I0609 15:19:23.570572 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0609 15:19:23.570793 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0609 15:19:23.570929 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0609 15:19:23.577599 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0609 15:19:23.577988 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0609 15:19:23.578291 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0609 15:19:23.578289 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0609 15:19:23.580556 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0609 15:19:23.771837 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0609 15:19:23.777070 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0609 15:19:23.777117 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0609 15:19:23.777287 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0609 15:19:23.780012 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0609 15:19:23.782596 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0609 15:19:23.788233 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0609 15:19:23.791166 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0609 15:19:23.793689 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0609 15:19:23.795656 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0609 15:19:23.795744 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0609 15:19:23.797817 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0609 15:19:23.799721 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0609 15:19:23.801593 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0609 15:19:23.804001 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0609 15:19:23.804272 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0609 15:19:23.808816 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0609 15:19:23.812905 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0609 15:19:23.814935 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0609 15:19:23.816904 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0609 15:19:23.818697 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0609 15:19:23.820554 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0609 15:19:23.822190 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0609 15:19:23.822221 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0609 15:19:23.822319 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0609 15:19:23.825615 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.827086 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.827386 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.829731 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.830331 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.830758 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.831872 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.840182 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:23.840289 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:19:24.001717 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0609 15:20:09.850433 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-06-09 15:20:09.849857904 +0000 UTC m=+46.322983672 I0609 15:20:09.851194 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0609 15:20:09.851231 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-06-09 15:20:09.851225156 +0000 UTC m=+46.324350924 I0609 15:20:09.864228 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:20:09.864300 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0609 15:20:09.864316 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-06-09 15:20:09.864310426 +0000 UTC m=+46.337436164 I0609 15:20:10.064991 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zthql" condition "Approved" to 2026-06-09 15:20:10.064978972 +0000 UTC m=+46.538104720 I0609 15:20:10.082132 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-zthql" condition "Ready" to 2026-06-09 15:20:10.082122278 +0000 UTC m=+46.555248016 I0609 15:20:10.114290 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-09 15:20:10.114271278 +0000 UTC m=+46.587397016 I0609 15:20:10.139879 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:22:36.023217 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0609 15:22:36.023283 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-06-09 15:22:36.023254342 +0000 UTC m=+192.496380120 I0609 15:22:36.023470 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-06-09 15:22:36.023453966 +0000 UTC m=+192.496579734 I0609 15:22:36.044168 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:22:36.044265 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0609 15:22:36.044292 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-06-09 15:22:36.04428328 +0000 UTC m=+192.517409058 I0609 15:22:36.303979 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-r7rdr" condition "Approved" to 2026-06-09 15:22:36.303968058 +0000 UTC m=+192.777093796 I0609 15:22:36.323113 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-r7rdr" condition "Ready" to 2026-06-09 15:22:36.323101361 +0000 UTC m=+192.796227109 I0609 15:22:36.351131 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-09 15:22:36.351118096 +0000 UTC m=+192.824243834 I0609 15:22:36.374087 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:23:50.820230 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-06-09 15:23:50.820197839 +0000 UTC m=+267.293323577 I0609 15:23:50.820332 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0609 15:23:50.820394 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-06-09 15:23:50.820386773 +0000 UTC m=+267.293512541 I0609 15:23:50.839315 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:23:50.839394 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-06-09 15:23:50.839386464 +0000 UTC m=+267.312512212 I0609 15:23:51.322529 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:23:51.356929 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-mmflj" condition "Approved" to 2026-06-09 15:23:51.356917823 +0000 UTC m=+267.830043571 I0609 15:23:51.386631 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-mmflj" condition "Ready" to 2026-06-09 15:23:51.386620127 +0000 UTC m=+267.859745875 I0609 15:23:51.422888 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-09 15:23:51.422862256 +0000 UTC m=+267.895988034 I0609 15:23:51.454726 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:23:51.455109 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-09 15:23:51.455103801 +0000 UTC m=+267.928229539 I0609 15:23:51.460126 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0609 15:23:51.484413 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" E0609 15:25:05.886519 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: etcdserver: request timed out