I0505 10:16:01.481345 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0505 10:16:01.481459 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0505 10:16:01.481537 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0505 10:16:01.484917 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0505 10:16:01.485298 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0505 10:16:01.485371 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0505 10:16:01.485411 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0505 10:16:01.487913 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0505 10:16:01.502794 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0505 10:16:01.502945 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0505 10:16:01.507183 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0505 10:16:01.513261 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0505 10:16:01.516142 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0505 10:16:01.516199 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0505 10:16:01.518762 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0505 10:16:01.521311 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0505 10:16:01.524696 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0505 10:16:01.531568 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0505 10:16:01.534007 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0505 10:16:01.534031 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0505 10:16:01.534107 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0505 10:16:01.536576 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0505 10:16:01.538908 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0505 10:16:01.541600 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0505 10:16:01.543903 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0505 10:16:01.546165 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0505 10:16:01.548173 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0505 10:16:01.555486 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0505 10:16:01.559615 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0505 10:16:01.561513 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0505 10:16:01.563499 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0505 10:16:01.563535 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0505 10:16:01.563550 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0505 10:16:01.566209 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.567985 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.568667 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.568994 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.569181 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.569610 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.569693 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.569996 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.570309 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:01.659619 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 10:16:18.670434 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-05 10:16:18.670395033 +0000 UTC m=+17.222470090 I0505 10:16:19.425910 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:16:19.425993 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-05 10:16:19.425984684 +0000 UTC m=+17.978059741 I0505 10:16:19.426280 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 10:16:19.426247742 +0000 UTC m=+17.978322829 I0505 10:16:19.443142 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:19.443238 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 10:16:19.443231644 +0000 UTC m=+17.995306701 E0505 10:16:19.445135 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 10:16:19.445228 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-05 10:16:19.445217378 +0000 UTC m=+17.997292435 E0505 10:16:19.445258 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:16:19.461144 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0505 10:16:19.461277 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:16:19.461317 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:16:19.461369 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0505 10:16:19.464216 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:19.490502 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-kqxck" condition "Approved" to 2026-05-05 10:16:19.490485223 +0000 UTC m=+18.042560290 I0505 10:16:19.503981 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-kqxck" condition "Ready" to 2026-05-05 10:16:19.503966513 +0000 UTC m=+18.056041570 I0505 10:16:19.528445 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:19.528241677 +0000 UTC m=+18.080316754 I0505 10:16:19.546840 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:19.547262 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:19.547252774 +0000 UTC m=+18.099327821 I0505 10:16:19.562703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:19.562921 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:19.562914304 +0000 UTC m=+18.114989361 I0505 10:16:24.462103 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:24.462084022 +0000 UTC m=+23.014159099 I0505 10:16:47.009700 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:16:47.009790 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 10:16:47.009728944 +0000 UTC m=+45.561804001 I0505 10:16:47.009824 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 10:16:47.009807736 +0000 UTC m=+45.561882833 I0505 10:16:47.026952 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-05 10:16:47.026925541 +0000 UTC m=+45.579000588 I0505 10:16:47.037019 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:47.037101 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 10:16:47.037091418 +0000 UTC m=+45.589166465 I0505 10:16:47.408902 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:47.441271 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4hdmx" condition "Approved" to 2026-05-05 10:16:47.441256398 +0000 UTC m=+45.993331455 I0505 10:16:47.477278 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4hdmx" condition "Ready" to 2026-05-05 10:16:47.477262761 +0000 UTC m=+46.029337818 I0505 10:16:47.510763 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:47.510746952 +0000 UTC m=+46.062822009 I0505 10:16:47.533101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:47.533492 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:47.533483552 +0000 UTC m=+46.085558599 I0505 10:16:47.551668 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:16:47.552041 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:16:47.551989731 +0000 UTC m=+46.104064768 I0505 10:16:47.553576 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:21:10.878243 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-177.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:21:10.878320 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-177.nip.io-tls" condition "Issuing" to 2026-05-05 10:21:10.8782726 +0000 UTC m=+309.430347687 I0505 10:21:10.878993 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-177.nip.io-tls" condition "Ready" to 2026-05-05 10:21:10.87897093 +0000 UTC m=+309.431045987 I0505 10:21:10.897826 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-177.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-177.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:21:10.897885 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-177.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:21:10.897899 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-177.nip.io-tls" condition "Issuing" to 2026-05-05 10:21:10.897893697 +0000 UTC m=+309.449968754 I0505 10:21:11.190749 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-177.nip.io-tls-4rszt" condition "Approved" to 2026-05-05 10:21:11.190732794 +0000 UTC m=+309.742807861 I0505 10:21:11.218588 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-177.nip.io-tls-4rszt" condition "Ready" to 2026-05-05 10:21:11.218570171 +0000 UTC m=+309.770645228 I0505 10:21:11.245741 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-177.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:21:11.245721858 +0000 UTC m=+309.797796895 I0505 10:21:11.267013 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-177.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-177.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:21:11.316434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-177.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-177.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:22:15.605544 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:22:15.605586 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-05 10:22:15.605572785 +0000 UTC m=+374.157647842 I0505 10:22:15.605689 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 10:22:15.605554255 +0000 UTC m=+374.157629362 I0505 10:22:15.618781 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:22:15.618863 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 10:22:15.618855592 +0000 UTC m=+374.170930649 E0505 10:22:15.620144 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 10:22:15.620241 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-05 10:22:15.620231824 +0000 UTC m=+374.172306901 E0505 10:22:15.620350 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:22:15.637471 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0505 10:22:15.637668 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:22:15.637711 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 10:22:15.637792 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0505 10:22:15.638511 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:22:15.660845 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-2mwxj" condition "Approved" to 2026-05-05 10:22:15.660825834 +0000 UTC m=+374.212900871 I0505 10:22:15.673153 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-2mwxj" condition "Ready" to 2026-05-05 10:22:15.673137531 +0000 UTC m=+374.225212588 I0505 10:22:15.692515 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:22:15.692500795 +0000 UTC m=+374.244575852 I0505 10:22:15.711846 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:22:15.712186 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:22:15.712174256 +0000 UTC m=+374.264249313 I0505 10:22:15.726351 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:22:20.637983 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:22:20.637971718 +0000 UTC m=+379.190046765 I0505 10:23:02.747561 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-05 10:23:02.747544094 +0000 UTC m=+421.299619141 I0505 10:23:02.748252 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:02.748275 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-05 10:23:02.748271838 +0000 UTC m=+421.300346875 I0505 10:23:02.767769 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-05 10:23:02.767752351 +0000 UTC m=+421.319827398 I0505 10:23:02.767990 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:02.768024 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-05 10:23:02.768017406 +0000 UTC m=+421.320092453 I0505 10:23:02.768189 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-05 10:23:02.76817873 +0000 UTC m=+421.320253777 I0505 10:23:02.768202 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:02.772731 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-05 10:23:02.772725309 +0000 UTC m=+421.324800356 I0505 10:23:02.804656 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:02.805177 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-05 10:23:02.805168356 +0000 UTC m=+421.357243393 I0505 10:23:02.805515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:02.806159 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-05 10:23:02.806154486 +0000 UTC m=+421.358229534 I0505 10:23:02.817295 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:02.817352 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:02.817375 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-05 10:23:02.817371257 +0000 UTC m=+421.369446304 I0505 10:23:02.895718 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:02.924768 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-d772x" condition "Approved" to 2026-05-05 10:23:02.924749659 +0000 UTC m=+421.476824716 I0505 10:23:02.942370 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-d772x" condition "Ready" to 2026-05-05 10:23:02.942355285 +0000 UTC m=+421.494430372 I0505 10:23:02.981998 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:02.981981815 +0000 UTC m=+421.534056902 I0505 10:23:03.006449 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:03.141183 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:03.150896 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-8xsf6" condition "Approved" to 2026-05-05 10:23:03.15088112 +0000 UTC m=+421.702956167 I0505 10:23:03.166441 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-8xsf6" condition "Ready" to 2026-05-05 10:23:03.166430364 +0000 UTC m=+421.718505421 I0505 10:23:03.167739 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-wvlh7" condition "Approved" to 2026-05-05 10:23:03.16771845 +0000 UTC m=+421.719793507 I0505 10:23:03.492208 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-wvlh7" condition "Ready" to 2026-05-05 10:23:03.492186685 +0000 UTC m=+422.044261772 I0505 10:23:03.599271 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:03.599258506 +0000 UTC m=+422.151333553 I0505 10:23:03.830513 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:03.830955 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:03.830946791 +0000 UTC m=+422.383021848 I0505 10:23:03.940150 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:03.940140564 +0000 UTC m=+422.492215611 I0505 10:23:04.186161 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:04.186562 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:04.186554158 +0000 UTC m=+422.738629205 I0505 10:23:04.228502 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:04.480986 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:11.320952 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" condition "Ready" to 2026-05-05 10:23:11.320912815 +0000 UTC m=+429.872987872 I0505 10:23:11.321389 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:11.321411 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" condition "Issuing" to 2026-05-05 10:23:11.321406885 +0000 UTC m=+429.873481942 I0505 10:23:11.338864 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-gn46c-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:11.338966 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" condition "Ready" to 2026-05-05 10:23:11.338954833 +0000 UTC m=+429.891029920 I0505 10:23:11.429589 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-gn46c-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:11.460244 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-gn46c-xtj76" condition "Approved" to 2026-05-05 10:23:11.460234767 +0000 UTC m=+430.012309814 I0505 10:23:11.483316 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-gn46c-xtj76" condition "Ready" to 2026-05-05 10:23:11.48330648 +0000 UTC m=+430.035381537 I0505 10:23:11.519242 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:11.519227482 +0000 UTC m=+430.071302539 I0505 10:23:11.556511 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-gn46c-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:11.556819 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:11.556812065 +0000 UTC m=+430.108887112 I0505 10:23:11.577501 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-gn46c-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-gn46c-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:23.001906 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:23:23.002161 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-05 10:23:23.002141128 +0000 UTC m=+441.554216185 I0505 10:23:23.003214 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-05 10:23:23.002720989 +0000 UTC m=+441.554796056 I0505 10:23:23.025847 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:23.025929 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-05 10:23:23.025920184 +0000 UTC m=+441.577995231 I0505 10:23:23.337622 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:23:23.377803 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-krqpq" condition "Approved" to 2026-05-05 10:23:23.377783972 +0000 UTC m=+441.929859039 I0505 10:23:23.410303 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-krqpq" condition "Ready" to 2026-05-05 10:23:23.410289121 +0000 UTC m=+441.962364178 I0505 10:23:23.439837 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:23:23.439822133 +0000 UTC m=+441.991897180 I0505 10:23:23.467486 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:26:34.635104 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-05 10:26:34.635067403 +0000 UTC m=+633.187142500 I0505 10:26:34.635178 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:26:34.635492 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 10:26:34.635484479 +0000 UTC m=+633.187559546 I0505 10:26:34.651432 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:26:34.651516 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:26:34.651606 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 10:26:34.651529264 +0000 UTC m=+633.203604321 I0505 10:26:34.910847 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-h49r2" condition "Approved" to 2026-05-05 10:26:34.910833199 +0000 UTC m=+633.462908276 I0505 10:26:34.934086 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-h49r2" condition "Ready" to 2026-05-05 10:26:34.932047399 +0000 UTC m=+633.484122446 I0505 10:26:34.965422 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:26:34.965404887 +0000 UTC m=+633.517479964 I0505 10:26:34.985047 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:26:34.985275 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:26:34.985249798 +0000 UTC m=+633.537324835 I0505 10:26:35.009813 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:26:35.010084 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:26:35.010076131 +0000 UTC m=+633.562151198 I0505 10:27:16.933849 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-05 10:27:16.933815104 +0000 UTC m=+675.485890191 I0505 10:27:16.933873 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:27:16.934130 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 10:27:16.934112828 +0000 UTC m=+675.486187885 I0505 10:27:16.954913 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:27:16.955152 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 10:27:16.955228 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 10:27:16.95521526 +0000 UTC m=+675.507290307 I0505 10:27:17.156294 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-cpswc" condition "Approved" to 2026-05-05 10:27:17.156281095 +0000 UTC m=+675.708356182 I0505 10:27:17.177510 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-cpswc" condition "Ready" to 2026-05-05 10:27:17.177493008 +0000 UTC m=+675.729568095 I0505 10:27:17.224445 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:27:17.224430379 +0000 UTC m=+675.776505456 I0505 10:27:17.258367 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:27:17.258752 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 10:27:17.25874299 +0000 UTC m=+675.810818047 I0505 10:27:17.262558 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 10:27:17.279188 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"