I0422 12:54:31.704508 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0422 12:54:31.704755 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0422 12:54:31.704832 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0422 12:54:31.704937 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0422 12:54:31.706934 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0422 12:54:31.708164 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0422 12:54:31.709291 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0422 12:54:31.709848 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0422 12:54:31.725247 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0422 12:54:31.726818 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0422 12:54:31.727550 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0422 12:54:31.727662 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0422 12:54:31.728782 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0422 12:54:31.728862 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0422 12:54:31.728970 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0422 12:54:31.730331 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0422 12:54:31.730424 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0422 12:54:31.731234 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0422 12:54:31.731558 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0422 12:54:31.732192 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0422 12:54:31.733050 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0422 12:54:31.733905 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0422 12:54:31.735059 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0422 12:54:31.735110 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0422 12:54:31.736288 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0422 12:54:31.736920 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0422 12:54:31.737502 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0422 12:54:31.738285 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0422 12:54:31.738728 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0422 12:54:31.739347 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0422 12:54:31.739597 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0422 12:54:31.739692 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0422 12:54:31.739718 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0422 12:54:59.578093 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-22 12:54:59.578070937 +0000 UTC m=+27.913060077 I0422 12:54:59.593245 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 12:54:59.593231126 +0000 UTC m=+27.928220296 I0422 12:54:59.593874 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:54:59.593954 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 12:54:59.593944125 +0000 UTC m=+27.928933295 I0422 12:54:59.610216 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0422 12:54:59.610330 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 12:54:59.610282338 +0000 UTC m=+27.945271478 E0422 12:54:59.610272 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a8af0777c37fb6", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"cc3a4e65-2a12-4413-949b-a19cb3bd77ee", APIVersion:"cert-manager.io/v1", ResourceVersion:"1354", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 22, 12, 54, 59, 606593462, time.Local), LastTimestamp:time.Date(2026, time.April, 22, 12, 54, 59, 606593462, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a8af0777c37fb6" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) E0422 12:54:59.611888 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0422 12:54:59.621179 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0422 12:54:59.643076 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 12:54:59.643062875 +0000 UTC m=+27.978052015 I0422 12:54:59.656324 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 12:54:59.656312939 +0000 UTC m=+27.991302079 I0422 12:54:59.656391 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:54:59.656420 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 12:54:59.65641447 +0000 UTC m=+27.991403610 I0422 12:54:59.670213 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 12:54:59.670464 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:54:59.670558 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 12:54:59.670494025 +0000 UTC m=+28.005483155 I0422 12:54:59.880949 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-8xv69" condition "Approved" to 2026-04-22 12:54:59.880934368 +0000 UTC m=+28.215923538 I0422 12:54:59.923337 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-8xv69" condition "Ready" to 2026-04-22 12:54:59.923325125 +0000 UTC m=+28.258314265 I0422 12:55:00.001625 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:00.001615677 +0000 UTC m=+28.336604817 I0422 12:55:00.045678 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" E0422 12:55:00.114957 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0422 12:55:00.269505 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 12:55:00.269480411 +0000 UTC m=+28.604469591 I0422 12:55:00.288180 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 12:55:00.288164743 +0000 UTC m=+28.623153893 I0422 12:55:00.290106 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:55:00.290141 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 12:55:00.290136358 +0000 UTC m=+28.625125498 I0422 12:55:00.308834 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 12:55:00.308930 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 12:55:00.308923179 +0000 UTC m=+28.643912309 I0422 12:55:00.607686 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 12:55:00.637602 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 12:55:00.637585148 +0000 UTC m=+28.972574278 I0422 12:55:00.682596 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:55:00.682624 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 12:55:00.682618235 +0000 UTC m=+29.017607375 I0422 12:55:00.683068 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 12:55:00.68306339 +0000 UTC m=+29.018052530 I0422 12:55:00.684813 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-bj44n" condition "Approved" to 2026-04-22 12:55:00.684802921 +0000 UTC m=+29.019792051 I0422 12:55:00.703528 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 12:55:00.703598 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 12:55:00.703590514 +0000 UTC m=+29.038579664 I0422 12:55:00.709535 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-bj44n" condition "Ready" to 2026-04-22 12:55:00.709522047 +0000 UTC m=+29.044511187 I0422 12:55:00.751624 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:00.751611658 +0000 UTC m=+29.086600788 I0422 12:55:00.773640 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 12:55:00.774773 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:00.774764196 +0000 UTC m=+29.109753336 I0422 12:55:00.787030 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 12:55:00.813053 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 12:55:00.813487 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:00.813473904 +0000 UTC m=+29.148463074 I0422 12:55:00.898230 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 12:55:00.966900 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-s47qw" condition "Approved" to 2026-04-22 12:55:00.966887063 +0000 UTC m=+29.301876193 I0422 12:55:01.045406 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 12:55:01.045387003 +0000 UTC m=+29.380376183 I0422 12:55:01.047527 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-s47qw" condition "Ready" to 2026-04-22 12:55:01.047512589 +0000 UTC m=+29.382501719 I0422 12:55:01.058498 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 12:55:01.058482854 +0000 UTC m=+29.393471994 I0422 12:55:01.058795 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:55:01.058823 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 12:55:01.058818398 +0000 UTC m=+29.393807528 I0422 12:55:01.406498 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 12:55:01.408974 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 12:55:01.409006 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 12:55:01.409001159 +0000 UTC m=+29.743990279 I0422 12:55:01.445025 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:01.445009913 +0000 UTC m=+29.779999053 I0422 12:55:01.589020 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 12:55:01.589411 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:01.589400634 +0000 UTC m=+29.924389794 I0422 12:55:02.046284 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 12:55:02.048869 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 12:55:02.298551 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 12:55:02.390829 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-hhnmq" condition "Approved" to 2026-04-22 12:55:02.390813005 +0000 UTC m=+30.725802135 I0422 12:55:02.442354 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-hhnmq" condition "Ready" to 2026-04-22 12:55:02.44234033 +0000 UTC m=+30.777329470 I0422 12:55:02.895003 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:02.894986445 +0000 UTC m=+31.229975575 I0422 12:55:03.037392 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 12:55:03.037828 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 12:55:03.03781858 +0000 UTC m=+31.372807720 I0422 12:55:03.290580 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 12:55:03.382919 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0422 12:56:11.232945 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0422 12:56:11.279754 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 12:56:11.279738131 +0000 UTC m=+99.614727291 I0422 12:56:11.424465 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 12:56:11.424449704 +0000 UTC m=+99.759438874 E0422 12:56:13.512578 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0422 12:56:13.565911 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 12:56:13.565896098 +0000 UTC m=+101.900885268 I0422 12:56:13.595014 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 12:56:13.595000048 +0000 UTC m=+101.929989198 E0422 12:56:15.317581 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0422 12:56:15.362729 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 12:56:15.362712695 +0000 UTC m=+103.697701865 I0422 12:56:15.387912 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 12:56:15.387871402 +0000 UTC m=+103.722860542 E0422 12:56:17.081446 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0422 12:56:17.115462 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 12:56:17.115426906 +0000 UTC m=+105.450416046 I0422 12:56:17.136436 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 12:56:17.134839321 +0000 UTC m=+105.469828461