I0330 20:15:43.739796 1 serving.go:386] Generated self-signed cert in-memory I0330 20:15:44.124042 1 controllermanager.go:188] "Starting" version="v1.33.4" I0330 20:15:44.124094 1 controllermanager.go:190] "Golang settings" GOGC="" GOMAXPROCS="" GOTRACEBACK="" I0330 20:15:44.126402 1 dynamic_cafile_content.go:161] "Starting controller" name="request-header::/etc/kubernetes/pki/front-proxy-ca.crt" I0330 20:15:44.126591 1 dynamic_cafile_content.go:161] "Starting controller" name="client-ca-bundle::/etc/kubernetes/pki/ca.crt" I0330 20:15:44.126798 1 secure_serving.go:211] Serving securely on [::]:10257 I0330 20:15:44.126887 1 tlsconfig.go:243] "Starting DynamicServingCertificateController" I0330 20:15:44.127147 1 leaderelection.go:257] attempting to acquire leader lease kube-system/kube-controller-manager... E0330 20:15:44.656726 1 leaderelection.go:436] error retrieving resource lock kube-system/kube-controller-manager: leases.coordination.k8s.io "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get resource "leases" in API group "coordination.k8s.io" in the namespace "kube-system": RBAC: [role.rbac.authorization.k8s.io "system::leader-locking-kube-controller-manager" not found, role.rbac.authorization.k8s.io "extension-apiserver-authentication-reader" not found]