I0520 20:22:21.893450 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0520 20:22:21.893603 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0520 20:22:21.893768 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0520 20:22:21.904546 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0520 20:22:21.906369 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0520 20:22:21.906802 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0520 20:22:21.907001 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0520 20:22:21.913184 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0520 20:22:21.933252 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0520 20:22:21.937819 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0520 20:22:21.940905 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0520 20:22:21.946313 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0520 20:22:21.951104 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0520 20:22:21.954065 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0520 20:22:21.954155 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0520 20:22:21.957219 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0520 20:22:21.960224 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0520 20:22:21.960324 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0520 20:22:21.962478 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0520 20:22:21.962510 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0520 20:22:21.962688 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0520 20:22:21.965094 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0520 20:22:21.971088 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0520 20:22:21.975523 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0520 20:22:21.977644 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0520 20:22:21.979822 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0520 20:22:21.981918 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0520 20:22:21.981989 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0520 20:22:21.984025 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0520 20:22:21.985842 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0520 20:22:21.985914 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0520 20:22:21.988031 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0520 20:22:21.990881 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0520 20:22:21.996116 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:21.996129 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:21.998523 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:21.999174 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.015970 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.032226 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.048074 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.067374 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.083852 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:22.107064 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 20:22:33.666960 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-20 20:22:33.6669408 +0000 UTC m=+11.811805343 I0520 20:22:34.528210 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-20 20:22:34.528196622 +0000 UTC m=+12.673061165 I0520 20:22:34.528827 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:22:34.528910 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-20 20:22:34.528899584 +0000 UTC m=+12.673764147 E0520 20:22:34.548239 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0520 20:22:34.548428 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-20 20:22:34.54841844 +0000 UTC m=+12.693282993 E0520 20:22:34.548482 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0520 20:22:34.550363 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:34.550498 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-20 20:22:34.550487876 +0000 UTC m=+12.695352409 E0520 20:22:34.570606 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0520 20:22:34.570766 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0520 20:22:34.570898 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0520 20:22:34.571162 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0520 20:22:34.572007 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:34.574501 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:34.574590 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-20 20:22:34.574581492 +0000 UTC m=+12.719446035 I0520 20:22:34.579491 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-jgcz7" condition "Approved" to 2026-05-20 20:22:34.579454626 +0000 UTC m=+12.724319169 I0520 20:22:34.600412 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-jgcz7" condition "Ready" to 2026-05-20 20:22:34.600400988 +0000 UTC m=+12.745265521 I0520 20:22:34.625308 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:22:34.625298386 +0000 UTC m=+12.770162919 I0520 20:22:34.644471 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:34.644829 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:22:34.644822193 +0000 UTC m=+12.789686726 I0520 20:22:34.662112 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:34.662531 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:22:34.662492358 +0000 UTC m=+12.807356881 I0520 20:22:34.664763 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:22:39.571393 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:22:39.571374925 +0000 UTC m=+17.716239488 I0520 20:23:10.866497 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-20 20:23:10.866481326 +0000 UTC m=+49.011345889 I0520 20:23:10.866490 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:23:10.866600 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-20 20:23:10.866588817 +0000 UTC m=+49.011453350 I0520 20:23:10.886516 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-20 20:23:10.886501254 +0000 UTC m=+49.031365787 I0520 20:23:10.907844 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:23:10.907937 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-20 20:23:10.907929532 +0000 UTC m=+49.052794055 I0520 20:23:11.038068 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:23:11.077654 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4cjnh" condition "Approved" to 2026-05-20 20:23:11.077637094 +0000 UTC m=+49.222501617 I0520 20:23:11.106036 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4cjnh" condition "Ready" to 2026-05-20 20:23:11.106021554 +0000 UTC m=+49.250886077 I0520 20:23:11.139369 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:23:11.139355568 +0000 UTC m=+49.284220111 I0520 20:23:11.169770 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:23:11.170086 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:23:11.170078478 +0000 UTC m=+49.314943001 I0520 20:23:11.200552 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:23:11.200953 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:23:11.20094149 +0000 UTC m=+49.345806023 I0520 20:28:15.368947 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-4.nip.io-tls" condition "Ready" to 2026-05-20 20:28:15.368934865 +0000 UTC m=+353.513799388 I0520 20:28:15.369465 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-4.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:28:15.369484 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-4.nip.io-tls" condition "Issuing" to 2026-05-20 20:28:15.369481214 +0000 UTC m=+353.514345737 I0520 20:28:15.385556 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-4.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-4.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:28:15.385642 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-4.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:28:15.385665 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-4.nip.io-tls" condition "Issuing" to 2026-05-20 20:28:15.385656424 +0000 UTC m=+353.530520977 I0520 20:28:15.619186 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-4.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-4.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:28:15.628889 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-4.nip.io-tls-pllzh" condition "Approved" to 2026-05-20 20:28:15.628869482 +0000 UTC m=+353.773734015 I0520 20:28:15.657358 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-4.nip.io-tls-pllzh" condition "Ready" to 2026-05-20 20:28:15.65734699 +0000 UTC m=+353.802211503 I0520 20:28:15.688486 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-4.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:28:15.688467642 +0000 UTC m=+353.833332175 I0520 20:28:15.709396 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-4.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-4.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:32:07.402916 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-20 20:32:07.402891624 +0000 UTC m=+585.547756177 I0520 20:32:07.403174 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:32:07.403271 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-20 20:32:07.403259118 +0000 UTC m=+585.548123681 I0520 20:32:07.429406 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:32:07.429521 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-20 20:32:07.429508929 +0000 UTC m=+585.574373462 I0520 20:32:07.766056 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:32:07.960824 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lj8fq" condition "Approved" to 2026-05-20 20:32:07.960805874 +0000 UTC m=+586.105670487 I0520 20:32:07.987929 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lj8fq" condition "Ready" to 2026-05-20 20:32:07.987911265 +0000 UTC m=+586.132775818 I0520 20:32:08.018776 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:32:08.01875946 +0000 UTC m=+586.163623993 I0520 20:32:08.043425 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:32:08.043720 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:32:08.043698236 +0000 UTC m=+586.188562769 I0520 20:32:08.065120 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:32:08.065588 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:32:08.065572327 +0000 UTC m=+586.210436860 I0520 20:35:28.195367 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-05-20 20:35:28.195305794 +0000 UTC m=+786.340170357 I0520 20:35:28.196118 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:35:28.196150 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-05-20 20:35:28.196143898 +0000 UTC m=+786.341008461 I0520 20:35:28.214951 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:35:28.215052 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 20:35:28.215081 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-05-20 20:35:28.215072411 +0000 UTC m=+786.359936944 I0520 20:35:28.507555 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-t2xd7" condition "Approved" to 2026-05-20 20:35:28.507544014 +0000 UTC m=+786.652408537 I0520 20:35:28.531164 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-t2xd7" condition "Ready" to 2026-05-20 20:35:28.531149981 +0000 UTC m=+786.676014534 I0520 20:35:28.559438 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:35:28.559427321 +0000 UTC m=+786.704291854 I0520 20:35:28.580810 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:35:28.585582 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:35:28.585572101 +0000 UTC m=+786.730436624 I0520 20:35:28.605307 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0520 20:35:28.605675 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 20:35:28.605663226 +0000 UTC m=+786.750527759 I0520 20:35:28.606478 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"