I0505 13:45:17.071930 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0505 13:45:17.072041 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0505 13:45:17.072092 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0505 13:45:17.074346 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0505 13:45:17.074656 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0505 13:45:17.074781 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0505 13:45:17.074807 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0505 13:45:17.076401 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0505 13:45:17.090391 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0505 13:45:17.095987 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0505 13:45:17.103052 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0505 13:45:17.106335 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0505 13:45:17.109065 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0505 13:45:17.109145 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0505 13:45:17.111494 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0505 13:45:17.113556 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0505 13:45:17.115409 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0505 13:45:17.115433 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0505 13:45:17.115656 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0505 13:45:17.118781 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0505 13:45:17.123097 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0505 13:45:17.125833 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0505 13:45:17.125931 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0505 13:45:17.128484 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0505 13:45:17.130814 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0505 13:45:17.132763 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0505 13:45:17.134427 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0505 13:45:17.134448 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0505 13:45:17.134531 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0505 13:45:17.136436 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0505 13:45:17.140584 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0505 13:45:17.146357 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0505 13:45:17.151649 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0505 13:45:17.153944 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.155321 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.155754 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.175795 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.193867 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.209096 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.248168 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.248995 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.269988 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:17.335778 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 13:45:32.628201 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-05 13:45:32.628189047 +0000 UTC m=+15.596120931 I0505 13:45:33.351170 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 13:45:33.351228 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-05 13:45:33.351213947 +0000 UTC m=+16.319145871 I0505 13:45:33.351748 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 13:45:33.351723886 +0000 UTC m=+16.319655800 I0505 13:45:33.374354 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:45:33.374437 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 13:45:33.374425307 +0000 UTC m=+16.342357201 E0505 13:45:33.375479 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 13:45:33.375550 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-05 13:45:33.37554012 +0000 UTC m=+16.343472004 E0505 13:45:33.375580 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 13:45:33.398418 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0505 13:45:33.398661 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 13:45:33.398708 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 13:45:33.398806 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0505 13:45:33.398978 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:45:33.432599 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-5bjcv" condition "Approved" to 2026-05-05 13:45:33.432577954 +0000 UTC m=+16.400509848 I0505 13:45:33.447925 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-5bjcv" condition "Ready" to 2026-05-05 13:45:33.447910526 +0000 UTC m=+16.415842410 I0505 13:45:33.475824 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:45:33.475808365 +0000 UTC m=+16.443740279 I0505 13:45:33.501140 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:45:33.501505 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:45:33.501496319 +0000 UTC m=+16.469428213 I0505 13:45:33.504011 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:45:33.512080 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:45:33.512243 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:45:33.512237357 +0000 UTC m=+16.480169251 I0505 13:45:38.399286 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:45:38.399244233 +0000 UTC m=+21.367176147 I0505 13:46:07.480243 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 13:46:07.480290 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 13:46:07.480281368 +0000 UTC m=+50.448213262 I0505 13:46:07.481165 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 13:46:07.481152361 +0000 UTC m=+50.449084285 I0505 13:46:07.510381 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-05 13:46:07.510367527 +0000 UTC m=+50.478299421 I0505 13:46:07.513952 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:46:07.514058 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 13:46:07.514082 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 13:46:07.514077909 +0000 UTC m=+50.482009793 I0505 13:46:07.691285 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:46:07.699702 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-p86qn" condition "Approved" to 2026-05-05 13:46:07.69968989 +0000 UTC m=+50.667621804 I0505 13:46:07.727676 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-p86qn" condition "Ready" to 2026-05-05 13:46:07.727663609 +0000 UTC m=+50.695595493 I0505 13:46:07.776971 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:46:07.776828048 +0000 UTC m=+50.744759952 I0505 13:46:07.813204 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:46:07.813617 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:46:07.813607443 +0000 UTC m=+50.781539337 I0505 13:46:07.821471 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:46:07.832979 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:46:07.833427 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 13:46:07.83341668 +0000 UTC m=+50.801348574