I0507 13:17:04.857990 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0507 13:17:04.858326 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0507 13:17:04.858543 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0507 13:17:04.862764 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0507 13:17:04.863214 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0507 13:17:04.863299 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0507 13:17:04.863329 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0507 13:17:04.866012 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0507 13:17:04.883046 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0507 13:17:04.887673 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0507 13:17:04.891434 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0507 13:17:04.891498 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0507 13:17:04.894302 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0507 13:17:04.896502 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0507 13:17:04.896666 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0507 13:17:04.898543 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0507 13:17:04.900191 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0507 13:17:04.902113 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0507 13:17:04.910929 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0507 13:17:04.914525 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0507 13:17:04.917457 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0507 13:17:04.920349 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0507 13:17:04.922832 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0507 13:17:04.925119 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0507 13:17:04.925138 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0507 13:17:04.925178 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0507 13:17:04.927176 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0507 13:17:04.929096 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0507 13:17:04.929375 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0507 13:17:04.934696 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0507 13:17:04.939512 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0507 13:17:04.939579 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0507 13:17:04.943989 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0507 13:17:04.947840 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:04.948673 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:04.948853 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:04.968776 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:04.981803 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:04.994015 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:05.014696 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:05.022149 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:05.029342 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:05.041970 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 13:17:27.699203 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-07 13:17:27.69919082 +0000 UTC m=+22.870247684 I0507 13:17:28.385274 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-07 13:17:28.385258392 +0000 UTC m=+23.556315286 I0507 13:17:28.385748 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:17:28.385818 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-07 13:17:28.385806093 +0000 UTC m=+23.556862967 E0507 13:17:28.401050 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0507 13:17:28.401111 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-07 13:17:28.401103735 +0000 UTC m=+23.572160599 E0507 13:17:28.401135 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0507 13:17:28.405904 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:17:28.405966 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-07 13:17:28.405960801 +0000 UTC m=+23.577017665 E0507 13:17:28.419387 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0507 13:17:28.419491 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 13:17:28.419528 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 13:17:28.419567 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0507 13:17:28.428012 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:17:28.451892 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-phbwq" condition "Approved" to 2026-05-07 13:17:28.451874716 +0000 UTC m=+23.622931610 I0507 13:17:28.466398 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-phbwq" condition "Ready" to 2026-05-07 13:17:28.46638416 +0000 UTC m=+23.637441024 I0507 13:17:28.491693 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:17:28.491679868 +0000 UTC m=+23.662736732 I0507 13:17:28.513784 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:17:33.420601 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:17:33.420583654 +0000 UTC m=+28.591640538 I0507 13:17:59.914297 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:17:59.916216 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-07 13:17:59.916204239 +0000 UTC m=+55.087261103 I0507 13:17:59.914912 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-07 13:17:59.914894356 +0000 UTC m=+55.085951220 I0507 13:17:59.924017 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-07 13:17:59.924004875 +0000 UTC m=+55.095061729 I0507 13:17:59.944585 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:17:59.944743 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-07 13:17:59.944708705 +0000 UTC m=+55.115765569 I0507 13:18:00.136677 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:18:00.169091 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-fmsz6" condition "Approved" to 2026-05-07 13:18:00.169080485 +0000 UTC m=+55.340137349 I0507 13:18:00.198819 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-fmsz6" condition "Ready" to 2026-05-07 13:18:00.198807429 +0000 UTC m=+55.369864293 I0507 13:18:00.229322 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:18:00.229310256 +0000 UTC m=+55.400367100 I0507 13:18:00.258132 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:18:00.258707 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:18:00.258696723 +0000 UTC m=+55.429753637 I0507 13:18:00.320923 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:18:00.321246 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:18:00.321240732 +0000 UTC m=+55.492297586 I0507 13:23:19.985389 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-168.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:23:19.985469 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Issuing" to 2026-05-07 13:23:19.985462884 +0000 UTC m=+375.156519738 I0507 13:23:19.985654 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Ready" to 2026-05-07 13:23:19.985553126 +0000 UTC m=+375.156609990 I0507 13:23:20.009394 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-168.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-168.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:23:20.009570 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Ready" to 2026-05-07 13:23:20.009560371 +0000 UTC m=+375.180617235 I0507 13:23:20.119706 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-168.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-168.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:23:20.147970 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-168.nip.io-tls-656js" condition "Approved" to 2026-05-07 13:23:20.147960303 +0000 UTC m=+375.319017167 I0507 13:23:20.175250 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-168.nip.io-tls-656js" condition "Ready" to 2026-05-07 13:23:20.17523432 +0000 UTC m=+375.346291204 I0507 13:23:20.203694 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:23:20.203684819 +0000 UTC m=+375.374741683 I0507 13:23:20.226745 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-168.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-168.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:23:20.233421 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-168.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-168.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:23:20.233863 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:23:20.233856793 +0000 UTC m=+375.404913657 I0507 13:23:20.250766 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-168.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-168.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:23:20.251169 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-168.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:23:20.251161477 +0000 UTC m=+375.422218341 I0507 13:24:25.314614 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:24:25.314667 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-07 13:24:25.314653598 +0000 UTC m=+440.485710502 I0507 13:24:25.315075 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-07 13:24:25.315058985 +0000 UTC m=+440.486115899 E0507 13:24:25.328807 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0507 13:24:25.328889 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-07 13:24:25.32887675 +0000 UTC m=+440.499933624 E0507 13:24:25.328959 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0507 13:24:25.329377 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:24:25.329480 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-07 13:24:25.32946996 +0000 UTC m=+440.500526824 E0507 13:24:25.346541 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0507 13:24:25.346696 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 13:24:25.346756 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 13:24:25.346882 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0507 13:24:25.352243 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:24:25.377671 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-qwbsh" condition "Approved" to 2026-05-07 13:24:25.377615899 +0000 UTC m=+440.548672763 I0507 13:24:25.394399 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-qwbsh" condition "Ready" to 2026-05-07 13:24:25.394378654 +0000 UTC m=+440.565435508 I0507 13:24:25.421917 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:24:25.421903903 +0000 UTC m=+440.592960767 I0507 13:24:25.438523 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:24:25.438954 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:24:25.438947213 +0000 UTC m=+440.610004077 I0507 13:24:25.455484 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:24:30.347789 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:24:30.347773484 +0000 UTC m=+445.518830368 I0507 13:25:10.979512 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:10.979952 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-07 13:25:10.979923766 +0000 UTC m=+486.150980630 I0507 13:25:10.979562 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-07 13:25:10.979554491 +0000 UTC m=+486.150611345 I0507 13:25:10.996733 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:10.996771 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-07 13:25:10.996765086 +0000 UTC m=+486.167821930 I0507 13:25:10.998110 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-07 13:25:10.998092787 +0000 UTC m=+486.169149671 I0507 13:25:10.999351 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:10.999407 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-07 13:25:10.999401218 +0000 UTC m=+486.170458092 I0507 13:25:10.999412 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-07 13:25:10.999398058 +0000 UTC m=+486.170454912 I0507 13:25:11.041850 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.041912 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:11.041936 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-07 13:25:11.041930836 +0000 UTC m=+486.212987690 I0507 13:25:11.048230 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.048340 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-07 13:25:11.048332749 +0000 UTC m=+486.219389613 I0507 13:25:11.051865 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.051935 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:11.051972 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-07 13:25:11.051965747 +0000 UTC m=+486.223022601 I0507 13:25:11.240248 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-ps7gf" condition "Approved" to 2026-05-07 13:25:11.240232704 +0000 UTC m=+486.411289568 I0507 13:25:11.256060 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-ps7gf" condition "Ready" to 2026-05-07 13:25:11.256049047 +0000 UTC m=+486.427105901 I0507 13:25:11.279432 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.316770 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.318584 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6k8dp" condition "Approved" to 2026-05-07 13:25:11.318568635 +0000 UTC m=+486.489625489 I0507 13:25:11.322929 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 13:25:11.322972 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-07 13:25:11.322962936 +0000 UTC m=+486.494019820 I0507 13:25:11.339143 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-bk687" condition "Approved" to 2026-05-07 13:25:11.339128873 +0000 UTC m=+486.510185737 I0507 13:25:11.351028 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:11.351020284 +0000 UTC m=+486.522077138 I0507 13:25:11.359553 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6k8dp" condition "Ready" to 2026-05-07 13:25:11.35954048 +0000 UTC m=+486.530597334 I0507 13:25:11.361551 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.370187 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-bk687" condition "Ready" to 2026-05-07 13:25:11.370175699 +0000 UTC m=+486.541232553 I0507 13:25:11.621827 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:11.622198 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:11.622189474 +0000 UTC m=+486.793246378 I0507 13:25:12.728164 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:12.728150775 +0000 UTC m=+487.899207619 I0507 13:25:12.738443 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-d94dz" condition "Approved" to 2026-05-07 13:25:12.738428249 +0000 UTC m=+487.909485093 I0507 13:25:13.579743 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:13.582585 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-d94dz" condition "Ready" to 2026-05-07 13:25:13.582574264 +0000 UTC m=+488.753631118 I0507 13:25:15.734172 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:15.734157192 +0000 UTC m=+490.905214076 I0507 13:25:16.730055 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:16.73004367 +0000 UTC m=+491.901100534 I0507 13:25:16.733455 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:17.729909 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:17.730071 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 13:25:17.730066677 +0000 UTC m=+492.901123531 I0507 13:25:17.755845 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:17.761715 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 13:25:17.834378 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" E0507 13:26:04.894651 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": context deadline exceeded I0507 13:26:04.894825 1 leaderelection.go:285] failed to renew lease cert-manager/cert-manager-controller: timed out waiting for the condition E0507 13:26:11.902272 1 leaderelection.go:308] Failed to release lock: etcdserver: request timed out I0507 13:26:11.902615 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.orders" I0507 13:26:11.902662 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.ingress-shim" I0507 13:26:11.902730 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-issuing" I0507 13:26:11.902753 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-approver" I0507 13:26:11.902780 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-vault" I0507 13:26:11.902887 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.challenges" I0507 13:26:11.902900 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-acme" I0507 13:26:11.902907 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.clusterissuers" I0507 13:26:11.902922 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-trigger" I0507 13:26:11.902923 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-selfsigned" I0507 13:26:11.902937 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-venafi" I0507 13:26:11.902935 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.issuers" I0507 13:26:11.902951 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-ca" I0507 13:26:11.902948 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-metrics" I0507 13:26:11.902958 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-revision-manager" I0507 13:26:11.902968 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-request-manager" I0507 13:26:11.902970 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-readiness" I0507 13:26:11.902974 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-key-manager" E0507 13:26:11.903729 1 main.go:35] "error executing command" err="error starting controller: leader election lost" logger="cert-manager"