I0505 17:02:16.895287 1 start.go:75] "cert-manager: starting controller" version="v1.12.10" git-commit="4131d77fe377e78a6fa562af6bdbd31532ddb1ad" I0505 17:02:16.895434 1 controller.go:262] "cert-manager/controller/build-context: configured acme dns01 nameservers" nameservers=["10.96.0.10:53"] W0505 17:02:16.895535 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0505 17:02:16.902389 1 controller.go:82] "cert-manager/controller: enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0505 17:02:16.903037 1 controller.go:156] "cert-manager/controller: starting leader election" I0505 17:02:16.903174 1 controller.go:103] "cert-manager/controller: starting metrics server" address="[::]:9402" I0505 17:02:16.903203 1 controller.go:149] "cert-manager/controller: starting healthz server" address="[::]:9403" I0505 17:02:16.905858 1 leaderelection.go:245] attempting to acquire leader lease cert-manager/cert-manager-controller... I0505 17:02:16.927801 1 leaderelection.go:255] successfully acquired lease cert-manager/cert-manager-controller I0505 17:02:16.932054 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-ca" I0505 17:02:16.932094 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-selfsigned" I0505 17:02:16.932141 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-selfsigned" I0505 17:02:16.935967 1 controller.go:226] "cert-manager/controller: starting controller" controller="ingress-shim" I0505 17:02:16.938694 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-issuing" I0505 17:02:16.943575 1 controller.go:226] "cert-manager/controller: starting controller" controller="clusterissuers" I0505 17:02:16.945888 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-trigger" I0505 17:02:16.948223 1 controller.go:226] "cert-manager/controller: starting controller" controller="orders" I0505 17:02:16.950477 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-venafi" I0505 17:02:16.950683 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-acme" I0505 17:02:16.953119 1 controller.go:226] "cert-manager/controller: starting controller" controller="issuers" I0505 17:02:16.955422 1 controller.go:226] "cert-manager/controller: starting controller" controller="challenges" I0505 17:02:16.958271 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-metrics" I0505 17:02:16.963358 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-readiness" I0505 17:02:16.967090 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-key-manager" I0505 17:02:16.969540 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-request-manager" I0505 17:02:16.971886 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-revision-manager" I0505 17:02:16.974477 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-ca" I0505 17:02:16.976822 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-vault" I0505 17:02:16.979251 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="gateway-shim" I0505 17:02:16.979329 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-venafi" I0505 17:02:16.981106 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-acme" I0505 17:02:16.981124 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-vault" I0505 17:02:16.981275 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-approver" I0505 17:02:36.289502 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-05 17:02:36.289473889 +0000 UTC m=+19.423568996 I0505 17:02:36.969608 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 17:02:36.969593149 +0000 UTC m=+20.103688266 I0505 17:02:36.969667 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:02:36.969715 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-05 17:02:36.969707931 +0000 UTC m=+20.103803038 E0505 17:02:36.984070 1 setup.go:48] "cert-manager/clusterissuers/setup: error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 17:02:36.984117 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-05 17:02:36.984109313 +0000 UTC m=+20.118204400 E0505 17:02:36.984174 1 sync.go:62] "cert-manager/clusterissuers: error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 17:02:36.986493 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:02:36.986590 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 17:02:36.986578395 +0000 UTC m=+20.120673522 E0505 17:02:36.993168 1 controller.go:167] "cert-manager/clusterissuers: re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" key="atmosphere" E0505 17:02:36.993279 1 setup.go:48] "cert-manager/clusterissuers/setup: error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 17:02:36.993320 1 sync.go:62] "cert-manager/clusterissuers: error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 17:02:36.993360 1 controller.go:167] "cert-manager/clusterissuers: re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" key="atmosphere" I0505 17:02:37.002740 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:02:37.023759 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-c7csv" condition "Approved" to 2026-05-05 17:02:37.023741699 +0000 UTC m=+20.157836786 I0505 17:02:37.034553 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-c7csv" condition "Ready" to 2026-05-05 17:02:37.034543323 +0000 UTC m=+20.168638410 I0505 17:02:37.055460 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:02:37.055440544 +0000 UTC m=+20.189535661 I0505 17:02:37.071201 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:02:37.071398 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:02:37.071391099 +0000 UTC m=+20.205486176 I0505 17:02:37.088152 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:02:41.994329 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:02:41.994308672 +0000 UTC m=+25.128403789 I0505 17:03:04.845061 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 17:03:04.845013371 +0000 UTC m=+47.979108458 I0505 17:03:04.845159 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:03:04.845202 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 17:03:04.845192495 +0000 UTC m=+47.979287582 I0505 17:03:04.863208 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-05 17:03:04.863188568 +0000 UTC m=+47.997283675 I0505 17:03:04.866910 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:03:04.867006 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 17:03:04.866996473 +0000 UTC m=+48.001091590 I0505 17:03:05.030096 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:03:05.066333 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2gxlt" condition "Approved" to 2026-05-05 17:03:05.066323709 +0000 UTC m=+48.200418796 I0505 17:03:05.098146 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2gxlt" condition "Ready" to 2026-05-05 17:03:05.098134741 +0000 UTC m=+48.232229818 I0505 17:03:05.133031 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:03:05.133014533 +0000 UTC m=+48.267109640 I0505 17:03:05.155439 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:03:05.208982 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:05:44.185181 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-140.nip.io-tls" condition "Ready" to 2026-05-05 17:05:44.185126873 +0000 UTC m=+207.319221990 I0505 17:05:44.185275 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="auth-system/keycloak.199-19-213-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:05:44.185310 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-140.nip.io-tls" condition "Issuing" to 2026-05-05 17:05:44.185301337 +0000 UTC m=+207.319396454 I0505 17:05:44.206236 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="auth-system/keycloak.199-19-213-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:05:44.206292 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="auth-system/keycloak.199-19-213-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:05:44.206305 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-140.nip.io-tls" condition "Issuing" to 2026-05-05 17:05:44.206299839 +0000 UTC m=+207.340394916 I0505 17:05:44.536056 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-140.nip.io-tls-ndbvf" condition "Approved" to 2026-05-05 17:05:44.536038059 +0000 UTC m=+207.670133166 I0505 17:05:44.564296 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-140.nip.io-tls-ndbvf" condition "Ready" to 2026-05-05 17:05:44.564278343 +0000 UTC m=+207.698373450 I0505 17:05:44.597263 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-140.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:05:44.597252431 +0000 UTC m=+207.731347578 I0505 17:05:44.615051 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="auth-system/keycloak.199-19-213-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:05:44.615475 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-140.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:05:44.615469069 +0000 UTC m=+207.749564146 I0505 17:05:44.626242 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="auth-system/keycloak.199-19-213-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:05:44.632278 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="auth-system/keycloak.199-19-213-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:45.870776 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:06:45.870829 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-05 17:06:45.870823853 +0000 UTC m=+269.004918930 I0505 17:06:45.871248 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 17:06:45.871244202 +0000 UTC m=+269.005339279 E0505 17:06:45.899918 1 setup.go:48] "cert-manager/clusterissuers/setup: error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 17:06:45.899974 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-05 17:06:45.899969133 +0000 UTC m=+269.034064210 E0505 17:06:45.899991 1 sync.go:62] "cert-manager/clusterissuers: error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 17:06:45.903435 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:45.903492 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 17:06:45.903485172 +0000 UTC m=+269.037580249 E0505 17:06:45.913943 1 controller.go:167] "cert-manager/clusterissuers: re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" key="kube-prometheus-stack" E0505 17:06:45.914033 1 setup.go:48] "cert-manager/clusterissuers/setup: error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 17:06:45.914075 1 sync.go:62] "cert-manager/clusterissuers: error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 17:06:45.914153 1 controller.go:167] "cert-manager/clusterissuers: re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" key="kube-prometheus-stack" I0505 17:06:45.915527 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:45.915820 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:45.915889 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 17:06:45.915880497 +0000 UTC m=+269.049975594 I0505 17:06:45.919874 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-t7jvn" condition "Approved" to 2026-05-05 17:06:45.919857007 +0000 UTC m=+269.053952124 I0505 17:06:45.938149 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 17:06:45.938132013 +0000 UTC m=+269.072227130 I0505 17:06:45.940712 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-t7jvn" condition "Ready" to 2026-05-05 17:06:45.940698651 +0000 UTC m=+269.074793768 I0505 17:06:45.947670 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:46.031266 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:06:46.031242889 +0000 UTC m=+269.165337996 I0505 17:06:46.046217 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:46.046801 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:06:46.046790746 +0000 UTC m=+269.180885833 I0505 17:06:46.070750 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:06:50.915168 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:06:50.915153895 +0000 UTC m=+274.049249002 I0505 17:07:29.614995 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.615036 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-05 17:07:29.61503032 +0000 UTC m=+312.749125397 I0505 17:07:29.615278 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-05 17:07:29.615273656 +0000 UTC m=+312.749368733 I0505 17:07:29.615508 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.615521 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-05 17:07:29.615518722 +0000 UTC m=+312.749613799 I0505 17:07:29.615625 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-05 17:07:29.615622654 +0000 UTC m=+312.749717731 I0505 17:07:29.615761 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-05 17:07:29.615758737 +0000 UTC m=+312.749853804 I0505 17:07:29.615898 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.615910 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-05 17:07:29.61590799 +0000 UTC m=+312.750003067 I0505 17:07:29.677581 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:29.677637 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.677653 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-05 17:07:29.677646931 +0000 UTC m=+312.811742018 I0505 17:07:29.680123 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:29.680170 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.680193 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-05 17:07:29.680187908 +0000 UTC m=+312.814282995 I0505 17:07:29.681571 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:29.681729 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:29.681763 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-05 17:07:29.681757193 +0000 UTC m=+312.815852270 I0505 17:07:29.885744 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:29.900848 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-x9wv8" condition "Approved" to 2026-05-05 17:07:29.900823363 +0000 UTC m=+313.034918470 I0505 17:07:29.928382 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-x9wv8" condition "Ready" to 2026-05-05 17:07:29.928365679 +0000 UTC m=+313.062460766 I0505 17:07:29.951316 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:29.961794 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-cjzb9" condition "Approved" to 2026-05-05 17:07:29.961763596 +0000 UTC m=+313.095858713 I0505 17:07:29.962314 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-25r66" condition "Approved" to 2026-05-05 17:07:29.962284607 +0000 UTC m=+313.096379694 I0505 17:07:29.979803 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:29.97978694 +0000 UTC m=+313.113882027 I0505 17:07:29.991263 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-25r66" condition "Ready" to 2026-05-05 17:07:29.991251786 +0000 UTC m=+313.125346863 I0505 17:07:29.992776 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-cjzb9" condition "Ready" to 2026-05-05 17:07:29.99276645 +0000 UTC m=+313.126861537 I0505 17:07:30.010424 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:30.011527 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:30.011512479 +0000 UTC m=+313.145607596 I0505 17:07:30.546252 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:30.54623575 +0000 UTC m=+313.680330857 I0505 17:07:30.662451 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:30.662418678 +0000 UTC m=+313.796513745 I0505 17:07:30.688070 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:30.784458 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:30.848896 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:30.849519 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:30.849511574 +0000 UTC m=+313.983606651 I0505 17:07:30.940493 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:30.941280 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:30.941268027 +0000 UTC m=+314.075363144 I0505 17:07:31.341431 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:31.461485 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:31.487085 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:31.540771 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:41.480103 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:07:41.480096 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Ready" to 2026-05-05 17:07:41.480064033 +0000 UTC m=+324.614159140 I0505 17:07:41.480139 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Issuing" to 2026-05-05 17:07:41.480130894 +0000 UTC m=+324.614225991 I0505 17:07:41.497729 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:41.497808 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Ready" to 2026-05-05 17:07:41.497799439 +0000 UTC m=+324.631894526 I0505 17:07:42.188681 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:42.327411 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-jwjk2-fs4j4" condition "Approved" to 2026-05-05 17:07:42.327396446 +0000 UTC m=+325.461491543 I0505 17:07:42.370599 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-jwjk2-fs4j4" condition "Ready" to 2026-05-05 17:07:42.370580503 +0000 UTC m=+325.504675610 I0505 17:07:42.415582 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:42.415562089 +0000 UTC m=+325.549657206 I0505 17:07:42.482198 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:42.482994 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:42.482984537 +0000 UTC m=+325.617079624 I0505 17:07:42.504990 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:07:42.504970779 +0000 UTC m=+325.639065866 I0505 17:07:42.653353 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:07:42.658347 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jwjk2-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:08:12.054299 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-05 17:08:12.054273061 +0000 UTC m=+355.188368178 I0505 17:08:12.054327 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:08:12.054368 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-05 17:08:12.054357873 +0000 UTC m=+355.188452980 I0505 17:08:12.072231 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:08:12.072354 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-05 17:08:12.072342124 +0000 UTC m=+355.206437231 I0505 17:08:12.358810 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:08:12.392540 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-jgvqh" condition "Approved" to 2026-05-05 17:08:12.392520207 +0000 UTC m=+355.526615284 I0505 17:08:12.413670 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-jgvqh" condition "Ready" to 2026-05-05 17:08:12.413658719 +0000 UTC m=+355.547753786 I0505 17:08:12.444277 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:08:12.444258984 +0000 UTC m=+355.578354071 I0505 17:08:12.962787 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:08:12.963290 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:08:12.963284693 +0000 UTC m=+356.097379770 I0505 17:08:12.993930 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:11:21.240997 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:11:21.241038 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 17:11:21.241030675 +0000 UTC m=+544.375125792 I0505 17:11:21.240963 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-05 17:11:21.240912452 +0000 UTC m=+544.375007559 I0505 17:11:21.255959 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:11:21.256192 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:11:21.256303 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 17:11:21.256225016 +0000 UTC m=+544.390320133 I0505 17:11:21.574770 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-q2f9f" condition "Approved" to 2026-05-05 17:11:21.574749834 +0000 UTC m=+544.708844951 I0505 17:11:21.592804 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-q2f9f" condition "Ready" to 2026-05-05 17:11:21.592790478 +0000 UTC m=+544.726885585 I0505 17:11:21.619977 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:11:21.619960958 +0000 UTC m=+544.754056065 I0505 17:11:21.632951 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:11:21.633662 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:11:21.633653776 +0000 UTC m=+544.767748893 I0505 17:11:21.643820 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:11:21.650493 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:13:45.568329 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-05-05 17:13:45.568262476 +0000 UTC m=+688.702357563 I0505 17:13:45.568786 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:13:45.568973 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-05-05 17:13:45.568956891 +0000 UTC m=+688.703052008 I0505 17:13:45.587199 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:13:45.587279 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-05-05 17:13:45.587271412 +0000 UTC m=+688.721366499 I0505 17:13:45.830799 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:13:45.866078 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-ht6x7" condition "Approved" to 2026-05-05 17:13:45.866052269 +0000 UTC m=+689.000147386 I0505 17:13:45.883424 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-ht6x7" condition "Ready" to 2026-05-05 17:13:45.883414139 +0000 UTC m=+689.017509226 I0505 17:13:45.915589 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:13:45.915580413 +0000 UTC m=+689.049675500 I0505 17:13:45.937831 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:13:45.938654 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:13:45.93864159 +0000 UTC m=+689.072736697 I0505 17:13:45.953654 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:13:45.954205 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:13:45.95419556 +0000 UTC m=+689.088290647 I0505 17:14:57.529585 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-05-05 17:14:57.529530757 +0000 UTC m=+760.663625864 I0505 17:14:57.529654 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:14:57.529678 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-05-05 17:14:57.52967323 +0000 UTC m=+760.663768317 I0505 17:14:57.547418 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:14:57.547545 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:14:57.547600 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-05-05 17:14:57.547591924 +0000 UTC m=+760.681687031 I0505 17:14:57.728531 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:14:57.734405 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-2ttfc" condition "Approved" to 2026-05-05 17:14:57.734379425 +0000 UTC m=+760.868474542 I0505 17:14:57.752662 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-2ttfc" condition "Ready" to 2026-05-05 17:14:57.752653776 +0000 UTC m=+760.886748863 I0505 17:14:57.790622 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:14:57.790612552 +0000 UTC m=+760.924707639 I0505 17:14:57.810641 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:18:03.015448 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-05-05 17:18:03.015411568 +0000 UTC m=+946.149506675 I0505 17:18:03.015593 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:18:03.015677 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-05-05 17:18:03.015666694 +0000 UTC m=+946.149761801 I0505 17:18:03.034269 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:18:03.034369 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-05-05 17:18:03.03435966 +0000 UTC m=+946.168454737 I0505 17:18:03.196729 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:18:03.247604 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-vjjm7" condition "Approved" to 2026-05-05 17:18:03.247581468 +0000 UTC m=+946.381676575 I0505 17:18:03.268277 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-vjjm7" condition "Ready" to 2026-05-05 17:18:03.268260139 +0000 UTC m=+946.402355226 I0505 17:18:03.302049 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:18:03.302033558 +0000 UTC m=+946.436128645 I0505 17:18:03.323245 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:18:03.324063 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:18:03.32405125 +0000 UTC m=+946.458146337 I0505 17:18:03.342953 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:18:03.343299 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:24:10.389992 1 conditions.go:203] Setting lastTransitionTime for Certificate "cinder-api-certs" condition "Ready" to 2026-05-05 17:24:10.389930476 +0000 UTC m=+1313.524025563 I0505 17:24:10.390173 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/cinder-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:24:10.390298 1 conditions.go:203] Setting lastTransitionTime for Certificate "cinder-api-certs" condition "Issuing" to 2026-05-05 17:24:10.390284214 +0000 UTC m=+1313.524379321 I0505 17:24:10.407591 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/cinder-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"cinder-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:24:10.407708 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/cinder-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:24:10.407747 1 conditions.go:203] Setting lastTransitionTime for Certificate "cinder-api-certs" condition "Issuing" to 2026-05-05 17:24:10.407738297 +0000 UTC m=+1313.541833384 I0505 17:24:10.692145 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/cinder-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"cinder-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:24:10.717675 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "cinder-api-certs-2gfkd" condition "Approved" to 2026-05-05 17:24:10.717659192 +0000 UTC m=+1313.851754279 I0505 17:24:10.757116 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "cinder-api-certs-2gfkd" condition "Ready" to 2026-05-05 17:24:10.757099599 +0000 UTC m=+1313.891194686 I0505 17:24:10.789109 1 conditions.go:192] Found status change for Certificate "cinder-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:24:10.789087829 +0000 UTC m=+1313.923182926 I0505 17:24:10.817024 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/cinder-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"cinder-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:24:10.817614 1 conditions.go:192] Found status change for Certificate "cinder-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:24:10.817606201 +0000 UTC m=+1313.951701288 I0505 17:24:10.836597 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/cinder-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"cinder-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:24:10.837096 1 conditions.go:192] Found status change for Certificate "cinder-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:24:10.83708862 +0000 UTC m=+1313.971183707 I0505 17:25:40.240155 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/placement-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:25:40.240610 1 conditions.go:203] Setting lastTransitionTime for Certificate "placement-api-certs" condition "Issuing" to 2026-05-05 17:25:40.240598623 +0000 UTC m=+1403.374693710 I0505 17:25:40.240338 1 conditions.go:203] Setting lastTransitionTime for Certificate "placement-api-certs" condition "Ready" to 2026-05-05 17:25:40.240320707 +0000 UTC m=+1403.374415824 I0505 17:25:40.258975 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/placement-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"placement-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:25:40.259210 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/placement-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:25:40.259312 1 conditions.go:203] Setting lastTransitionTime for Certificate "placement-api-certs" condition "Issuing" to 2026-05-05 17:25:40.259302173 +0000 UTC m=+1403.393397290 I0505 17:25:40.557661 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/placement-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"placement-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:25:40.562326 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "placement-api-certs-ndqxg" condition "Approved" to 2026-05-05 17:25:40.562307203 +0000 UTC m=+1403.696402280 I0505 17:25:40.584360 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "placement-api-certs-ndqxg" condition "Ready" to 2026-05-05 17:25:40.584349508 +0000 UTC m=+1403.718444586 I0505 17:25:40.612034 1 conditions.go:192] Found status change for Certificate "placement-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:25:40.612014611 +0000 UTC m=+1403.746109728 I0505 17:25:40.630165 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/placement-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"placement-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:25:40.630968 1 conditions.go:192] Found status change for Certificate "placement-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:25:40.630957968 +0000 UTC m=+1403.765053085 I0505 17:25:40.655651 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/placement-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"placement-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:39.781555 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-vnc-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:26:39.781586 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Issuing" to 2026-05-05 17:26:39.781578645 +0000 UTC m=+1462.915673732 I0505 17:26:39.781750 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-05 17:26:39.781724728 +0000 UTC m=+1462.915819835 I0505 17:26:39.796061 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:39.796165 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-vnc-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:26:39.796195 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Issuing" to 2026-05-05 17:26:39.796184134 +0000 UTC m=+1462.930279221 I0505 17:26:39.862065 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:39.876096 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-8lv6h" condition "Approved" to 2026-05-05 17:26:39.876080042 +0000 UTC m=+1463.010175119 I0505 17:26:39.900358 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-8lv6h" condition "Ready" to 2026-05-05 17:26:39.900344378 +0000 UTC m=+1463.034439465 I0505 17:26:39.938752 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:26:39.938727692 +0000 UTC m=+1463.072822769 I0505 17:26:39.962809 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:39.963291 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:26:39.963276104 +0000 UTC m=+1463.097371211 I0505 17:26:39.986282 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:40.488392 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:26:40.488630 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Ready" to 2026-05-05 17:26:40.488402102 +0000 UTC m=+1463.622497189 I0505 17:26:40.488430 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-05-05 17:26:40.488422933 +0000 UTC m=+1463.622518030 I0505 17:26:40.536753 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:40.536868 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:26:40.536884 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-05-05 17:26:40.536879344 +0000 UTC m=+1463.670974421 I0505 17:26:40.604375 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-zc5t6" condition "Approved" to 2026-05-05 17:26:40.604362112 +0000 UTC m=+1463.738457189 I0505 17:26:40.622941 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-zc5t6" condition "Ready" to 2026-05-05 17:26:40.622920759 +0000 UTC m=+1463.757015846 I0505 17:26:40.660306 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:26:40.660287021 +0000 UTC m=+1463.794382138 I0505 17:26:40.681485 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:40.681881 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:26:40.681862636 +0000 UTC m=+1463.815957723 I0505 17:26:40.701053 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:26:41.240451 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-vnc" condition "Ready" to 2026-05-05 17:26:41.240431988 +0000 UTC m=+1464.374527075 I0505 17:26:41.918180 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-api" condition "Ready" to 2026-05-05 17:26:41.91815784 +0000 UTC m=+1465.052252947 I0505 17:27:28.527620 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-vencrypt" condition "Ready" to 2026-05-05 17:27:28.527605911 +0000 UTC m=+1511.661700988 I0505 17:27:28.528085 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/nova-novncproxy-vencrypt" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:27:28.528104 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-vencrypt" condition "Issuing" to 2026-05-05 17:27:28.528100732 +0000 UTC m=+1511.662195799 I0505 17:27:28.566572 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-vencrypt" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-vencrypt\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:27:28.566725 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-vencrypt" condition "Ready" to 2026-05-05 17:27:28.566716581 +0000 UTC m=+1511.700811668 I0505 17:27:31.228716 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-vencrypt" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-vencrypt\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:27:31.268881 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-novncproxy-vencrypt-xbjgs" condition "Approved" to 2026-05-05 17:27:31.268866544 +0000 UTC m=+1514.402961621 I0505 17:27:31.289273 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-novncproxy-vencrypt-xbjgs" condition "Ready" to 2026-05-05 17:27:31.289259493 +0000 UTC m=+1514.423354580 I0505 17:27:31.319328 1 conditions.go:192] Found status change for Certificate "nova-novncproxy-vencrypt" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:27:31.319314349 +0000 UTC m=+1514.453409436 I0505 17:27:31.340215 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-vencrypt" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-vencrypt\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:27:31.397372 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-vencrypt" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-vencrypt\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:25.665656 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/nova-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:30:25.665715 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-api-certs" condition "Issuing" to 2026-05-05 17:30:25.665702376 +0000 UTC m=+1688.799797483 I0505 17:30:25.666106 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-api-certs" condition "Ready" to 2026-05-05 17:30:25.666068774 +0000 UTC m=+1688.800163911 I0505 17:30:25.687570 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/nova-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:25.687718 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/nova-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:30:25.687750 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-api-certs" condition "Issuing" to 2026-05-05 17:30:25.687741273 +0000 UTC m=+1688.821836360 I0505 17:30:26.014453 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/nova-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:26.014896 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-api-certs-lv5bg" condition "Approved" to 2026-05-05 17:30:26.014885499 +0000 UTC m=+1689.148980586 I0505 17:30:26.040458 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-api-certs-lv5bg" condition "Ready" to 2026-05-05 17:30:26.040440455 +0000 UTC m=+1689.174535572 I0505 17:30:26.075903 1 conditions.go:192] Found status change for Certificate "nova-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:30:26.075841862 +0000 UTC m=+1689.209936939 I0505 17:30:26.104299 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/nova-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:26.104669 1 conditions.go:192] Found status change for Certificate "nova-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:30:26.104663711 +0000 UTC m=+1689.238758778 I0505 17:30:26.127147 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/nova-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:26.136231 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/nova-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:27.368764 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/nova-novncproxy-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:30:27.368800 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-certs" condition "Ready" to 2026-05-05 17:30:27.368780455 +0000 UTC m=+1690.502875542 I0505 17:30:27.368824 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-certs" condition "Issuing" to 2026-05-05 17:30:27.368808286 +0000 UTC m=+1690.502903373 I0505 17:30:27.577047 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:27.577446 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/nova-novncproxy-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:30:27.577475 1 conditions.go:203] Setting lastTransitionTime for Certificate "nova-novncproxy-certs" condition "Issuing" to 2026-05-05 17:30:27.577468305 +0000 UTC m=+1690.711563392 I0505 17:30:27.996937 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-novncproxy-certs-vl5tr" condition "Approved" to 2026-05-05 17:30:27.9969201 +0000 UTC m=+1691.131015177 I0505 17:30:28.020926 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "nova-novncproxy-certs-vl5tr" condition "Ready" to 2026-05-05 17:30:28.020911779 +0000 UTC m=+1691.155006866 I0505 17:30:28.059836 1 conditions.go:192] Found status change for Certificate "nova-novncproxy-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:30:28.059817766 +0000 UTC m=+1691.193912853 I0505 17:30:28.087670 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:28.088213 1 conditions.go:192] Found status change for Certificate "nova-novncproxy-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:30:28.088203045 +0000 UTC m=+1691.222298142 I0505 17:30:28.101428 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:30:28.101928 1 conditions.go:192] Found status change for Certificate "nova-novncproxy-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:30:28.101918944 +0000 UTC m=+1691.236014031 I0505 17:30:28.105134 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/nova-novncproxy-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"nova-novncproxy-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:10.778914 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-libvirt-default-wfdmt-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:35:10.778942 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-vnc" condition "Issuing" to 2026-05-05 17:35:10.77893532 +0000 UTC m=+1973.913030397 I0505 17:35:10.779338 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-vnc" condition "Ready" to 2026-05-05 17:35:10.779333719 +0000 UTC m=+1973.913428786 I0505 17:35:10.780281 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-libvirt-default-wfdmt-api" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:35:10.780337 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-api" condition "Issuing" to 2026-05-05 17:35:10.780329431 +0000 UTC m=+1973.914424508 I0505 17:35:10.780392 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-api" condition "Ready" to 2026-05-05 17:35:10.780385092 +0000 UTC m=+1973.914480169 I0505 17:35:10.806813 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:10.806901 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-libvirt-default-wfdmt-vnc" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:35:10.806935 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-vnc" condition "Issuing" to 2026-05-05 17:35:10.806914751 +0000 UTC m=+1973.941009838 I0505 17:35:10.807356 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-api\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:10.807392 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/libvirt-libvirt-default-wfdmt-api" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:35:10.807403 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-libvirt-default-wfdmt-api" condition "Issuing" to 2026-05-05 17:35:10.807399362 +0000 UTC m=+1973.941494449 I0505 17:35:11.019692 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-wfdmt-vnc-f8xph" condition "Approved" to 2026-05-05 17:35:11.019671583 +0000 UTC m=+1974.153766670 I0505 17:35:11.043866 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-wfdmt-vnc-f8xph" condition "Ready" to 2026-05-05 17:35:11.043851448 +0000 UTC m=+1974.177946535 I0505 17:35:11.076277 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-wfdmt-vnc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:35:11.07625535 +0000 UTC m=+1974.210350467 I0505 17:35:11.097054 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:11.098276 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-wfdmt-vnc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:35:11.098258427 +0000 UTC m=+1974.232353554 I0505 17:35:11.104035 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:11.128797 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-vnc" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-vnc\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:11.210531 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-api\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:11.221800 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-wfdmt-api-dkgvx" condition "Approved" to 2026-05-05 17:35:11.221777004 +0000 UTC m=+1974.355872091 I0505 17:35:11.238632 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-libvirt-default-wfdmt-api-dkgvx" condition "Ready" to 2026-05-05 17:35:11.238617924 +0000 UTC m=+1974.372713021 I0505 17:35:11.271695 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-wfdmt-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:35:11.27167561 +0000 UTC m=+1974.405770697 I0505 17:35:11.289451 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-api\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:35:11.290050 1 conditions.go:192] Found status change for Certificate "libvirt-libvirt-default-wfdmt-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:35:11.290040504 +0000 UTC m=+1974.424135591 I0505 17:35:11.321459 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/libvirt-libvirt-default-wfdmt-api" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-libvirt-default-wfdmt-api\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:36:23.457521 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/neutron-server-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:36:23.457575 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Issuing" to 2026-05-05 17:36:23.457563136 +0000 UTC m=+2046.591658253 I0505 17:36:23.457817 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Ready" to 2026-05-05 17:36:23.457803651 +0000 UTC m=+2046.591898748 I0505 17:36:23.592031 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:36:23.592184 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/neutron-server-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:36:23.592219 1 conditions.go:203] Setting lastTransitionTime for Certificate "neutron-server-certs" condition "Issuing" to 2026-05-05 17:36:23.592209921 +0000 UTC m=+2046.726305038 I0505 17:36:23.908381 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:36:23.909368 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "neutron-server-certs-55x7l" condition "Approved" to 2026-05-05 17:36:23.90935364 +0000 UTC m=+2047.043448737 I0505 17:36:23.929059 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "neutron-server-certs-55x7l" condition "Ready" to 2026-05-05 17:36:23.929044024 +0000 UTC m=+2047.063139131 I0505 17:36:24.048047 1 conditions.go:192] Found status change for Certificate "neutron-server-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:36:24.048030426 +0000 UTC m=+2047.182125513 I0505 17:36:24.089837 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/neutron-server-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"neutron-server-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:39:09.207744 1 conditions.go:203] Setting lastTransitionTime for Certificate "senlin-api-certs" condition "Ready" to 2026-05-05 17:39:09.207704734 +0000 UTC m=+2212.341799831 I0505 17:39:09.207764 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/senlin-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:39:09.208225 1 conditions.go:203] Setting lastTransitionTime for Certificate "senlin-api-certs" condition "Issuing" to 2026-05-05 17:39:09.208212556 +0000 UTC m=+2212.342307633 I0505 17:39:09.237196 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/senlin-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"senlin-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:39:09.237480 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/senlin-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:39:09.237576 1 conditions.go:203] Setting lastTransitionTime for Certificate "senlin-api-certs" condition "Issuing" to 2026-05-05 17:39:09.237562178 +0000 UTC m=+2212.371657285 I0505 17:39:09.377778 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/senlin-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"senlin-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:39:09.386054 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "senlin-api-certs-9dbxp" condition "Approved" to 2026-05-05 17:39:09.386041915 +0000 UTC m=+2212.520137022 I0505 17:39:09.408244 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "senlin-api-certs-9dbxp" condition "Ready" to 2026-05-05 17:39:09.408222125 +0000 UTC m=+2212.542317222 I0505 17:39:09.444787 1 conditions.go:192] Found status change for Certificate "senlin-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:39:09.444776749 +0000 UTC m=+2212.578871826 I0505 17:39:09.474606 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/senlin-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"senlin-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:39:09.475344 1 conditions.go:192] Found status change for Certificate "senlin-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:39:09.475334438 +0000 UTC m=+2212.609429515 I0505 17:39:09.493879 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/senlin-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"senlin-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:39:09.494572 1 conditions.go:192] Found status change for Certificate "senlin-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:39:09.4945598 +0000 UTC m=+2212.628654887 I0505 17:39:09.497665 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/senlin-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"senlin-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:03.796172 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/heat-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:43:03.796227 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Issuing" to 2026-05-05 17:43:03.796219805 +0000 UTC m=+2446.930314892 I0505 17:43:03.796241 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Ready" to 2026-05-05 17:43:03.796226775 +0000 UTC m=+2446.930321892 I0505 17:43:04.046637 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:04.046733 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/heat-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:43:04.046755 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-api-certs" condition "Issuing" to 2026-05-05 17:43:04.046746557 +0000 UTC m=+2447.180841664 I0505 17:43:04.692532 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-api-certs-8898j" condition "Approved" to 2026-05-05 17:43:04.692506016 +0000 UTC m=+2447.826601123 I0505 17:43:04.728200 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-api-certs-8898j" condition "Ready" to 2026-05-05 17:43:04.728183378 +0000 UTC m=+2447.862278455 I0505 17:43:04.925313 1 conditions.go:192] Found status change for Certificate "heat-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:43:04.92529471 +0000 UTC m=+2448.059389797 I0505 17:43:05.134970 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:05.211108 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/heat-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:05.309306 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/heat-cfn-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:43:05.309346 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Issuing" to 2026-05-05 17:43:05.309336085 +0000 UTC m=+2448.443431192 I0505 17:43:05.309836 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Ready" to 2026-05-05 17:43:05.309811105 +0000 UTC m=+2448.443906222 I0505 17:43:05.337189 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:05.337331 1 conditions.go:203] Setting lastTransitionTime for Certificate "heat-cfn-certs" condition "Ready" to 2026-05-05 17:43:05.337314834 +0000 UTC m=+2448.471409951 I0505 17:43:05.696561 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:43:05.762124 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-cfn-certs-xg5s5" condition "Approved" to 2026-05-05 17:43:05.762106854 +0000 UTC m=+2448.896201941 I0505 17:43:05.794960 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "heat-cfn-certs-xg5s5" condition "Ready" to 2026-05-05 17:43:05.794944482 +0000 UTC m=+2448.929039579 I0505 17:43:05.832430 1 conditions.go:192] Found status change for Certificate "heat-cfn-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:43:05.832410974 +0000 UTC m=+2448.966506081 I0505 17:43:05.863159 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/heat-cfn-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"heat-cfn-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:53.009272 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:46:53.009316 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-05-05 17:46:53.009307077 +0000 UTC m=+2676.143402194 I0505 17:46:53.009944 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-05-05 17:46:53.009912592 +0000 UTC m=+2676.144007709 E0505 17:46:53.024358 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0505 17:46:53.024434 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-client" condition "Ready" to 2026-05-05 17:46:53.024426368 +0000 UTC m=+2676.158521445 I0505 17:46:53.024457 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0505 17:46:53.033235 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:53.033328 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-05-05 17:46:53.033319598 +0000 UTC m=+2676.167414675 E0505 17:46:53.038583 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" key="openstack/octavia-client" E0505 17:46:53.038685 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0505 17:46:53.038715 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0505 17:46:53.038752 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" key="openstack/octavia-client" I0505 17:46:53.056373 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:53.089941 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-gc594" condition "Approved" to 2026-05-05 17:46:53.08992207 +0000 UTC m=+2676.224017147 I0505 17:46:53.110349 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-gc594" condition "Ready" to 2026-05-05 17:46:53.110332779 +0000 UTC m=+2676.244427866 I0505 17:46:53.146951 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:53.146933032 +0000 UTC m=+2676.281028109 I0505 17:46:53.176284 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:53.776339 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-05-05 17:46:53.776311906 +0000 UTC m=+2676.910406983 I0505 17:46:53.776513 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:46:53.776568 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-05-05 17:46:53.776549632 +0000 UTC m=+2676.910644749 I0505 17:46:53.909691 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:53.909891 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:46:53.909944 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-05-05 17:46:53.909935702 +0000 UTC m=+2677.044030789 E0505 17:46:54.224494 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0505 17:46:54.224527 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-server" condition "Ready" to 2026-05-05 17:46:54.224521326 +0000 UTC m=+2677.358616403 I0505 17:46:54.224566 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0505 17:46:54.258396 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" key="openstack/octavia-server" E0505 17:46:54.258780 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0505 17:46:54.258912 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0505 17:46:54.259081 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" key="openstack/octavia-server" I0505 17:46:54.317779 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-rll9t" condition "Approved" to 2026-05-05 17:46:54.317759852 +0000 UTC m=+2677.451854969 I0505 17:46:54.342715 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-rll9t" condition "Ready" to 2026-05-05 17:46:54.342696173 +0000 UTC m=+2677.476791280 I0505 17:46:54.455079 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:54.45505479 +0000 UTC m=+2677.589149907 I0505 17:46:54.611219 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:54.686650 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:55.068976 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:46:55.069049 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-05-05 17:46:55.069037598 +0000 UTC m=+2678.203132715 I0505 17:46:55.069350 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-05 17:46:55.069328535 +0000 UTC m=+2678.203423622 I0505 17:46:55.100707 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:55.101017 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-05 17:46:55.101002997 +0000 UTC m=+2678.235098104 I0505 17:46:55.122840 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:55.122927 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-05 17:46:55.12290892 +0000 UTC m=+2678.257004007 I0505 17:46:55.134663 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-zhfxc" condition "Approved" to 2026-05-05 17:46:55.134649464 +0000 UTC m=+2678.268744581 I0505 17:46:55.145692 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-05 17:46:55.145671572 +0000 UTC m=+2678.279766659 I0505 17:46:55.152532 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-zhfxc" condition "Ready" to 2026-05-05 17:46:55.152523935 +0000 UTC m=+2678.286619022 I0505 17:46:55.156607 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:58.039835 1 conditions.go:85] Found status change for Issuer "octavia-client" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:58.039814237 +0000 UTC m=+2681.173909354 I0505 17:46:58.055787 1 conditions.go:252] Found status change for CertificateRequest "octavia-client-certs-zhfxc" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:58.055748426 +0000 UTC m=+2681.189843543 I0505 17:46:58.090683 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:58.090662971 +0000 UTC m=+2681.224758058 I0505 17:46:58.113006 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:58.113251 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:58.113240398 +0000 UTC m=+2681.247335485 I0505 17:46:58.125838 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:58.141298 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:46:59.259911 1 conditions.go:85] Found status change for Issuer "octavia-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:46:59.259891375 +0000 UTC m=+2682.393986482 I0505 17:49:34.943835 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-05 17:49:34.943793267 +0000 UTC m=+2838.077888344 I0505 17:49:34.944190 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:49:34.944288 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-05-05 17:49:34.944275708 +0000 UTC m=+2838.078370815 I0505 17:49:34.963831 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:49:34.964015 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-05 17:49:34.964005572 +0000 UTC m=+2838.098100669 I0505 17:49:35.451687 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:49:35.533807 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-88zjk" condition "Approved" to 2026-05-05 17:49:35.533789628 +0000 UTC m=+2838.667884705 I0505 17:49:35.559195 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-88zjk" condition "Ready" to 2026-05-05 17:49:35.559180269 +0000 UTC m=+2838.693275346 I0505 17:49:35.596748 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:49:35.596738715 +0000 UTC m=+2838.730833792 I0505 17:49:35.625274 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:49:35.626238 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:49:35.626228108 +0000 UTC m=+2838.760323235 I0505 17:49:35.639602 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:49:35.659337 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:24.398215 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-05 17:50:24.398194301 +0000 UTC m=+2887.532289378 I0505 17:50:24.415630 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-05 17:50:24.415599033 +0000 UTC m=+2887.549694150 I0505 17:50:24.415658 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:24.415870 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-05 17:50:24.415833568 +0000 UTC m=+2887.549928675 I0505 17:50:24.447794 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="cert-manager-test/selfsigned-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:24.447947 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:24.447996 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-05 17:50:24.447982341 +0000 UTC m=+2887.582077458 E0505 17:50:24.465918 1 controller.go:134] "cert-manager/issuers: issuer in work queue no longer exists" err="issuer.cert-manager.io \"test-selfsigned\" not found" E0505 17:50:24.466055 1 event.go:280] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18acbcb1bc87f7cf", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"a8c82051-c0cf-47cc-ad71-faa6a3b71d6f", APIVersion:"cert-manager.io/v1", ResourceVersion:"26599", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 5, 17, 50, 24, 462763983, time.Local), LastTimestamp:time.Date(2026, time.May, 5, 17, 50, 24, 462763983, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18acbcb1bc87f7cf" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0505 17:50:24.532678 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-05 17:50:24.532648055 +0000 UTC m=+2887.666743132 I0505 17:50:24.558349 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-system/capi-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:24.558394 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-05 17:50:24.558383945 +0000 UTC m=+2887.692479022 I0505 17:50:24.558534 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-05 17:50:24.558509778 +0000 UTC m=+2887.692604875 I0505 17:50:24.605652 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:24.605788 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-05 17:50:24.60577677 +0000 UTC m=+2887.739871847 E0505 17:50:24.644611 1 controller.go:167] "cert-manager/certificates-key-manager: re-queuing item due to error processing" err="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" key="cert-manager-test/selfsigned-cert" I0505 17:50:25.479040 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:26.136343 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-b7fnr" condition "Approved" to 2026-05-05 17:50:26.136326119 +0000 UTC m=+2889.270421196 I0505 17:50:26.784214 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-b7fnr" condition "Ready" to 2026-05-05 17:50:26.784197882 +0000 UTC m=+2889.918292969 I0505 17:50:27.411614 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:27.411594924 +0000 UTC m=+2890.545690041 I0505 17:50:27.798305 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:27.798719 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:27.798708572 +0000 UTC m=+2890.932803649 I0505 17:50:27.819604 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:27.821529 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:27.821513224 +0000 UTC m=+2890.955608311 I0505 17:50:34.119010 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-05 17:50:34.118987739 +0000 UTC m=+2897.253082856 I0505 17:50:34.151436 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:34.151484 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-05 17:50:34.1514734 +0000 UTC m=+2897.285568517 I0505 17:50:34.152039 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-05 17:50:34.152017542 +0000 UTC m=+2897.286112619 I0505 17:50:34.182533 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:34.182663 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-05 17:50:34.182652992 +0000 UTC m=+2897.316748079 I0505 17:50:34.438642 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:34.523936 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-gst99" condition "Approved" to 2026-05-05 17:50:34.523920458 +0000 UTC m=+2897.658015535 I0505 17:50:34.590862 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-gst99" condition "Ready" to 2026-05-05 17:50:34.590847114 +0000 UTC m=+2897.724942201 I0505 17:50:34.708961 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:34.70894867 +0000 UTC m=+2897.843043757 I0505 17:50:34.751269 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:34.895299 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:34.996614 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-05 17:50:34.996593261 +0000 UTC m=+2898.130688348 I0505 17:50:35.031013 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-05 17:50:35.030992794 +0000 UTC m=+2898.165087881 I0505 17:50:35.031416 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:35.031437 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-05 17:50:35.031432744 +0000 UTC m=+2898.165527831 I0505 17:50:35.054071 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:35.054227 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-05 17:50:35.054215576 +0000 UTC m=+2898.188310663 I0505 17:50:35.204147 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:35.258876 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-qnch9" condition "Approved" to 2026-05-05 17:50:35.25885278 +0000 UTC m=+2898.392947867 I0505 17:50:35.306732 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-qnch9" condition "Ready" to 2026-05-05 17:50:35.306651124 +0000 UTC m=+2898.440746201 I0505 17:50:35.455766 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:35.455747829 +0000 UTC m=+2898.589842916 I0505 17:50:35.533062 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:36.035397 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-05 17:50:36.035373506 +0000 UTC m=+2899.169468593 I0505 17:50:36.064456 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-05 17:50:36.064435861 +0000 UTC m=+2899.198530968 I0505 17:50:36.064610 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capo-system/capo-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:50:36.064672 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-05 17:50:36.064662656 +0000 UTC m=+2899.198757743 I0505 17:50:36.085850 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:36.085967 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-05 17:50:36.085951995 +0000 UTC m=+2899.220047122 I0505 17:50:36.818543 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:50:36.861499 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-xwxmj" condition "Approved" to 2026-05-05 17:50:36.861482729 +0000 UTC m=+2899.995577816 I0505 17:50:36.890005 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-xwxmj" condition "Ready" to 2026-05-05 17:50:36.889990131 +0000 UTC m=+2900.024085208 I0505 17:50:36.942143 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:50:36.942127993 +0000 UTC m=+2900.076223080 I0505 17:50:37.171607 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:00.134417 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:56:00.134533 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-05 17:56:00.134522505 +0000 UTC m=+3223.268617612 I0505 17:56:00.134537 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Ready" to 2026-05-05 17:56:00.134006084 +0000 UTC m=+3223.268101251 I0505 17:56:00.194870 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:00.195014 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:56:00.195040 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-05 17:56:00.195032606 +0000 UTC m=+3223.329127683 I0505 17:56:00.467427 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:00.486624 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-s76kt" condition "Approved" to 2026-05-05 17:56:00.486606002 +0000 UTC m=+3223.620701089 I0505 17:56:00.517735 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-s76kt" condition "Ready" to 2026-05-05 17:56:00.517716132 +0000 UTC m=+3223.651811219 I0505 17:56:00.575845 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:56:00.575824949 +0000 UTC m=+3223.709920026 I0505 17:56:00.631530 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:00.633084 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:56:00.633071776 +0000 UTC m=+3223.767166893 I0505 17:56:00.649137 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:00.749215 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:03.455237 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Ready" to 2026-05-05 17:56:03.455215217 +0000 UTC m=+3226.589310304 I0505 17:56:03.456011 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:56:03.456033 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-05-05 17:56:03.456029605 +0000 UTC m=+3226.590124692 I0505 17:56:03.473738 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:03.473805 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 17:56:03.473824 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-05-05 17:56:03.473817306 +0000 UTC m=+3226.607912393 I0505 17:56:04.004726 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-cjnq6" condition "Approved" to 2026-05-05 17:56:04.004708493 +0000 UTC m=+3227.138803570 I0505 17:56:04.034275 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-cjnq6" condition "Ready" to 2026-05-05 17:56:04.034259629 +0000 UTC m=+3227.168354716 I0505 17:56:04.151471 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:56:04.151429952 +0000 UTC m=+3227.285525059 I0505 17:56:04.243586 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:04.244354 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 17:56:04.244343133 +0000 UTC m=+3227.378438210 I0505 17:56:04.389958 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 17:56:04.395848 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" E0505 17:57:59.184041 1 leaderelection.go:364] Failed to update lock: etcdserver: request timed out E0505 17:58:53.954063 1 leaderelection.go:364] Failed to update lock: etcdserver: request timed out E0505 17:59:08.955436 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused I0505 17:59:15.266545 1 leaderelection.go:280] failed to renew lease cert-manager/cert-manager-controller: timed out waiting for the condition E0505 17:59:15.267380 1 leaderelection.go:303] Failed to release lock: Put "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused I0505 17:59:15.267567 1 controller.go:127] "cert-manager/ingress-shim: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267575 1 controller.go:127] "cert-manager/certificates-issuing: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267632 1 controller.go:127] "cert-manager/certificaterequests-issuer-selfsigned: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267678 1 controller.go:127] "cert-manager/certificates-request-manager: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267685 1 controller.go:127] "cert-manager/certificaterequests-approver: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267715 1 controller.go:127] "cert-manager/certificaterequests-issuer-venafi: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267729 1 controller.go:127] "cert-manager/certificaterequests-issuer-vault: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267745 1 controller.go:127] "cert-manager/certificaterequests-issuer-ca: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267768 1 controller.go:127] "cert-manager/certificates-revision-manager: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267842 1 controller.go:127] "cert-manager/certificates-trigger: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267872 1 controller.go:127] "cert-manager/clusterissuers: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267893 1 controller.go:127] "cert-manager/certificates-readiness: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267924 1 controller.go:127] "cert-manager/certificates-metrics: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267951 1 controller.go:127] "cert-manager/challenges: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267977 1 controller.go:127] "cert-manager/issuers: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.268004 1 controller.go:127] "cert-manager/certificaterequests-issuer-acme: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.268030 1 controller.go:127] "cert-manager/orders: shutting down queue as workqueue signaled shutdown" I0505 17:59:15.267873 1 controller.go:127] "cert-manager/certificates-key-manager: shutting down queue as workqueue signaled shutdown" E0505 17:59:15.268002 1 event.go:289] Unable to write event: '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"cert-manager-controller.18acbd2d52f48e6f", GenerateName:"", Namespace:"cert-manager", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Lease", Namespace:"cert-manager", Name:"cert-manager-controller", UID:"b7f7c490-0e25-4cb3-85b3-664d871e6139", APIVersion:"coordination.k8s.io/v1", ResourceVersion:"30491", FieldPath:""}, Reason:"LeaderElection", Message:"cert-manager-75969b45cf-tp494-external-cert-manager-controller stopped leading", Source:v1.EventSource{Component:"cert-manager-leader-election", Host:""}, FirstTimestamp:time.Date(2026, time.May, 5, 17, 59, 15, 267440239, time.Local), LastTimestamp:time.Date(2026, time.May, 5, 17, 59, 15, 267440239, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'Post "https://10.96.0.1:443/api/v1/namespaces/cert-manager/events": dial tcp 10.96.0.1:443: connect: connection refused'(may retry after sleeping) E0505 17:59:15.268197 1 main.go:35] "cert-manager: error executing command" err="error starting controller: leader election lost"