I0512 01:44:12.745415 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0512 01:44:12.745528 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0512 01:44:12.745596 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0512 01:44:12.749763 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0512 01:44:12.750219 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0512 01:44:12.750311 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0512 01:44:12.750326 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0512 01:44:12.752956 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0512 01:44:12.766068 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0512 01:44:12.770091 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0512 01:44:12.776644 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0512 01:44:12.780220 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0512 01:44:12.782157 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0512 01:44:12.783874 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0512 01:44:12.785567 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0512 01:44:12.787352 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0512 01:44:12.790248 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0512 01:44:12.795605 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0512 01:44:12.800431 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0512 01:44:12.800463 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0512 01:44:12.800485 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0512 01:44:12.800577 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0512 01:44:12.803701 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0512 01:44:12.806474 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0512 01:44:12.806496 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0512 01:44:12.806502 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0512 01:44:12.809385 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0512 01:44:12.811829 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0512 01:44:12.814326 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0512 01:44:12.817013 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0512 01:44:12.819450 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0512 01:44:12.819499 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0512 01:44:12.822272 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0512 01:44:12.825430 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.828212 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.828717 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.828985 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.844852 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.865097 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.878971 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.896424 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.911847 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:12.923584 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0512 01:44:28.609646 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-12 01:44:28.609629138 +0000 UTC m=+15.907725573 I0512 01:44:29.426878 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-12 01:44:29.426857216 +0000 UTC m=+16.724953651 I0512 01:44:29.428373 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:44:29.428407 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-12 01:44:29.428399784 +0000 UTC m=+16.726496229 I0512 01:44:29.661669 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:44:29.661750 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-12 01:44:29.66174264 +0000 UTC m=+16.959839055 E0512 01:44:29.663496 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:44:29.663830 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-12 01:44:29.663814374 +0000 UTC m=+16.961910819 E0512 01:44:29.663976 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:44:29.865010 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0512 01:44:29.865416 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:44:29.865502 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:44:29.865552 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0512 01:44:30.143955 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:44:30.474290 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rkj9h" condition "Approved" to 2026-05-12 01:44:30.474276377 +0000 UTC m=+17.772372822 I0512 01:44:30.602494 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rkj9h" condition "Ready" to 2026-05-12 01:44:30.602481399 +0000 UTC m=+17.900577814 I0512 01:44:31.140300 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:44:31.140289365 +0000 UTC m=+18.438385780 I0512 01:44:31.230597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:44:34.865599 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:44:34.865583711 +0000 UTC m=+22.163680116 I0512 01:45:10.104224 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-12 01:45:10.104202232 +0000 UTC m=+57.402298647 I0512 01:45:10.104437 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:45:10.104501 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-12 01:45:10.10449626 +0000 UTC m=+57.402592665 I0512 01:45:10.120524 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-12 01:45:10.120512398 +0000 UTC m=+57.418608803 I0512 01:45:10.148435 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:45:10.149154 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:45:10.149192 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-12 01:45:10.149184899 +0000 UTC m=+57.447281314 I0512 01:45:10.603292 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:45:10.616477 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2ptct" condition "Approved" to 2026-05-12 01:45:10.616463305 +0000 UTC m=+57.914559740 I0512 01:45:10.692255 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2ptct" condition "Ready" to 2026-05-12 01:45:10.692245856 +0000 UTC m=+57.990342261 I0512 01:45:10.746409 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:45:10.746395516 +0000 UTC m=+58.044491931 I0512 01:45:10.790174 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:55.360163 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-135.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:52:55.360200 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-135.nip.io-tls" condition "Issuing" to 2026-05-12 01:52:55.36019129 +0000 UTC m=+522.658287705 I0512 01:52:55.360251 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-135.nip.io-tls" condition "Ready" to 2026-05-12 01:52:55.360240851 +0000 UTC m=+522.658337266 I0512 01:52:55.389118 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-135.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-135.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:55.389204 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-214-135.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:52:55.389222 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-214-135.nip.io-tls" condition "Issuing" to 2026-05-12 01:52:55.389216032 +0000 UTC m=+522.687312437 I0512 01:52:55.771792 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-214-135.nip.io-tls-k47ll" condition "Approved" to 2026-05-12 01:52:55.771779101 +0000 UTC m=+523.069875546 I0512 01:52:55.818577 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-214-135.nip.io-tls-k47ll" condition "Ready" to 2026-05-12 01:52:55.818562462 +0000 UTC m=+523.116658897 I0512 01:52:55.850137 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-214-135.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:52:55.850119986 +0000 UTC m=+523.148216411 I0512 01:52:55.870762 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-214-135.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-135.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:55.871266 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-214-135.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:52:55.871259297 +0000 UTC m=+523.169355712 I0512 01:52:55.888603 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-214-135.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-135.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:52:55.889613 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-214-135.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-214-135.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:58.183569 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-12 01:53:58.183516633 +0000 UTC m=+585.481613078 I0512 01:53:58.184025 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:53:58.184091 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-12 01:53:58.184080222 +0000 UTC m=+585.482176667 E0512 01:53:58.197196 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:53:58.197351 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-12 01:53:58.197342489 +0000 UTC m=+585.495438894 E0512 01:53:58.197686 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0512 01:53:58.199853 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:58.199912 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-12 01:53:58.199905488 +0000 UTC m=+585.498001903 E0512 01:53:58.209108 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0512 01:53:58.209581 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:53:58.209627 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0512 01:53:58.209806 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0512 01:53:58.229239 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:58.257324 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-wdnsm" condition "Approved" to 2026-05-12 01:53:58.257312676 +0000 UTC m=+585.555409091 I0512 01:53:58.271240 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-wdnsm" condition "Ready" to 2026-05-12 01:53:58.271224046 +0000 UTC m=+585.569320491 I0512 01:53:58.296872 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:58.296860429 +0000 UTC m=+585.594956834 I0512 01:53:58.313458 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:58.313900 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:58.313809613 +0000 UTC m=+585.611906038 I0512 01:53:58.330325 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:53:58.330713 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:53:58.330701306 +0000 UTC m=+585.628797751 I0512 01:54:03.209568 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:54:03.209554129 +0000 UTC m=+590.507650564 I0512 01:54:50.553711 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:54:50.553751 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-12 01:54:50.553744029 +0000 UTC m=+637.851840434 I0512 01:54:50.556490 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-12 01:54:50.556475293 +0000 UTC m=+637.854571688 I0512 01:54:50.556771 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-12 01:54:50.556767952 +0000 UTC m=+637.854864347 I0512 01:54:50.556979 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:54:50.556996 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-12 01:54:50.556993129 +0000 UTC m=+637.855089524 I0512 01:54:50.557166 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:54:50.557182 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-12 01:54:50.557179745 +0000 UTC m=+637.855276140 I0512 01:54:50.557337 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-12 01:54:50.557334501 +0000 UTC m=+637.855430906 I0512 01:54:50.612173 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:50.612439 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-12 01:54:50.612421302 +0000 UTC m=+637.910517737 I0512 01:54:50.614706 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:50.614776 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-12 01:54:50.614771895 +0000 UTC m=+637.912868300 I0512 01:54:50.617853 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:50.623282 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-12 01:54:50.623252927 +0000 UTC m=+637.921349372 I0512 01:54:50.833597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:50.844965 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:51.024859 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-cmrkl" condition "Approved" to 2026-05-12 01:54:51.024840056 +0000 UTC m=+638.322936501 I0512 01:54:51.088528 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-ld2t4" condition "Approved" to 2026-05-12 01:54:51.08851139 +0000 UTC m=+638.386607825 I0512 01:54:51.221016 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-cmrkl" condition "Ready" to 2026-05-12 01:54:51.220999366 +0000 UTC m=+638.519095781 I0512 01:54:51.545413 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:51.548147 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-ld2t4" condition "Ready" to 2026-05-12 01:54:51.548135435 +0000 UTC m=+638.846231840 I0512 01:54:51.801808 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-zknxg" condition "Approved" to 2026-05-12 01:54:51.801791829 +0000 UTC m=+639.099888254 I0512 01:54:51.855010 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:54:51.854991719 +0000 UTC m=+639.153088164 I0512 01:54:52.083343 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:54:52.083329457 +0000 UTC m=+639.381425872 I0512 01:54:52.084243 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-zknxg" condition "Ready" to 2026-05-12 01:54:52.084231405 +0000 UTC m=+639.382327810 I0512 01:54:52.124858 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:52.145740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:52.147182 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:54:52.147176382 +0000 UTC m=+639.445272787 I0512 01:54:52.185307 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:54:52.185294286 +0000 UTC m=+639.483390711 I0512 01:54:52.211247 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:52.213616 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:54:52.435346 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:55:14.793638 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Ready" to 2026-05-12 01:55:14.793604192 +0000 UTC m=+662.091700617 I0512 01:55:14.794407 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:55:14.794591 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Issuing" to 2026-05-12 01:55:14.79457731 +0000 UTC m=+662.092673745 I0512 01:55:14.811921 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:55:14.812351 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:55:14.812388 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Issuing" to 2026-05-12 01:55:14.812380226 +0000 UTC m=+662.110476621 I0512 01:55:14.944067 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:55:14.957180 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-tf9jx-j6ggz" condition "Approved" to 2026-05-12 01:55:14.957167115 +0000 UTC m=+662.255263530 I0512 01:55:14.983441 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-tf9jx-j6ggz" condition "Ready" to 2026-05-12 01:55:14.98343106 +0000 UTC m=+662.281527475 I0512 01:55:15.012126 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:55:15.012117555 +0000 UTC m=+662.310213970 I0512 01:55:15.041517 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:55:15.041887 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:55:15.041878591 +0000 UTC m=+662.339974996 I0512 01:55:15.073352 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:55:15.073678 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-tf9jx-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:55:15.073669546 +0000 UTC m=+662.371765961 I0512 01:56:41.742501 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-12 01:56:41.742429591 +0000 UTC m=+749.040526006 I0512 01:56:41.742972 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 01:56:41.743029 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-12 01:56:41.743015726 +0000 UTC m=+749.041112181 I0512 01:56:42.030517 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:56:42.030729 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-12 01:56:42.030717805 +0000 UTC m=+749.328814250 I0512 01:56:42.902025 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 01:56:43.486089 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-9h9j4" condition "Approved" to 2026-05-12 01:56:43.486065222 +0000 UTC m=+750.784161677 I0512 01:56:43.614295 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-9h9j4" condition "Ready" to 2026-05-12 01:56:43.61428583 +0000 UTC m=+750.912382235 I0512 01:56:44.918577 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 01:56:44.918554948 +0000 UTC m=+752.216651393 I0512 01:56:45.316299 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:00:26.961333 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 02:00:26.961333 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-12 02:00:26.961305127 +0000 UTC m=+974.259401542 I0512 02:00:26.961360 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-12 02:00:26.961355528 +0000 UTC m=+974.259451923 I0512 02:00:26.977381 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:00:26.977522 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 02:00:26.977557 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-12 02:00:26.977550612 +0000 UTC m=+974.275647027 I0512 02:00:27.139993 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-f46hb" condition "Approved" to 2026-05-12 02:00:27.139978253 +0000 UTC m=+974.438074668 I0512 02:00:27.163959 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-f46hb" condition "Ready" to 2026-05-12 02:00:27.163949356 +0000 UTC m=+974.462045781 I0512 02:00:27.190660 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 02:00:27.190645512 +0000 UTC m=+974.488741927 I0512 02:00:27.217576 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:00:27.217868 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 02:00:27.217862527 +0000 UTC m=+974.515958922 I0512 02:00:27.246041 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:01:46.986415 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 02:01:46.986505 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-12 02:01:46.98649504 +0000 UTC m=+1054.284591475 I0512 02:01:46.986421 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-12 02:01:46.986405488 +0000 UTC m=+1054.284501893 I0512 02:01:47.195829 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:01:47.195954 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0512 02:01:47.195989 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-12 02:01:47.195978922 +0000 UTC m=+1054.494075367 I0512 02:01:48.039902 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:01:48.040420 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-wvg4k" condition "Approved" to 2026-05-12 02:01:48.040412628 +0000 UTC m=+1055.338509033 I0512 02:01:48.227540 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-wvg4k" condition "Ready" to 2026-05-12 02:01:48.22752612 +0000 UTC m=+1055.525622565 I0512 02:01:48.359576 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 02:01:48.359559611 +0000 UTC m=+1055.657656046 I0512 02:01:48.434710 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0512 02:01:48.435049 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-12 02:01:48.435041194 +0000 UTC m=+1055.733137619 I0512 02:01:48.571960 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"