 2026-05-28 21:42:59.813802617 +0000 UTC m=+26.974837310 I0528 21:42:59.911543 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-fbfpf" condition "Ready" to 2026-05-28 21:42:59.911535916 +0000 UTC m=+27.072570609 I0528 21:43:00.147088 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:43:00.147075189 +0000 UTC m=+27.308109903 I0528 21:43:00.294123 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0528 21:43:00.294551 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:43:00.294542137 +0000 UTC m=+27.455576880 I0528 21:43:00.604758 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-4gf87" condition "Approved" to 2026-05-28 21:43:00.604745777 +0000 UTC m=+27.765780500 I0528 21:43:00.644019 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0528 21:43:01.013051 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-4gf87" condition "Ready" to 2026-05-28 21:43:01.013041059 +0000 UTC m=+28.174075772 I0528 21:43:01.250485 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:43:01.250475952 +0000 UTC m=+28.411510655 I0528 21:43:01.372357 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0528 21:43:01.372715 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-28 21:43:01.372710653 +0000 UTC m=+28.533745346 I0528 21:43:01.596858 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0528 21:43:01.644087 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" E0528 21:44:06.606828 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0528 21:44:06.650706 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-28 21:44:06.650694131 +0000 UTC m=+93.811728844 I0528 21:44:06.668662 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-28 21:44:06.668653203 +0000 UTC m=+93.829687916 E0528 21:44:08.663166 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0528 21:44:08.693592 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-28 21:44:08.693578404 +0000 UTC m=+95.854613117 I0528 21:44:08.712273 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-28 21:44:08.712261516 +0000 UTC m=+95.873296229 E0528 21:44:10.136689 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0528 21:44:10.178797 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-28 21:44:10.178786469 +0000 UTC m=+97.339821182 I0528 21:44:10.196671 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-28 21:44:10.196665206 +0000 UTC m=+97.357699919 E0528 21:44:11.713408 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0528 21:44:11.754418 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-28 21:44:11.754403144 +0000 UTC m=+98.915437887 I0528 21:44:11.780523 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-28 21:44:11.780511343 +0000 UTC m=+98.941546056