I0507 13:26:17.270394 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0507 13:26:17.270481 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0507 13:26:17.270533 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0507 13:26:17.272899 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0507 13:26:17.273712 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0507 13:26:17.273782 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0507 13:26:17.273870 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0507 13:26:17.279112 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0507 13:26:17.306849 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0507 13:26:17.316050 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0507 13:26:17.317361 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0507 13:26:17.360494 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0507 13:26:17.372277 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0507 13:26:17.373091 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0507 13:26:17.374818 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0507 13:26:17.381127 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0507 13:26:17.385634 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0507 13:26:17.388837 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0507 13:26:17.391255 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0507 13:26:17.393639 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0507 13:26:17.400574 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0507 13:26:17.423510 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0507 13:26:17.425642 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0507 13:26:17.460290 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0507 13:26:17.461442 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0507 13:26:17.465223 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0507 13:26:17.465698 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0507 13:26:17.470406 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0507 13:26:17.475755 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0507 13:26:17.481401 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0507 13:26:17.481423 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0507 13:26:17.481534 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0507 13:26:17.488091 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0507 13:26:17.489740 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.491463 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.491723 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.495913 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.498435 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.498812 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.499738 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.500185 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.500873 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:17.818766 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:26:18.287909 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:26:18.288116 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" condition "Issuing" to 2026-05-07 13:26:18.287935939 +0000 UTC m=+1.132244110 I0507 13:26:18.289070 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" condition "Ready" to 2026-05-07 13:26:18.289065676 +0000 UTC m=+1.133373847 I0507 13:26:18.305440 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-k6khl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:18.305495 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" condition "Ready" to 2026-05-07 13:26:18.305489822 +0000 UTC m=+1.149797993 I0507 13:26:18.531336 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-k6khl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:18.567034 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-k6khl-4nrwk" condition "Approved" to 2026-05-07 13:26:18.567016792 +0000 UTC m=+1.411324963 I0507 13:26:18.583590 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-k6khl-4nrwk" condition "Ready" to 2026-05-07 13:26:18.583578711 +0000 UTC m=+1.427886882 I0507 13:26:18.611361 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:26:18.611349047 +0000 UTC m=+1.455657218 I0507 13:26:18.631259 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-k6khl-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-k6khl-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.392410 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:26:56.392470 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-07 13:26:56.392463792 +0000 UTC m=+39.236771943 I0507 13:26:56.397174 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-07 13:26:56.397167851 +0000 UTC m=+39.241476012 I0507 13:26:56.411818 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.411923 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:26:56.411945 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-07 13:26:56.411939166 +0000 UTC m=+39.256247327 I0507 13:26:56.637326 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-wjmmk" condition "Approved" to 2026-05-07 13:26:56.637281512 +0000 UTC m=+39.481589663 I0507 13:26:56.659715 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-wjmmk" condition "Ready" to 2026-05-07 13:26:56.65970008 +0000 UTC m=+39.504008281 I0507 13:26:56.698462 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:26:56.698445966 +0000 UTC m=+39.542754167 I0507 13:26:56.716720 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.717041 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:26:56.717034407 +0000 UTC m=+39.561342568 I0507 13:26:56.729906 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.738369 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.738607 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:26:56.738912 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:26:56.738904217 +0000 UTC m=+39.583212388 I0507 13:30:19.759535 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-07 13:30:19.759515431 +0000 UTC m=+242.603823602 I0507 13:30:19.759576 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:30:19.759642 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-07 13:30:19.759632275 +0000 UTC m=+242.603940466 I0507 13:30:19.776341 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:30:19.776420 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-07 13:30:19.776410971 +0000 UTC m=+242.620719162 I0507 13:30:19.966318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:30:19.995543 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zx5th" condition "Approved" to 2026-05-07 13:30:19.995532664 +0000 UTC m=+242.839840825 I0507 13:30:20.019173 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zx5th" condition "Ready" to 2026-05-07 13:30:20.019163823 +0000 UTC m=+242.863471984 I0507 13:30:20.049563 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:30:20.049539883 +0000 UTC m=+242.893848074 I0507 13:30:20.085322 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:30:20.085711 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:30:20.085703471 +0000 UTC m=+242.930011642 I0507 13:30:20.090078 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:30:20.106854 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:30:20.107431 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:30:20.107421175 +0000 UTC m=+242.951729336 I0507 13:31:07.038727 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:31:07.038817 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-07 13:31:07.038807908 +0000 UTC m=+289.883116099 I0507 13:31:07.039134 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-07 13:31:07.039124638 +0000 UTC m=+289.883432829 I0507 13:31:07.061363 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:31:07.061425 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-07 13:31:07.061416535 +0000 UTC m=+289.905724716 I0507 13:31:07.162294 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:31:07.190060 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-2n4q5" condition "Approved" to 2026-05-07 13:31:07.190044428 +0000 UTC m=+290.034352609 I0507 13:31:07.211509 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-2n4q5" condition "Ready" to 2026-05-07 13:31:07.211496029 +0000 UTC m=+290.055804190 I0507 13:31:07.243593 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:31:07.243584203 +0000 UTC m=+290.087892354 I0507 13:31:07.268799 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:31:07.269110 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:31:07.269104671 +0000 UTC m=+290.113412832 I0507 13:31:07.282614 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:31:07.288701 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"