I0404 10:13:25.548187 1 controller.go:284] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0404 10:13:25.548419 1 client_config.go:659] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0404 10:13:25.568546 1 options.go:259] "enabling the sig-network Gateway API certificate-shim and HTTP-01 solver" logger="cert-manager" I0404 10:13:25.568612 1 controller.go:89] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers gateway-shim ingress-shim issuers orders]" logger="cert-manager.controller" I0404 10:13:25.568633 1 controller.go:435] "serving insecurely as tls certificate data not provided" logger="cert-manager.controller" I0404 10:13:25.568643 1 controller.go:102] "listening for insecure connections" logger="cert-manager.controller" address="0.0.0.0:9402" I0404 10:13:25.569251 1 controller.go:178] "starting leader election" logger="cert-manager.controller" I0404 10:13:25.570130 1 controller.go:171] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0404 10:13:25.570145 1 controller.go:127] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0404 10:13:25.602830 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0404 10:13:25.618626 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0404 10:13:25.627320 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0404 10:13:25.631348 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0404 10:13:25.635099 1 controller.go:225] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0404 10:13:25.635123 1 controller.go:225] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0404 10:13:25.635133 1 controller.go:225] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0404 10:13:25.638518 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0404 10:13:25.659397 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="gateway-shim" I0404 10:13:25.664600 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0404 10:13:25.669864 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="orders" I0404 10:13:25.672907 1 controller.go:225] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0404 10:13:25.673158 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0404 10:13:25.676269 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0404 10:13:25.679593 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0404 10:13:25.682986 1 controller.go:225] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0404 10:13:25.683019 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0404 10:13:25.687518 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="issuers" I0404 10:13:25.695914 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0404 10:13:25.700399 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0404 10:13:25.705447 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0404 10:13:25.709536 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0404 10:13:25.714225 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0404 10:13:25.721119 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0404 10:13:25.726033 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0404 10:13:25.733119 1 controller.go:248] "starting controller" logger="cert-manager.controller" controller="challenges" I0404 10:13:25.735630 1 reflector.go:359] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.736242 1 reflector.go:359] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.736524 1 reflector.go:359] Caches populated for *v1.HTTPRoute from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.737046 1 reflector.go:359] Caches populated for *v1.Gateway from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.737234 1 reflector.go:359] Caches populated for *v1.Secret from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.737416 1 reflector.go:359] Caches populated for *v1.Ingress from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.736251 1 reflector.go:359] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.757739 1 reflector.go:359] Caches populated for *v1.Challenge from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.777120 1 reflector.go:359] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.796508 1 reflector.go:359] Caches populated for *v1.Certificate from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.818241 1 reflector.go:359] Caches populated for *v1.Issuer from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.841403 1 reflector.go:359] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:25.857576 1 reflector.go:359] Caches populated for *v1.Order from k8s.io/client-go@v0.30.1/tools/cache/reflector.go:232 I0404 10:13:47.073007 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-04 10:13:47.072973075 +0000 UTC m=+21.555475622 I0404 10:13:47.981814 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:13:47.981869 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-04 10:13:47.981852107 +0000 UTC m=+22.464354654 I0404 10:13:47.982074 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-04 10:13:47.982031534 +0000 UTC m=+22.464534091 E0404 10:13:48.258019 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0404 10:13:48.258242 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-04 10:13:48.258170663 +0000 UTC m=+22.740673210 E0404 10:13:48.258452 1 sync.go:62] "error setting up issuer" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0404 10:13:48.260609 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:13:48.260749 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:13:48.260792 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-04 10:13:48.260781696 +0000 UTC m=+22.743284253 E0404 10:13:48.500643 1 controller.go:162] "re-queuing item due to error processing" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller" key="atmosphere" E0404 10:13:48.500963 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0404 10:13:48.500998 1 sync.go:62] "error setting up issuer" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0404 10:13:48.501034 1 controller.go:162] "re-queuing item due to error processing" err="secrets \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.controller" key="atmosphere" I0404 10:13:49.296515 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:13:49.474921 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-1" condition "Approved" to 2026-04-04 10:13:49.47490288 +0000 UTC m=+23.957405407 I0404 10:13:49.734282 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-1" condition "Ready" to 2026-04-04 10:13:49.734267125 +0000 UTC m=+24.216769642 I0404 10:13:50.385926 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:13:50.385911365 +0000 UTC m=+24.868413912 I0404 10:13:52.977094 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:13:52.977649 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:13:52.977639603 +0000 UTC m=+27.460142130 I0404 10:13:53.456696 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:13:53.501367 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:13:53.501350032 +0000 UTC m=+27.983852589 I0404 10:15:06.007343 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:15:06.007534 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-04 10:15:06.007517852 +0000 UTC m=+100.490020379 I0404 10:15:06.007567 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-04 10:15:06.007563692 +0000 UTC m=+100.490066219 I0404 10:15:06.022716 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:15:06.022934 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-04 10:15:06.022897393 +0000 UTC m=+100.505399920 I0404 10:15:06.023559 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:15:06.023638 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-04 10:15:06.023632632 +0000 UTC m=+100.506135159 I0404 10:15:06.314236 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-1" condition "Approved" to 2026-04-04 10:15:06.314224075 +0000 UTC m=+100.796726592 I0404 10:15:06.337211 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-1" condition "Ready" to 2026-04-04 10:15:06.337195432 +0000 UTC m=+100.819697979 I0404 10:15:06.374553 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:15:06.374542947 +0000 UTC m=+100.857045474 I0404 10:15:06.393584 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:15:06.394020 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:15:06.39401385 +0000 UTC m=+100.876516367 I0404 10:15:06.491836 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:09.943169 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="auth-system/keycloak.199-204-45-22.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:21:09.943426 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Issuing" to 2026-04-04 10:21:09.943211277 +0000 UTC m=+464.425713804 I0404 10:21:09.943432 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Ready" to 2026-04-04 10:21:09.942934187 +0000 UTC m=+464.425436704 I0404 10:21:09.953078 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="auth-system/keycloak.199-204-45-22.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-22.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:09.953217 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Ready" to 2026-04-04 10:21:09.953207524 +0000 UTC m=+464.435710051 I0404 10:21:10.298910 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="auth-system/keycloak.199-204-45-22.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-22.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:10.326287 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-22.nip.io-tls-1" condition "Approved" to 2026-04-04 10:21:10.326273451 +0000 UTC m=+464.808775998 I0404 10:21:10.342540 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-22.nip.io-tls-1" condition "Ready" to 2026-04-04 10:21:10.342529321 +0000 UTC m=+464.825031848 I0404 10:21:10.360320 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:21:10.360311147 +0000 UTC m=+464.842813674 I0404 10:21:10.372413 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="auth-system/keycloak.199-204-45-22.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-22.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:10.373354 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:21:10.373345562 +0000 UTC m=+464.855848119 I0404 10:21:10.385148 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="auth-system/keycloak.199-204-45-22.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-22.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:10.393451 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-22.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:21:10.39343554 +0000 UTC m=+464.875938057 I0404 10:21:11.647654 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="envoy-gateway-system/gateway-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:21:11.647700 1 conditions.go:203] Setting lastTransitionTime for Certificate "gateway-tls" condition "Issuing" to 2026-04-04 10:21:11.647694264 +0000 UTC m=+466.130196801 I0404 10:21:11.648220 1 conditions.go:203] Setting lastTransitionTime for Certificate "gateway-tls" condition "Ready" to 2026-04-04 10:21:11.648213432 +0000 UTC m=+466.130715959 I0404 10:21:11.658647 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="envoy-gateway-system/gateway-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"gateway-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:11.658711 1 conditions.go:203] Setting lastTransitionTime for Certificate "gateway-tls" condition "Ready" to 2026-04-04 10:21:11.658703637 +0000 UTC m=+466.141206174 I0404 10:21:11.788273 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="envoy-gateway-system/gateway-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"gateway-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:11.818921 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "gateway-tls-1" condition "Approved" to 2026-04-04 10:21:11.818912473 +0000 UTC m=+466.301414990 I0404 10:21:11.833164 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "gateway-tls-1" condition "Ready" to 2026-04-04 10:21:11.833153891 +0000 UTC m=+466.315656408 I0404 10:21:11.867585 1 conditions.go:192] Found status change for Certificate "gateway-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:21:11.867573651 +0000 UTC m=+466.350076168 I0404 10:21:11.922624 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="envoy-gateway-system/gateway-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"gateway-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:21:11.923040 1 conditions.go:192] Found status change for Certificate "gateway-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:21:11.923033203 +0000 UTC m=+466.405535730 I0404 10:21:11.962543 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="envoy-gateway-system/gateway-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"gateway-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:22:17.854386 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:22:17.854450 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-04 10:22:17.854437906 +0000 UTC m=+532.336940423 I0404 10:22:17.854921 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-04 10:22:17.854915854 +0000 UTC m=+532.337418371 E0404 10:22:17.869421 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0404 10:22:17.869486 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-04 10:22:17.869475422 +0000 UTC m=+532.351977949 E0404 10:22:17.869574 1 sync.go:62] "error setting up issuer" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0404 10:22:17.878913 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:22:17.879025 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:22:17.879069 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-04 10:22:17.87906341 +0000 UTC m=+532.361565927 E0404 10:22:17.879514 1 controller.go:162] "re-queuing item due to error processing" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller" key="kube-prometheus-stack" E0404 10:22:17.879846 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0404 10:22:17.879997 1 sync.go:62] "error setting up issuer" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0404 10:22:17.880074 1 controller.go:162] "re-queuing item due to error processing" err="secrets \"kube-prometheus-stack-ca\" not found" logger="cert-manager.controller" key="kube-prometheus-stack" I0404 10:22:17.918409 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-1" condition "Approved" to 2026-04-04 10:22:17.918389608 +0000 UTC m=+532.400892125 I0404 10:22:17.935843 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-1" condition "Ready" to 2026-04-04 10:22:17.935831641 +0000 UTC m=+532.418334168 I0404 10:22:17.959013 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:22:17.958997452 +0000 UTC m=+532.441499979 I0404 10:22:17.974417 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:22:17.974838 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:22:17.974829767 +0000 UTC m=+532.457332294 I0404 10:22:17.995704 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:22:22.880431 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:22:22.880418846 +0000 UTC m=+537.362921403 I0404 10:23:12.529128 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:23:12.529603 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" condition "Ready" to 2026-04-04 10:23:12.529549564 +0000 UTC m=+587.012052121 I0404 10:23:12.529732 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" condition "Issuing" to 2026-04-04 10:23:12.529716177 +0000 UTC m=+587.012218734 I0404 10:23:12.543088 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-6lzww-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:12.543232 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:23:12.543307 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" condition "Issuing" to 2026-04-04 10:23:12.543298352 +0000 UTC m=+587.025800909 I0404 10:23:12.797954 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls-1" condition "Approved" to 2026-04-04 10:23:12.797942611 +0000 UTC m=+587.280445128 I0404 10:23:12.815986 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls-1" condition "Ready" to 2026-04-04 10:23:12.815977949 +0000 UTC m=+587.298480466 I0404 10:23:12.845450 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:23:12.845438218 +0000 UTC m=+587.327940745 I0404 10:23:12.862901 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-6lzww-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:12.863310 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:23:12.863301733 +0000 UTC m=+587.345804250 I0404 10:23:12.877442 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-6lzww-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-6lzww-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:32.737414 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-04 10:23:32.737401988 +0000 UTC m=+607.219904495 I0404 10:23:32.738202 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:23:32.738251 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-04 10:23:32.738243113 +0000 UTC m=+607.220745630 I0404 10:23:32.761101 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:32.761505 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:23:32.761530 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-04 10:23:32.7615234 +0000 UTC m=+607.244025917 I0404 10:23:33.031868 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:33.043310 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-1" condition "Approved" to 2026-04-04 10:23:33.043299869 +0000 UTC m=+607.525802396 I0404 10:23:33.063392 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-1" condition "Ready" to 2026-04-04 10:23:33.063384211 +0000 UTC m=+607.545886728 I0404 10:23:33.094729 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:23:33.094717375 +0000 UTC m=+607.577219892 I0404 10:23:33.113469 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:23:33.114200 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:23:33.114194366 +0000 UTC m=+607.596696883 I0404 10:23:33.131844 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:26:59.165011 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:26:59.165062 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-04 10:26:59.165054325 +0000 UTC m=+813.647556852 I0404 10:26:59.165197 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-04 10:26:59.165179368 +0000 UTC m=+813.647681935 I0404 10:26:59.176059 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:26:59.176780 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:26:59.176802 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-04 10:26:59.176796435 +0000 UTC m=+813.659298952 I0404 10:26:59.496082 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-1" condition "Approved" to 2026-04-04 10:26:59.496072927 +0000 UTC m=+813.978575444 I0404 10:26:59.512459 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-1" condition "Ready" to 2026-04-04 10:26:59.512449234 +0000 UTC m=+813.994951761 I0404 10:26:59.539834 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:26:59.539818552 +0000 UTC m=+814.022321079 I0404 10:26:59.552882 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:26:59.553451 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:26:59.553443744 +0000 UTC m=+814.035946271 I0404 10:26:59.574601 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.398598 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:27:54.398589 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-04 10:27:54.398575406 +0000 UTC m=+868.881077933 I0404 10:27:54.398645 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-04 10:27:54.398637498 +0000 UTC m=+868.881140045 I0404 10:27:54.449018 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.449271 1 trigger_controller.go:215] "Certificate must be re-issued" logger="cert-manager.controller" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0404 10:27:54.449343 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-04 10:27:54.449303586 +0000 UTC m=+868.931806143 I0404 10:27:54.846476 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.861279 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-1" condition "Approved" to 2026-04-04 10:27:54.861268449 +0000 UTC m=+869.343770956 I0404 10:27:54.879190 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-1" condition "Ready" to 2026-04-04 10:27:54.879181384 +0000 UTC m=+869.361683901 I0404 10:27:54.905209 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:27:54.905191942 +0000 UTC m=+869.387694469 I0404 10:27:54.924454 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.925108 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-04 10:27:54.925101185 +0000 UTC m=+869.407603722 I0404 10:27:54.929180 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.940149 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0404 10:27:54.954976 1 controller.go:157] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"