I0513 14:16:43.071083 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0513 14:16:43.071708 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0513 14:16:43.071966 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0513 14:16:43.078778 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0513 14:16:43.079210 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0513 14:16:43.079336 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0513 14:16:43.079480 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0513 14:16:43.083105 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0513 14:16:43.098072 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0513 14:16:43.105177 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0513 14:16:43.108229 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0513 14:16:43.114286 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0513 14:16:43.117339 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0513 14:16:43.120001 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0513 14:16:43.120103 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0513 14:16:43.123322 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0513 14:16:43.124827 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0513 14:16:43.126860 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0513 14:16:43.129698 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0513 14:16:43.134505 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0513 14:16:43.134537 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0513 14:16:43.134597 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0513 14:16:43.137563 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0513 14:16:43.140032 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0513 14:16:43.140128 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0513 14:16:43.142672 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0513 14:16:43.145474 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0513 14:16:43.145501 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0513 14:16:43.145616 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0513 14:16:43.148159 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0513 14:16:43.150285 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0513 14:16:43.152154 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0513 14:16:43.154074 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0513 14:16:43.158638 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.161316 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.162707 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.171880 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.187443 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.206648 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.218721 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.231732 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.244744 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:43.253468 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0513 14:16:54.974959 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-13 14:16:54.974936286 +0000 UTC m=+11.937606165 I0513 14:16:55.749780 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:16:55.749974 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-13 14:16:55.749962817 +0000 UTC m=+12.712632716 I0513 14:16:55.749750 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-13 14:16:55.74973489 +0000 UTC m=+12.712404769 E0513 14:16:55.765545 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0513 14:16:55.765630 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-13 14:16:55.765621545 +0000 UTC m=+12.728291424 E0513 14:16:55.765657 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0513 14:16:55.771977 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:16:55.772096 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-13 14:16:55.772088778 +0000 UTC m=+12.734758657 E0513 14:16:55.775562 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0513 14:16:55.775640 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0513 14:16:55.775670 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0513 14:16:55.775707 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0513 14:16:55.789970 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:16:55.790044 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-13 14:16:55.790036793 +0000 UTC m=+12.752706672 I0513 14:16:55.791767 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-m6lct" condition "Approved" to 2026-05-13 14:16:55.791758709 +0000 UTC m=+12.754428618 I0513 14:16:55.805449 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-m6lct" condition "Ready" to 2026-05-13 14:16:55.805436291 +0000 UTC m=+12.768106170 I0513 14:16:55.830210 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:16:55.83020072 +0000 UTC m=+12.792870599 I0513 14:16:55.848203 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:16:55.848471 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:16:55.848464264 +0000 UTC m=+12.811134143 I0513 14:16:55.867899 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:17:00.776519 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:17:00.776504164 +0000 UTC m=+17.739174073 I0513 14:17:23.347613 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:17:23.347596 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-13 14:17:23.347520004 +0000 UTC m=+40.310189903 I0513 14:17:23.347685 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-13 14:17:23.347676638 +0000 UTC m=+40.310346527 I0513 14:17:23.368443 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-13 14:17:23.368424408 +0000 UTC m=+40.331094307 I0513 14:17:23.396149 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:17:23.398419 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-13 14:17:23.398406632 +0000 UTC m=+40.361076501 I0513 14:17:23.579845 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:17:23.615479 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-j2h7s" condition "Approved" to 2026-05-13 14:17:23.615462138 +0000 UTC m=+40.578132037 I0513 14:17:23.650900 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-j2h7s" condition "Ready" to 2026-05-13 14:17:23.650885233 +0000 UTC m=+40.613555112 I0513 14:17:23.682666 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:17:23.68264744 +0000 UTC m=+40.645317309 I0513 14:17:23.721970 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:21:57.346148 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-44.nip.io-tls" condition "Ready" to 2026-05-13 14:21:57.346098832 +0000 UTC m=+314.308768711 I0513 14:21:57.356896 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-44.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:21:57.356939 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-44.nip.io-tls" condition "Issuing" to 2026-05-13 14:21:57.356929253 +0000 UTC m=+314.319599122 I0513 14:21:57.365572 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-44.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-44.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:21:57.365743 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-44.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:21:57.365863 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-44.nip.io-tls" condition "Issuing" to 2026-05-13 14:21:57.365761978 +0000 UTC m=+314.328431857 I0513 14:21:57.560345 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-44.nip.io-tls-726t5" condition "Approved" to 2026-05-13 14:21:57.560328088 +0000 UTC m=+314.522997998 I0513 14:21:57.596930 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-44.nip.io-tls-726t5" condition "Ready" to 2026-05-13 14:21:57.596914518 +0000 UTC m=+314.559584427 I0513 14:21:57.625297 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-44.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:21:57.625288388 +0000 UTC m=+314.587958267 I0513 14:21:57.647929 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-44.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-44.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:12.976886 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-13 14:23:12.976835552 +0000 UTC m=+389.939505431 I0513 14:23:12.977504 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:23:12.977526 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-13 14:23:12.977521684 +0000 UTC m=+389.940191563 I0513 14:23:12.992791 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:12.992912 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-13 14:23:12.992903586 +0000 UTC m=+389.955573465 E0513 14:23:12.995917 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0513 14:23:12.995993 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-13 14:23:12.995986931 +0000 UTC m=+389.958656800 E0513 14:23:12.996081 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0513 14:23:13.010065 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0513 14:23:13.010407 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0513 14:23:13.010471 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0513 14:23:13.010534 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0513 14:23:13.015749 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:13.036907 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-629sg" condition "Approved" to 2026-05-13 14:23:13.036896174 +0000 UTC m=+389.999566053 I0513 14:23:13.049441 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-629sg" condition "Ready" to 2026-05-13 14:23:13.049430545 +0000 UTC m=+390.012100424 I0513 14:23:13.074340 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:13.074324675 +0000 UTC m=+390.036994584 I0513 14:23:13.101476 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:13.138512 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:18.011026 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:18.011007355 +0000 UTC m=+394.973677264 I0513 14:23:58.037906 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-13 14:23:58.03789009 +0000 UTC m=+435.000559959 I0513 14:23:58.038072 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:23:58.038352 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-13 14:23:58.038348517 +0000 UTC m=+435.001018386 I0513 14:23:58.065311 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-13 14:23:58.065293969 +0000 UTC m=+435.027963848 I0513 14:23:58.065684 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:23:58.065702 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-13 14:23:58.065699035 +0000 UTC m=+435.028368904 I0513 14:23:58.065920 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-13 14:23:58.065916959 +0000 UTC m=+435.028586828 I0513 14:23:58.066044 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:23:58.066057 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-13 14:23:58.066055241 +0000 UTC m=+435.028725110 I0513 14:23:58.074468 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.082314 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:23:58.082891 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-13 14:23:58.082884043 +0000 UTC m=+435.045553912 I0513 14:23:58.096151 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.097169 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-13 14:23:58.097140096 +0000 UTC m=+435.059809965 I0513 14:23:58.097655 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.098506 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-13 14:23:58.098501358 +0000 UTC m=+435.061171227 I0513 14:23:58.262299 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-8dtp8" condition "Approved" to 2026-05-13 14:23:58.262291127 +0000 UTC m=+435.224960996 I0513 14:23:58.291269 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-8dtp8" condition "Ready" to 2026-05-13 14:23:58.291243721 +0000 UTC m=+435.253913580 I0513 14:23:58.317848 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.324630 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:58.324620132 +0000 UTC m=+435.287290001 I0513 14:23:58.346335 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.355145 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-jp9vj" condition "Approved" to 2026-05-13 14:23:58.355130859 +0000 UTC m=+435.317800728 I0513 14:23:58.388885 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-jp9vj" condition "Ready" to 2026-05-13 14:23:58.388873016 +0000 UTC m=+435.351542895 I0513 14:23:58.417259 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.528761 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:58.528740681 +0000 UTC m=+435.491410550 I0513 14:23:58.642445 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-mtcmp" condition "Approved" to 2026-05-13 14:23:58.642431218 +0000 UTC m=+435.605101087 I0513 14:23:58.725202 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:58.834460 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-mtcmp" condition "Ready" to 2026-05-13 14:23:58.83444578 +0000 UTC m=+435.797115659 I0513 14:23:59.428445 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:59.428430476 +0000 UTC m=+436.391100355 I0513 14:23:59.631531 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:59.632049 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:23:59.63204176 +0000 UTC m=+436.594711639 I0513 14:23:59.931491 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:23:59.978797 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:05.810285 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:24:05.810331 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" condition "Issuing" to 2026-05-13 14:24:05.810319322 +0000 UTC m=+442.772989221 I0513 14:24:05.811233 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" condition "Ready" to 2026-05-13 14:24:05.811215615 +0000 UTC m=+442.773885524 I0513 14:24:05.833490 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:05.833648 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" condition "Ready" to 2026-05-13 14:24:05.833571139 +0000 UTC m=+442.796241018 I0513 14:24:06.111578 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:06.139799 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-rw2sm-8kmht" condition "Approved" to 2026-05-13 14:24:06.139784741 +0000 UTC m=+443.102454620 I0513 14:24:06.167228 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-rw2sm-8kmht" condition "Ready" to 2026-05-13 14:24:06.167209032 +0000 UTC m=+443.129878911 I0513 14:24:06.201718 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:24:06.201700111 +0000 UTC m=+443.164369970 I0513 14:24:06.220532 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:06.278792 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-rw2sm-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:18.491563 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-13 14:24:18.491541793 +0000 UTC m=+455.454211662 I0513 14:24:18.491964 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:24:18.491999 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-13 14:24:18.491996129 +0000 UTC m=+455.454665998 I0513 14:24:18.505331 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:18.505403 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-13 14:24:18.50539712 +0000 UTC m=+455.468066989 I0513 14:24:18.754768 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:24:18.781568 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-5w8jt" condition "Approved" to 2026-05-13 14:24:18.781556112 +0000 UTC m=+455.744225981 I0513 14:24:18.799549 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-5w8jt" condition "Ready" to 2026-05-13 14:24:18.799538901 +0000 UTC m=+455.762208770 I0513 14:24:18.828439 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:24:18.828420032 +0000 UTC m=+455.791089941 I0513 14:24:18.849061 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.027350 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-13 14:27:38.027331898 +0000 UTC m=+654.990001777 I0513 14:27:38.027857 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:27:38.028020 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-13 14:27:38.027901765 +0000 UTC m=+654.990571674 I0513 14:27:38.058624 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.058713 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-13 14:27:38.058704605 +0000 UTC m=+655.021374474 I0513 14:27:38.122767 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.158650 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-hprht" condition "Approved" to 2026-05-13 14:27:38.158635402 +0000 UTC m=+655.121305311 I0513 14:27:38.179389 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-hprht" condition "Ready" to 2026-05-13 14:27:38.179373294 +0000 UTC m=+655.142043173 I0513 14:27:38.210636 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:27:38.21061833 +0000 UTC m=+655.173288209 I0513 14:27:38.235136 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.235717 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:27:38.235708743 +0000 UTC m=+655.198378622 I0513 14:27:38.242935 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.255093 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:27:38.255406 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:27:38.255398933 +0000 UTC m=+655.218068812 I0513 14:27:38.257324 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:29:02.392045 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0513 14:29:02.392101 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-13 14:29:02.392094754 +0000 UTC m=+739.354764633 I0513 14:29:02.392550 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-13 14:29:02.392545289 +0000 UTC m=+739.355215168 I0513 14:29:02.407431 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:29:02.407519 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-13 14:29:02.407510888 +0000 UTC m=+739.370180767 I0513 14:29:02.499227 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:29:02.534680 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-b9txb" condition "Approved" to 2026-05-13 14:29:02.534672121 +0000 UTC m=+739.497341990 I0513 14:29:02.552896 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-b9txb" condition "Ready" to 2026-05-13 14:29:02.552886915 +0000 UTC m=+739.515556784 I0513 14:29:02.588351 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:29:02.588337445 +0000 UTC m=+739.551007314 I0513 14:29:02.612054 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0513 14:29:02.613341 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-13 14:29:02.613327947 +0000 UTC m=+739.575997826 I0513 14:29:02.634757 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"