I0413 17:24:51.336595 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0413 17:24:51.336779 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0413 17:24:51.336881 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0413 17:24:51.339766 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0413 17:24:51.340157 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0413 17:24:51.340218 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0413 17:24:51.340251 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0413 17:24:51.344688 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0413 17:24:51.358853 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0413 17:24:51.363022 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0413 17:24:51.363078 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0413 17:24:51.366429 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0413 17:24:51.366463 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0413 17:24:51.369235 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0413 17:24:51.372157 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0413 17:24:51.378973 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0413 17:24:51.379258 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0413 17:24:51.382028 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0413 17:24:51.382058 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0413 17:24:51.382238 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0413 17:24:51.384924 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0413 17:24:51.387480 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0413 17:24:51.389866 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0413 17:24:51.392060 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0413 17:24:51.394097 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0413 17:24:51.400628 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0413 17:24:51.403645 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0413 17:24:51.406556 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0413 17:24:51.408738 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0413 17:24:51.408838 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0413 17:24:51.411065 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0413 17:24:51.413023 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0413 17:24:51.415288 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0413 17:24:51.418571 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.420753 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.421315 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.439662 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.453464 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.474309 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.490678 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.503079 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.516344 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:24:51.523718 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 17:25:17.650130 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-13 17:25:17.650111249 +0000 UTC m=+26.352624120 I0413 17:25:18.419725 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-13 17:25:18.419715218 +0000 UTC m=+27.122228089 I0413 17:25:18.419944 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:18.420040 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-13 17:25:18.420020691 +0000 UTC m=+27.122533612 I0413 17:25:18.442220 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:18.442328 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-13 17:25:18.442318862 +0000 UTC m=+27.144831743 E0413 17:25:18.444003 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0413 17:25:18.444082 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-13 17:25:18.444073589 +0000 UTC m=+27.146586460 E0413 17:25:18.444104 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 17:25:18.456093 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0413 17:25:18.456168 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 17:25:18.456190 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 17:25:18.456220 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0413 17:25:18.468134 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:18.503205 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-wr2vx" condition "Approved" to 2026-04-13 17:25:18.50318974 +0000 UTC m=+27.205702641 I0413 17:25:18.520307 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-wr2vx" condition "Ready" to 2026-04-13 17:25:18.520292774 +0000 UTC m=+27.222805665 I0413 17:25:18.547176 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:18.547163199 +0000 UTC m=+27.249676060 I0413 17:25:18.578082 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:18.651658 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:23.457213 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:23.457196425 +0000 UTC m=+32.159709306 I0413 17:25:24.077809 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-13 17:25:24.077790767 +0000 UTC m=+32.780303658 I0413 17:25:24.079109 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:24.079137 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-13 17:25:24.079133009 +0000 UTC m=+32.781645890 I0413 17:25:24.104311 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-13 17:25:24.104299246 +0000 UTC m=+32.806812127 I0413 17:25:24.107801 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:24.107918 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:24.107941 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-13 17:25:24.107936909 +0000 UTC m=+32.810449780 I0413 17:25:24.569725 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-zqxcv" condition "Approved" to 2026-04-13 17:25:24.56971214 +0000 UTC m=+33.272225021 I0413 17:25:24.602651 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-zqxcv" condition "Ready" to 2026-04-13 17:25:24.60263896 +0000 UTC m=+33.305151841 I0413 17:25:24.634982 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:24.634963803 +0000 UTC m=+33.337476704 I0413 17:25:24.665165 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.267307 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-13 17:25:28.26723962 +0000 UTC m=+36.969752521 I0413 17:25:28.268049 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:28.268146 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-13 17:25:28.268138069 +0000 UTC m=+36.970650970 E0413 17:25:28.285388 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0413 17:25:28.285560 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-04-13 17:25:28.285526981 +0000 UTC m=+36.988039892 I0413 17:25:28.285691 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0413 17:25:28.291507 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.291598 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:28.291631 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-13 17:25:28.291625868 +0000 UTC m=+36.994138749 E0413 17:25:28.299504 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0413 17:25:28.299611 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0413 17:25:28.299653 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0413 17:25:28.299722 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0413 17:25:28.305389 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-13 17:25:28.305382436 +0000 UTC m=+37.007895317 I0413 17:25:28.306088 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:28.306264 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-13 17:25:28.306252645 +0000 UTC m=+37.008765586 I0413 17:25:28.330649 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.330803 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 17:25:28.330856 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-13 17:25:28.330844124 +0000 UTC m=+37.033357035 I0413 17:25:28.496542 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.511352 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-sgkkd" condition "Approved" to 2026-04-13 17:25:28.511338339 +0000 UTC m=+37.213851230 I0413 17:25:28.537574 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-sgkkd" condition "Ready" to 2026-04-13 17:25:28.537562264 +0000 UTC m=+37.240075125 I0413 17:25:28.694623 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.708315 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-wc2h8" condition "Approved" to 2026-04-13 17:25:28.708298558 +0000 UTC m=+37.410811449 I0413 17:25:28.746415 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-wc2h8" condition "Ready" to 2026-04-13 17:25:28.746399534 +0000 UTC m=+37.448912405 I0413 17:25:28.808334 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:28.808319622 +0000 UTC m=+37.510832483 I0413 17:25:28.836594 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.836995 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:28.836987139 +0000 UTC m=+37.539500020 I0413 17:25:28.874274 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:28.886148 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:33.300310 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:33.300293638 +0000 UTC m=+42.002806519 I0413 17:25:33.317088 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-sgkkd" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:33.317073674 +0000 UTC m=+42.019586585 I0413 17:25:33.356644 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 17:25:33.35661652 +0000 UTC m=+42.059129401 I0413 17:25:33.383974 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0413 17:25:33.436703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again"