I0524 12:52:52.768820 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0524 12:52:52.768977 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0524 12:52:52.769056 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0524 12:52:52.775417 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0524 12:52:52.776519 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0524 12:52:52.776692 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0524 12:52:52.776860 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0524 12:52:52.779464 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0524 12:52:52.791866 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0524 12:52:52.796748 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0524 12:52:52.799298 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0524 12:52:52.801018 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0524 12:52:52.804204 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0524 12:52:52.808656 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0524 12:52:52.811045 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0524 12:52:52.813463 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0524 12:52:52.816044 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0524 12:52:52.818839 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0524 12:52:52.820725 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0524 12:52:52.820748 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0524 12:52:52.820818 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0524 12:52:52.822773 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0524 12:52:52.822938 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0524 12:52:52.827218 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0524 12:52:52.829897 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0524 12:52:52.832385 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0524 12:52:52.832406 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0524 12:52:52.832499 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0524 12:52:52.835006 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0524 12:52:52.836973 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0524 12:52:52.838897 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0524 12:52:52.840695 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0524 12:52:52.840847 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0524 12:52:52.844372 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.844991 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.845318 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.847987 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.861453 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.881837 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.895691 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.913618 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.926554 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:52:52.933818 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0524 12:53:04.036862 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-24 12:53:04.036836089 +0000 UTC m=+11.313137956 I0524 12:53:04.772323 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:53:04.772401 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-24 12:53:04.772392124 +0000 UTC m=+12.048694041 I0524 12:53:04.773451 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-24 12:53:04.773443622 +0000 UTC m=+12.049745519 E0524 12:53:04.789265 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0524 12:53:04.789315 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-24 12:53:04.78930991 +0000 UTC m=+12.065611777 E0524 12:53:04.789370 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0524 12:53:04.790875 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:04.790963 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-24 12:53:04.790957738 +0000 UTC m=+12.067259605 E0524 12:53:04.800438 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0524 12:53:04.800589 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0524 12:53:04.800674 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0524 12:53:04.800752 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0524 12:53:04.814616 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:04.839746 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-cgbns" condition "Approved" to 2026-05-24 12:53:04.839735814 +0000 UTC m=+12.116037681 I0524 12:53:04.850493 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-cgbns" condition "Ready" to 2026-05-24 12:53:04.850480613 +0000 UTC m=+12.126782470 I0524 12:53:04.875059 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:04.875048118 +0000 UTC m=+12.151349985 I0524 12:53:04.896491 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:04.897375 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:04.897625 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:04.897618342 +0000 UTC m=+12.173920209 I0524 12:53:04.911748 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:09.800938 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:09.800923419 +0000 UTC m=+17.077225306 I0524 12:53:32.205012 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-24 12:53:32.204940635 +0000 UTC m=+39.481242532 I0524 12:53:32.206532 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:53:32.207994 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-24 12:53:32.207982103 +0000 UTC m=+39.484284050 I0524 12:53:32.225667 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-24 12:53:32.225647449 +0000 UTC m=+39.501949346 I0524 12:53:32.242937 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:32.243015 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:53:32.243045 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-24 12:53:32.243036388 +0000 UTC m=+39.519338255 I0524 12:53:32.420293 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-vmr48" condition "Approved" to 2026-05-24 12:53:32.420281186 +0000 UTC m=+39.696583053 I0524 12:53:32.451966 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-vmr48" condition "Ready" to 2026-05-24 12:53:32.451951014 +0000 UTC m=+39.728252881 I0524 12:53:32.482886 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:32.482866563 +0000 UTC m=+39.759168450 I0524 12:53:32.505913 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:32.506389 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:32.506380599 +0000 UTC m=+39.782682466 I0524 12:53:32.528525 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:53:32.528967 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:53:32.528955742 +0000 UTC m=+39.805257609 I0524 12:57:56.452290 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-242.nip.io-tls" condition "Ready" to 2026-05-24 12:57:56.452275703 +0000 UTC m=+303.728577570 I0524 12:57:56.452537 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-242.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:57:56.452619 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-242.nip.io-tls" condition "Issuing" to 2026-05-24 12:57:56.452612782 +0000 UTC m=+303.728914669 I0524 12:57:56.472860 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-242.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-242.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:57:56.472973 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-242.nip.io-tls" condition "Ready" to 2026-05-24 12:57:56.472959202 +0000 UTC m=+303.749261099 I0524 12:57:56.613643 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-242.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-242.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:57:56.650419 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-242.nip.io-tls-fld8m" condition "Approved" to 2026-05-24 12:57:56.650403313 +0000 UTC m=+303.926705200 I0524 12:57:56.677979 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-242.nip.io-tls-fld8m" condition "Ready" to 2026-05-24 12:57:56.677963436 +0000 UTC m=+303.954265303 I0524 12:57:56.705410 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-242.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:57:56.705386167 +0000 UTC m=+303.981688034 I0524 12:57:56.724320 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-242.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-242.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:57:56.724843 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-242.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:57:56.724829422 +0000 UTC m=+304.001131299 I0524 12:57:56.747961 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-242.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-242.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:57:56.752389 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-242.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-242.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:03.361216 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:03.361993 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-24 12:59:03.361965778 +0000 UTC m=+370.638267635 I0524 12:59:03.361259 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-24 12:59:03.361250384 +0000 UTC m=+370.637552241 E0524 12:59:03.393586 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0524 12:59:03.393629 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-24 12:59:03.393620605 +0000 UTC m=+370.669922452 E0524 12:59:03.393674 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0524 12:59:03.408515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:03.408654 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:03.408682 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-24 12:59:03.408676773 +0000 UTC m=+370.684978630 E0524 12:59:03.436207 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0524 12:59:03.436339 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0524 12:59:03.436423 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0524 12:59:03.437032 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0524 12:59:03.456864 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:03.459703 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-bd8g7" condition "Approved" to 2026-05-24 12:59:03.459696374 +0000 UTC m=+370.735998231 I0524 12:59:03.472339 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-bd8g7" condition "Ready" to 2026-05-24 12:59:03.472325394 +0000 UTC m=+370.748627261 I0524 12:59:03.504416 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:03.504400549 +0000 UTC m=+370.780702416 I0524 12:59:03.521121 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:08.437674 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:08.437659427 +0000 UTC m=+375.713961294 I0524 12:59:51.159632 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:51.159678 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-24 12:59:51.159667629 +0000 UTC m=+418.435969486 I0524 12:59:51.160335 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-24 12:59:51.16031892 +0000 UTC m=+418.436620777 I0524 12:59:51.177017 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-24 12:59:51.176989907 +0000 UTC m=+418.453291774 I0524 12:59:51.177254 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:51.177302 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-24 12:59:51.177281761 +0000 UTC m=+418.453583618 I0524 12:59:51.215958 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-24 12:59:51.215947747 +0000 UTC m=+418.492249604 I0524 12:59:51.216230 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:51.216276 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-24 12:59:51.216264993 +0000 UTC m=+418.492566850 I0524 12:59:51.238904 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.238982 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:51.239010 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-24 12:59:51.239002654 +0000 UTC m=+418.515304501 I0524 12:59:51.281550 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.281657 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:51.281688 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-24 12:59:51.281683089 +0000 UTC m=+418.557984946 I0524 12:59:51.308693 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.319595 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-24 12:59:51.31958521 +0000 UTC m=+418.595887067 I0524 12:59:51.458228 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.466923 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-n4zx5" condition "Approved" to 2026-05-24 12:59:51.466914166 +0000 UTC m=+418.743216023 I0524 12:59:51.500539 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-n4zx5" condition "Ready" to 2026-05-24 12:59:51.500526754 +0000 UTC m=+418.776828631 I0524 12:59:51.506875 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.548224 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-sbg4w" condition "Approved" to 2026-05-24 12:59:51.548208185 +0000 UTC m=+418.824510082 I0524 12:59:51.550718 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:51.550700628 +0000 UTC m=+418.827002485 I0524 12:59:51.586248 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-sbg4w" condition "Ready" to 2026-05-24 12:59:51.586230678 +0000 UTC m=+418.862532535 I0524 12:59:51.588216 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.647850 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:51.647831268 +0000 UTC m=+418.924133125 I0524 12:59:51.677734 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.678103 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:51.678097449 +0000 UTC m=+418.954399306 I0524 12:59:51.856745 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:51.955843 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:52.156918 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:52.218136 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-m8glw" condition "Approved" to 2026-05-24 12:59:52.218122322 +0000 UTC m=+419.494424179 I0524 12:59:52.417723 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-m8glw" condition "Ready" to 2026-05-24 12:59:52.417709057 +0000 UTC m=+419.694010924 I0524 12:59:52.756905 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:52.756890018 +0000 UTC m=+420.033191885 I0524 12:59:52.857710 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:53.207460 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:57.893288 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:57.893352 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" condition "Issuing" to 2026-05-24 12:59:57.893338391 +0000 UTC m=+425.169640288 I0524 12:59:57.893995 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" condition "Ready" to 2026-05-24 12:59:57.893983701 +0000 UTC m=+425.170285598 I0524 12:59:57.917192 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g7njq-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:57.917357 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 12:59:57.917387 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" condition "Issuing" to 2026-05-24 12:59:57.917379877 +0000 UTC m=+425.193681744 I0524 12:59:58.212948 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g7njq-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:58.256083 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-g7njq-sfpr5" condition "Approved" to 2026-05-24 12:59:58.256042775 +0000 UTC m=+425.532344672 I0524 12:59:58.286931 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-g7njq-sfpr5" condition "Ready" to 2026-05-24 12:59:58.286915597 +0000 UTC m=+425.563217494 I0524 12:59:58.384667 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:58.384646099 +0000 UTC m=+425.660947996 I0524 12:59:58.487952 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g7njq-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:58.488572 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 12:59:58.488545795 +0000 UTC m=+425.764847642 I0524 12:59:58.519729 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g7njq-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 12:59:58.528341 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-g7njq-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-g7njq-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:00:23.289829 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 13:00:23.289866 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-24 13:00:23.289857265 +0000 UTC m=+450.566159122 I0524 13:00:23.290082 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-24 13:00:23.290075499 +0000 UTC m=+450.566377346 I0524 13:00:23.307645 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:00:23.307715 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 13:00:23.307737 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-24 13:00:23.30773061 +0000 UTC m=+450.584032467 I0524 13:00:23.540509 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-87phh" condition "Approved" to 2026-05-24 13:00:23.540495111 +0000 UTC m=+450.816796968 I0524 13:00:23.564430 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-87phh" condition "Ready" to 2026-05-24 13:00:23.564404683 +0000 UTC m=+450.840706550 I0524 13:00:23.598083 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 13:00:23.59806431 +0000 UTC m=+450.874366177 I0524 13:00:23.621475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:03:24.004484 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 13:03:24.004533 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-24 13:03:24.004520392 +0000 UTC m=+631.280822299 I0524 13:03:24.004757 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-24 13:03:24.004731815 +0000 UTC m=+631.281033702 I0524 13:03:24.023793 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:03:24.023991 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-24 13:03:24.023979766 +0000 UTC m=+631.300281633 I0524 13:03:24.188313 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:03:24.222013 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cplsl" condition "Approved" to 2026-05-24 13:03:24.22200145 +0000 UTC m=+631.498303307 I0524 13:03:24.244099 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cplsl" condition "Ready" to 2026-05-24 13:03:24.244087928 +0000 UTC m=+631.520389785 I0524 13:03:24.273021 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 13:03:24.273010422 +0000 UTC m=+631.549312289 I0524 13:03:24.296347 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:04:04.237630 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 13:04:04.237773 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-24 13:04:04.237763999 +0000 UTC m=+671.514065866 I0524 13:04:04.238336 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-24 13:04:04.238329965 +0000 UTC m=+671.514631832 I0524 13:04:04.256411 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0524 13:04:04.256467 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0524 13:04:04.256482 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-24 13:04:04.256475248 +0000 UTC m=+671.532777115 I0524 13:04:04.580418 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-w7tvp" condition "Approved" to 2026-05-24 13:04:04.580397693 +0000 UTC m=+671.856699580 I0524 13:04:04.611774 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-w7tvp" condition "Ready" to 2026-05-24 13:04:04.611763429 +0000 UTC m=+671.888065286 I0524 13:04:04.649287 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-24 13:04:04.649277091 +0000 UTC m=+671.925578958 I0524 13:04:04.670844 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"