I0511 10:45:30.753703 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0511 10:45:30.753829 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0511 10:45:30.753950 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0511 10:45:30.759904 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0511 10:45:30.760480 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0511 10:45:30.760550 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0511 10:45:30.760544 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0511 10:45:30.765115 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0511 10:45:30.782888 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0511 10:45:30.788846 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0511 10:45:30.791554 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0511 10:45:30.796543 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0511 10:45:30.799322 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0511 10:45:30.801450 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0511 10:45:30.803539 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0511 10:45:30.803573 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0511 10:45:30.803643 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0511 10:45:30.805557 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0511 10:45:30.805766 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0511 10:45:30.807665 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0511 10:45:30.809546 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0511 10:45:30.811922 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0511 10:45:30.818392 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0511 10:45:30.823303 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0511 10:45:30.825366 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0511 10:45:30.827341 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0511 10:45:30.827441 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0511 10:45:30.829403 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0511 10:45:30.829733 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0511 10:45:30.831722 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0511 10:45:30.833682 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0511 10:45:30.833772 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0511 10:45:30.835716 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0511 10:45:30.844395 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.844785 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.845349 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.845759 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.866289 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.879979 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.893514 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.907230 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.933766 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:30.945584 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:45:42.857051 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-11 10:45:42.857023081 +0000 UTC m=+12.146791064 I0511 10:45:43.682216 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:45:43.682263 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-11 10:45:43.682256162 +0000 UTC m=+12.972024125 I0511 10:45:43.683319 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-11 10:45:43.683313724 +0000 UTC m=+12.973081687 E0511 10:45:43.698576 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:45:43.698696 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-11 10:45:43.698686654 +0000 UTC m=+12.988454617 E0511 10:45:43.698746 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:45:43.702621 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:45:43.702693 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-11 10:45:43.702684232 +0000 UTC m=+12.992452185 E0511 10:45:43.709265 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0511 10:45:43.709509 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:45:43.709545 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:45:43.709579 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0511 10:45:43.718343 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:45:43.743763 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-mbmb8" condition "Approved" to 2026-05-11 10:45:43.743743806 +0000 UTC m=+13.033511799 I0511 10:45:43.760020 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-mbmb8" condition "Ready" to 2026-05-11 10:45:43.760007503 +0000 UTC m=+13.049775446 I0511 10:45:43.781029 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:45:43.78102011 +0000 UTC m=+13.070788063 I0511 10:45:43.803242 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:45:48.710058 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:45:48.710044963 +0000 UTC m=+17.999812946 I0511 10:46:13.532635 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-11 10:46:13.532602413 +0000 UTC m=+42.822370406 I0511 10:46:13.532917 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:46:13.532980 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-11 10:46:13.532961131 +0000 UTC m=+42.822729084 I0511 10:46:13.547738 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-11 10:46:13.547728046 +0000 UTC m=+42.837495989 I0511 10:46:13.574919 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:13.575000 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-11 10:46:13.574989987 +0000 UTC m=+42.864757960 I0511 10:46:13.798895 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:13.834373 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-cssth" condition "Approved" to 2026-05-11 10:46:13.834356793 +0000 UTC m=+43.124124776 I0511 10:46:13.874646 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-cssth" condition "Ready" to 2026-05-11 10:46:13.87463262 +0000 UTC m=+43.164400583 I0511 10:46:13.906996 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:13.906983712 +0000 UTC m=+43.196751665 I0511 10:46:13.930735 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:13.932122 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:13.932108775 +0000 UTC m=+43.221876728 I0511 10:46:13.951601 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:13.952025 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:13.952014305 +0000 UTC m=+43.241782268 I0511 10:46:13.955766 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:51:40.972236 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-11.nip.io-tls" condition "Ready" to 2026-05-11 10:51:40.97218365 +0000 UTC m=+370.261951633 I0511 10:51:40.973000 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-11.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:51:40.973031 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-11.nip.io-tls" condition "Issuing" to 2026-05-11 10:51:40.973024468 +0000 UTC m=+370.262792451 I0511 10:51:41.001528 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-11.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-11.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:51:41.001619 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-11.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:51:41.001646 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-11.nip.io-tls" condition "Issuing" to 2026-05-11 10:51:41.00163885 +0000 UTC m=+370.291406833 I0511 10:51:41.186558 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-11.nip.io-tls-kff54" condition "Approved" to 2026-05-11 10:51:41.186545692 +0000 UTC m=+370.476313655 I0511 10:51:41.215426 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-11.nip.io-tls-kff54" condition "Ready" to 2026-05-11 10:51:41.215409767 +0000 UTC m=+370.505177760 I0511 10:51:41.246835 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-11.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:51:41.246823325 +0000 UTC m=+370.536591288 I0511 10:51:41.270408 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-11.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-11.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:51:41.313840 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-11.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-11.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:46.371620 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:52:46.371690 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-11 10:52:46.371652806 +0000 UTC m=+435.661420759 I0511 10:52:46.371727 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-11 10:52:46.371713097 +0000 UTC m=+435.661481100 E0511 10:52:46.384851 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:52:46.384908 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-11 10:52:46.384898201 +0000 UTC m=+435.674666194 E0511 10:52:46.384976 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:52:46.388570 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:46.388642 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:52:46.388673 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-11 10:52:46.388669158 +0000 UTC m=+435.678437121 E0511 10:52:46.395555 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0511 10:52:46.395686 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:52:46.395721 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:52:46.395765 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0511 10:52:46.433544 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-vkfd7" condition "Approved" to 2026-05-11 10:52:46.433532162 +0000 UTC m=+435.723300125 I0511 10:52:46.447052 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-vkfd7" condition "Ready" to 2026-05-11 10:52:46.447044562 +0000 UTC m=+435.736812525 I0511 10:52:46.474511 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:46.474486778 +0000 UTC m=+435.764254741 I0511 10:52:46.494587 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:46.495026 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:46.495018002 +0000 UTC m=+435.784785965 I0511 10:52:46.510458 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:46.510658 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:46.510651319 +0000 UTC m=+435.800419282 I0511 10:52:46.513292 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:51.396337 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:51.396322928 +0000 UTC m=+440.686090921 I0511 10:53:33.403013 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:33.403088 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-11 10:53:33.403055629 +0000 UTC m=+482.692823582 I0511 10:53:33.403305 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-11 10:53:33.403292073 +0000 UTC m=+482.693060026 I0511 10:53:33.410821 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-11 10:53:33.410810917 +0000 UTC m=+482.700578880 I0511 10:53:33.413024 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:33.413063 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-11 10:53:33.413056753 +0000 UTC m=+482.702824696 I0511 10:53:33.413479 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:33.413500 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-11 10:53:33.41349706 +0000 UTC m=+482.703265013 I0511 10:53:33.413512 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-11 10:53:33.41350555 +0000 UTC m=+482.703273513 I0511 10:53:33.440843 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.440883 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-11 10:53:33.440878448 +0000 UTC m=+482.730646401 I0511 10:53:33.455596 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.455636 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-11 10:53:33.45563152 +0000 UTC m=+482.745399463 I0511 10:53:33.456196 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.456226 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:33.456237 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-11 10:53:33.45623497 +0000 UTC m=+482.746002923 I0511 10:53:33.642544 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7v7s4" condition "Approved" to 2026-05-11 10:53:33.642534369 +0000 UTC m=+482.932302342 I0511 10:53:33.662573 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7v7s4" condition "Ready" to 2026-05-11 10:53:33.662563007 +0000 UTC m=+482.952330970 I0511 10:53:33.718302 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:33.718341 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-11 10:53:33.718335549 +0000 UTC m=+483.008103502 I0511 10:53:33.742691 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.745491 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:33.745482354 +0000 UTC m=+483.035250307 E0511 10:53:33.753156 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"grafana-tls-gqblj\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" I0511 10:53:33.761819 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.883194 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:33.926004 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-grkjn" condition "Approved" to 2026-05-11 10:53:33.925980398 +0000 UTC m=+483.215748361 I0511 10:53:33.959677 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-grkjn" condition "Ready" to 2026-05-11 10:53:33.959669319 +0000 UTC m=+483.249437272 I0511 10:53:33.987750 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:33.987738429 +0000 UTC m=+483.277506382 I0511 10:53:34.013830 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:34.014043 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:34.01403859 +0000 UTC m=+483.303806543 I0511 10:53:34.183590 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:34.280320 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:34.535552 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rq74q" condition "Approved" to 2026-05-11 10:53:34.535536964 +0000 UTC m=+483.825304927 I0511 10:53:34.947011 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rq74q" condition "Ready" to 2026-05-11 10:53:34.947000769 +0000 UTC m=+484.236768732 E0511 10:53:34.972437 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-s6vsj\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0511 10:53:35.178369 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" resource_name="prometheus-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="prometheus-tls-rq74q" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="prometheus-tls-8lvq6" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0511 10:53:35.343365 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-x4jpl" condition "Approved" to 2026-05-11 10:53:35.343346248 +0000 UTC m=+484.633114231 I0511 10:53:35.390630 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-x4jpl" condition "Ready" to 2026-05-11 10:53:35.39062024 +0000 UTC m=+484.680388203 I0511 10:53:35.980444 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:35.980420977 +0000 UTC m=+485.270188940 I0511 10:53:36.007428 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.170950 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.170977 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" condition "Issuing" to 2026-05-11 10:53:42.170968528 +0000 UTC m=+491.460736481 I0511 10:53:42.171303 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" condition "Ready" to 2026-05-11 10:53:42.171300023 +0000 UTC m=+491.461067976 I0511 10:53:42.186668 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n64gl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.186736 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" condition "Ready" to 2026-05-11 10:53:42.186729012 +0000 UTC m=+491.476496975 I0511 10:53:42.551160 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n64gl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.678639 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-n64gl-rlsg2" condition "Approved" to 2026-05-11 10:53:42.678620652 +0000 UTC m=+491.968388615 I0511 10:53:42.974950 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-n64gl-rlsg2" condition "Ready" to 2026-05-11 10:53:42.974941032 +0000 UTC m=+492.264708985 I0511 10:53:43.015861 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.015847172 +0000 UTC m=+492.305615145 I0511 10:53:43.039676 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n64gl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.039947 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.039940861 +0000 UTC m=+492.329708814 I0511 10:53:43.054832 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n64gl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n64gl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:56.322156 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:56.322183 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-11 10:53:56.322177281 +0000 UTC m=+505.611945224 I0511 10:53:56.322220 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-11 10:53:56.322205101 +0000 UTC m=+505.611973054 I0511 10:53:56.346324 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:56.346408 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-11 10:53:56.346399025 +0000 UTC m=+505.636166988 I0511 10:53:56.506125 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:56.539892 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-b4zsn" condition "Approved" to 2026-05-11 10:53:56.539878656 +0000 UTC m=+505.829646619 I0511 10:53:56.559454 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-b4zsn" condition "Ready" to 2026-05-11 10:53:56.559443726 +0000 UTC m=+505.849211679 I0511 10:53:56.589367 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:56.589353161 +0000 UTC m=+505.879121124 I0511 10:53:56.614030 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:08.319858 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-11 10:57:08.319835997 +0000 UTC m=+697.609603960 I0511 10:57:08.320900 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:57:08.321003 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-11 10:57:08.320996163 +0000 UTC m=+697.610764166 I0511 10:57:08.337776 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:08.337912 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:57:08.338005 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-11 10:57:08.337998199 +0000 UTC m=+697.627766152 I0511 10:57:08.663311 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-xqt6h" condition "Approved" to 2026-05-11 10:57:08.663294763 +0000 UTC m=+697.953062726 I0511 10:57:08.690660 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-xqt6h" condition "Ready" to 2026-05-11 10:57:08.690646913 +0000 UTC m=+697.980414876 I0511 10:57:08.720060 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:57:08.720042682 +0000 UTC m=+698.009810645 I0511 10:57:08.746242 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:08.792904 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:49.563321 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:57:49.563395 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-11 10:57:49.563387821 +0000 UTC m=+738.853155784 I0511 10:57:49.564326 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-11 10:57:49.564319616 +0000 UTC m=+738.854087579 I0511 10:57:49.580388 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:49.580464 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-11 10:57:49.580455319 +0000 UTC m=+738.870223282 I0511 10:57:49.794501 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:49.827037 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-rcc8p" condition "Approved" to 2026-05-11 10:57:49.827024529 +0000 UTC m=+739.116792482 I0511 10:57:49.847626 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-rcc8p" condition "Ready" to 2026-05-11 10:57:49.847612279 +0000 UTC m=+739.137380242 I0511 10:57:49.878626 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:57:49.878607108 +0000 UTC m=+739.168375071 I0511 10:57:49.899826 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:49.945793 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"