I0429 21:45:37.480221 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0429 21:45:37.480447 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0429 21:45:37.480505 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0429 21:45:37.480613 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0429 21:45:37.482756 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0429 21:45:37.483303 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0429 21:45:37.483860 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0429 21:45:37.484491 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0429 21:45:37.502842 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0429 21:45:37.504134 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0429 21:45:37.504691 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0429 21:45:37.504976 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0429 21:45:37.505678 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0429 21:45:37.506221 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0429 21:45:37.507420 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0429 21:45:37.508099 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0429 21:45:37.508198 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0429 21:45:37.508455 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0429 21:45:37.508987 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0429 21:45:37.509031 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0429 21:45:37.509039 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0429 21:45:37.509704 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0429 21:45:37.510334 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0429 21:45:37.510771 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0429 21:45:37.511183 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0429 21:45:37.511203 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0429 21:45:37.511276 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0429 21:45:37.512232 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0429 21:45:37.512798 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0429 21:45:37.513355 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0429 21:45:37.513542 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0429 21:45:37.515909 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0429 21:45:37.516290 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0429 21:46:00.453296 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-29 21:46:00.453263142 +0000 UTC m=+23.007468907 I0429 21:46:00.470916 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:00.470942 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-29 21:46:00.470936462 +0000 UTC m=+23.025142177 I0429 21:46:00.471002 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-29 21:46:00.470981153 +0000 UTC m=+23.025186878 E0429 21:46:00.484558 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18aaf211a1201ac0", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"bc6e0ddc-6a62-4b33-b29c-28af5ccb0425", APIVersion:"cert-manager.io/v1", ResourceVersion:"1301", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 29, 21, 46, 0, 482683584, time.Local), LastTimestamp:time.Date(2026, time.April, 29, 21, 46, 0, 482683584, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18aaf211a1201ac0" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0429 21:46:00.485777 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0429 21:46:00.485846 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-29 21:46:00.485841392 +0000 UTC m=+23.040047107 E0429 21:46:00.489291 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0429 21:46:00.519569 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-29 21:46:00.519559261 +0000 UTC m=+23.073764986 I0429 21:46:00.532088 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:00.532119 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-29 21:46:00.532113393 +0000 UTC m=+23.086319128 I0429 21:46:00.532317 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-29 21:46:00.532312228 +0000 UTC m=+23.086517953 I0429 21:46:00.550823 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0429 21:46:00.550889 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-29 21:46:00.550881861 +0000 UTC m=+23.105087586 E0429 21:46:00.689059 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0429 21:46:01.091730 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-29 21:46:01.091717985 +0000 UTC m=+23.645923690 I0429 21:46:01.091968 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0429 21:46:01.104905 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-29 21:46:01.104896719 +0000 UTC m=+23.659102444 I0429 21:46:01.104957 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:01.104986 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-29 21:46:01.104981721 +0000 UTC m=+23.659187446 I0429 21:46:01.122922 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0429 21:46:01.122979 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-29 21:46:01.122973185 +0000 UTC m=+23.677178910 I0429 21:46:01.130074 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-v2bvx" condition "Approved" to 2026-04-29 21:46:01.130069309 +0000 UTC m=+23.684275024 I0429 21:46:01.171277 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-v2bvx" condition "Ready" to 2026-04-29 21:46:01.171266266 +0000 UTC m=+23.725471991 I0429 21:46:01.211213 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:01.211198879 +0000 UTC m=+23.765404594 I0429 21:46:01.273323 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0429 21:46:01.273546 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:01.273542096 +0000 UTC m=+23.827747811 I0429 21:46:01.297664 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0429 21:46:01.297669 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0429 21:46:01.306529 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:01.306513928 +0000 UTC m=+23.860719643 I0429 21:46:01.426737 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0429 21:46:01.432602 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-29 21:46:01.432587275 +0000 UTC m=+23.986792990 I0429 21:46:01.451384 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-29 21:46:01.451375119 +0000 UTC m=+24.005580844 I0429 21:46:01.451858 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:01.451884 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-29 21:46:01.451880221 +0000 UTC m=+24.006085946 I0429 21:46:01.468957 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-79r5n" condition "Approved" to 2026-04-29 21:46:01.468950321 +0000 UTC m=+24.023156036 I0429 21:46:01.489201 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0429 21:46:01.489297 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:01.489350 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-29 21:46:01.489344984 +0000 UTC m=+24.043550699 I0429 21:46:01.495203 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-79r5n" condition "Ready" to 2026-04-29 21:46:01.495174778 +0000 UTC m=+24.049380503 I0429 21:46:01.520751 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:01.520742028 +0000 UTC m=+24.074947743 I0429 21:46:01.542187 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0429 21:46:01.550615 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:01.550609035 +0000 UTC m=+24.104814750 I0429 21:46:01.560765 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0429 21:46:01.573585 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0429 21:46:01.852713 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-29 21:46:01.852701819 +0000 UTC m=+24.406907534 I0429 21:46:01.873502 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-29 21:46:01.873493382 +0000 UTC m=+24.427699097 I0429 21:46:01.873718 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0429 21:46:01.873731 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-29 21:46:01.873729487 +0000 UTC m=+24.427935202 I0429 21:46:01.902926 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0429 21:46:01.903011 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-29 21:46:01.903002979 +0000 UTC m=+24.457208724 I0429 21:46:01.981106 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0429 21:46:02.124995 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-mf46d" condition "Approved" to 2026-04-29 21:46:02.124986502 +0000 UTC m=+24.679192217 I0429 21:46:02.221147 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-mf46d" condition "Ready" to 2026-04-29 21:46:02.22114012 +0000 UTC m=+24.775345835 I0429 21:46:02.702684 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:02.702669176 +0000 UTC m=+25.256874901 I0429 21:46:02.749682 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0429 21:46:02.885584 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0429 21:46:02.886053 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:02.886046003 +0000 UTC m=+25.440251718 I0429 21:46:03.192377 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-76dz6" condition "Approved" to 2026-04-29 21:46:03.19236342 +0000 UTC m=+25.746569135 I0429 21:46:03.232496 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0429 21:46:03.280938 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0429 21:46:03.346321 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-76dz6" condition "Ready" to 2026-04-29 21:46:03.346309464 +0000 UTC m=+25.900515189 I0429 21:46:03.884118 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:03.884108054 +0000 UTC m=+26.438313769 I0429 21:46:04.030525 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0429 21:46:04.030807 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-29 21:46:04.030800056 +0000 UTC m=+26.585005781 I0429 21:46:04.230125 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0429 21:47:03.686786 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0429 21:47:03.716849 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-29 21:47:03.716832246 +0000 UTC m=+86.271037991 I0429 21:47:03.741845 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-29 21:47:03.741836584 +0000 UTC m=+86.296042309 E0429 21:47:05.658757 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0429 21:47:05.693440 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-29 21:47:05.693428601 +0000 UTC m=+88.247634326 I0429 21:47:05.712112 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-29 21:47:05.712072616 +0000 UTC m=+88.266278371 E0429 21:47:07.171743 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0429 21:47:07.206018 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-29 21:47:07.206001971 +0000 UTC m=+89.760207726 I0429 21:47:07.224507 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-29 21:47:07.22438872 +0000 UTC m=+89.778594445 E0429 21:47:08.789766 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0429 21:47:08.831126 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-29 21:47:08.831113387 +0000 UTC m=+91.385319112 I0429 21:47:08.851155 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-29 21:47:08.851143038 +0000 UTC m=+91.405348763