I0327 01:57:25.588752 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0327 01:57:25.588954 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0327 01:57:25.589021 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0327 01:57:25.596532 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0327 01:57:25.597081 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0327 01:57:25.597192 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0327 01:57:25.597196 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0327 01:57:25.599694 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0327 01:57:25.614766 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0327 01:57:25.618398 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0327 01:57:25.620812 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0327 01:57:25.623245 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0327 01:57:25.623271 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0327 01:57:25.623400 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0327 01:57:25.623280 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0327 01:57:25.629170 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0327 01:57:25.631621 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0327 01:57:25.634008 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0327 01:57:25.635998 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0327 01:57:25.637748 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0327 01:57:25.639665 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0327 01:57:25.641470 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0327 01:57:25.644152 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0327 01:57:25.644478 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0327 01:57:25.649834 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0327 01:57:25.649907 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0327 01:57:25.652547 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0327 01:57:25.654963 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0327 01:57:25.657420 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0327 01:57:25.659466 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0327 01:57:25.659563 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0327 01:57:25.661476 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0327 01:57:25.664167 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0327 01:57:25.665964 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.666499 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.667193 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.667735 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.694695 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.706183 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.726126 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.742034 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.758942 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:25.768747 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0327 01:57:38.015911 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-03-27 01:57:38.015893221 +0000 UTC m=+12.460492255 I0327 01:57:38.707263 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 01:57:38.707336 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-27 01:57:38.707325779 +0000 UTC m=+13.151924813 I0327 01:57:38.707526 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-03-27 01:57:38.707518994 +0000 UTC m=+13.152118028 E0327 01:57:38.724260 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0327 01:57:38.724366 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-03-27 01:57:38.72435712 +0000 UTC m=+13.168956124 E0327 01:57:38.724395 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0327 01:57:38.725346 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:57:38.725539 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 01:57:38.725601 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-27 01:57:38.725570674 +0000 UTC m=+13.170169678 E0327 01:57:38.734631 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0327 01:57:38.735039 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0327 01:57:38.735263 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0327 01:57:38.735533 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0327 01:57:38.770038 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-7p75p" condition "Approved" to 2026-03-27 01:57:38.770022552 +0000 UTC m=+13.214621586 I0327 01:57:38.784862 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-7p75p" condition "Ready" to 2026-03-27 01:57:38.784851162 +0000 UTC m=+13.229450166 I0327 01:57:38.807625 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:57:38.807567625 +0000 UTC m=+13.252166629 I0327 01:57:38.828065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:57:38.828344 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:57:38.828336723 +0000 UTC m=+13.272935727 I0327 01:57:38.841498 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:57:38.844749 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:57:38.845034 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:57:38.845026165 +0000 UTC m=+13.289625169 I0327 01:57:43.736496 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:57:43.736431712 +0000 UTC m=+18.181030756 I0327 01:58:04.141858 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-03-27 01:58:04.141799419 +0000 UTC m=+38.586398443 I0327 01:58:04.142048 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 01:58:04.142158 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-03-27 01:58:04.142148429 +0000 UTC m=+38.586747463 I0327 01:58:04.153341 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-03-27 01:58:04.153327801 +0000 UTC m=+38.597926815 I0327 01:58:04.165208 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:58:04.165282 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-03-27 01:58:04.165275954 +0000 UTC m=+38.609874958 I0327 01:58:04.544704 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:58:04.577847 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2d45l" condition "Approved" to 2026-03-27 01:58:04.577837241 +0000 UTC m=+39.022436245 I0327 01:58:04.611821 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-2d45l" condition "Ready" to 2026-03-27 01:58:04.61180744 +0000 UTC m=+39.056406474 I0327 01:58:04.642506 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:58:04.642486306 +0000 UTC m=+39.087085330 I0327 01:58:04.668270 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:58:04.668605 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:58:04.668596755 +0000 UTC m=+39.113195759 I0327 01:58:04.687145 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:58:04.687974 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:58:04.687964936 +0000 UTC m=+39.132563940 I0327 01:59:38.690595 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 01:59:38.690644 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-03-27 01:59:38.690632443 +0000 UTC m=+133.135231477 I0327 01:59:38.690616 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-03-27 01:59:38.690522569 +0000 UTC m=+133.135121593 I0327 01:59:38.709507 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:38.709566 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-03-27 01:59:38.709559875 +0000 UTC m=+133.154158879 E0327 01:59:38.711021 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0327 01:59:38.711153 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-03-27 01:59:38.711136609 +0000 UTC m=+133.155735633 I0327 01:59:38.711261 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0327 01:59:38.725461 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0327 01:59:38.725590 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0327 01:59:38.725628 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 01:59:38.725659 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-03-27 01:59:38.725653939 +0000 UTC m=+133.170252943 I0327 01:59:38.725548 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-03-27 01:59:38.725536256 +0000 UTC m=+133.170135250 I0327 01:59:38.725635 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0327 01:59:38.725802 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0327 01:59:38.743786 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:38.743886 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-03-27 01:59:38.743878023 +0000 UTC m=+133.188477027 I0327 01:59:38.846397 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:38.877232 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-7rh4x" condition "Approved" to 2026-03-27 01:59:38.877211873 +0000 UTC m=+133.321810897 I0327 01:59:38.903240 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-7rh4x" condition "Ready" to 2026-03-27 01:59:38.903229471 +0000 UTC m=+133.347828465 I0327 01:59:38.931606 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:59:38.931582874 +0000 UTC m=+133.376181908 I0327 01:59:38.949212 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:38.949745 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:59:38.949735175 +0000 UTC m=+133.394334199 I0327 01:59:38.966698 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:38.971786 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:39.386049 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0327 01:59:39.423845 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-qplqn" condition "Approved" to 2026-03-27 01:59:39.423818352 +0000 UTC m=+133.868417386 I0327 01:59:39.440460 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-qplqn" condition "Ready" to 2026-03-27 01:59:39.440435641 +0000 UTC m=+133.885034675 I0327 01:59:43.726276 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:59:43.726267933 +0000 UTC m=+138.170866927 I0327 01:59:43.748731 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-qplqn" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:59:43.748718013 +0000 UTC m=+138.193317017 I0327 01:59:43.793963 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 01:59:43.793951191 +0000 UTC m=+138.238550185 I0327 01:59:43.847705 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:02:16.142643 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.162-253-55-62.nip.io-tls" condition "Ready" to 2026-03-27 02:02:16.142601786 +0000 UTC m=+290.587200810 I0327 02:02:16.142728 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.162-253-55-62.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:02:16.142771 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.162-253-55-62.nip.io-tls" condition "Issuing" to 2026-03-27 02:02:16.142758461 +0000 UTC m=+290.587357515 I0327 02:02:16.161217 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.162-253-55-62.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.162-253-55-62.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:02:16.161290 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.162-253-55-62.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:02:16.161311 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.162-253-55-62.nip.io-tls" condition "Issuing" to 2026-03-27 02:02:16.161304363 +0000 UTC m=+290.605903397 I0327 02:02:16.323860 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.162-253-55-62.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.162-253-55-62.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:02:16.336127 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.162-253-55-62.nip.io-tls-zdcsv" condition "Approved" to 2026-03-27 02:02:16.336108666 +0000 UTC m=+290.780707690 I0327 02:02:16.357200 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.162-253-55-62.nip.io-tls-zdcsv" condition "Ready" to 2026-03-27 02:02:16.357183207 +0000 UTC m=+290.801782231 I0327 02:02:16.386376 1 conditions.go:192] Found status change for Certificate "keycloak.162-253-55-62.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:02:16.386364169 +0000 UTC m=+290.830963163 I0327 02:02:16.404770 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.162-253-55-62.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.162-253-55-62.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:03:27.522349 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:03:27.522406 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-03-27 02:03:27.522394502 +0000 UTC m=+361.966993536 I0327 02:03:27.522345 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-03-27 02:03:27.522312069 +0000 UTC m=+361.966911103 E0327 02:03:27.533601 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0327 02:03:27.533767 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-03-27 02:03:27.533747801 +0000 UTC m=+361.978346845 E0327 02:03:27.533935 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0327 02:03:27.536108 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:03:27.536172 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:03:27.536189 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-03-27 02:03:27.536182818 +0000 UTC m=+361.980781812 E0327 02:03:27.543681 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0327 02:03:27.543822 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0327 02:03:27.543889 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0327 02:03:27.543964 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0327 02:03:27.572463 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-8scxf" condition "Approved" to 2026-03-27 02:03:27.572447526 +0000 UTC m=+362.017046550 I0327 02:03:27.584557 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-8scxf" condition "Ready" to 2026-03-27 02:03:27.584540896 +0000 UTC m=+362.029139930 I0327 02:03:27.606457 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:03:27.606437463 +0000 UTC m=+362.051036487 I0327 02:03:27.625543 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:03:27.663231 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:03:32.544890 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:03:32.544875867 +0000 UTC m=+366.989474891 I0327 02:04:10.149119 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:10.149156 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-03-27 02:04:10.149149035 +0000 UTC m=+404.593748029 I0327 02:04:10.149339 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-03-27 02:04:10.14932046 +0000 UTC m=+404.593919484 I0327 02:04:10.151170 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:10.151398 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-03-27 02:04:10.151366966 +0000 UTC m=+404.595965970 I0327 02:04:10.151469 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-03-27 02:04:10.151463668 +0000 UTC m=+404.596062652 I0327 02:04:10.151551 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-03-27 02:04:10.151477689 +0000 UTC m=+404.596076743 I0327 02:04:10.151627 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:10.151638 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-03-27 02:04:10.151635763 +0000 UTC m=+404.596234757 I0327 02:04:10.200541 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.200597 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-03-27 02:04:10.200590368 +0000 UTC m=+404.645189362 I0327 02:04:10.201024 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.201063 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:10.201082 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-03-27 02:04:10.201078412 +0000 UTC m=+404.645677406 I0327 02:04:10.240097 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.240342 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:10.240425 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-03-27 02:04:10.240419164 +0000 UTC m=+404.685018168 I0327 02:04:10.440348 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.458820 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.465698 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6bpc9" condition "Approved" to 2026-03-27 02:04:10.465688866 +0000 UTC m=+404.910287870 I0327 02:04:10.485683 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-6bpc9" condition "Ready" to 2026-03-27 02:04:10.485673031 +0000 UTC m=+404.930272035 I0327 02:04:10.489958 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-wt46k" condition "Approved" to 2026-03-27 02:04:10.489950048 +0000 UTC m=+404.934549042 I0327 02:04:10.505741 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-wt46k" condition "Ready" to 2026-03-27 02:04:10.505731698 +0000 UTC m=+404.950330702 I0327 02:04:10.521306 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:10.521291622 +0000 UTC m=+404.965890626 I0327 02:04:10.542422 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:10.542409897 +0000 UTC m=+404.987008881 I0327 02:04:10.544851 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.563458 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.564013 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:10.564003887 +0000 UTC m=+405.008602921 I0327 02:04:10.636047 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:10.636558 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:10.636487403 +0000 UTC m=+405.081086437 I0327 02:04:10.835689 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:11.139597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:11.192684 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-s9tlh" condition "Approved" to 2026-03-27 02:04:11.192663539 +0000 UTC m=+405.637262563 I0327 02:04:11.346587 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-s9tlh" condition "Ready" to 2026-03-27 02:04:11.346571584 +0000 UTC m=+405.791170578 I0327 02:04:11.789634 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:11.789617215 +0000 UTC m=+406.234216219 I0327 02:04:11.886588 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:11.886981 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:11.886974059 +0000 UTC m=+406.331573063 I0327 02:04:12.088373 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:12.189715 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:17.804883 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:17.804926 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" condition "Issuing" to 2026-03-27 02:04:17.804914691 +0000 UTC m=+412.249513725 I0327 02:04:17.805662 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" condition "Ready" to 2026-03-27 02:04:17.805652151 +0000 UTC m=+412.250251185 I0327 02:04:17.820913 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:17.821085 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:17.821128 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" condition "Issuing" to 2026-03-27 02:04:17.821116034 +0000 UTC m=+412.265715058 I0327 02:04:18.141313 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-g5nqs-4gv4t" condition "Approved" to 2026-03-27 02:04:18.141293243 +0000 UTC m=+412.585892247 I0327 02:04:18.156538 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-g5nqs-4gv4t" condition "Ready" to 2026-03-27 02:04:18.156525903 +0000 UTC m=+412.601124907 I0327 02:04:18.183218 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:18.18320371 +0000 UTC m=+412.627802694 I0327 02:04:18.205182 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g5nqs-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:45.879116 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:04:45.879174 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-03-27 02:04:45.879161607 +0000 UTC m=+440.323760611 I0327 02:04:45.879727 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-03-27 02:04:45.878956022 +0000 UTC m=+440.323555046 I0327 02:04:45.895230 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:45.895336 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-03-27 02:04:45.895326453 +0000 UTC m=+440.339925457 I0327 02:04:46.170059 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:46.214629 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-drkl9" condition "Approved" to 2026-03-27 02:04:46.214612897 +0000 UTC m=+440.659211931 I0327 02:04:46.236259 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-drkl9" condition "Ready" to 2026-03-27 02:04:46.236244495 +0000 UTC m=+440.680843519 I0327 02:04:46.269871 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:46.269846353 +0000 UTC m=+440.714445347 I0327 02:04:46.286240 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:46.286702 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:04:46.286688367 +0000 UTC m=+440.731287371 I0327 02:04:46.304820 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:04:46.305990 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:08:04.791993 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-03-27 02:08:04.791924902 +0000 UTC m=+639.236523916 I0327 02:08:04.792546 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:08:04.792642 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-03-27 02:08:04.792633212 +0000 UTC m=+639.237232236 I0327 02:08:04.812643 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:08:04.812709 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-03-27 02:08:04.812701827 +0000 UTC m=+639.257300831 I0327 02:08:04.925718 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:08:04.957460 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zrrhq" condition "Approved" to 2026-03-27 02:08:04.957450672 +0000 UTC m=+639.402049676 I0327 02:08:04.978032 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zrrhq" condition "Ready" to 2026-03-27 02:08:04.978023311 +0000 UTC m=+639.422622305 I0327 02:08:05.000880 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:08:05.000868844 +0000 UTC m=+639.445467848 I0327 02:08:05.022902 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:08:05.023270 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:08:05.023262934 +0000 UTC m=+639.467861938 I0327 02:08:05.033078 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:08:05.043360 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:10:19.572603 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-03-27 02:10:19.572576568 +0000 UTC m=+774.017175562 I0327 02:10:19.572848 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:10:19.573002 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-03-27 02:10:19.572988129 +0000 UTC m=+774.017587203 I0327 02:10:19.590260 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:10:19.590357 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:10:19.590392 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-03-27 02:10:19.590384157 +0000 UTC m=+774.034983161 I0327 02:10:19.949101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:10:19.954050 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-n4bqj" condition "Approved" to 2026-03-27 02:10:19.954037975 +0000 UTC m=+774.398636979 I0327 02:10:19.969289 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-n4bqj" condition "Ready" to 2026-03-27 02:10:19.969279604 +0000 UTC m=+774.413878608 I0327 02:10:19.999990 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:10:19.999977878 +0000 UTC m=+774.444576882 I0327 02:10:20.022892 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:10:20.023205 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:10:20.023199867 +0000 UTC m=+774.467798861 I0327 02:10:20.052328 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:11:23.883490 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-03-27 02:11:23.883477261 +0000 UTC m=+838.328076255 I0327 02:11:23.883986 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:11:23.884019 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-03-27 02:11:23.884016576 +0000 UTC m=+838.328615570 I0327 02:11:23.914380 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:11:23.914474 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-03-27 02:11:23.914462771 +0000 UTC m=+838.359061795 I0327 02:11:24.083553 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:11:24.116109 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-l4d9h" condition "Approved" to 2026-03-27 02:11:24.116096008 +0000 UTC m=+838.560695002 I0327 02:11:24.133289 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-l4d9h" condition "Ready" to 2026-03-27 02:11:24.133278239 +0000 UTC m=+838.577877243 I0327 02:11:24.172155 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:11:24.172138324 +0000 UTC m=+838.616737348 I0327 02:11:24.198871 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:11:24.199176 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:11:24.199168884 +0000 UTC m=+838.643767908 I0327 02:11:24.230190 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:11:24.230627 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:11:24.230618456 +0000 UTC m=+838.675217460 I0327 02:14:07.766036 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-03-27 02:14:07.766013759 +0000 UTC m=+1002.210612783 I0327 02:14:07.766309 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:14:07.766404 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-03-27 02:14:07.766393989 +0000 UTC m=+1002.210993013 I0327 02:14:07.785775 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:14:07.785894 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0327 02:14:07.785914 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-03-27 02:14:07.785906627 +0000 UTC m=+1002.230505631 I0327 02:14:08.018898 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-rk659" condition "Approved" to 2026-03-27 02:14:08.018885886 +0000 UTC m=+1002.463484900 I0327 02:14:08.036533 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-rk659" condition "Ready" to 2026-03-27 02:14:08.036519154 +0000 UTC m=+1002.481118178 I0327 02:14:08.071068 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:14:08.071056006 +0000 UTC m=+1002.515655010 I0327 02:14:08.094046 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0327 02:14:08.094369 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-27 02:14:08.094363579 +0000 UTC m=+1002.538962573 I0327 02:14:08.114115 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"