I0520 21:25:03.163730 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0520 21:25:03.163882 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0520 21:25:03.163921 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0520 21:25:03.164000 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0520 21:25:03.165347 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0520 21:25:03.165682 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0520 21:25:03.166128 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0520 21:25:03.166592 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0520 21:25:03.177779 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0520 21:25:03.179579 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0520 21:25:03.179735 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0520 21:25:03.180858 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0520 21:25:03.181883 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0520 21:25:03.182652 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0520 21:25:03.183526 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0520 21:25:03.184666 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0520 21:25:03.185356 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0520 21:25:03.185376 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0520 21:25:03.185406 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0520 21:25:03.186142 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0520 21:25:03.186749 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0520 21:25:03.188541 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0520 21:25:03.188604 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0520 21:25:03.188655 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0520 21:25:03.191062 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0520 21:25:03.191651 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0520 21:25:03.192267 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0520 21:25:03.192421 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0520 21:25:03.193252 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0520 21:25:03.193881 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0520 21:25:03.194562 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0520 21:25:03.195241 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0520 21:25:03.196142 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0520 21:25:31.455589 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-20 21:25:31.455540011 +0000 UTC m=+28.324277178 I0520 21:25:31.474888 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-20 21:25:31.474878444 +0000 UTC m=+28.343615581 I0520 21:25:31.475002 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:31.475221 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-20 21:25:31.475214178 +0000 UTC m=+28.343951315 E0520 21:25:31.496956 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18b163236723eefd", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"082990c6-f5d6-4506-8131-725eca14bfc8", APIVersion:"cert-manager.io/v1", ResourceVersion:"1364", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 20, 21, 25, 31, 493469949, time.Local), LastTimestamp:time.Date(2026, time.May, 20, 21, 25, 31, 493469949, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18b163236723eefd" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0520 21:25:31.497508 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0520 21:25:31.497598 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-20 21:25:31.497592784 +0000 UTC m=+28.366329911 E0520 21:25:31.504893 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0520 21:25:31.537126 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-20 21:25:31.53711706 +0000 UTC m=+28.405854187 I0520 21:25:31.549283 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-20 21:25:31.549270625 +0000 UTC m=+28.418007762 I0520 21:25:31.549380 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:31.549412 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-20 21:25:31.549407016 +0000 UTC m=+28.418144153 I0520 21:25:31.563494 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0520 21:25:31.563584 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-20 21:25:31.563575422 +0000 UTC m=+28.432312559 E0520 21:25:31.608289 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0520 21:25:31.763522 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0520 21:25:31.803906 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-k2fm8" condition "Approved" to 2026-05-20 21:25:31.803897823 +0000 UTC m=+28.672634950 I0520 21:25:31.858842 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-k2fm8" condition "Ready" to 2026-05-20 21:25:31.858831708 +0000 UTC m=+28.727568845 I0520 21:25:31.897916 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:31.897906319 +0000 UTC m=+28.766643446 I0520 21:25:31.934871 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0520 21:25:31.935229 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:31.93522405 +0000 UTC m=+28.803961177 I0520 21:25:31.971456 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0520 21:25:31.979482 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0520 21:25:31.979881 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:31.979859432 +0000 UTC m=+28.848596559 I0520 21:25:32.807202 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-20 21:25:32.807182365 +0000 UTC m=+29.675919522 I0520 21:25:33.379195 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:33.379308 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-20 21:25:33.379299708 +0000 UTC m=+30.248036835 I0520 21:25:33.379370 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-20 21:25:33.379350309 +0000 UTC m=+30.248087476 I0520 21:25:34.164368 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0520 21:25:34.165573 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:34.165609 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-20 21:25:34.165602493 +0000 UTC m=+31.034339640 I0520 21:25:35.418675 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-lfqp4" condition "Approved" to 2026-05-20 21:25:35.418667216 +0000 UTC m=+32.287404363 I0520 21:25:35.463698 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-lfqp4" condition "Ready" to 2026-05-20 21:25:35.463686686 +0000 UTC m=+32.332423813 I0520 21:25:35.520619 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:35.520608375 +0000 UTC m=+32.389345502 I0520 21:25:35.552212 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0520 21:25:35.552893 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:35.552887176 +0000 UTC m=+32.421624303 I0520 21:25:35.581165 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0520 21:25:35.588739 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-20 21:25:35.588730656 +0000 UTC m=+32.457467793 I0520 21:25:35.607863 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-20 21:25:35.607840114 +0000 UTC m=+32.476577261 I0520 21:25:35.607962 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:35.607996 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-20 21:25:35.607989276 +0000 UTC m=+32.476726413 I0520 21:25:35.629994 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0520 21:25:35.630070 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:35.630093 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-20 21:25:35.630085095 +0000 UTC m=+32.498822242 I0520 21:25:35.963214 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-20 21:25:35.963204099 +0000 UTC m=+32.831941236 I0520 21:25:35.986110 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-20 21:25:35.98609904 +0000 UTC m=+32.854836187 I0520 21:25:35.987226 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:35.987331 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-20 21:25:35.987265192 +0000 UTC m=+32.856002329 I0520 21:25:36.003426 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0520 21:25:36.003532 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0520 21:25:36.003571 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-20 21:25:36.003556849 +0000 UTC m=+32.872294006 I0520 21:25:36.091529 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-bzk9k" condition "Approved" to 2026-05-20 21:25:36.091520653 +0000 UTC m=+32.960257780 I0520 21:25:36.142860 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-bzk9k" condition "Ready" to 2026-05-20 21:25:36.142850019 +0000 UTC m=+33.011587166 I0520 21:25:36.225881 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:36.22586576 +0000 UTC m=+33.094602917 I0520 21:25:36.267020 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0520 21:25:36.299973 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-5l2ds" condition "Approved" to 2026-05-20 21:25:36.299964663 +0000 UTC m=+33.168701790 I0520 21:25:36.321105 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-5l2ds" condition "Ready" to 2026-05-20 21:25:36.321093952 +0000 UTC m=+33.189831079 I0520 21:25:36.395520 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:36.395507689 +0000 UTC m=+33.264244826 I0520 21:25:36.430996 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0520 21:25:36.431299 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 21:25:36.431293507 +0000 UTC m=+33.300030644 I0520 21:25:36.621546 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0520 21:26:54.500837 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0520 21:26:54.541094 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-20 21:26:54.541078491 +0000 UTC m=+111.409815628 I0520 21:26:54.561742 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-20 21:26:54.561729962 +0000 UTC m=+111.430467099 E0520 21:26:56.661500 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0520 21:26:56.699887 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-20 21:26:56.699875033 +0000 UTC m=+113.568612170 I0520 21:26:56.718666 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-20 21:26:56.718647337 +0000 UTC m=+113.587384514 E0520 21:26:58.306112 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0520 21:26:58.351119 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-20 21:26:58.351103571 +0000 UTC m=+115.219840738 I0520 21:26:58.372356 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-20 21:26:58.372341956 +0000 UTC m=+115.241079093 E0520 21:27:00.267566 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0520 21:27:00.306485 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-20 21:27:00.3064734 +0000 UTC m=+117.175210537 I0520 21:27:00.327601 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-20 21:27:00.327591034 +0000 UTC m=+117.196328171