I0501 00:54:10.084957 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0501 00:54:10.085154 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0501 00:54:10.085360 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0501 00:54:10.092993 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0501 00:54:10.093763 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0501 00:54:10.093763 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0501 00:54:10.093803 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0501 00:54:10.097386 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0501 00:54:10.114538 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0501 00:54:10.118145 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0501 00:54:10.121354 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0501 00:54:10.124841 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0501 00:54:10.124998 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0501 00:54:10.125063 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0501 00:54:10.124881 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0501 00:54:10.132273 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0501 00:54:10.134609 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0501 00:54:10.134671 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0501 00:54:10.136754 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0501 00:54:10.138697 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0501 00:54:10.140564 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0501 00:54:10.142459 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0501 00:54:10.144196 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0501 00:54:10.144269 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0501 00:54:10.144300 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0501 00:54:10.148908 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0501 00:54:10.150789 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0501 00:54:10.152498 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0501 00:54:10.154405 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0501 00:54:10.156413 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0501 00:54:10.158194 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0501 00:54:10.160473 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0501 00:54:10.162131 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0501 00:54:10.167394 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.167641 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.168853 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.183464 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.192464 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.207532 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.224826 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.239110 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.250926 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:10.254774 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0501 00:54:26.856242 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-01 00:54:26.856209384 +0000 UTC m=+16.802441672 I0501 00:54:27.590036 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 00:54:27.590076 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-01 00:54:27.590067822 +0000 UTC m=+17.536300090 I0501 00:54:27.590045 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-01 00:54:27.590024591 +0000 UTC m=+17.536256879 E0501 00:54:27.605250 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0501 00:54:27.605320 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-01 00:54:27.605313244 +0000 UTC m=+17.551545512 E0501 00:54:27.605342 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0501 00:54:27.608168 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:27.608223 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 00:54:27.608240 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-01 00:54:27.608235308 +0000 UTC m=+17.554467576 E0501 00:54:27.616101 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0501 00:54:27.616209 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0501 00:54:27.616263 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0501 00:54:27.616295 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0501 00:54:27.647929 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:27.656596 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vnnrp" condition "Approved" to 2026-05-01 00:54:27.656581217 +0000 UTC m=+17.602813505 I0501 00:54:27.675126 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vnnrp" condition "Ready" to 2026-05-01 00:54:27.675110779 +0000 UTC m=+17.621343067 I0501 00:54:27.695176 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:54:27.695165294 +0000 UTC m=+17.641397562 I0501 00:54:27.712385 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:27.712794 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:54:27.712786352 +0000 UTC m=+17.659018620 I0501 00:54:27.729697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:32.617441 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:54:32.617422399 +0000 UTC m=+22.563654687 I0501 00:54:54.542513 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 00:54:54.542608 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-01 00:54:54.542587909 +0000 UTC m=+44.488820177 I0501 00:54:54.542619 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-01 00:54:54.542582199 +0000 UTC m=+44.488814457 I0501 00:54:54.567481 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-01 00:54:54.567461196 +0000 UTC m=+44.513693474 I0501 00:54:54.577957 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:54.578045 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-01 00:54:54.578036258 +0000 UTC m=+44.524268526 I0501 00:54:54.837733 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:54:54.874164 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8szq5" condition "Approved" to 2026-05-01 00:54:54.874150923 +0000 UTC m=+44.820383191 I0501 00:54:54.904378 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8szq5" condition "Ready" to 2026-05-01 00:54:54.904364967 +0000 UTC m=+44.850597235 I0501 00:54:54.933643 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:54:54.933631429 +0000 UTC m=+44.879863697 I0501 00:54:54.956803 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:08.612990 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready" to 2026-05-01 00:59:08.61293231 +0000 UTC m=+298.559164608 I0501 00:59:08.613814 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 00:59:08.613842 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Issuing" to 2026-05-01 00:59:08.613834959 +0000 UTC m=+298.560067227 I0501 00:59:08.634942 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:08.635043 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-156.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 00:59:08.635070 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Issuing" to 2026-05-01 00:59:08.635063469 +0000 UTC m=+298.581295737 I0501 00:59:08.999930 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-156.nip.io-tls-pgrdp" condition "Approved" to 2026-05-01 00:59:08.999918825 +0000 UTC m=+298.946151103 I0501 00:59:09.035709 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-156.nip.io-tls-pgrdp" condition "Ready" to 2026-05-01 00:59:09.035702284 +0000 UTC m=+298.981934552 I0501 00:59:09.061928 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:59:09.061917326 +0000 UTC m=+299.008149594 I0501 00:59:09.085134 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:09.085513 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:59:09.085507274 +0000 UTC m=+299.031739542 I0501 00:59:09.085922 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:09.097951 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:09.100203 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-156.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-156.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 00:59:09.100508 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-156.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 00:59:09.100502314 +0000 UTC m=+299.046734582 I0501 01:00:11.046599 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:11.046651 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-01 01:00:11.046634369 +0000 UTC m=+360.992866637 I0501 01:00:11.047601 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-01 01:00:11.046542648 +0000 UTC m=+360.992774966 I0501 01:00:11.107397 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:11.107459 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:11.107473 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-01 01:00:11.107468531 +0000 UTC m=+361.053700779 E0501 01:00:11.114615 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0501 01:00:11.114636 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-01 01:00:11.114632152 +0000 UTC m=+361.060864410 E0501 01:00:11.114728 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0501 01:00:11.141981 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0501 01:00:11.145352 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0501 01:00:11.145450 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0501 01:00:11.145519 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0501 01:00:11.160076 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:11.165165 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-dnlmw" condition "Approved" to 2026-05-01 01:00:11.165153589 +0000 UTC m=+361.111385887 I0501 01:00:11.177553 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-dnlmw" condition "Ready" to 2026-05-01 01:00:11.177537569 +0000 UTC m=+361.123769837 I0501 01:00:11.195821 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:11.195808079 +0000 UTC m=+361.142040337 I0501 01:00:11.213868 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:11.258528 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:16.143112 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:16.143097819 +0000 UTC m=+366.089330117 I0501 01:00:56.799053 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:56.799104 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-01 01:00:56.799078259 +0000 UTC m=+406.745310517 I0501 01:00:56.799107 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-01 01:00:56.79908859 +0000 UTC m=+406.745320858 I0501 01:00:56.830704 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-01 01:00:56.83069159 +0000 UTC m=+406.776923848 I0501 01:00:56.832212 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:56.832230 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-01 01:00:56.832227604 +0000 UTC m=+406.778459862 I0501 01:00:56.832510 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:56.832548 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-01 01:00:56.832541278 +0000 UTC m=+406.778773546 I0501 01:00:56.886401 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-01 01:00:56.886388596 +0000 UTC m=+406.832620844 I0501 01:00:56.894631 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:56.894679 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-01 01:00:56.894673632 +0000 UTC m=+406.840905890 I0501 01:00:56.947219 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:56.947282 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:00:56.947298 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-01 01:00:56.947293893 +0000 UTC m=+406.893526141 I0501 01:00:56.956402 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:56.956474 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-01 01:00:56.956465872 +0000 UTC m=+406.902698160 I0501 01:00:57.060119 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.084927 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-pxln9" condition "Approved" to 2026-05-01 01:00:57.084910832 +0000 UTC m=+407.031143120 I0501 01:00:57.104789 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-pxln9" condition "Ready" to 2026-05-01 01:00:57.104780083 +0000 UTC m=+407.051012341 I0501 01:00:57.167951 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:57.167941401 +0000 UTC m=+407.114173669 I0501 01:00:57.183013 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.183241 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:57.183234683 +0000 UTC m=+407.129466941 I0501 01:00:57.184916 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.202119 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.222177 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.233963 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-rlhdr" condition "Approved" to 2026-05-01 01:00:57.233952603 +0000 UTC m=+407.180184881 I0501 01:00:57.249622 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-rlhdr" condition "Ready" to 2026-05-01 01:00:57.24961455 +0000 UTC m=+407.195846818 I0501 01:00:57.275948 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:57.27593298 +0000 UTC m=+407.222165268 I0501 01:00:57.338502 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.338957 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:57.338944256 +0000 UTC m=+407.285176504 I0501 01:00:57.635351 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.687047 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.737416 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:57.942294 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rhwn9" condition "Approved" to 2026-05-01 01:00:57.942277357 +0000 UTC m=+407.888509615 I0501 01:00:58.251831 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rhwn9" condition "Ready" to 2026-05-01 01:00:58.251820345 +0000 UTC m=+408.198052613 I0501 01:00:58.490134 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:58.490086671 +0000 UTC m=+408.436318959 I0501 01:00:58.588552 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:58.589071 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:00:58.589060548 +0000 UTC m=+408.535292846 I0501 01:00:58.847582 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:00:58.888760 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:06.042968 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:01:06.043025 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" condition "Issuing" to 2026-05-01 01:01:06.043014476 +0000 UTC m=+415.989246764 I0501 01:01:06.043713 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" condition "Ready" to 2026-05-01 01:01:06.043704567 +0000 UTC m=+415.989936855 I0501 01:01:06.069033 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:06.069173 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" condition "Ready" to 2026-05-01 01:01:06.069151055 +0000 UTC m=+416.015383313 I0501 01:01:06.126384 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:06.171379 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-wdhnl-6j9n6" condition "Approved" to 2026-05-01 01:01:06.171367167 +0000 UTC m=+416.117599435 I0501 01:01:06.193576 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-wdhnl-6j9n6" condition "Ready" to 2026-05-01 01:01:06.193565798 +0000 UTC m=+416.139798066 I0501 01:01:06.226899 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:01:06.226882744 +0000 UTC m=+416.173115022 I0501 01:01:06.244687 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-wdhnl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:18.993036 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:01:18.993101 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-01 01:01:18.993089426 +0000 UTC m=+428.939321694 I0501 01:01:18.993382 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-01 01:01:18.993377641 +0000 UTC m=+428.939609909 I0501 01:01:19.007252 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:19.007348 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-01 01:01:19.007339493 +0000 UTC m=+428.953571761 I0501 01:01:19.157337 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:01:19.197038 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vsfds" condition "Approved" to 2026-05-01 01:01:19.197023196 +0000 UTC m=+429.143255454 I0501 01:01:19.224406 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vsfds" condition "Ready" to 2026-05-01 01:01:19.224393794 +0000 UTC m=+429.170626062 I0501 01:01:19.261316 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:01:19.261295709 +0000 UTC m=+429.207527977 I0501 01:01:19.283393 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:04:28.748800 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-01 01:04:28.748770011 +0000 UTC m=+618.695002279 I0501 01:04:28.749382 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:04:28.749431 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-01 01:04:28.749426409 +0000 UTC m=+618.695658677 I0501 01:04:28.765398 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:04:28.765481 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:04:28.765502 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-01 01:04:28.765494069 +0000 UTC m=+618.711726327 I0501 01:04:29.035332 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-86rhb" condition "Approved" to 2026-05-01 01:04:29.035318342 +0000 UTC m=+618.981550620 I0501 01:04:29.060125 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-86rhb" condition "Ready" to 2026-05-01 01:04:29.060098605 +0000 UTC m=+619.006330873 I0501 01:04:29.090301 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:04:29.090287653 +0000 UTC m=+619.036519921 I0501 01:04:29.114179 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:04:29.114505 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:04:29.114496448 +0000 UTC m=+619.060728706 I0501 01:04:29.134662 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:05:06.873152 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-01 01:05:06.873133306 +0000 UTC m=+656.819365574 I0501 01:05:06.873585 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:05:06.873608 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-01 01:05:06.873604042 +0000 UTC m=+656.819836320 I0501 01:05:06.887875 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:05:06.887944 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0501 01:05:06.887979 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-01 01:05:06.887970499 +0000 UTC m=+656.834202797 I0501 01:05:07.344763 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:05:07.353883 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-242sx" condition "Approved" to 2026-05-01 01:05:07.353872527 +0000 UTC m=+657.300104785 I0501 01:05:07.373428 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-242sx" condition "Ready" to 2026-05-01 01:05:07.373416315 +0000 UTC m=+657.319648593 I0501 01:05:07.405146 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:05:07.405130123 +0000 UTC m=+657.351362381 I0501 01:05:07.431770 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:05:07.432124 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:05:07.432106237 +0000 UTC m=+657.378338495 I0501 01:05:07.452161 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0501 01:05:07.452769 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-01 01:05:07.452756747 +0000 UTC m=+657.398989035