I0418 17:54:30.907488 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0418 17:54:30.907629 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0418 17:54:30.907707 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0418 17:54:30.907845 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0418 17:54:30.909107 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0418 17:54:30.909548 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0418 17:54:30.909744 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0418 17:54:30.910181 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0418 17:54:30.988930 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0418 17:54:30.990082 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0418 17:54:30.990280 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0418 17:54:30.996166 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0418 17:54:30.996766 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0418 17:54:30.997315 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0418 17:54:30.997614 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0418 17:54:30.998153 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0418 17:54:30.998614 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0418 17:54:30.998664 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0418 17:54:30.998744 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0418 17:54:30.999218 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0418 17:54:30.999628 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0418 17:54:30.999942 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0418 17:54:31.000845 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0418 17:54:31.000975 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0418 17:54:31.001274 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0418 17:54:31.001322 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0418 17:54:31.001743 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0418 17:54:31.001986 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0418 17:54:31.002743 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0418 17:54:31.003227 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0418 17:54:31.003241 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0418 17:54:31.003358 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0418 17:54:31.003984 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0418 17:54:56.825563 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-18 17:54:56.825527908 +0000 UTC m=+25.956482470 I0418 17:54:56.842368 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:56.842403 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-18 17:54:56.842398483 +0000 UTC m=+25.973353005 I0418 17:54:56.842408 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-18 17:54:56.842402973 +0000 UTC m=+25.973357505 E0418 17:54:56.857966 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a7851382262754", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"c38744b6-49ee-4c17-b668-1259dff00627", APIVersion:"cert-manager.io/v1", ResourceVersion:"1257", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 18, 17, 54, 56, 855361364, time.Local), LastTimestamp:time.Date(2026, time.April, 18, 17, 54, 56, 855361364, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a7851382262754" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) E0418 17:54:56.861467 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0418 17:54:56.862740 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0418 17:54:56.862791 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-18 17:54:56.86278553 +0000 UTC m=+25.993740052 E0418 17:54:56.875335 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0418 17:54:56.890978 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-18 17:54:56.890962736 +0000 UTC m=+26.021917278 I0418 17:54:56.908733 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-18 17:54:56.908722832 +0000 UTC m=+26.039677364 I0418 17:54:56.908823 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:56.908856 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-18 17:54:56.908848134 +0000 UTC m=+26.039802686 I0418 17:54:56.923763 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0418 17:54:56.923879 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-18 17:54:56.923871067 +0000 UTC m=+26.054825599 E0418 17:54:56.987729 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0418 17:54:57.078406 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0418 17:54:57.161977 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-frf65" condition "Approved" to 2026-04-18 17:54:57.161965984 +0000 UTC m=+26.292920506 I0418 17:54:57.202015 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-frf65" condition "Ready" to 2026-04-18 17:54:57.202002598 +0000 UTC m=+26.332957130 I0418 17:54:57.243217 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:57.243205054 +0000 UTC m=+26.374159576 I0418 17:54:57.329560 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0418 17:54:57.414296 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0418 17:54:57.616490 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-18 17:54:57.616479135 +0000 UTC m=+26.747433667 I0418 17:54:57.628471 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-18 17:54:57.628456053 +0000 UTC m=+26.759410575 I0418 17:54:57.630541 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:57.630567 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-18 17:54:57.630561408 +0000 UTC m=+26.761515930 I0418 17:54:57.641744 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0418 17:54:57.641803 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:57.641834 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-18 17:54:57.641829389 +0000 UTC m=+26.772783931 I0418 17:54:57.794727 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-jxdqn" condition "Approved" to 2026-04-18 17:54:57.794719497 +0000 UTC m=+26.925674029 I0418 17:54:57.831847 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-jxdqn" condition "Ready" to 2026-04-18 17:54:57.831832858 +0000 UTC m=+26.962787390 I0418 17:54:57.886399 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:57.886389939 +0000 UTC m=+27.017344451 I0418 17:54:57.932256 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0418 17:54:58.716233 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-18 17:54:58.716217792 +0000 UTC m=+27.847172324 I0418 17:54:58.718320 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0418 17:54:58.735487 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:58.735519 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-18 17:54:58.735513935 +0000 UTC m=+27.866468477 I0418 17:54:58.735466 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-18 17:54:58.735450254 +0000 UTC m=+27.866404796 I0418 17:54:58.751914 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0418 17:54:58.751990 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:58.752014 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-18 17:54:58.752007996 +0000 UTC m=+27.882962528 I0418 17:54:59.034822 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0418 17:54:59.054188 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-18 17:54:59.054170058 +0000 UTC m=+28.185124580 I0418 17:54:59.067474 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-18 17:54:59.067462881 +0000 UTC m=+28.198417413 I0418 17:54:59.067578 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:59.067642 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-18 17:54:59.067601133 +0000 UTC m=+28.198555665 I0418 17:54:59.068257 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-67l8b" condition "Approved" to 2026-04-18 17:54:59.06825006 +0000 UTC m=+28.199204592 I0418 17:54:59.082564 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0418 17:54:59.082634 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0418 17:54:59.082651 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-18 17:54:59.082646336 +0000 UTC m=+28.213600868 I0418 17:54:59.097682 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-67l8b" condition "Ready" to 2026-04-18 17:54:59.097670979 +0000 UTC m=+28.228625501 I0418 17:54:59.145578 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:59.145554373 +0000 UTC m=+28.276508885 I0418 17:54:59.186115 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0418 17:54:59.187268 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:59.187262364 +0000 UTC m=+28.318216886 I0418 17:54:59.188422 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0418 17:54:59.245145 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0418 17:54:59.245417 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:59.245412755 +0000 UTC m=+28.376367277 I0418 17:54:59.471235 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-75dvg" condition "Approved" to 2026-04-18 17:54:59.471225403 +0000 UTC m=+28.602179925 I0418 17:54:59.596355 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-75dvg" condition "Ready" to 2026-04-18 17:54:59.596343986 +0000 UTC m=+28.727298508 I0418 17:54:59.996514 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:54:59.996497356 +0000 UTC m=+29.127451918 I0418 17:55:00.146021 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0418 17:55:00.148466 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-18 17:55:00.148455639 +0000 UTC m=+29.279410161 I0418 17:55:00.335020 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0418 17:56:41.547262 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0418 17:56:41.601706 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-18 17:56:41.60169066 +0000 UTC m=+130.732645192 I0418 17:56:41.621107 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-18 17:56:41.621099178 +0000 UTC m=+130.752053700 E0418 17:56:44.092855 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0418 17:56:44.134698 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-18 17:56:44.134667802 +0000 UTC m=+133.265622334 I0418 17:56:44.163399 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-18 17:56:44.163358455 +0000 UTC m=+133.294312987 E0418 17:56:46.029238 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0418 17:56:46.071602 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-18 17:56:46.071586737 +0000 UTC m=+135.202541299 I0418 17:56:46.094857 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-18 17:56:46.09484268 +0000 UTC m=+135.225797212 E0418 17:56:47.861166 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0418 17:56:48.062673 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-18 17:56:48.062653913 +0000 UTC m=+137.193608435 I0418 17:56:48.084033 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-18 17:56:48.084019643 +0000 UTC m=+137.214974165