I0421 19:13:22.089585 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0421 19:13:22.089802 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0421 19:13:22.090030 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0421 19:13:22.097022 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0421 19:13:22.097553 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0421 19:13:22.097562 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0421 19:13:22.097791 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0421 19:13:22.100743 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0421 19:13:22.149999 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0421 19:13:22.150322 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0421 19:13:22.150422 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0421 19:13:22.156612 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0421 19:13:22.160107 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0421 19:13:22.164689 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0421 19:13:22.167820 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0421 19:13:22.171033 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0421 19:13:22.173620 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0421 19:13:22.175877 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0421 19:13:22.177844 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0421 19:13:22.179820 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0421 19:13:22.181626 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0421 19:13:22.186240 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0421 19:13:22.192635 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0421 19:13:22.192677 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0421 19:13:22.192783 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0421 19:13:22.195794 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0421 19:13:22.197715 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0421 19:13:22.197818 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0421 19:13:22.199695 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0421 19:13:22.199832 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0421 19:13:22.202110 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0421 19:13:22.204217 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0421 19:13:22.206743 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0421 19:13:22.212380 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.212420 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.212508 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.212787 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.213102 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.213195 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.213404 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.215615 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.218395 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:22.304033 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0421 19:13:37.591927 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-21 19:13:37.591911905 +0000 UTC m=+15.539011496 I0421 19:13:38.296716 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-21 19:13:38.296704014 +0000 UTC m=+16.243803575 I0421 19:13:38.297479 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0421 19:13:38.297500 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-21 19:13:38.297496208 +0000 UTC m=+16.244595769 E0421 19:13:38.312883 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0421 19:13:38.312970 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-21 19:13:38.312956415 +0000 UTC m=+16.260056006 E0421 19:13:38.313007 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0421 19:13:38.317282 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:13:38.317653 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-21 19:13:38.317635382 +0000 UTC m=+16.264734973 E0421 19:13:38.327094 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0421 19:13:38.327179 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0421 19:13:38.327210 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0421 19:13:38.327364 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0421 19:13:38.331480 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:13:38.331534 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-21 19:13:38.33152607 +0000 UTC m=+16.278625621 I0421 19:13:38.343128 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vmbl9" condition "Approved" to 2026-04-21 19:13:38.343115624 +0000 UTC m=+16.290215195 I0421 19:13:38.354307 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-vmbl9" condition "Ready" to 2026-04-21 19:13:38.354298642 +0000 UTC m=+16.301398203 I0421 19:13:38.377074 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:13:38.377059324 +0000 UTC m=+16.324158885 I0421 19:13:38.394816 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:13:43.328040 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:13:43.328026809 +0000 UTC m=+21.275126390 I0421 19:14:07.851737 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-21 19:14:07.851689375 +0000 UTC m=+45.798788966 I0421 19:14:07.852417 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0421 19:14:07.852502 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-21 19:14:07.852492904 +0000 UTC m=+45.799592495 I0421 19:14:07.872172 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-21 19:14:07.872157455 +0000 UTC m=+45.819257016 I0421 19:14:07.886076 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:14:07.886164 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0421 19:14:07.886212 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-21 19:14:07.886183261 +0000 UTC m=+45.833282832 I0421 19:14:08.087571 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:14:08.094799 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8sd42" condition "Approved" to 2026-04-21 19:14:08.094790054 +0000 UTC m=+46.041889615 I0421 19:14:08.129618 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-8sd42" condition "Ready" to 2026-04-21 19:14:08.129607103 +0000 UTC m=+46.076706654 I0421 19:14:08.164173 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:14:08.164158496 +0000 UTC m=+46.111258057 I0421 19:14:08.189434 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:14:08.189879 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:14:08.189870416 +0000 UTC m=+46.136969977 I0421 19:14:08.220892 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:14:08.221089 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:14:08.22108134 +0000 UTC m=+46.168180891 I0421 19:14:08.224175 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:19:12.132354 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready" to 2026-04-21 19:19:12.132343928 +0000 UTC m=+350.079443489 I0421 19:19:12.132992 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-53.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0421 19:19:12.133065 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Issuing" to 2026-04-21 19:19:12.133055343 +0000 UTC m=+350.080154924 I0421 19:19:12.151041 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:19:12.151119 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready" to 2026-04-21 19:19:12.151110319 +0000 UTC m=+350.098209900 I0421 19:19:12.241041 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:19:12.266304 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-53.nip.io-tls-nx9fr" condition "Approved" to 2026-04-21 19:19:12.266290958 +0000 UTC m=+350.213390549 I0421 19:19:12.294173 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-53.nip.io-tls-nx9fr" condition "Ready" to 2026-04-21 19:19:12.294162052 +0000 UTC m=+350.241261613 I0421 19:19:12.318822 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:19:12.318799909 +0000 UTC m=+350.265899470 I0421 19:19:12.335928 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0421 19:19:12.336284 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-53.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-21 19:19:12.336277101 +0000 UTC m=+350.283376652 I0421 19:19:12.355621 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-53.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-53.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again"