I0506 14:16:04.470513 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0506 14:16:04.470842 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0506 14:16:04.470940 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0506 14:16:04.476524 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0506 14:16:04.477229 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0506 14:16:04.478020 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0506 14:16:04.478043 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0506 14:16:04.480467 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0506 14:16:04.497353 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0506 14:16:04.497697 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0506 14:16:04.500877 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0506 14:16:04.503640 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0506 14:16:04.506465 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0506 14:16:04.510773 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0506 14:16:04.515352 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0506 14:16:04.518126 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0506 14:16:04.518258 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0506 14:16:04.520736 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0506 14:16:04.523119 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0506 14:16:04.525923 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0506 14:16:04.528598 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0506 14:16:04.528686 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0506 14:16:04.534318 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0506 14:16:04.534437 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0506 14:16:04.537192 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0506 14:16:04.539613 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0506 14:16:04.539634 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0506 14:16:04.539692 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0506 14:16:04.542379 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0506 14:16:04.544983 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0506 14:16:04.547280 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0506 14:16:04.549434 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0506 14:16:04.551155 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0506 14:16:04.554102 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.555834 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.556945 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.557172 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.577509 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.625182 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.638085 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.639556 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.657252 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:04.671149 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 14:16:25.291099 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-06 14:16:25.291076625 +0000 UTC m=+20.852015228 I0506 14:16:26.032576 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:16:26.032771 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 14:16:26.03276529 +0000 UTC m=+21.593703853 I0506 14:16:26.032871 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 14:16:26.032849562 +0000 UTC m=+21.593788145 E0506 14:16:26.163210 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 14:16:26.163318 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-06 14:16:26.163308627 +0000 UTC m=+21.724247200 E0506 14:16:26.163360 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 14:16:26.167514 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:16:26.167669 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 14:16:26.167595411 +0000 UTC m=+21.728534014 E0506 14:16:26.227478 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0506 14:16:26.227612 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 14:16:26.227795 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 14:16:26.227906 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0506 14:16:26.329793 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:16:26.479803 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6h9vz" condition "Approved" to 2026-05-06 14:16:26.479786505 +0000 UTC m=+22.040725168 I0506 14:16:26.532469 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6h9vz" condition "Ready" to 2026-05-06 14:16:26.532452844 +0000 UTC m=+22.093391447 I0506 14:16:26.736614 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:16:26.736604037 +0000 UTC m=+22.297542610 I0506 14:16:26.821237 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:16:26.821623 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:16:26.821613833 +0000 UTC m=+22.382552426 I0506 14:16:27.017111 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:16:31.227979 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:16:31.227965646 +0000 UTC m=+26.788904249 I0506 14:17:07.327508 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:17:07.327539 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 14:17:07.327489403 +0000 UTC m=+62.888428006 I0506 14:17:07.327616 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 14:17:07.327603484 +0000 UTC m=+62.888542087 I0506 14:17:07.355811 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-06 14:17:07.35578611 +0000 UTC m=+62.916724703 I0506 14:17:07.360436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:17:07.361020 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:17:07.361080 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 14:17:07.361073054 +0000 UTC m=+62.922011627 I0506 14:17:07.637106 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ljwck" condition "Approved" to 2026-05-06 14:17:07.637091749 +0000 UTC m=+63.198030332 I0506 14:17:07.678833 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ljwck" condition "Ready" to 2026-05-06 14:17:07.67881995 +0000 UTC m=+63.239758523 I0506 14:17:07.715717 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:17:07.715701743 +0000 UTC m=+63.276640316 I0506 14:17:07.743591 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:17:07.811298 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:22:45.541468 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-227.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:22:45.541544 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-227.nip.io-tls" condition "Ready" to 2026-05-06 14:22:45.54153808 +0000 UTC m=+401.102476653 I0506 14:22:45.541543 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-227.nip.io-tls" condition "Issuing" to 2026-05-06 14:22:45.5415141 +0000 UTC m=+401.102452673 I0506 14:22:45.592008 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-227.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-227.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:22:45.592253 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-227.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:22:45.592367 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-227.nip.io-tls" condition "Issuing" to 2026-05-06 14:22:45.592359076 +0000 UTC m=+401.153297649 I0506 14:22:45.905210 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-227.nip.io-tls-q5bv6" condition "Approved" to 2026-05-06 14:22:45.905197662 +0000 UTC m=+401.466136265 I0506 14:22:46.158514 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-227.nip.io-tls-q5bv6" condition "Ready" to 2026-05-06 14:22:46.158505364 +0000 UTC m=+401.719443927 I0506 14:22:46.332274 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-227.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:22:46.332260102 +0000 UTC m=+401.893198675 I0506 14:22:46.444445 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-227.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-227.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:23:53.150473 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 14:23:53.150430835 +0000 UTC m=+468.711369408 I0506 14:23:53.150994 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:23:53.151014 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 14:23:53.151010414 +0000 UTC m=+468.711948987 E0506 14:23:53.187696 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 14:23:53.187747 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-06 14:23:53.187735995 +0000 UTC m=+468.748674598 E0506 14:23:53.187816 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 14:23:53.190908 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:23:53.191019 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:23:53.191043 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 14:23:53.191034787 +0000 UTC m=+468.751973370 E0506 14:23:53.202516 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0506 14:23:53.202725 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 14:23:53.202830 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 14:23:53.202957 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0506 14:23:53.321211 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:23:53.321398 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-whh6l" condition "Approved" to 2026-05-06 14:23:53.321382455 +0000 UTC m=+468.882321088 I0506 14:23:53.354651 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-whh6l" condition "Ready" to 2026-05-06 14:23:53.354637203 +0000 UTC m=+468.915575776 I0506 14:23:53.486461 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:23:53.486445064 +0000 UTC m=+469.047383657 I0506 14:23:53.827976 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:23:53.828420 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:23:53.828413115 +0000 UTC m=+469.389351688 I0506 14:23:54.039065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:23:58.209163 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:23:58.20915375 +0000 UTC m=+473.770092313 I0506 14:24:43.578945 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:24:43.579747 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-06 14:24:43.579732715 +0000 UTC m=+519.140671278 I0506 14:24:43.579006 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-06 14:24:43.578972344 +0000 UTC m=+519.139910927 I0506 14:24:43.586767 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:24:43.586825 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-06 14:24:43.586818361 +0000 UTC m=+519.147756934 I0506 14:24:43.587080 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-06 14:24:43.587075845 +0000 UTC m=+519.148014418 I0506 14:24:43.606596 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:24:43.606961 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-06 14:24:43.606948805 +0000 UTC m=+519.167887418 I0506 14:24:43.607253 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-06 14:24:43.60724796 +0000 UTC m=+519.168186533 I0506 14:24:43.655772 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.655832 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-06 14:24:43.655825371 +0000 UTC m=+519.216763944 I0506 14:24:43.661298 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.661359 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-06 14:24:43.661353354 +0000 UTC m=+519.222291917 I0506 14:24:43.702446 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.709349 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-06 14:24:43.709336137 +0000 UTC m=+519.270274690 I0506 14:24:43.817312 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.849286 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6wkxv" condition "Approved" to 2026-05-06 14:24:43.849267025 +0000 UTC m=+519.410205628 I0506 14:24:43.877913 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-6wkxv" condition "Ready" to 2026-05-06 14:24:43.877895546 +0000 UTC m=+519.438834119 I0506 14:24:43.929901 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:24:43.929891259 +0000 UTC m=+519.490829822 I0506 14:24:43.940823 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.954099 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.954457 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:24:43.95445096 +0000 UTC m=+519.515389533 I0506 14:24:43.983068 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:43.987585 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-b7ddh" condition "Approved" to 2026-05-06 14:24:43.987569988 +0000 UTC m=+519.548508591 I0506 14:24:43.996752 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:44.021449 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-b7ddh" condition "Ready" to 2026-05-06 14:24:44.021440639 +0000 UTC m=+519.582379212 I0506 14:24:44.111215 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:24:44.11120164 +0000 UTC m=+519.672140203 I0506 14:24:44.257854 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:44.315096 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:44.673771 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rvcsh" condition "Approved" to 2026-05-06 14:24:44.673752028 +0000 UTC m=+520.234690631 I0506 14:24:44.969251 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rvcsh" condition "Ready" to 2026-05-06 14:24:44.969241877 +0000 UTC m=+520.530180440 I0506 14:24:45.265937 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:24:45.265919902 +0000 UTC m=+520.826858465 I0506 14:24:45.362205 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:45.362740 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:24:45.362700377 +0000 UTC m=+520.923638990 I0506 14:24:45.610683 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:24:45.729757 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:02.683929 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" condition "Ready" to 2026-05-06 14:25:02.683889994 +0000 UTC m=+538.244828557 I0506 14:25:02.683985 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:25:02.684013 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" condition "Issuing" to 2026-05-06 14:25:02.684005627 +0000 UTC m=+538.244944200 I0506 14:25:02.704327 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-45d6v-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:02.704587 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" condition "Ready" to 2026-05-06 14:25:02.704574594 +0000 UTC m=+538.265513197 I0506 14:25:02.933671 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-45d6v-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:02.973159 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-45d6v-7pz8j" condition "Approved" to 2026-05-06 14:25:02.973136831 +0000 UTC m=+538.534075424 I0506 14:25:02.998067 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-45d6v-7pz8j" condition "Ready" to 2026-05-06 14:25:02.998055082 +0000 UTC m=+538.558993645 I0506 14:25:03.033859 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:25:03.033841295 +0000 UTC m=+538.594779878 I0506 14:25:03.056515 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-45d6v-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:03.056824 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:25:03.056817349 +0000 UTC m=+538.617755912 I0506 14:25:03.082590 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-45d6v-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-45d6v-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:23.065474 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:25:23.065511 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-06 14:25:23.065499152 +0000 UTC m=+558.626437715 I0506 14:25:23.065821 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-06 14:25:23.065815567 +0000 UTC m=+558.626754130 I0506 14:25:23.081905 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:25:23.082002 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:25:23.082028 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-06 14:25:23.082021527 +0000 UTC m=+558.642960090 I0506 14:25:23.262390 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-7b92v" condition "Approved" to 2026-05-06 14:25:23.262379363 +0000 UTC m=+558.823317926 I0506 14:25:23.293558 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-7b92v" condition "Ready" to 2026-05-06 14:25:23.293546674 +0000 UTC m=+558.854485247 I0506 14:25:23.341815 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:25:23.341799657 +0000 UTC m=+558.902738230 I0506 14:25:23.374017 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:30:03.893782 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:30:03.893872 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-06 14:30:03.893860321 +0000 UTC m=+839.454798924 I0506 14:30:03.894191 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-06 14:30:03.894174662 +0000 UTC m=+839.455113235 I0506 14:30:04.289334 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:30:04.289433 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:30:04.289459 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-06 14:30:04.289453639 +0000 UTC m=+839.850392212 I0506 14:30:05.431098 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:30:06.049939 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-fl7h2" condition "Approved" to 2026-05-06 14:30:06.049925757 +0000 UTC m=+841.610864360 I0506 14:30:06.244197 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-fl7h2" condition "Ready" to 2026-05-06 14:30:06.244185664 +0000 UTC m=+841.805124237 I0506 14:30:06.729906 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:30:06.729889492 +0000 UTC m=+842.290828095 I0506 14:30:07.017656 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:30:07.019509 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:30:07.019500888 +0000 UTC m=+842.580439451 I0506 14:30:07.908741 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:30:07.910595 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:31:10.178132 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 14:31:10.178199 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-06 14:31:10.178184189 +0000 UTC m=+905.739122792 I0506 14:31:10.178734 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-06 14:31:10.178726163 +0000 UTC m=+905.739664756 I0506 14:31:10.205035 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:31:10.205424 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-06 14:31:10.205411738 +0000 UTC m=+905.766350341 I0506 14:31:10.756889 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:31:10.784381 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-g7shv" condition "Approved" to 2026-05-06 14:31:10.784371387 +0000 UTC m=+906.345309960 I0506 14:31:10.819180 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-g7shv" condition "Ready" to 2026-05-06 14:31:10.819170239 +0000 UTC m=+906.380108812 I0506 14:31:10.853074 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:31:10.853056838 +0000 UTC m=+906.413995441 I0506 14:31:10.880895 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:31:10.881616 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 14:31:10.881608643 +0000 UTC m=+906.442547206 I0506 14:31:10.902249 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 14:31:10.904079 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"