I0420 10:10:35.231979 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0420 10:10:35.232119 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0420 10:10:35.232268 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 10:10:35.237016 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0420 10:10:35.237383 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0420 10:10:35.237443 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0420 10:10:35.237446 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0420 10:10:35.240178 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 10:10:35.258168 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0420 10:10:35.264967 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0420 10:10:35.271572 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0420 10:10:35.277935 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0420 10:10:35.278335 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0420 10:10:35.282280 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0420 10:10:35.284746 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0420 10:10:35.286875 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0420 10:10:35.288794 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0420 10:10:35.290577 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0420 10:10:35.290597 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0420 10:10:35.290603 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0420 10:10:35.290660 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0420 10:10:35.292729 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0420 10:10:35.298836 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0420 10:10:35.301349 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0420 10:10:35.303948 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0420 10:10:35.306413 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0420 10:10:35.308296 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0420 10:10:35.308334 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0420 10:10:35.310362 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0420 10:10:35.312174 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0420 10:10:35.313816 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0420 10:10:35.313875 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0420 10:10:35.315641 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0420 10:10:35.322391 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.322742 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.323211 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.323649 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.323666 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.323836 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.324036 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.324506 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.324677 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:35.408945 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 10:10:45.488414 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-20 10:10:45.488399032 +0000 UTC m=+10.292702910 I0420 10:10:46.195966 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-20 10:10:46.195956254 +0000 UTC m=+11.000260122 I0420 10:10:46.196732 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:10:46.198559 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 10:10:46.198551907 +0000 UTC m=+11.002855825 E0420 10:10:46.211959 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 10:10:46.212110 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-20 10:10:46.212104783 +0000 UTC m=+11.016408661 E0420 10:10:46.212165 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 10:10:46.213869 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:10:46.213939 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:10:46.213966 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 10:10:46.213962233 +0000 UTC m=+11.018266111 E0420 10:10:46.224072 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0420 10:10:46.224247 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 10:10:46.224543 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 10:10:46.224624 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0420 10:10:46.248318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:10:46.252568 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-r82rw" condition "Approved" to 2026-04-20 10:10:46.252556882 +0000 UTC m=+11.056860750 I0420 10:10:46.264817 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-r82rw" condition "Ready" to 2026-04-20 10:10:46.264808726 +0000 UTC m=+11.069112594 I0420 10:10:46.287357 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:10:46.28734862 +0000 UTC m=+11.091652498 I0420 10:10:46.312303 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:10:46.312547 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:10:46.31254111 +0000 UTC m=+11.116844988 I0420 10:10:46.323473 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:10:51.225196 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:10:51.225178533 +0000 UTC m=+16.029482431 I0420 10:11:12.351600 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:11:12.351672 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 10:11:12.351662796 +0000 UTC m=+37.155966734 I0420 10:11:12.351672 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 10:11:12.351661876 +0000 UTC m=+37.155965754 I0420 10:11:12.367239 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-20 10:11:12.367223034 +0000 UTC m=+37.171526922 I0420 10:11:12.381076 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:11:12.384582 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:11:12.384647 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 10:11:12.384627347 +0000 UTC m=+37.188931225 I0420 10:11:12.500766 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:11:12.510356 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-rjgd8" condition "Approved" to 2026-04-20 10:11:12.51034638 +0000 UTC m=+37.314650258 I0420 10:11:12.544797 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-rjgd8" condition "Ready" to 2026-04-20 10:11:12.544788167 +0000 UTC m=+37.349092025 I0420 10:11:12.577432 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:11:12.577412949 +0000 UTC m=+37.381716857 I0420 10:11:12.603787 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:11:12.603988 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:11:12.603980665 +0000 UTC m=+37.408284533 I0420 10:11:12.629212 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:15:15.830891 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-118.nip.io-tls" condition "Ready" to 2026-04-20 10:15:15.830860211 +0000 UTC m=+280.635164089 I0420 10:15:15.831256 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-118.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:15:15.831411 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-118.nip.io-tls" condition "Issuing" to 2026-04-20 10:15:15.831291677 +0000 UTC m=+280.635595575 I0420 10:15:15.851597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-118.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-118.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:15:15.851675 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-118.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 10:15:15.851689 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-118.nip.io-tls" condition "Issuing" to 2026-04-20 10:15:15.851683671 +0000 UTC m=+280.655987539 I0420 10:15:16.041141 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-118.nip.io-tls-sdt5m" condition "Approved" to 2026-04-20 10:15:16.041132641 +0000 UTC m=+280.845436509 I0420 10:15:16.065299 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-118.nip.io-tls-sdt5m" condition "Ready" to 2026-04-20 10:15:16.065288848 +0000 UTC m=+280.869592716 I0420 10:15:16.092390 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-118.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 10:15:16.092380312 +0000 UTC m=+280.896684190 I0420 10:15:16.111817 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-118.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-118.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 10:15:16.153334 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-118.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-118.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again"