I0420 01:59:39.976407 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0420 01:59:39.976558 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0420 01:59:39.976665 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 01:59:39.980650 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0420 01:59:39.981028 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0420 01:59:39.981091 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0420 01:59:39.981125 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0420 01:59:39.983729 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 01:59:39.998012 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0420 01:59:40.001330 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0420 01:59:40.003529 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0420 01:59:40.003558 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0420 01:59:40.003709 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0420 01:59:40.006186 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0420 01:59:40.008220 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0420 01:59:40.010421 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0420 01:59:40.014197 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0420 01:59:40.014233 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0420 01:59:40.014280 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0420 01:59:40.016972 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0420 01:59:40.019570 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0420 01:59:40.022020 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0420 01:59:40.024107 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0420 01:59:40.025881 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0420 01:59:40.027736 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0420 01:59:40.029564 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0420 01:59:40.035901 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0420 01:59:40.035988 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0420 01:59:40.039767 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0420 01:59:40.042938 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0420 01:59:40.045117 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0420 01:59:40.045260 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0420 01:59:40.048204 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0420 01:59:40.050811 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.051018 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.051545 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.051965 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.076397 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.093940 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.109755 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.121304 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.136439 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:40.138832 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 01:59:51.199366 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-20 01:59:51.199347963 +0000 UTC m=+11.259537691 I0420 01:59:51.926875 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-20 01:59:51.926861139 +0000 UTC m=+11.987050857 I0420 01:59:51.927932 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 01:59:51.927970 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 01:59:51.927961441 +0000 UTC m=+11.988151159 I0420 01:59:51.945757 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 01:59:51.945817 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 01:59:51.945833 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 01:59:51.945827286 +0000 UTC m=+12.006016974 E0420 01:59:51.946042 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 01:59:51.946120 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-20 01:59:51.946112747 +0000 UTC m=+12.006302435 E0420 01:59:51.946148 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 01:59:51.961495 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0420 01:59:51.961662 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 01:59:51.961819 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 01:59:51.961972 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0420 01:59:51.992760 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rnsft" condition "Approved" to 2026-04-20 01:59:51.99274972 +0000 UTC m=+12.052939418 I0420 01:59:52.004305 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rnsft" condition "Ready" to 2026-04-20 01:59:52.004294926 +0000 UTC m=+12.064484634 I0420 01:59:52.028384 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 01:59:52.028369646 +0000 UTC m=+12.088559334 I0420 01:59:52.046070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 01:59:56.962026 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 01:59:56.962012708 +0000 UTC m=+17.022202426 I0420 02:00:21.213899 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:00:21.213946 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 02:00:21.213928742 +0000 UTC m=+41.274118460 I0420 02:00:21.213960 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 02:00:21.213951913 +0000 UTC m=+41.274141601 I0420 02:00:21.226721 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-20 02:00:21.226709783 +0000 UTC m=+41.286899471 I0420 02:00:21.241187 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:00:21.241237 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:00:21.241251 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 02:00:21.241245754 +0000 UTC m=+41.301435442 I0420 02:00:21.595340 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-54f5g" condition "Approved" to 2026-04-20 02:00:21.595327832 +0000 UTC m=+41.655517530 I0420 02:00:21.642654 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-54f5g" condition "Ready" to 2026-04-20 02:00:21.642641365 +0000 UTC m=+41.702831063 I0420 02:00:21.708013 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:00:21.708002974 +0000 UTC m=+41.768192662 I0420 02:00:21.747465 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:00:21.748299 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:00:21.748285044 +0000 UTC m=+41.808474762 I0420 02:00:21.770204 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:04:50.738743 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-144.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:04:50.738803 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-144.nip.io-tls" condition "Issuing" to 2026-04-20 02:04:50.73878005 +0000 UTC m=+310.798969758 I0420 02:04:50.739199 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-144.nip.io-tls" condition "Ready" to 2026-04-20 02:04:50.739190096 +0000 UTC m=+310.799379784 I0420 02:04:50.762533 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-144.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-144.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:04:50.762620 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-144.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:04:50.762635 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-144.nip.io-tls" condition "Issuing" to 2026-04-20 02:04:50.76262884 +0000 UTC m=+310.822818538 I0420 02:04:50.942683 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-144.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-144.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:04:50.947853 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-144.nip.io-tls-bkxtl" condition "Approved" to 2026-04-20 02:04:50.947840357 +0000 UTC m=+311.008030085 I0420 02:04:50.977729 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-144.nip.io-tls-bkxtl" condition "Ready" to 2026-04-20 02:04:50.977720436 +0000 UTC m=+311.037910124 I0420 02:04:51.005047 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-144.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:04:51.005037151 +0000 UTC m=+311.065226849 I0420 02:04:51.021370 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-144.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-144.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:05:51.824731 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:05:51.824723 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-20 02:05:51.824683569 +0000 UTC m=+371.884873347 I0420 02:05:51.824769 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 02:05:51.824762872 +0000 UTC m=+371.884952570 E0420 02:05:51.838037 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 02:05:51.838089 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-20 02:05:51.83807832 +0000 UTC m=+371.898268028 E0420 02:05:51.838152 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 02:05:51.847659 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:05:51.847763 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:05:51.847787 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 02:05:51.847779924 +0000 UTC m=+371.907969622 E0420 02:05:51.856003 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0420 02:05:51.856199 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:05:51.856274 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:05:51.856355 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0420 02:05:51.881051 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:05:51.885830 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-c8m82" condition "Approved" to 2026-04-20 02:05:51.885816034 +0000 UTC m=+371.946005732 I0420 02:05:51.896884 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-c8m82" condition "Ready" to 2026-04-20 02:05:51.896872158 +0000 UTC m=+371.957061856 I0420 02:05:51.917496 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:05:51.917481323 +0000 UTC m=+371.977671021 I0420 02:05:51.935323 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:05:56.856550 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:05:56.856532749 +0000 UTC m=+376.916722477 I0420 02:06:38.677216 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 02:06:38.677186162 +0000 UTC m=+418.737375850 I0420 02:06:38.677566 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.677590 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 02:06:38.677585922 +0000 UTC m=+418.737775630 I0420 02:06:38.677963 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.678691 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-20 02:06:38.678683978 +0000 UTC m=+418.738873676 I0420 02:06:38.680389 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 02:06:38.678414632 +0000 UTC m=+418.738604330 I0420 02:06:38.706072 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.706106 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 02:06:38.706099196 +0000 UTC m=+418.766288894 I0420 02:06:38.706377 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-20 02:06:38.706371332 +0000 UTC m=+418.766561020 I0420 02:06:38.731283 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.731640 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.731711 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.731738 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-20 02:06:38.731732189 +0000 UTC m=+418.791921877 I0420 02:06:38.732060 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.737954 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 02:06:38.73793733 +0000 UTC m=+418.798127018 I0420 02:06:38.738169 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.738241 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 02:06:38.738234259 +0000 UTC m=+418.798423947 I0420 02:06:38.995740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.996962 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:39.028154 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-86rfw" condition "Approved" to 2026-04-20 02:06:39.028141181 +0000 UTC m=+419.088330879 I0420 02:06:39.044623 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-86rfw" condition "Ready" to 2026-04-20 02:06:39.044612681 +0000 UTC m=+419.104802369 I0420 02:06:39.054200 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-plnmm" condition "Approved" to 2026-04-20 02:06:39.054192733 +0000 UTC m=+419.114382421 I0420 02:06:39.105552 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-nfr9f" condition "Approved" to 2026-04-20 02:06:39.10553946 +0000 UTC m=+419.165729158 I0420 02:06:39.105850 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-plnmm" condition "Ready" to 2026-04-20 02:06:39.105841287 +0000 UTC m=+419.166030975 I0420 02:06:39.125755 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:39.12574159 +0000 UTC m=+419.185931288 I0420 02:06:39.132383 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-nfr9f" condition "Ready" to 2026-04-20 02:06:39.13237377 +0000 UTC m=+419.192563458 I0420 02:06:39.254210 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:39.254922 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:39.254911704 +0000 UTC m=+419.315101432 I0420 02:06:39.354718 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:39.354710026 +0000 UTC m=+419.414899714 E0420 02:06:39.454299 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"alertmanager-tls-4br4x\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" I0420 02:06:39.820585 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:39.820959 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:39.820953069 +0000 UTC m=+419.881142767 I0420 02:06:39.857505 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:39.857487255 +0000 UTC m=+419.917676983 I0420 02:06:39.908235 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:39.954635 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:40.211009 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:40.211950 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:40.211940502 +0000 UTC m=+420.272130200 I0420 02:06:40.305118 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:40.655836 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:40.705098 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:44.919323 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" condition "Ready" to 2026-04-20 02:06:44.919282316 +0000 UTC m=+424.979472044 I0420 02:06:44.920788 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:44.920823 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" condition "Issuing" to 2026-04-20 02:06:44.920815333 +0000 UTC m=+424.981005071 I0420 02:06:44.939438 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:44.939526 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:44.939545 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" condition "Issuing" to 2026-04-20 02:06:44.93953913 +0000 UTC m=+424.999728828 I0420 02:06:45.231005 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-x8wpk-vhknd" condition "Approved" to 2026-04-20 02:06:45.230994066 +0000 UTC m=+425.291183754 I0420 02:06:45.253935 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-x8wpk-vhknd" condition "Ready" to 2026-04-20 02:06:45.253923483 +0000 UTC m=+425.314113181 I0420 02:06:45.286107 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:45.286091141 +0000 UTC m=+425.346280849 I0420 02:06:45.318870 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-x8wpk-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:07:01.519435 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 02:07:01.519393368 +0000 UTC m=+441.579583056 I0420 02:07:01.519510 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:07:01.519549 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 02:07:01.519541661 +0000 UTC m=+441.579731349 I0420 02:07:01.542694 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:07:01.542773 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 02:07:01.542765661 +0000 UTC m=+441.602955359 I0420 02:07:01.618718 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:07:01.658580 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-4vhg6" condition "Approved" to 2026-04-20 02:07:01.658570636 +0000 UTC m=+441.718760334 I0420 02:07:01.684119 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-4vhg6" condition "Ready" to 2026-04-20 02:07:01.684109649 +0000 UTC m=+441.744299337 I0420 02:07:01.731999 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:07:01.731985003 +0000 UTC m=+441.792174701 I0420 02:07:01.757536 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:10.374373 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-20 02:10:10.374336411 +0000 UTC m=+630.434526119 I0420 02:10:10.374728 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:10:10.374801 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 02:10:10.374793349 +0000 UTC m=+630.434983047 I0420 02:10:10.389476 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:10.389543 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:10:10.389558 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 02:10:10.389551679 +0000 UTC m=+630.449741377 I0420 02:10:10.522481 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:10.532859 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-bbs9c" condition "Approved" to 2026-04-20 02:10:10.532849234 +0000 UTC m=+630.593038932 I0420 02:10:10.551833 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-bbs9c" condition "Ready" to 2026-04-20 02:10:10.551819865 +0000 UTC m=+630.612009553 I0420 02:10:10.583399 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:10:10.583384992 +0000 UTC m=+630.643574690 I0420 02:10:10.608657 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:10.609015 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:10:10.609008367 +0000 UTC m=+630.669198065 I0420 02:10:10.626727 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:49.689687 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-20 02:10:49.689169567 +0000 UTC m=+669.749359265 I0420 02:10:49.693309 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:10:49.694097 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-20 02:10:49.693345887 +0000 UTC m=+669.753535605 I0420 02:10:49.711956 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:10:49.712276 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:10:49.712445 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-20 02:10:49.712435082 +0000 UTC m=+669.772624780 I0420 02:10:49.939499 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ph98z" condition "Approved" to 2026-04-20 02:10:49.939468995 +0000 UTC m=+669.999658693 I0420 02:10:49.957166 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ph98z" condition "Ready" to 2026-04-20 02:10:49.957149857 +0000 UTC m=+670.017339555 I0420 02:10:49.988956 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:10:49.988942802 +0000 UTC m=+670.049132500 I0420 02:10:50.015984 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"