I0504 01:35:24.237640 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0504 01:35:24.237819 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0504 01:35:24.238042 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0504 01:35:24.244399 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0504 01:35:24.245049 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0504 01:35:24.245337 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0504 01:35:24.245356 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0504 01:35:24.248968 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0504 01:35:24.266186 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0504 01:35:24.270509 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0504 01:35:24.273334 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0504 01:35:24.281244 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0504 01:35:24.281353 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0504 01:35:24.284457 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0504 01:35:24.287460 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0504 01:35:24.290230 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0504 01:35:24.290312 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0504 01:35:24.292860 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0504 01:35:24.294561 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0504 01:35:24.294686 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0504 01:35:24.297722 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0504 01:35:24.302037 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0504 01:35:24.307354 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0504 01:35:24.309147 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0504 01:35:24.309169 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0504 01:35:24.309200 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0504 01:35:24.311188 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0504 01:35:24.313667 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0504 01:35:24.315584 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0504 01:35:24.317423 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0504 01:35:24.319177 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0504 01:35:24.319563 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0504 01:35:24.324740 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0504 01:35:24.328845 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.328963 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.329993 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.348314 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.365158 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.403011 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.420428 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.420697 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.439176 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:24.456783 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0504 01:35:36.024144 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-04 01:35:36.023993932 +0000 UTC m=+11.818569761 I0504 01:35:36.760091 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:35:36.760190 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-04 01:35:36.760176294 +0000 UTC m=+12.554752163 I0504 01:35:36.760301 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-04 01:35:36.760285626 +0000 UTC m=+12.554861455 E0504 01:35:36.784757 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0504 01:35:36.784844 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-04 01:35:36.784828592 +0000 UTC m=+12.579404451 E0504 01:35:36.784924 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0504 01:35:36.787209 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:35:36.787305 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:35:36.787330 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-04 01:35:36.787318942 +0000 UTC m=+12.581894771 E0504 01:35:36.796154 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0504 01:35:36.796763 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0504 01:35:36.796893 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0504 01:35:36.796985 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0504 01:35:36.833128 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:35:36.839841 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-76td4" condition "Approved" to 2026-05-04 01:35:36.839828478 +0000 UTC m=+12.634404307 I0504 01:35:36.857234 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-76td4" condition "Ready" to 2026-05-04 01:35:36.857220378 +0000 UTC m=+12.651796207 I0504 01:35:36.884140 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:35:36.884116181 +0000 UTC m=+12.678692030 I0504 01:35:36.907244 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:35:36.907561 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:35:36.907535339 +0000 UTC m=+12.702111158 I0504 01:35:36.911875 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:35:36.919165 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:35:36.919408 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:35:36.91939826 +0000 UTC m=+12.713974089 I0504 01:35:41.796633 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:35:41.796619169 +0000 UTC m=+17.591195018 I0504 01:36:14.001585 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:36:14.001642 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-04 01:36:14.001634255 +0000 UTC m=+49.796210094 I0504 01:36:14.002077 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-04 01:36:14.001481263 +0000 UTC m=+49.796057122 I0504 01:36:14.021125 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-04 01:36:14.021114022 +0000 UTC m=+49.815689851 I0504 01:36:14.029491 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:36:14.029557 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-04 01:36:14.029551369 +0000 UTC m=+49.824127178 I0504 01:36:14.171635 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:36:14.204200 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8lz22" condition "Approved" to 2026-05-04 01:36:14.204190246 +0000 UTC m=+49.998766075 I0504 01:36:14.233341 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8lz22" condition "Ready" to 2026-05-04 01:36:14.233329386 +0000 UTC m=+50.027905215 I0504 01:36:14.273087 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:36:14.27306953 +0000 UTC m=+50.067645389 I0504 01:36:14.303273 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:36:14.428705 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:41:32.946264 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Ready" to 2026-05-04 01:41:32.946224318 +0000 UTC m=+368.740800177 I0504 01:41:32.948377 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:41:32.948498 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Issuing" to 2026-05-04 01:41:32.948409996 +0000 UTC m=+368.742985865 I0504 01:41:32.962780 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:41:32.962969 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:41:32.963038 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Issuing" to 2026-05-04 01:41:32.963030956 +0000 UTC m=+368.757606785 I0504 01:41:33.215832 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:41:33.269299 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-140.nip.io-tls-5sflj" condition "Approved" to 2026-05-04 01:41:33.269258658 +0000 UTC m=+369.063834517 I0504 01:41:33.386488 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-140.nip.io-tls-5sflj" condition "Ready" to 2026-05-04 01:41:33.386477867 +0000 UTC m=+369.181053696 I0504 01:41:33.624697 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:41:33.62468669 +0000 UTC m=+369.419262519 I0504 01:41:33.668831 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:41:33.669152 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:41:33.669146918 +0000 UTC m=+369.463722727 I0504 01:41:33.756839 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:42:33.674926 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:42:33.674925 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-04 01:42:33.674875929 +0000 UTC m=+429.469451788 I0504 01:42:33.674976 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-04 01:42:33.67496753 +0000 UTC m=+429.469543389 E0504 01:42:33.687494 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0504 01:42:33.687530 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-04 01:42:33.687524293 +0000 UTC m=+429.482100122 E0504 01:42:33.687566 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0504 01:42:33.688925 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:42:33.688978 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:42:33.688995 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-04 01:42:33.688990631 +0000 UTC m=+429.483566460 E0504 01:42:33.698658 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0504 01:42:33.698725 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0504 01:42:33.698747 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0504 01:42:33.698777 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0504 01:42:33.723697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:42:33.727799 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-wjc97" condition "Approved" to 2026-05-04 01:42:33.727781702 +0000 UTC m=+429.522357521 I0504 01:42:33.740383 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-wjc97" condition "Ready" to 2026-05-04 01:42:33.740371005 +0000 UTC m=+429.534946834 I0504 01:42:33.761176 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:42:33.761156451 +0000 UTC m=+429.555732280 I0504 01:42:33.780404 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:42:38.699245 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:42:38.699226372 +0000 UTC m=+434.493802231 I0504 01:43:23.782453 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-04 01:43:23.782416662 +0000 UTC m=+479.576992491 I0504 01:43:23.782738 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:43:23.782778 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-04 01:43:23.782774757 +0000 UTC m=+479.577350586 I0504 01:43:23.803867 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:43:23.803902 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-04 01:43:23.803894325 +0000 UTC m=+479.598470164 I0504 01:43:23.804146 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-04 01:43:23.804141389 +0000 UTC m=+479.598717208 I0504 01:43:23.804555 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:43:23.805154 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-04 01:43:23.805140977 +0000 UTC m=+479.599716806 I0504 01:43:23.804570 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-04 01:43:23.804566967 +0000 UTC m=+479.599142786 I0504 01:43:23.937030 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:23.937467 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:23.937614 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-04 01:43:23.937605471 +0000 UTC m=+479.732181290 I0504 01:43:23.937731 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:23.937782 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-04 01:43:23.937776804 +0000 UTC m=+479.732352613 I0504 01:43:23.938036 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:43:23.938085 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-04 01:43:23.938079699 +0000 UTC m=+479.732655528 I0504 01:43:24.055122 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:24.063028 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:24.168426 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-fkzcc" condition "Approved" to 2026-05-04 01:43:24.168414894 +0000 UTC m=+479.962990723 I0504 01:43:24.170070 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-xpph2" condition "Approved" to 2026-05-04 01:43:24.17006434 +0000 UTC m=+479.964640159 I0504 01:43:24.255047 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-xpph2" condition "Ready" to 2026-05-04 01:43:24.254680923 +0000 UTC m=+480.049256762 I0504 01:43:24.255125 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-fkzcc" condition "Ready" to 2026-05-04 01:43:24.25511419 +0000 UTC m=+480.049690019 I0504 01:43:24.519332 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:24.5193217 +0000 UTC m=+480.313897529 I0504 01:43:24.632396 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:24.632377061 +0000 UTC m=+480.426952910 I0504 01:43:24.642922 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:24.645405 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:24.645396666 +0000 UTC m=+480.439972505 I0504 01:43:24.698789 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-gwrls" condition "Approved" to 2026-05-04 01:43:24.698778134 +0000 UTC m=+480.493353963 I0504 01:43:24.704576 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:24.704920 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:24.704914875 +0000 UTC m=+480.499490694 I0504 01:43:24.807124 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:24.999785 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:25.001649 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-gwrls" condition "Ready" to 2026-05-04 01:43:25.00164143 +0000 UTC m=+480.796217259 I0504 01:43:25.081109 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:25.081661 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:25.081653944 +0000 UTC m=+480.876229773 I0504 01:43:25.459926 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:25.670816 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:25.670801843 +0000 UTC m=+481.465377672 I0504 01:43:25.766461 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:26.200685 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:41.553962 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:43:41.554045 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" condition "Issuing" to 2026-05-04 01:43:41.554027441 +0000 UTC m=+497.348603290 I0504 01:43:41.553959 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" condition "Ready" to 2026-05-04 01:43:41.55392309 +0000 UTC m=+497.348498939 I0504 01:43:41.584339 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:41.584422 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" condition "Ready" to 2026-05-04 01:43:41.584415656 +0000 UTC m=+497.378991505 I0504 01:43:41.702949 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:41.746293 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-vzqc9-lhlsl" condition "Approved" to 2026-05-04 01:43:41.746281213 +0000 UTC m=+497.540857042 I0504 01:43:41.777176 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-vzqc9-lhlsl" condition "Ready" to 2026-05-04 01:43:41.777155744 +0000 UTC m=+497.571731573 I0504 01:43:41.826008 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:41.825992783 +0000 UTC m=+497.620568612 I0504 01:43:41.851902 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:43:41.852234 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:43:41.85221772 +0000 UTC m=+497.646793559 I0504 01:43:41.877949 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-vzqc9-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:44:21.095921 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-04 01:44:21.095907357 +0000 UTC m=+536.890483186 I0504 01:44:21.096399 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:44:21.096469 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-04 01:44:21.096460745 +0000 UTC m=+536.891036574 I0504 01:44:21.122197 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:44:21.122439 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:44:21.122473 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-04 01:44:21.122457422 +0000 UTC m=+536.917033251 I0504 01:44:21.700359 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vsn89" condition "Approved" to 2026-05-04 01:44:21.70034636 +0000 UTC m=+537.494922179 I0504 01:44:21.736819 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vsn89" condition "Ready" to 2026-05-04 01:44:21.736809854 +0000 UTC m=+537.531385673 I0504 01:44:21.909823 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:44:21.909805113 +0000 UTC m=+537.704381032 I0504 01:44:21.924531 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:44:21.924845 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:44:21.924839908 +0000 UTC m=+537.719415727 I0504 01:44:21.992317 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:16.127562 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-04 01:47:16.127541089 +0000 UTC m=+711.922116908 I0504 01:47:16.127963 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:47:16.127978 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-04 01:47:16.127975045 +0000 UTC m=+711.922550864 I0504 01:47:16.158002 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:16.158066 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-04 01:47:16.158059972 +0000 UTC m=+711.952635801 I0504 01:47:16.371725 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:16.410224 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lxnn6" condition "Approved" to 2026-05-04 01:47:16.410212305 +0000 UTC m=+712.204788134 I0504 01:47:16.437443 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lxnn6" condition "Ready" to 2026-05-04 01:47:16.437433975 +0000 UTC m=+712.232009794 I0504 01:47:16.471189 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:47:16.471176599 +0000 UTC m=+712.265752428 I0504 01:47:16.501896 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:16.586669 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:54.281169 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0504 01:47:54.281225 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-04 01:47:54.281218779 +0000 UTC m=+750.075794608 I0504 01:47:54.281538 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-04 01:47:54.281524101 +0000 UTC m=+750.076099920 I0504 01:47:54.299221 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:54.299297 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-04 01:47:54.299290514 +0000 UTC m=+750.093866343 I0504 01:47:54.517242 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:54.544101 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-th695" condition "Approved" to 2026-05-04 01:47:54.544090012 +0000 UTC m=+750.338665851 I0504 01:47:54.562172 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-th695" condition "Ready" to 2026-05-04 01:47:54.562164846 +0000 UTC m=+750.356740665 I0504 01:47:54.591424 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:47:54.591414687 +0000 UTC m=+750.385990516 I0504 01:47:54.622848 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0504 01:47:54.623188 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-04 01:47:54.623181789 +0000 UTC m=+750.417757608 I0504 01:47:54.646941 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"