I0320 10:13:57.765517 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0320 10:13:57.765616 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0320 10:13:57.765684 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0320 10:13:57.770340 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0320 10:13:57.770719 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0320 10:13:57.770873 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0320 10:13:57.770921 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0320 10:13:57.773119 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0320 10:13:57.787973 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0320 10:13:57.788262 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0320 10:13:57.788338 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0320 10:13:57.793357 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0320 10:13:57.795994 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0320 10:13:57.800182 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0320 10:13:57.800419 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0320 10:13:57.803014 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0320 10:13:57.805424 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0320 10:13:57.805470 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0320 10:13:57.807946 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0320 10:13:57.809714 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0320 10:13:57.811493 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0320 10:13:57.813279 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0320 10:13:57.817251 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0320 10:13:57.821803 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0320 10:13:57.825372 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0320 10:13:57.828442 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0320 10:13:57.830088 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0320 10:13:57.830135 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0320 10:13:57.832017 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0320 10:13:57.834112 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0320 10:13:57.835719 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0320 10:13:57.837346 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0320 10:13:57.838705 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0320 10:13:57.840001 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.841032 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.843304 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.843487 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.844667 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.844953 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.845233 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.845552 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.845604 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:13:57.879238 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0320 10:14:13.807688 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-03-20 10:14:13.807666591 +0000 UTC m=+16.071623239 I0320 10:14:14.479563 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-03-20 10:14:14.479549037 +0000 UTC m=+16.743505715 I0320 10:14:14.479721 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:14:14.479790 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-20 10:14:14.479781074 +0000 UTC m=+16.743737722 E0320 10:14:14.495165 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0320 10:14:14.495307 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-03-20 10:14:14.495299321 +0000 UTC m=+16.759255969 E0320 10:14:14.495350 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0320 10:14:14.498756 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:14:14.498901 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:14:14.498943 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-20 10:14:14.498931323 +0000 UTC m=+16.762887991 E0320 10:14:14.508878 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0320 10:14:14.509101 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0320 10:14:14.509144 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0320 10:14:14.510004 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0320 10:14:14.536407 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-s5dsz" condition "Approved" to 2026-03-20 10:14:14.536388337 +0000 UTC m=+16.800345015 I0320 10:14:14.552237 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-s5dsz" condition "Ready" to 2026-03-20 10:14:14.552225343 +0000 UTC m=+16.816181991 I0320 10:14:14.579118 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:14:14.579101109 +0000 UTC m=+16.843057757 I0320 10:14:14.595407 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:14:14.595688 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:14:14.595680325 +0000 UTC m=+16.859636973 I0320 10:14:14.599783 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:14:14.614136 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:14:19.510389 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:14:19.510375306 +0000 UTC m=+21.774331974 I0320 10:14:40.034769 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-03-20 10:14:40.034727015 +0000 UTC m=+42.298683663 I0320 10:14:40.034796 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:14:40.035102 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-03-20 10:14:40.035038293 +0000 UTC m=+42.298994961 I0320 10:14:40.044349 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-03-20 10:14:40.044326978 +0000 UTC m=+42.308283636 I0320 10:14:40.068489 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:14:40.068560 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:14:40.068592 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-03-20 10:14:40.068584784 +0000 UTC m=+42.332541442 I0320 10:14:40.206948 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-9q2cc" condition "Approved" to 2026-03-20 10:14:40.206914498 +0000 UTC m=+42.470871226 I0320 10:14:40.234346 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-9q2cc" condition "Ready" to 2026-03-20 10:14:40.23432942 +0000 UTC m=+42.498286068 I0320 10:14:40.263661 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:14:40.263646945 +0000 UTC m=+42.527603593 I0320 10:14:40.285944 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:25.774412 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-03-20 10:16:25.774376283 +0000 UTC m=+148.038332961 I0320 10:16:25.774714 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:16:25.774766 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-03-20 10:16:25.774754924 +0000 UTC m=+148.038711592 E0320 10:16:25.788656 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0320 10:16:25.788728 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-03-20 10:16:25.788718878 +0000 UTC m=+148.052675526 I0320 10:16:25.788773 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0320 10:16:25.790461 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:25.790520 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:16:25.790539 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-03-20 10:16:25.790533188 +0000 UTC m=+148.054489836 E0320 10:16:25.799036 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0320 10:16:25.799099 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0320 10:16:25.799122 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0320 10:16:25.799151 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0320 10:16:25.803802 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-03-20 10:16:25.803787512 +0000 UTC m=+148.067744170 I0320 10:16:25.803891 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:16:25.803927 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-03-20 10:16:25.803918806 +0000 UTC m=+148.067875454 I0320 10:16:25.820648 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:25.820714 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:16:25.820734 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-03-20 10:16:25.820727038 +0000 UTC m=+148.084683686 I0320 10:16:26.193811 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:26.202914 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-pc4cp" condition "Approved" to 2026-03-20 10:16:26.202900099 +0000 UTC m=+148.466856757 I0320 10:16:26.229844 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-pc4cp" condition "Ready" to 2026-03-20 10:16:26.22983456 +0000 UTC m=+148.493791198 I0320 10:16:26.236803 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:26.245158 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-xhtgx" condition "Approved" to 2026-03-20 10:16:26.245131951 +0000 UTC m=+148.509088599 I0320 10:16:26.261276 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:26.261263155 +0000 UTC m=+148.525219803 I0320 10:16:26.263086 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-xhtgx" condition "Ready" to 2026-03-20 10:16:26.263075314 +0000 UTC m=+148.527031982 I0320 10:16:26.279019 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:26.279549 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:26.279542787 +0000 UTC m=+148.543499435 I0320 10:16:26.287280 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:26.312850 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:26.313208 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:26.313201463 +0000 UTC m=+148.577158111 I0320 10:16:30.800393 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:30.800383385 +0000 UTC m=+153.064340023 I0320 10:16:30.814272 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-xhtgx" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:30.814258396 +0000 UTC m=+153.078215044 I0320 10:16:30.843272 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:30.843254844 +0000 UTC m=+153.107211522 I0320 10:16:30.861779 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:30.862215 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:30.862206655 +0000 UTC m=+153.126163323 I0320 10:16:30.866975 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:30.880179 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:16:30.880498 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:16:30.880486298 +0000 UTC m=+153.144442966 I0320 10:16:30.885892 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:06.969275 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Ready" to 2026-03-20 10:19:06.969224847 +0000 UTC m=+309.233181495 I0320 10:19:06.969613 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-109.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:19:06.969745 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Issuing" to 2026-03-20 10:19:06.969733301 +0000 UTC m=+309.233689979 I0320 10:19:06.987835 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-109.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-109.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:06.987895 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-109.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0320 10:19:06.987909 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Issuing" to 2026-03-20 10:19:06.987905171 +0000 UTC m=+309.251861819 I0320 10:19:07.258964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-109.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-109.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:07.264637 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-109.nip.io-tls-pzdwq" condition "Approved" to 2026-03-20 10:19:07.264623302 +0000 UTC m=+309.528579950 I0320 10:19:07.283020 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-109.nip.io-tls-pzdwq" condition "Ready" to 2026-03-20 10:19:07.283003378 +0000 UTC m=+309.546960056 I0320 10:19:07.310465 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:19:07.310447713 +0000 UTC m=+309.574404381 I0320 10:19:07.331221 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-109.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-109.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:07.331662 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:19:07.331653737 +0000 UTC m=+309.595610415 I0320 10:19:07.336434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-109.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-109.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:07.344163 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-109.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-109.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0320 10:19:07.344394 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-109.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-20 10:19:07.344387398 +0000 UTC m=+309.608344036 E0320 10:20:32.980385 1 leaderelection.go:369] Failed to update lock: etcdserver: request timed out