I0603 00:44:24.890121 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0603 00:44:24.890228 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0603 00:44:24.890336 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0603 00:44:24.892966 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0603 00:44:24.893410 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0603 00:44:24.893444 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0603 00:44:24.893496 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0603 00:44:24.899278 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... E0603 00:44:54.900809 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout E0603 00:45:44.778015 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout I0603 00:46:27.200142 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0603 00:46:27.202073 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0603 00:46:27.206108 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0603 00:46:27.208703 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0603 00:46:27.211224 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0603 00:46:27.213222 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0603 00:46:27.218501 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0603 00:46:27.224946 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0603 00:46:27.224935 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0603 00:46:27.225016 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0603 00:46:27.225041 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0603 00:46:27.229792 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0603 00:46:27.234281 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0603 00:46:27.236941 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0603 00:46:27.239381 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0603 00:46:27.241858 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0603 00:46:27.244145 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0603 00:46:27.244169 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0603 00:46:27.244288 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0603 00:46:27.246231 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0603 00:46:27.248049 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0603 00:46:27.249868 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0603 00:46:27.251839 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0603 00:46:27.257711 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0603 00:46:27.261156 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0603 00:46:27.262713 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.265291 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.267238 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.267401 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.267702 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.267725 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.270474 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.273485 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.283336 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:46:27.535473 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0603 00:47:26.995173 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:47:26.995245 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Issuing" to 2026-06-03 00:47:26.995197642 +0000 UTC m=+182.175219233 I0603 00:47:26.995479 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-06-03 00:47:26.995208462 +0000 UTC m=+182.175230063 E0603 00:47:27.040415 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.040478 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-client" condition "Ready" to 2026-06-03 00:47:27.040466743 +0000 UTC m=+182.220488344 I0603 00:47:27.040511 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.046219 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:27.046301 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-06-03 00:47:27.046295074 +0000 UTC m=+182.226316645 E0603 00:47:27.103836 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" E0603 00:47:27.103962 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.104002 1 sync.go:62] "Error initializing issuer: secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-client" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0603 00:47:27.104045 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-client-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-client" I0603 00:47:27.108024 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:27.108096 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-ca" condition "Ready" to 2026-06-03 00:47:27.108089023 +0000 UTC m=+182.288110594 I0603 00:47:27.137700 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-wcl7x" condition "Approved" to 2026-06-03 00:47:27.137688523 +0000 UTC m=+182.317710094 I0603 00:47:27.173432 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-ca-wcl7x" condition "Ready" to 2026-06-03 00:47:27.173419791 +0000 UTC m=+182.353441362 I0603 00:47:27.354129 1 conditions.go:192] Found status change for Certificate "octavia-client-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:27.354114075 +0000 UTC m=+182.534135646 I0603 00:47:27.397636 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:27.512781 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:27.803844 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-server-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:47:27.803981 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Issuing" to 2026-06-03 00:47:27.803969887 +0000 UTC m=+182.983991488 I0603 00:47:27.804225 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-06-03 00:47:27.804218252 +0000 UTC m=+182.984239823 E0603 00:47:27.916366 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.916403 1 conditions.go:96] Setting lastTransitionTime for Issuer "octavia-server" condition "Ready" to 2026-06-03 00:47:27.916395426 +0000 UTC m=+183.096416997 I0603 00:47:27.916422 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.921326 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:27.921397 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-server-ca" condition "Ready" to 2026-06-03 00:47:27.921390888 +0000 UTC m=+183.101412439 E0603 00:47:27.960203 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" E0603 00:47:27.960314 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers.setup" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0603 00:47:27.960349 1 sync.go:62] "Error initializing issuer: secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" resource_name="octavia-server" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0603 00:47:27.960396 1 controller.go:167] "re-queuing item due to error processing" err="secret \"octavia-server-ca\" not found" logger="cert-manager.issuers" key="openstack/octavia-server" I0603 00:47:27.969315 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:28.098513 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-mgpj9" condition "Approved" to 2026-06-03 00:47:28.098496091 +0000 UTC m=+183.278517702 I0603 00:47:28.138627 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-server-ca-mgpj9" condition "Ready" to 2026-06-03 00:47:28.138614397 +0000 UTC m=+183.318635958 I0603 00:47:28.223242 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:28.223225246 +0000 UTC m=+183.403246837 I0603 00:47:28.330332 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:28.331192 1 conditions.go:192] Found status change for Certificate "octavia-server-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:28.331167645 +0000 UTC m=+183.511189216 I0603 00:47:28.355609 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-server-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-server-ca\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:28.628863 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Ready" to 2026-06-03 00:47:28.628845371 +0000 UTC m=+183.808866962 I0603 00:47:28.628941 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:47:28.628977 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-06-03 00:47:28.628969594 +0000 UTC m=+183.808991155 I0603 00:47:28.650377 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:28.650504 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-client-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:47:28.650522 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-client-certs" condition "Issuing" to 2026-06-03 00:47:28.650515354 +0000 UTC m=+183.830536935 I0603 00:47:28.741895 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-wjs76" condition "Approved" to 2026-06-03 00:47:28.741880664 +0000 UTC m=+183.921902235 I0603 00:47:28.958134 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-client-certs-wjs76" condition "Ready" to 2026-06-03 00:47:28.958122751 +0000 UTC m=+184.138144332 I0603 00:47:32.104452 1 conditions.go:85] Found status change for Issuer "octavia-client" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:32.104437516 +0000 UTC m=+187.284459087 I0603 00:47:32.139850 1 conditions.go:252] Found status change for CertificateRequest "octavia-client-certs-wjs76" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:32.139838667 +0000 UTC m=+187.319860238 I0603 00:47:32.511781 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:32.51176385 +0000 UTC m=+187.691785441 I0603 00:47:32.579187 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:32.579530 1 conditions.go:192] Found status change for Certificate "octavia-client-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:32.579520542 +0000 UTC m=+187.759542133 I0603 00:47:32.631196 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-client-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-client-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:47:32.964943 1 conditions.go:85] Found status change for Issuer "octavia-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:47:32.964927925 +0000 UTC m=+188.144949486 I0603 00:50:14.805924 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Ready" to 2026-06-03 00:50:14.805884346 +0000 UTC m=+349.985905917 I0603 00:50:14.806185 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:50:14.806293 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-06-03 00:50:14.806284306 +0000 UTC m=+349.986305907 I0603 00:50:14.834043 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:50:14.834176 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/octavia-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:50:14.834210 1 conditions.go:203] Setting lastTransitionTime for Certificate "octavia-api-certs" condition "Issuing" to 2026-06-03 00:50:14.834202049 +0000 UTC m=+350.014223620 I0603 00:50:15.083500 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-55h88" condition "Approved" to 2026-06-03 00:50:15.083481484 +0000 UTC m=+350.263503075 I0603 00:50:15.118300 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "octavia-api-certs-55h88" condition "Ready" to 2026-06-03 00:50:15.118283621 +0000 UTC m=+350.298305232 I0603 00:50:15.167183 1 conditions.go:192] Found status change for Certificate "octavia-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:50:15.167174492 +0000 UTC m=+350.347196073 I0603 00:50:15.224665 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:50:15.303836 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/octavia-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"octavia-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:07.732006 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-06-03 00:51:07.73198696 +0000 UTC m=+402.912008561 I0603 00:51:07.753003 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager-test/selfsigned-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:07.753043 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-06-03 00:51:07.753030731 +0000 UTC m=+402.933052322 I0603 00:51:07.753360 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-06-03 00:51:07.753345658 +0000 UTC m=+402.933367299 I0603 00:51:07.770545 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager-test/selfsigned-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:07.770626 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-06-03 00:51:07.770619144 +0000 UTC m=+402.950640715 E0603 00:51:07.791081 1 controller.go:134] "issuer in work queue no longer exists" err="issuer.cert-manager.io \"test-selfsigned\" not found" logger="cert-manager.issuers" I0603 00:51:07.847920 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-06-03 00:51:07.847900612 +0000 UTC m=+403.027922203 I0603 00:51:07.870419 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-system/capi-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:07.870462 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-06-03 00:51:07.870452226 +0000 UTC m=+403.050473797 I0603 00:51:07.870531 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-06-03 00:51:07.870522878 +0000 UTC m=+403.050544459 E0603 00:51:07.890254 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" logger="cert-manager.certificates-key-manager" key="cert-manager-test/selfsigned-cert" I0603 00:51:07.890999 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:07.891078 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-system/capi-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:07.891109 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-06-03 00:51:07.891101707 +0000 UTC m=+403.071123298 I0603 00:51:08.136859 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-hw6vr" condition "Approved" to 2026-06-03 00:51:08.136839601 +0000 UTC m=+403.316861192 I0603 00:51:08.172429 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-hw6vr" condition "Ready" to 2026-06-03 00:51:08.172414067 +0000 UTC m=+403.352435638 I0603 00:51:08.217898 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:08.217887773 +0000 UTC m=+403.397909324 I0603 00:51:08.245861 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:08.246089 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:08.246081903 +0000 UTC m=+403.426103464 I0603 00:51:08.265497 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:08.265824 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:08.265813854 +0000 UTC m=+403.445835425 I0603 00:51:08.270082 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-system/capi-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:08.657341 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-06-03 00:51:08.657321017 +0000 UTC m=+403.837342618 I0603 00:51:08.682118 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:08.682156 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-06-03 00:51:08.682140612 +0000 UTC m=+403.862162193 I0603 00:51:08.682192 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-06-03 00:51:08.682178713 +0000 UTC m=+403.862200314 I0603 00:51:08.704246 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:08.704308 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:08.704333 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-06-03 00:51:08.704325627 +0000 UTC m=+403.884347188 I0603 00:51:09.087592 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-449mg" condition "Approved" to 2026-06-03 00:51:09.087575525 +0000 UTC m=+404.267597096 I0603 00:51:09.107589 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-449mg" condition "Ready" to 2026-06-03 00:51:09.107578692 +0000 UTC m=+404.287600263 I0603 00:51:09.150726 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:09.150711907 +0000 UTC m=+404.330733478 I0603 00:51:09.161423 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-06-03 00:51:09.161404026 +0000 UTC m=+404.341425607 I0603 00:51:09.175804 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.186708 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-06-03 00:51:09.186693711 +0000 UTC m=+404.366715272 I0603 00:51:09.186857 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:09.186910 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-06-03 00:51:09.186902016 +0000 UTC m=+404.366923577 I0603 00:51:09.210929 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.211021 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:09.211046 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-06-03 00:51:09.211039825 +0000 UTC m=+404.391061386 I0603 00:51:09.517218 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.528205 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-zbh2t" condition "Approved" to 2026-06-03 00:51:09.528191805 +0000 UTC m=+404.708213366 I0603 00:51:09.557767 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-zbh2t" condition "Ready" to 2026-06-03 00:51:09.557757146 +0000 UTC m=+404.737778697 I0603 00:51:09.593717 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:09.59370405 +0000 UTC m=+404.773725621 I0603 00:51:09.614131 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.712101 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-06-03 00:51:09.712085486 +0000 UTC m=+404.892107057 I0603 00:51:09.736230 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="capo-system/capo-serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:51:09.736283 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-06-03 00:51:09.736273347 +0000 UTC m=+404.916294908 I0603 00:51:09.736738 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-06-03 00:51:09.736710896 +0000 UTC m=+404.916732467 I0603 00:51:09.749362 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.893540 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:09.893611 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-06-03 00:51:09.893603904 +0000 UTC m=+405.073625455 I0603 00:51:10.171373 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:10.248995 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-55fs7" condition "Approved" to 2026-06-03 00:51:10.248981238 +0000 UTC m=+405.429002809 I0603 00:51:10.318512 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-55fs7" condition "Ready" to 2026-06-03 00:51:10.318497333 +0000 UTC m=+405.498518904 I0603 00:51:10.792631 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:10.792618252 +0000 UTC m=+405.972639823 I0603 00:51:10.940305 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:10.940816 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:51:10.940804084 +0000 UTC m=+406.120825675 I0603 00:51:11.185043 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:51:11.435660 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="capo-system/capo-serving-cert" error="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:50.402163 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Ready" to 2026-06-03 00:54:50.40212649 +0000 UTC m=+625.582148041 I0603 00:54:50.402590 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:54:50.402618 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Issuing" to 2026-06-03 00:54:50.402611362 +0000 UTC m=+625.582632923 I0603 00:54:50.442717 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:50.442810 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-api-certs" condition "Ready" to 2026-06-03 00:54:50.4428028 +0000 UTC m=+625.622824371 I0603 00:54:50.585134 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:50.620838 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-bqzsl" condition "Approved" to 2026-06-03 00:54:50.620823391 +0000 UTC m=+625.800844952 I0603 00:54:50.646676 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-api-certs-bqzsl" condition "Ready" to 2026-06-03 00:54:50.646667718 +0000 UTC m=+625.826689279 I0603 00:54:50.674848 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:54:50.674832708 +0000 UTC m=+625.854854289 I0603 00:54:50.702823 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:50.703211 1 conditions.go:192] Found status change for Certificate "magnum-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:54:50.703203162 +0000 UTC m=+625.883224733 I0603 00:54:50.728617 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:53.433593 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Ready" to 2026-06-03 00:54:53.433578075 +0000 UTC m=+628.613599646 I0603 00:54:53.434230 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:54:53.434254 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-06-03 00:54:53.43424945 +0000 UTC m=+628.614271011 I0603 00:54:53.452882 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:53.453023 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/magnum-registry-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0603 00:54:53.453056 1 conditions.go:203] Setting lastTransitionTime for Certificate "magnum-registry-certs" condition "Issuing" to 2026-06-03 00:54:53.45304597 +0000 UTC m=+628.633067561 I0603 00:54:53.689031 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:53.718774 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-f82pp" condition "Approved" to 2026-06-03 00:54:53.7187606 +0000 UTC m=+628.898782181 I0603 00:54:53.738680 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "magnum-registry-certs-f82pp" condition "Ready" to 2026-06-03 00:54:53.738662966 +0000 UTC m=+628.918684527 I0603 00:54:53.769478 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:54:53.769467065 +0000 UTC m=+628.949488626 I0603 00:54:53.805405 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again" I0603 00:54:53.805611 1 conditions.go:192] Found status change for Certificate "magnum-registry-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-03 00:54:53.805606192 +0000 UTC m=+628.985627743 I0603 00:54:53.870529 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/magnum-registry-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"magnum-registry-certs\": the object has been modified; please apply your changes to the latest version and try again"