I0419 01:07:23.945202 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0419 01:07:23.945472 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0419 01:07:23.945555 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0419 01:07:23.945693 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0419 01:07:23.947956 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0419 01:07:23.948660 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0419 01:07:23.948848 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0419 01:07:23.949591 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0419 01:07:23.967750 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0419 01:07:23.969574 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0419 01:07:23.970552 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0419 01:07:23.971793 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0419 01:07:23.972886 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0419 01:07:23.973762 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0419 01:07:23.974381 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0419 01:07:23.974405 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0419 01:07:23.974414 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0419 01:07:23.974419 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0419 01:07:23.975118 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0419 01:07:23.975166 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0419 01:07:23.976353 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0419 01:07:23.977705 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0419 01:07:23.980090 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0419 01:07:23.982081 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0419 01:07:23.982761 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0419 01:07:23.983482 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0419 01:07:23.983519 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0419 01:07:23.983531 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0419 01:07:23.984347 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0419 01:07:23.984906 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0419 01:07:23.985364 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0419 01:07:23.985914 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0419 01:07:23.988006 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0419 01:07:44.342072 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-19 01:07:44.342043402 +0000 UTC m=+20.443714226 I0419 01:07:44.354611 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-19 01:07:44.354593961 +0000 UTC m=+20.456264775 I0419 01:07:44.354937 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:44.355616 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-19 01:07:44.355599959 +0000 UTC m=+20.457270783 E0419 01:07:44.374395 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0419 01:07:44.375039 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0419 01:07:44.375117 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:44.375177 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-19 01:07:44.375140903 +0000 UTC m=+20.476811707 E0419 01:07:44.387226 1 controller.go:167] cert-manager/certificates-trigger "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0419 01:07:44.404329 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-19 01:07:44.404317033 +0000 UTC m=+20.505987877 I0419 01:07:44.429888 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-19 01:07:44.429874805 +0000 UTC m=+20.531545619 I0419 01:07:44.430184 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:44.432772 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-19 01:07:44.432758918 +0000 UTC m=+20.534429732 I0419 01:07:44.468863 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0419 01:07:44.469945 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:44.469982 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-19 01:07:44.469977452 +0000 UTC m=+20.571648266 I0419 01:07:44.889898 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0419 01:07:44.904609 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-pl6pg" condition "Approved" to 2026-04-19 01:07:44.904601203 +0000 UTC m=+21.006272027 I0419 01:07:44.936376 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-pl6pg" condition "Ready" to 2026-04-19 01:07:44.936366824 +0000 UTC m=+21.038037638 I0419 01:07:44.972392 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:44.972377268 +0000 UTC m=+21.074048112 I0419 01:07:45.008816 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0419 01:07:45.010444 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:45.010437908 +0000 UTC m=+21.112108722 I0419 01:07:45.010546 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-19 01:07:45.010535139 +0000 UTC m=+21.112205963 I0419 01:07:45.022808 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:45.022835 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-19 01:07:45.022826815 +0000 UTC m=+21.124497639 I0419 01:07:45.023174 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-19 01:07:45.023169908 +0000 UTC m=+21.124840732 I0419 01:07:45.029118 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0419 01:07:45.034386 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0419 01:07:45.035068 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:45.035062282 +0000 UTC m=+21.136733106 I0419 01:07:45.042673 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0419 01:07:45.042769 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:45.042787 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-19 01:07:45.042782202 +0000 UTC m=+21.144453026 I0419 01:07:45.332507 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-19 01:07:45.332495379 +0000 UTC m=+21.434166193 I0419 01:07:45.362043 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:45.362069 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-19 01:07:45.362062131 +0000 UTC m=+21.463732955 I0419 01:07:45.363014 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-19 01:07:45.362998218 +0000 UTC m=+21.464669032 I0419 01:07:45.396977 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0419 01:07:45.397053 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-19 01:07:45.397048396 +0000 UTC m=+21.498719210 I0419 01:07:45.543268 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0419 01:07:45.607816 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-brpgs" condition "Approved" to 2026-04-19 01:07:45.607807382 +0000 UTC m=+21.709478196 I0419 01:07:45.663357 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-brpgs" condition "Ready" to 2026-04-19 01:07:45.663346489 +0000 UTC m=+21.765017303 I0419 01:07:45.722104 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:45.72208933 +0000 UTC m=+21.823760184 I0419 01:07:45.749521 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-19 01:07:45.749511215 +0000 UTC m=+21.851182029 I0419 01:07:45.759113 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0419 01:07:45.766306 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:45.766326 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-19 01:07:45.766322328 +0000 UTC m=+21.867993142 I0419 01:07:45.766413 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-19 01:07:45.766397168 +0000 UTC m=+21.868067982 I0419 01:07:45.783533 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0419 01:07:45.783583 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0419 01:07:45.783594 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-19 01:07:45.783590463 +0000 UTC m=+21.885261277 I0419 01:07:45.918049 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-c2psc" condition "Approved" to 2026-04-19 01:07:45.918035599 +0000 UTC m=+22.019706423 I0419 01:07:45.953576 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-c2psc" condition "Ready" to 2026-04-19 01:07:45.953556519 +0000 UTC m=+22.055227333 I0419 01:07:46.222669 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:46.222658986 +0000 UTC m=+22.324329800 I0419 01:07:46.332997 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0419 01:07:46.716430 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0419 01:07:46.774533 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-d7tdr" condition "Approved" to 2026-04-19 01:07:46.774522731 +0000 UTC m=+22.876193545 I0419 01:07:47.184717 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-d7tdr" condition "Ready" to 2026-04-19 01:07:47.184664883 +0000 UTC m=+23.286335697 I0419 01:07:47.418168 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-19 01:07:47.418154731 +0000 UTC m=+23.519825555 I0419 01:07:47.516126 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0419 01:07:47.815349 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0419 01:08:51.991322 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0419 01:08:52.036601 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-19 01:08:52.036015457 +0000 UTC m=+88.137686281 I0419 01:08:52.056378 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-19 01:08:52.056361648 +0000 UTC m=+88.158032492 E0419 01:08:54.165652 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0419 01:08:54.216859 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-19 01:08:54.216814514 +0000 UTC m=+90.318485358 I0419 01:08:54.243454 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-19 01:08:54.243438529 +0000 UTC m=+90.345109383 E0419 01:08:55.835037 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0419 01:08:55.874570 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-19 01:08:55.874425931 +0000 UTC m=+91.976096755 I0419 01:08:55.894276 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-19 01:08:55.894267055 +0000 UTC m=+91.995937879 E0419 01:08:57.623115 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0419 01:08:57.654718 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-19 01:08:57.654705281 +0000 UTC m=+93.756376105 I0419 01:08:57.674326 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-19 01:08:57.6743187 +0000 UTC m=+93.775989524