I0511 10:46:05.179425 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0511 10:46:05.179790 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0511 10:46:05.179982 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0511 10:46:05.186424 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0511 10:46:05.186922 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0511 10:46:05.187089 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0511 10:46:05.187072 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0511 10:46:05.189261 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0511 10:46:05.204496 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0511 10:46:05.207516 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0511 10:46:05.207652 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0511 10:46:05.210079 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0511 10:46:05.214195 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0511 10:46:05.217324 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0511 10:46:05.219276 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0511 10:46:05.221149 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0511 10:46:05.223238 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0511 10:46:05.224969 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0511 10:46:05.225002 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0511 10:46:05.225024 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0511 10:46:05.225055 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0511 10:46:05.226957 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0511 10:46:05.229674 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0511 10:46:05.234562 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0511 10:46:05.238451 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0511 10:46:05.238547 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0511 10:46:05.240742 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0511 10:46:05.242597 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0511 10:46:05.244550 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0511 10:46:05.246948 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0511 10:46:05.248736 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0511 10:46:05.250575 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0511 10:46:05.251226 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0511 10:46:05.262440 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.263736 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.264156 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.266113 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.278526 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.292362 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.309301 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.324734 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.346778 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:05.350193 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0511 10:46:16.364117 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-11 10:46:16.36410156 +0000 UTC m=+11.219242821 I0511 10:46:17.121646 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:46:17.121761 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-11 10:46:17.121753199 +0000 UTC m=+11.976894450 I0511 10:46:17.122631 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-11 10:46:17.122625937 +0000 UTC m=+11.977767178 I0511 10:46:17.142740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:17.142839 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-11 10:46:17.14279809 +0000 UTC m=+11.997939331 E0511 10:46:17.146692 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:46:17.146999 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-11 10:46:17.146989723 +0000 UTC m=+12.002130954 E0511 10:46:17.147019 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:46:17.160420 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0511 10:46:17.160756 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:46:17.160818 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:46:17.160905 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0511 10:46:17.163129 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:17.187726 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-xz6p8" condition "Approved" to 2026-05-11 10:46:17.187706312 +0000 UTC m=+12.042847583 I0511 10:46:17.202208 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-xz6p8" condition "Ready" to 2026-05-11 10:46:17.202197704 +0000 UTC m=+12.057338935 I0511 10:46:17.225601 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:17.225585149 +0000 UTC m=+12.080726400 I0511 10:46:17.245378 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:17.246082 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:17.246069942 +0000 UTC m=+12.101211193 I0511 10:46:17.252813 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:17.262258 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:22.162351 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:22.162332438 +0000 UTC m=+17.017473709 I0511 10:46:44.935064 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:46:44.935209 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-11 10:46:44.935200232 +0000 UTC m=+39.790341473 I0511 10:46:44.935081 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-11 10:46:44.935040288 +0000 UTC m=+39.790181529 I0511 10:46:44.952152 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-11 10:46:44.952137903 +0000 UTC m=+39.807279154 I0511 10:46:44.973956 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:44.974054 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-11 10:46:44.974048018 +0000 UTC m=+39.829189249 I0511 10:46:45.180170 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:45.211611 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hzx29" condition "Approved" to 2026-05-11 10:46:45.211593203 +0000 UTC m=+40.066734484 I0511 10:46:45.245732 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hzx29" condition "Ready" to 2026-05-11 10:46:45.245720418 +0000 UTC m=+40.100861659 I0511 10:46:45.282277 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:45.282258757 +0000 UTC m=+40.137399998 I0511 10:46:45.308972 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:45.309217 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:45.309210842 +0000 UTC m=+40.164352073 I0511 10:46:45.326149 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:46:45.326437 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:46:45.326428999 +0000 UTC m=+40.181570240 I0511 10:51:50.416185 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-128.nip.io-tls" condition "Ready" to 2026-05-11 10:51:50.416152708 +0000 UTC m=+345.271293949 I0511 10:51:50.416187 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-128.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:51:50.416296 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-128.nip.io-tls" condition "Issuing" to 2026-05-11 10:51:50.416283982 +0000 UTC m=+345.271425243 I0511 10:51:50.433388 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-128.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-128.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:51:50.433456 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-128.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:51:50.433479 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-128.nip.io-tls" condition "Issuing" to 2026-05-11 10:51:50.43347188 +0000 UTC m=+345.288613121 I0511 10:51:50.592040 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-128.nip.io-tls-q75zj" condition "Approved" to 2026-05-11 10:51:50.592024945 +0000 UTC m=+345.447166196 I0511 10:51:50.626747 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-128.nip.io-tls-q75zj" condition "Ready" to 2026-05-11 10:51:50.626732052 +0000 UTC m=+345.481873313 I0511 10:51:50.652914 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-128.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:51:50.652893892 +0000 UTC m=+345.508035133 I0511 10:51:50.673833 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-128.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-128.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:51:50.716515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-128.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-128.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:55.994088 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:52:55.994092 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-11 10:52:55.994072709 +0000 UTC m=+410.849213960 I0511 10:52:55.994131 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-11 10:52:55.99412269 +0000 UTC m=+410.849263931 E0511 10:52:56.008788 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:52:56.008852 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-11 10:52:56.008845022 +0000 UTC m=+410.863986263 E0511 10:52:56.009003 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0511 10:52:56.017046 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:56.017274 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:52:56.017309 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-11 10:52:56.017300791 +0000 UTC m=+410.872442042 E0511 10:52:56.018203 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0511 10:52:56.018331 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:52:56.018405 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0511 10:52:56.018452 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0511 10:52:56.055646 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:56.056213 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-m9kmr" condition "Approved" to 2026-05-11 10:52:56.056195448 +0000 UTC m=+410.911336669 I0511 10:52:56.068619 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-m9kmr" condition "Ready" to 2026-05-11 10:52:56.068603869 +0000 UTC m=+410.923745130 I0511 10:52:56.093343 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:56.093319779 +0000 UTC m=+410.948461050 I0511 10:52:56.108592 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:52:56.109064 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:52:56.109056116 +0000 UTC m=+410.964197357 I0511 10:52:56.126805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:01.019757 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:01.019741271 +0000 UTC m=+415.874882532 I0511 10:53:42.643655 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-11 10:53:42.643632059 +0000 UTC m=+457.498773300 I0511 10:53:42.645659 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.645686 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-11 10:53:42.645681418 +0000 UTC m=+457.500822659 I0511 10:53:42.661314 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.661378 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-11 10:53:42.661366474 +0000 UTC m=+457.516507735 I0511 10:53:42.661922 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-11 10:53:42.661905997 +0000 UTC m=+457.517047228 I0511 10:53:42.678128 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.678217 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-11 10:53:42.678208298 +0000 UTC m=+457.533349529 I0511 10:53:42.679852 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-11 10:53:42.679830527 +0000 UTC m=+457.534971758 I0511 10:53:42.728582 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.728644 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.728664 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-11 10:53:42.728657458 +0000 UTC m=+457.583798689 I0511 10:53:42.730288 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.730394 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-11 10:53:42.730382529 +0000 UTC m=+457.585523890 I0511 10:53:42.777905 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:42.777980 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:42.778004 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-11 10:53:42.77799907 +0000 UTC m=+457.633140301 I0511 10:53:43.002511 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-kvtdj" condition "Approved" to 2026-05-11 10:53:43.002488881 +0000 UTC m=+457.857630172 I0511 10:53:43.033119 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-kvtdj" condition "Ready" to 2026-05-11 10:53:43.033099134 +0000 UTC m=+457.888240365 I0511 10:53:43.094153 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.094192 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.094178105 +0000 UTC m=+457.949319346 I0511 10:53:43.144225 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-lj9ft" condition "Approved" to 2026-05-11 10:53:43.144210733 +0000 UTC m=+457.999351954 I0511 10:53:43.152701 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.153025 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.153017713 +0000 UTC m=+458.008158944 I0511 10:53:43.169716 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-lj9ft" condition "Ready" to 2026-05-11 10:53:43.169707773 +0000 UTC m=+458.024849004 I0511 10:53:43.170689 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.177915 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.178375 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.178366971 +0000 UTC m=+458.033508212 I0511 10:53:43.190139 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-h78k9" condition "Approved" to 2026-05-11 10:53:43.190119412 +0000 UTC m=+458.045260643 I0511 10:53:43.198169 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.198154964 +0000 UTC m=+458.053296205 I0511 10:53:43.298296 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-h78k9" condition "Ready" to 2026-05-11 10:53:43.29828176 +0000 UTC m=+458.153423021 I0511 10:53:43.642098 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:43.642579 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:43.642569111 +0000 UTC m=+458.497710372 I0511 10:53:44.037173 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:44.037157835 +0000 UTC m=+458.892299096 I0511 10:53:44.087441 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:44.137681 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:44.236574 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:44.583884 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:48.811582 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:53:48.811705 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Issuing" to 2026-05-11 10:53:48.81169541 +0000 UTC m=+463.666836651 I0511 10:53:48.812348 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Ready" to 2026-05-11 10:53:48.812326625 +0000 UTC m=+463.667467866 I0511 10:53:48.831384 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:48.831675 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Ready" to 2026-05-11 10:53:48.831659645 +0000 UTC m=+463.686800906 I0511 10:53:48.972968 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:49.006732 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-hr4m6-8dh47" condition "Approved" to 2026-05-11 10:53:49.006719515 +0000 UTC m=+463.861860756 I0511 10:53:49.041041 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-hr4m6-8dh47" condition "Ready" to 2026-05-11 10:53:49.04102819 +0000 UTC m=+463.896169431 I0511 10:53:49.070900 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:49.070869748 +0000 UTC m=+463.926010999 I0511 10:53:49.094745 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:49.095045 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:49.095036061 +0000 UTC m=+463.950177282 I0511 10:53:49.118690 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:53:49.119139 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-hr4m6-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:53:49.119129163 +0000 UTC m=+463.974270404 I0511 10:54:04.255168 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-11 10:54:04.255141082 +0000 UTC m=+479.110282313 I0511 10:54:04.255566 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:54:04.255581 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-11 10:54:04.255578322 +0000 UTC m=+479.110719543 I0511 10:54:04.287276 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:54:04.287351 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:54:04.287367 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-11 10:54:04.287360932 +0000 UTC m=+479.142502183 I0511 10:54:04.625720 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-9tzs9" condition "Approved" to 2026-05-11 10:54:04.625709136 +0000 UTC m=+479.480850377 I0511 10:54:04.652391 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-9tzs9" condition "Ready" to 2026-05-11 10:54:04.652379636 +0000 UTC m=+479.507520867 I0511 10:54:04.689472 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:54:04.689454859 +0000 UTC m=+479.544596090 I0511 10:54:04.717801 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:22.939278 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:57:22.939309 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-11 10:57:22.939302096 +0000 UTC m=+677.794443327 I0511 10:57:22.939621 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-11 10:57:22.939599442 +0000 UTC m=+677.794740673 I0511 10:57:22.959145 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:22.959234 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:57:22.959257 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-11 10:57:22.959250191 +0000 UTC m=+677.814391432 I0511 10:57:23.179871 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:23.193190 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-4x8hh" condition "Approved" to 2026-05-11 10:57:23.193178579 +0000 UTC m=+678.048319800 I0511 10:57:23.219055 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-4x8hh" condition "Ready" to 2026-05-11 10:57:23.219040666 +0000 UTC m=+678.074181937 I0511 10:57:23.252914 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:57:23.252902164 +0000 UTC m=+678.108043405 I0511 10:57:23.281870 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:57:23.282368 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:57:23.282360833 +0000 UTC m=+678.137502074 I0511 10:57:23.303886 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:58:07.327336 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0511 10:58:07.327438 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-11 10:58:07.327426609 +0000 UTC m=+722.182567870 I0511 10:58:07.327511 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-11 10:58:07.3274955 +0000 UTC m=+722.182636751 I0511 10:58:07.347297 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:58:07.347439 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-11 10:58:07.34742579 +0000 UTC m=+722.202567041 I0511 10:58:07.496395 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0511 10:58:07.542104 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-9rgjn" condition "Approved" to 2026-05-11 10:58:07.542089745 +0000 UTC m=+722.397230976 I0511 10:58:07.568408 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-9rgjn" condition "Ready" to 2026-05-11 10:58:07.568392684 +0000 UTC m=+722.423533925 I0511 10:58:07.602139 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-11 10:58:07.602126313 +0000 UTC m=+722.457267554 I0511 10:58:07.629544 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"