I0415 07:27:08.767866 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0415 07:27:08.768019 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0415 07:27:08.768121 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0415 07:27:08.773445 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0415 07:27:08.774052 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0415 07:27:08.774159 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0415 07:27:08.774283 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0415 07:27:08.777832 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0415 07:27:08.789179 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0415 07:27:08.792307 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0415 07:27:08.796128 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0415 07:27:08.798578 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0415 07:27:08.803828 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0415 07:27:08.807173 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0415 07:27:08.810463 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0415 07:27:08.810553 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0415 07:27:08.814839 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0415 07:27:08.814875 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0415 07:27:08.814884 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0415 07:27:08.814890 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0415 07:27:08.819134 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0415 07:27:08.823387 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0415 07:27:08.825534 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0415 07:27:08.830212 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0415 07:27:08.833618 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0415 07:27:08.835901 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0415 07:27:08.835923 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0415 07:27:08.836030 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0415 07:27:08.838476 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0415 07:27:08.840800 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0415 07:27:08.843641 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0415 07:27:08.845349 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0415 07:27:08.847783 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0415 07:27:08.849075 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.850751 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.851848 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.851960 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.852171 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.854010 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.854245 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.854508 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.854718 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:08.938235 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0415 07:27:24.245068 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-15 07:27:24.245041529 +0000 UTC m=+15.511897226 I0415 07:27:24.978353 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-15 07:27:24.978336214 +0000 UTC m=+16.245191911 I0415 07:27:24.978340 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:27:24.978445 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-15 07:27:24.978430557 +0000 UTC m=+16.245286274 E0415 07:27:24.994335 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0415 07:27:24.994439 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-15 07:27:24.994427318 +0000 UTC m=+16.261283045 E0415 07:27:24.994475 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0415 07:27:24.997458 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:24.997627 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:27:24.997725 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-15 07:27:24.997714771 +0000 UTC m=+16.264570488 E0415 07:27:25.007879 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0415 07:27:25.008077 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0415 07:27:25.008157 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0415 07:27:25.008257 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0415 07:27:25.041069 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-2sw4g" condition "Approved" to 2026-04-15 07:27:25.041056287 +0000 UTC m=+16.307911984 I0415 07:27:25.055270 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-2sw4g" condition "Ready" to 2026-04-15 07:27:25.055258056 +0000 UTC m=+16.322113753 I0415 07:27:25.078278 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:25.078263362 +0000 UTC m=+16.345119059 I0415 07:27:25.098898 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:25.099534 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:25.099526944 +0000 UTC m=+16.366382641 I0415 07:27:25.103592 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:25.109705 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:25.110206 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:25.110196291 +0000 UTC m=+16.377051988 I0415 07:27:30.008662 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:30.00864038 +0000 UTC m=+21.275496097 I0415 07:27:52.233657 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-15 07:27:52.233629999 +0000 UTC m=+43.500485696 I0415 07:27:52.234361 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:27:52.234394 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-15 07:27:52.234387013 +0000 UTC m=+43.501242730 I0415 07:27:52.259520 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-15 07:27:52.259507761 +0000 UTC m=+43.526363448 I0415 07:27:52.286923 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:52.287922 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-15 07:27:52.28790388 +0000 UTC m=+43.554759607 I0415 07:27:52.467014 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:52.499756 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-xk5r4" condition "Approved" to 2026-04-15 07:27:52.49974561 +0000 UTC m=+43.766601307 I0415 07:27:52.530725 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-xk5r4" condition "Ready" to 2026-04-15 07:27:52.5307164 +0000 UTC m=+43.797572077 I0415 07:27:52.557945 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:52.557932523 +0000 UTC m=+43.824788220 I0415 07:27:52.582115 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:52.582638 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:52.582569366 +0000 UTC m=+43.849425063 I0415 07:27:52.599044 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:27:52.599372 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:27:52.599364026 +0000 UTC m=+43.866219713 I0415 07:31:54.779227 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-25.nip.io-tls" condition "Ready" to 2026-04-15 07:31:54.779189701 +0000 UTC m=+286.046045388 I0415 07:31:54.779267 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-25.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:31:54.779304 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-25.nip.io-tls" condition "Issuing" to 2026-04-15 07:31:54.779296364 +0000 UTC m=+286.046152061 I0415 07:31:54.798061 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-25.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-25.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:31:54.798148 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-25.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:31:54.798169 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-25.nip.io-tls" condition "Issuing" to 2026-04-15 07:31:54.798162575 +0000 UTC m=+286.065018272 I0415 07:31:55.098108 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-25.nip.io-tls-7pg4w" condition "Approved" to 2026-04-15 07:31:55.098097008 +0000 UTC m=+286.364952715 I0415 07:31:55.122891 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-25.nip.io-tls-7pg4w" condition "Ready" to 2026-04-15 07:31:55.122880946 +0000 UTC m=+286.389736643 I0415 07:31:55.146171 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-25.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:31:55.146160159 +0000 UTC m=+286.413015856 I0415 07:31:55.210939 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-25.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-25.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:32:59.101400 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-15 07:32:59.10136174 +0000 UTC m=+350.368217447 I0415 07:32:59.101655 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:32:59.101702 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-15 07:32:59.101693889 +0000 UTC m=+350.368549576 E0415 07:32:59.113278 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0415 07:32:59.113319 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-15 07:32:59.113311357 +0000 UTC m=+350.380167054 E0415 07:32:59.113364 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0415 07:32:59.116830 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:32:59.116893 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-15 07:32:59.116886723 +0000 UTC m=+350.383742420 E0415 07:32:59.125424 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0415 07:32:59.125601 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0415 07:32:59.125669 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0415 07:32:59.125709 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0415 07:32:59.131102 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:32:59.146733 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-jxq62" condition "Approved" to 2026-04-15 07:32:59.146718396 +0000 UTC m=+350.413574123 I0415 07:32:59.157895 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-jxq62" condition "Ready" to 2026-04-15 07:32:59.157884092 +0000 UTC m=+350.424739789 I0415 07:32:59.173731 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:32:59.173722004 +0000 UTC m=+350.440577701 I0415 07:32:59.195880 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:32:59.233303 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:04.126763 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:04.12675051 +0000 UTC m=+355.393606227 I0415 07:33:44.131585 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:44.131636 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-15 07:33:44.131608798 +0000 UTC m=+395.398464485 I0415 07:33:44.131873 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-15 07:33:44.131870084 +0000 UTC m=+395.398725771 I0415 07:33:44.167224 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:44.167256 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-15 07:33:44.167251826 +0000 UTC m=+395.434107513 I0415 07:33:44.167464 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-15 07:33:44.167460502 +0000 UTC m=+395.434316189 I0415 07:33:44.167690 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:44.167704 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-15 07:33:44.167701287 +0000 UTC m=+395.434556974 I0415 07:33:44.167821 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-15 07:33:44.1678187 +0000 UTC m=+395.434674387 I0415 07:33:44.200788 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.200836 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-15 07:33:44.200829834 +0000 UTC m=+395.467685521 I0415 07:33:44.247230 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.247280 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:44.247296 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-15 07:33:44.247291653 +0000 UTC m=+395.514147340 I0415 07:33:44.250695 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.258033 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-15 07:33:44.258023279 +0000 UTC m=+395.524878966 I0415 07:33:44.450815 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.459029 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.459829 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-vftzv" condition "Approved" to 2026-04-15 07:33:44.459817051 +0000 UTC m=+395.726672738 I0415 07:33:44.476056 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-vftzv" condition "Ready" to 2026-04-15 07:33:44.476039725 +0000 UTC m=+395.742895412 I0415 07:33:44.506594 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-4xdpw" condition "Approved" to 2026-04-15 07:33:44.506583157 +0000 UTC m=+395.773438844 I0415 07:33:44.547390 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:44.547427 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-15 07:33:44.547418506 +0000 UTC m=+395.814274203 I0415 07:33:44.548440 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-4xdpw" condition "Ready" to 2026-04-15 07:33:44.54843086 +0000 UTC m=+395.815286547 I0415 07:33:44.550573 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:44.550569364 +0000 UTC m=+395.817425051 I0415 07:33:44.586440 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.593265 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.593695 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:44.593683449 +0000 UTC m=+395.860539176 I0415 07:33:44.594959 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:44.594952481 +0000 UTC m=+395.861808168 I0415 07:33:44.631706 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-4cbrb" condition "Approved" to 2026-04-15 07:33:44.631692626 +0000 UTC m=+395.898548313 I0415 07:33:44.767674 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:44.837599 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-4cbrb" condition "Ready" to 2026-04-15 07:33:44.83758798 +0000 UTC m=+396.104443667 I0415 07:33:45.474461 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:45.823207 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-zljjj" condition "Approved" to 2026-04-15 07:33:45.823190009 +0000 UTC m=+397.090045706 I0415 07:33:46.134544 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-zljjj" condition "Ready" to 2026-04-15 07:33:46.134515467 +0000 UTC m=+397.401371224 I0415 07:33:46.422548 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:46.469334 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:46.716004 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:46.769887 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:46.76987488 +0000 UTC m=+398.036730567 I0415 07:33:46.876597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:46.882821 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:46.882802559 +0000 UTC m=+398.149658256 I0415 07:33:47.072559 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:52.164479 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:52.164528 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" condition "Issuing" to 2026-04-15 07:33:52.164511584 +0000 UTC m=+403.431367311 I0415 07:33:52.165206 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" condition "Ready" to 2026-04-15 07:33:52.16519734 +0000 UTC m=+403.432053057 I0415 07:33:52.181225 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:52.181291 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:33:52.181312 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" condition "Issuing" to 2026-04-15 07:33:52.181306319 +0000 UTC m=+403.448162006 I0415 07:33:52.507909 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-kvkrz-84mwn" condition "Approved" to 2026-04-15 07:33:52.507886843 +0000 UTC m=+403.774742530 I0415 07:33:52.524981 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-kvkrz-84mwn" condition "Ready" to 2026-04-15 07:33:52.524967885 +0000 UTC m=+403.791823582 I0415 07:33:52.555924 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:52.55590817 +0000 UTC m=+403.822763867 I0415 07:33:52.581248 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:33:52.581506 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:33:52.581497542 +0000 UTC m=+403.848353239 I0415 07:33:52.603782 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-kvkrz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:34:08.010792 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:34:08.011597 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-15 07:34:08.011591671 +0000 UTC m=+419.278447358 I0415 07:34:08.011491 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-15 07:34:08.011481878 +0000 UTC m=+419.278337575 I0415 07:34:08.033358 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:34:08.033448 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-15 07:34:08.03343986 +0000 UTC m=+419.300295547 I0415 07:34:08.562890 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:34:08.597121 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-njjfj" condition "Approved" to 2026-04-15 07:34:08.597112028 +0000 UTC m=+419.863967715 I0415 07:34:08.625866 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-njjfj" condition "Ready" to 2026-04-15 07:34:08.625855455 +0000 UTC m=+419.892711142 I0415 07:34:08.666480 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:34:08.66646806 +0000 UTC m=+419.933323757 I0415 07:34:08.689585 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:34:08.689969 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:34:08.689963661 +0000 UTC m=+419.956819348 I0415 07:34:08.707602 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:37:35.901506 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0415 07:37:35.901562 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-15 07:37:35.901555854 +0000 UTC m=+627.168411541 I0415 07:37:35.901864 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-15 07:37:35.90184623 +0000 UTC m=+627.168701927 I0415 07:37:35.917339 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:37:35.917446 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-15 07:37:35.917439307 +0000 UTC m=+627.184294994 I0415 07:37:36.127271 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:37:36.161306 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lgjcg" condition "Approved" to 2026-04-15 07:37:36.161288331 +0000 UTC m=+627.428144048 I0415 07:37:36.185152 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-lgjcg" condition "Ready" to 2026-04-15 07:37:36.185142029 +0000 UTC m=+627.451997736 I0415 07:37:36.210728 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:37:36.210716263 +0000 UTC m=+627.477571960 I0415 07:37:36.232473 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:37:36.232762 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:37:36.23275581 +0000 UTC m=+627.499611507 I0415 07:37:36.252364 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0415 07:37:36.252606 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-15 07:37:36.25259966 +0000 UTC m=+627.519455347 I0415 07:37:36.253708 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again"