I0519 17:00:03.598976 1 start.go:75] "cert-manager: starting controller" version="v1.12.10" git-commit="4131d77fe377e78a6fa562af6bdbd31532ddb1ad" I0519 17:00:03.599086 1 controller.go:262] "cert-manager/controller/build-context: configured acme dns01 nameservers" nameservers=["10.96.0.10:53"] W0519 17:00:03.599175 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0519 17:00:03.603942 1 controller.go:82] "cert-manager/controller: enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0519 17:00:03.604382 1 controller.go:156] "cert-manager/controller: starting leader election" I0519 17:00:03.604439 1 controller.go:103] "cert-manager/controller: starting metrics server" address="[::]:9402" I0519 17:00:03.604649 1 controller.go:149] "cert-manager/controller: starting healthz server" address="[::]:9403" I0519 17:00:03.611434 1 leaderelection.go:245] attempting to acquire leader lease cert-manager/cert-manager-controller... I0519 17:00:04.337586 1 leaderelection.go:255] successfully acquired lease cert-manager/cert-manager-controller I0519 17:00:04.337908 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-vault" I0519 17:00:04.343029 1 controller.go:226] "cert-manager/controller: starting controller" controller="issuers" I0519 17:00:04.346407 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-key-manager" I0519 17:00:04.351483 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-metrics" I0519 17:00:04.353530 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-request-manager" I0519 17:00:04.356130 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-trigger" I0519 17:00:04.359825 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-vault" I0519 17:00:04.363010 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-readiness" I0519 17:00:04.364627 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-revision-manager" I0519 17:00:04.366933 1 controller.go:226] "cert-manager/controller: starting controller" controller="orders" I0519 17:00:04.369031 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-acme" I0519 17:00:04.369942 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="gateway-shim" I0519 17:00:04.369992 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-venafi" I0519 17:00:04.371875 1 controller.go:226] "cert-manager/controller: starting controller" controller="ingress-shim" I0519 17:00:04.373520 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-acme" I0519 17:00:04.373539 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-selfsigned" I0519 17:00:04.373642 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-approver" I0519 17:00:04.375450 1 controller.go:226] "cert-manager/controller: starting controller" controller="clusterissuers" I0519 17:00:04.377177 1 controller.go:226] "cert-manager/controller: starting controller" controller="challenges" I0519 17:00:04.382302 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-issuing" I0519 17:00:04.385871 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-ca" I0519 17:00:04.389337 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-ca" I0519 17:00:04.389441 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-venafi" I0519 17:00:04.389384 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-selfsigned" I0519 17:02:36.264628 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:02:36.264657 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-05-19 17:02:36.264638953 +0000 UTC m=+152.712887557 I0519 17:02:36.264680 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-05-19 17:02:36.264663744 +0000 UTC m=+152.712912378 E0519 17:02:36.280719 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:36.280763 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-client" condition "Ready" to 2026-05-19 17:02:36.28075486 +0000 UTC m=+152.729003464 I0519 17:02:36.280786 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:36.282998 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:36.283105 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:02:36.283169 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-05-19 17:02:36.283161974 +0000 UTC m=+152.731410578 E0519 17:02:36.297218 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" key="openstack/octavia-client" E0519 17:02:36.297319 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:36.297397 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-client-ca\" not found" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0519 17:02:36.297446 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" key="openstack/octavia-client" I0519 17:02:36.333172 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:36.342931 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-xs9kd" condition "Approved" to 2026-05-19 17:02:36.342914923 +0000 UTC m=+152.791163507 I0519 17:02:36.362701 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-xs9kd" condition "Ready" to 2026-05-19 17:02:36.362687103 +0000 UTC m=+152.810935707 I0519 17:02:36.406500 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:36.406485398 +0000 UTC m=+152.854733992 I0519 17:02:36.426465 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:36.426682 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:36.426675737 +0000 UTC m=+152.874924331 I0519 17:02:36.464562 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:36.993789 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:02:36.993823 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-05-19 17:02:36.993815771 +0000 UTC m=+153.442064355 I0519 17:02:36.994092 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-05-19 17:02:36.994072857 +0000 UTC m=+153.442321461 E0519 17:02:37.013550 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:37.013606 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-server" condition "Ready" to 2026-05-19 17:02:37.013592931 +0000 UTC m=+153.461841565 I0519 17:02:37.013646 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:37.016879 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.016986 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-05-19 17:02:37.016973218 +0000 UTC m=+153.465221862 E0519 17:02:37.035404 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" key="openstack/octavia-server" E0519 17:02:37.035754 1 setup.go:48] "cert-manager/issuers/setup: error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0519 17:02:37.035783 1 sync.go:62] "cert-manager/issuers: Error initializing issuer: secret \"octavia-server-ca\" not found" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0519 17:02:37.035819 1 controller.go:167] "cert-manager/issuers: re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" key="openstack/octavia-server" I0519 17:02:37.048402 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.082640 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-4ktf5" condition "Approved" to 2026-05-19 17:02:37.082620001 +0000 UTC m=+153.530868635 I0519 17:02:37.108944 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-4ktf5" condition "Ready" to 2026-05-19 17:02:37.108931728 +0000 UTC m=+153.557180322 I0519 17:02:37.137616 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:37.13759766 +0000 UTC m=+153.585846284 I0519 17:02:37.164437 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.164714 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:37.164706157 +0000 UTC m=+153.612954761 I0519 17:02:37.195668 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.806433 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:02:37.806464 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-05-19 17:02:37.806457227 +0000 UTC m=+154.254705831 I0519 17:02:37.807058 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-05-19 17:02:37.80702891 +0000 UTC m=+154.255277534 I0519 17:02:37.828912 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.829007 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:02:37.829027 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-05-19 17:02:37.82902108 +0000 UTC m=+154.277269684 I0519 17:02:37.870948 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:37.883769 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-m86kq" condition "Approved" to 2026-05-19 17:02:37.883747095 +0000 UTC m=+154.331995719 I0519 17:02:37.907450 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-m86kq" condition "Ready" to 2026-05-19 17:02:37.907432853 +0000 UTC m=+154.355681467 I0519 17:02:41.298577 1 conditions.go:85] Found status change for Issuer "octavia-client" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:41.298567644 +0000 UTC m=+157.746816238 I0519 17:02:42.036513 1 conditions.go:85] Found status change for Issuer "octavia-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:42.036496301 +0000 UTC m=+158.484744925 I0519 17:02:42.162313 1 conditions.go:252] Found status change for CertificateRequest "octavia-client-certs-m86kq" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:42.162298041 +0000 UTC m=+158.610546655 I0519 17:02:43.291292 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:43.291277629 +0000 UTC m=+159.739526233 I0519 17:02:43.505763 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:02:43.506174 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:02:43.506162905 +0000 UTC m=+159.954411509 I0519 17:02:44.028420 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:05:06.651797 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:05:06.651833 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-05-19 17:05:06.651825506 +0000 UTC m=+303.100074100 I0519 17:05:06.652268 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-19 17:05:06.652248206 +0000 UTC m=+303.100496810 I0519 17:05:06.673661 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:05:06.673760 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-05-19 17:05:06.673752165 +0000 UTC m=+303.122000759 I0519 17:05:06.825024 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:05:06.854973 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-qndft" condition "Approved" to 2026-05-19 17:05:06.854952202 +0000 UTC m=+303.303200796 I0519 17:05:06.879512 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-qndft" condition "Ready" to 2026-05-19 17:05:06.879501839 +0000 UTC m=+303.327750433 I0519 17:05:06.916802 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:05:06.916786576 +0000 UTC m=+303.365035170 I0519 17:05:06.940728 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:05:06.948957 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:05:06.948943407 +0000 UTC m=+303.397192001 I0519 17:05:06.980215 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:05:06.980855 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:05:06.980847382 +0000 UTC m=+303.429095976 I0519 17:06:05.836535 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-19 17:06:05.836508781 +0000 UTC m=+362.284757385 I0519 17:06:05.869921 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-19 17:06:05.869900189 +0000 UTC m=+362.318148823 I0519 17:06:05.869948 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:05.870176 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-19 17:06:05.870169355 +0000 UTC m=+362.318417939 I0519 17:06:05.897848 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="cert-manager-test/selfsigned-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:05.897962 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:05.897993 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-19 17:06:05.897985718 +0000 UTC m=+362.346234332 E0519 17:06:05.909373 1 controller.go:134] "cert-manager/issuers: issuer in work queue no longer exists" err="issuer.cert-manager.io \"test-selfsigned\" not found" E0519 17:06:05.914777 1 event.go:280] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18b10666b0cc72d0", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"a45889f9-bd70-4775-bc7c-5d6f86371dd2", APIVersion:"cert-manager.io/v1", ResourceVersion:"32382", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 19, 17, 6, 5, 910676176, time.Local), LastTimestamp:time.Date(2026, time.May, 19, 17, 6, 5, 910676176, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18b10666b0cc72d0" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0519 17:06:05.988965 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-19 17:06:05.988951725 +0000 UTC m=+362.437200319 I0519 17:06:06.014521 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-19 17:06:06.014507675 +0000 UTC m=+362.462756269 I0519 17:06:06.017686 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-system/capi-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:06.017726 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-19 17:06:06.017719038 +0000 UTC m=+362.465967632 I0519 17:06:06.041941 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:06.042036 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-19 17:06:06.04202662 +0000 UTC m=+362.490275224 E0519 17:06:06.080200 1 controller.go:167] "cert-manager/certificates-key-manager: re-queuing item due to error processing" err="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" key="cert-manager-test/selfsigned-cert" I0519 17:06:06.274027 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:06.347630 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-p5mx6" condition "Approved" to 2026-05-19 17:06:06.347613033 +0000 UTC m=+362.795861647 I0519 17:06:06.394231 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-p5mx6" condition "Ready" to 2026-05-19 17:06:06.394218742 +0000 UTC m=+362.842467336 I0519 17:06:06.455355 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:06.45534078 +0000 UTC m=+362.903589384 I0519 17:06:06.526723 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:06.527323 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:06.527316496 +0000 UTC m=+362.975565110 I0519 17:06:06.532058 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:06.568995 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:06.569824 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:06.569812821 +0000 UTC m=+363.018061435 I0519 17:06:06.576523 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:07.559450 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-19 17:06:07.559426425 +0000 UTC m=+364.007675009 I0519 17:06:07.623159 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:07.623183 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-19 17:06:07.623177823 +0000 UTC m=+364.071426417 I0519 17:06:07.623454 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-19 17:06:07.623444929 +0000 UTC m=+364.071693523 I0519 17:06:07.650678 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:07.650813 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-19 17:06:07.650802591 +0000 UTC m=+364.099051195 I0519 17:06:07.896059 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:07.981901 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-fmvc2" condition "Approved" to 2026-05-19 17:06:07.981883603 +0000 UTC m=+364.430132207 I0519 17:06:08.008975 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-fmvc2" condition "Ready" to 2026-05-19 17:06:08.008962829 +0000 UTC m=+364.457211433 I0519 17:06:08.057236 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:08.057222465 +0000 UTC m=+364.505471069 I0519 17:06:08.092736 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.093474 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:08.093454858 +0000 UTC m=+364.541703452 I0519 17:06:08.133040 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.133676 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.134789 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:08.134775307 +0000 UTC m=+364.583023931 I0519 17:06:08.345214 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-19 17:06:08.345094915 +0000 UTC m=+364.793343529 I0519 17:06:08.384239 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:08.384275 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-19 17:06:08.384267335 +0000 UTC m=+364.832515929 I0519 17:06:08.384600 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-19 17:06:08.384595403 +0000 UTC m=+364.832844007 I0519 17:06:08.419071 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.419164 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:08.419192 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-19 17:06:08.419184428 +0000 UTC m=+364.867433032 I0519 17:06:08.800152 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.819625 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-qp8v6" condition "Approved" to 2026-05-19 17:06:08.819608506 +0000 UTC m=+365.267857120 I0519 17:06:08.847172 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-qp8v6" condition "Ready" to 2026-05-19 17:06:08.847147541 +0000 UTC m=+365.295396165 I0519 17:06:08.919167 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:08.919151718 +0000 UTC m=+365.367400312 I0519 17:06:08.980758 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:08.983915 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:08.983899628 +0000 UTC m=+365.432148242 I0519 17:06:09.034177 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:09.053892 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:09.265144 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-19 17:06:09.265124127 +0000 UTC m=+365.713372751 I0519 17:06:09.370656 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-19 17:06:09.370635575 +0000 UTC m=+365.818884189 I0519 17:06:09.370695 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="capo-system/capo-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:06:09.370914 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-19 17:06:09.370903571 +0000 UTC m=+365.819152185 I0519 17:06:09.820402 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:09.820485 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-19 17:06:09.820477735 +0000 UTC m=+366.268726339 I0519 17:06:10.252890 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:10.373389 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-pqdzm" condition "Approved" to 2026-05-19 17:06:10.373341476 +0000 UTC m=+366.821590080 I0519 17:06:10.439298 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-pqdzm" condition "Ready" to 2026-05-19 17:06:10.439285334 +0000 UTC m=+366.887533938 I0519 17:06:10.667626 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:10.667613482 +0000 UTC m=+367.115862086 I0519 17:06:10.717552 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:10.718034 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:06:10.718026197 +0000 UTC m=+367.166274791 I0519 17:06:10.742045 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:06:10.797616 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:35.306292 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:09:35.306333 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-19 17:09:35.306324411 +0000 UTC m=+571.754573045 I0519 17:09:35.306291 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Ready" to 2026-05-19 17:09:35.306240949 +0000 UTC m=+571.754489573 I0519 17:09:35.347571 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:35.347666 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:09:35.347687 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-05-19 17:09:35.34767884 +0000 UTC m=+571.795927464 I0519 17:09:35.711958 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-mp5zx" condition "Approved" to 2026-05-19 17:09:35.711945423 +0000 UTC m=+572.160194027 I0519 17:09:35.732251 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-mp5zx" condition "Ready" to 2026-05-19 17:09:35.732238504 +0000 UTC m=+572.180487098 I0519 17:09:35.760622 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:09:35.760604148 +0000 UTC m=+572.208852782 I0519 17:09:35.785679 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:35.786647 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:09:35.78664041 +0000 UTC m=+572.234889014 I0519 17:09:35.811739 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:35.814361 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:35.814949 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:09:35.814939722 +0000 UTC m=+572.263188326 I0519 17:09:39.734155 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:09:39.734303 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-05-19 17:09:39.734290597 +0000 UTC m=+576.182539231 I0519 17:09:39.734382 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Ready" to 2026-05-19 17:09:39.734362258 +0000 UTC m=+576.182610882 I0519 17:09:39.761851 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:39.761958 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0519 17:09:39.761986 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-05-19 17:09:39.761978026 +0000 UTC m=+576.210226660 I0519 17:09:40.152734 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-wlhwx" condition "Approved" to 2026-05-19 17:09:40.15272189 +0000 UTC m=+576.600970494 I0519 17:09:40.173066 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-wlhwx" condition "Ready" to 2026-05-19 17:09:40.173051151 +0000 UTC m=+576.621299765 I0519 17:09:40.223536 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:09:40.223520357 +0000 UTC m=+576.671768961 I0519 17:09:40.425633 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0519 17:09:40.426022 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-19 17:09:40.426015687 +0000 UTC m=+576.874264281 I0519 17:09:40.606158 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" E0519 17:10:10.207954 1 leaderelection.go:364] Failed to update lock: etcdserver: request timed out E0519 17:11:46.436190 1 leaderelection.go:364] Failed to update lock: Put "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused E0519 17:12:01.436839 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused E0519 17:12:16.437120 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused I0519 17:12:20.346831 1 leaderelection.go:280] failed to renew lease cert-manager/cert-manager-controller: timed out waiting for the condition E0519 17:12:20.347317 1 leaderelection.go:303] Failed to release lock: Put "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: connect: connection refused I0519 17:12:20.347631 1 controller.go:127] "cert-manager/certificaterequests-issuer-acme: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347652 1 controller.go:127] "cert-manager/orders: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347665 1 controller.go:127] "cert-manager/certificates-readiness: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347676 1 controller.go:127] "cert-manager/certificaterequests-issuer-vault: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347690 1 controller.go:127] "cert-manager/certificates-trigger: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347702 1 controller.go:127] "cert-manager/certificates-request-manager: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347715 1 controller.go:127] "cert-manager/certificates-key-manager: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347727 1 controller.go:127] "cert-manager/issuers: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347738 1 controller.go:127] "cert-manager/certificaterequests-issuer-selfsigned: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347751 1 controller.go:127] "cert-manager/certificaterequests-issuer-ca: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347764 1 controller.go:127] "cert-manager/certificates-issuing: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347776 1 controller.go:127] "cert-manager/challenges: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347787 1 controller.go:127] "cert-manager/clusterissuers: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347798 1 controller.go:127] "cert-manager/certificaterequests-issuer-venafi: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347812 1 controller.go:127] "cert-manager/certificaterequests-approver: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347824 1 controller.go:127] "cert-manager/ingress-shim: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347838 1 controller.go:127] "cert-manager/certificates-revision-manager: shutting down queue as workqueue signaled shutdown" I0519 17:12:20.347849 1 controller.go:127] "cert-manager/certificates-metrics: shutting down queue as workqueue signaled shutdown" E0519 17:12:20.348126 1 main.go:35] "cert-manager: error executing command" err="error starting controller: leader election lost"