I0413 21:06:00.645836 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0413 21:06:00.645964 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0413 21:06:00.646047 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0413 21:06:00.650500 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0413 21:06:00.650918 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0413 21:06:00.651013 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0413 21:06:00.651078 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0413 21:06:00.653158 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0413 21:06:00.668090 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0413 21:06:00.674065 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0413 21:06:00.674100 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0413 21:06:00.674112 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0413 21:06:00.674124 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0413 21:06:00.674151 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0413 21:06:00.679687 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0413 21:06:00.685786 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0413 21:06:00.688686 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0413 21:06:00.690954 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0413 21:06:00.690983 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0413 21:06:00.690986 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0413 21:06:00.693240 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0413 21:06:00.695312 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0413 21:06:00.697853 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0413 21:06:00.700312 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0413 21:06:00.706940 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0413 21:06:00.709658 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0413 21:06:00.712272 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0413 21:06:00.714499 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0413 21:06:00.716741 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0413 21:06:00.718479 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0413 21:06:00.720204 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0413 21:06:00.721998 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0413 21:06:00.726884 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0413 21:06:00.729260 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.729993 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.730020 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.730168 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.730330 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.730996 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.731156 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.731675 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.732262 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:00.809644 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0413 21:06:17.403295 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-13 21:06:17.403277862 +0000 UTC m=+16.786514348 I0413 21:06:18.149633 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-13 21:06:18.149621335 +0000 UTC m=+17.532857801 I0413 21:06:18.149744 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:06:18.149801 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-13 21:06:18.149794782 +0000 UTC m=+17.533031248 I0413 21:06:18.163761 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:18.163809 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-13 21:06:18.163802027 +0000 UTC m=+17.547038493 E0413 21:06:18.166170 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0413 21:06:18.166219 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-13 21:06:18.166213528 +0000 UTC m=+17.549449984 E0413 21:06:18.166235 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 21:06:18.176972 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0413 21:06:18.177322 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 21:06:18.177417 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 21:06:18.177464 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0413 21:06:18.179576 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:18.205955 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-q9xv4" condition "Approved" to 2026-04-13 21:06:18.205919477 +0000 UTC m=+17.589155983 I0413 21:06:18.218395 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-q9xv4" condition "Ready" to 2026-04-13 21:06:18.218381864 +0000 UTC m=+17.601618330 I0413 21:06:18.242597 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:06:18.242586602 +0000 UTC m=+17.625823068 I0413 21:06:18.265714 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:18.266023 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:06:18.26601289 +0000 UTC m=+17.649249386 I0413 21:06:18.278105 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:18.278350 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:06:18.278340994 +0000 UTC m=+17.661577460 I0413 21:06:23.177695 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:06:23.177686163 +0000 UTC m=+22.560922619 I0413 21:06:45.447482 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-13 21:06:45.446185904 +0000 UTC m=+44.829422390 I0413 21:06:45.447613 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:06:45.447688 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-13 21:06:45.447675659 +0000 UTC m=+44.830912125 I0413 21:06:45.457091 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-13 21:06:45.457075786 +0000 UTC m=+44.840312252 I0413 21:06:45.496793 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:45.496885 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:06:45.496913 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-13 21:06:45.496904182 +0000 UTC m=+44.880140648 I0413 21:06:45.627778 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:45.638996 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-nksbk" condition "Approved" to 2026-04-13 21:06:45.638983589 +0000 UTC m=+45.022220055 I0413 21:06:45.667369 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-nksbk" condition "Ready" to 2026-04-13 21:06:45.667357605 +0000 UTC m=+45.050594071 I0413 21:06:45.698706 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:06:45.698688951 +0000 UTC m=+45.081925437 I0413 21:06:45.719658 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:06:45.761565 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:10:55.530813 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-162.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:10:55.530878 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-162.nip.io-tls" condition "Issuing" to 2026-04-13 21:10:55.530871615 +0000 UTC m=+294.914108111 I0413 21:10:55.530656 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-162.nip.io-tls" condition "Ready" to 2026-04-13 21:10:55.5306415 +0000 UTC m=+294.913877986 I0413 21:10:55.543501 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-162.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-162.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:10:55.543543 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-162.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:10:55.543555 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-162.nip.io-tls" condition "Issuing" to 2026-04-13 21:10:55.54355092 +0000 UTC m=+294.926787386 I0413 21:10:55.886824 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-162.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-162.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:10:55.896608 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-162.nip.io-tls-q77dh" condition "Approved" to 2026-04-13 21:10:55.896590279 +0000 UTC m=+295.279826755 I0413 21:10:55.920726 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-162.nip.io-tls-q77dh" condition "Ready" to 2026-04-13 21:10:55.920705767 +0000 UTC m=+295.303942263 I0413 21:10:55.945261 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-162.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:10:55.945244176 +0000 UTC m=+295.328480672 I0413 21:10:55.967411 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-162.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-162.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:00.055593 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:00.055659 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-13 21:12:00.055635524 +0000 UTC m=+359.438872030 I0413 21:12:00.055680 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-13 21:12:00.055662885 +0000 UTC m=+359.438899441 E0413 21:12:00.070287 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0413 21:12:00.070335 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-13 21:12:00.070325353 +0000 UTC m=+359.453561829 E0413 21:12:00.070388 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0413 21:12:00.073347 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:00.073392 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-13 21:12:00.073386701 +0000 UTC m=+359.456623147 E0413 21:12:00.081941 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0413 21:12:00.082030 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 21:12:00.082056 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0413 21:12:00.082088 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0413 21:12:00.089675 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:00.089884 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-13 21:12:00.089872598 +0000 UTC m=+359.473109094 I0413 21:12:00.100767 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-cnn8s" condition "Approved" to 2026-04-13 21:12:00.10075854 +0000 UTC m=+359.483995006 I0413 21:12:00.117656 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-cnn8s" condition "Ready" to 2026-04-13 21:12:00.117644576 +0000 UTC m=+359.500881052 I0413 21:12:00.135364 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:00.135351041 +0000 UTC m=+359.518587507 I0413 21:12:00.151029 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:00.151304 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:00.151295916 +0000 UTC m=+359.534532382 I0413 21:12:00.169923 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:05.082675 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:05.082656163 +0000 UTC m=+364.465892659 I0413 21:12:44.246211 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:44.246310 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-13 21:12:44.246302402 +0000 UTC m=+403.629538868 I0413 21:12:44.247116 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-13 21:12:44.247098149 +0000 UTC m=+403.630334605 I0413 21:12:44.306693 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-13 21:12:44.306677931 +0000 UTC m=+403.689914387 I0413 21:12:44.312613 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:44.313365 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-13 21:12:44.313357512 +0000 UTC m=+403.696593978 I0413 21:12:44.313962 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:44.313990 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-13 21:12:44.313983985 +0000 UTC m=+403.697220431 I0413 21:12:44.313766 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-13 21:12:44.313753371 +0000 UTC m=+403.696989827 I0413 21:12:44.350078 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:44.350141 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:44.350280 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-13 21:12:44.350258584 +0000 UTC m=+403.733495050 I0413 21:12:44.358888 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:44.358973 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:44.359011 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-13 21:12:44.359005689 +0000 UTC m=+403.742242145 I0413 21:12:44.366553 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:44.366657 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-13 21:12:44.366649301 +0000 UTC m=+403.749885747 I0413 21:12:44.650728 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-9bw54" condition "Approved" to 2026-04-13 21:12:44.650702885 +0000 UTC m=+404.033939351 I0413 21:12:44.680234 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-9bw54" condition "Ready" to 2026-04-13 21:12:44.6802243 +0000 UTC m=+404.063460746 I0413 21:12:44.737956 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:44.737938252 +0000 UTC m=+404.121174718 I0413 21:12:44.771139 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:44.856829 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:44.869007 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:45.080271 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-zcdh6" condition "Approved" to 2026-04-13 21:12:45.080259689 +0000 UTC m=+404.463496145 E0413 21:12:45.101997 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"alertmanager-tls-9qwm7\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" I0413 21:12:45.104026 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-zcdh6" condition "Ready" to 2026-04-13 21:12:45.104018371 +0000 UTC m=+404.487254837 I0413 21:12:45.111358 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:45.121574 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-jhf8t" condition "Approved" to 2026-04-13 21:12:45.121561832 +0000 UTC m=+404.504798298 I0413 21:12:45.150347 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-jhf8t" condition "Ready" to 2026-04-13 21:12:45.150334732 +0000 UTC m=+404.533571198 I0413 21:12:45.532554 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" resource_name="alertmanager-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="alertmanager-tls-zcdh6" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="alertmanager-tls-dnbtr" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0413 21:12:45.660890 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:45.66086768 +0000 UTC m=+405.044104146 I0413 21:12:45.834475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:45.835624 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:45.835609716 +0000 UTC m=+405.218846202 I0413 21:12:45.889543 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-p9ttz" condition "Approved" to 2026-04-13 21:12:45.889523637 +0000 UTC m=+405.272760103 I0413 21:12:46.098246 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-p9ttz" condition "Ready" to 2026-04-13 21:12:46.09823276 +0000 UTC m=+405.481469226 I0413 21:12:46.434522 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:46.732666 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:46.732653727 +0000 UTC m=+406.115890183 I0413 21:12:46.885637 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:46.886261 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:46.886253012 +0000 UTC m=+406.269489478 I0413 21:12:47.086105 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:51.680868 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" condition "Ready" to 2026-04-13 21:12:51.680847775 +0000 UTC m=+411.064084271 I0413 21:12:51.680939 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:12:51.680986 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" condition "Issuing" to 2026-04-13 21:12:51.680973898 +0000 UTC m=+411.064210394 I0413 21:12:51.696315 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:51.696441 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" condition "Ready" to 2026-04-13 21:12:51.696432313 +0000 UTC m=+411.079668789 I0413 21:12:51.815463 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:12:51.851161 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-xc2fz-68nbn" condition "Approved" to 2026-04-13 21:12:51.851149217 +0000 UTC m=+411.234385683 I0413 21:12:51.874760 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-xc2fz-68nbn" condition "Ready" to 2026-04-13 21:12:51.874745233 +0000 UTC m=+411.257981729 I0413 21:12:51.904501 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:12:51.904490629 +0000 UTC m=+411.287727095 I0413 21:12:51.925350 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-xc2fz-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:13:03.504907 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:13:03.504950 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-13 21:13:03.504929049 +0000 UTC m=+422.888165495 I0413 21:13:03.505370 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-13 21:13:03.505365678 +0000 UTC m=+422.888602134 I0413 21:13:03.525053 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:13:03.527224 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:13:03.527254 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-13 21:13:03.527247943 +0000 UTC m=+422.910484399 I0413 21:13:03.687194 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-nbhqh" condition "Approved" to 2026-04-13 21:13:03.68718495 +0000 UTC m=+423.070421406 I0413 21:13:03.705651 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-nbhqh" condition "Ready" to 2026-04-13 21:13:03.705640183 +0000 UTC m=+423.088876649 I0413 21:13:03.735331 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:13:03.735318541 +0000 UTC m=+423.118555007 I0413 21:13:03.755376 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:13:03.755659 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:13:03.755641323 +0000 UTC m=+423.138877789 I0413 21:13:03.778623 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:16:20.044845 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-13 21:16:20.044829364 +0000 UTC m=+619.428065860 I0413 21:16:20.045616 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:16:20.045672 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-13 21:16:20.045664401 +0000 UTC m=+619.428900897 I0413 21:16:20.064994 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:16:20.065100 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-13 21:16:20.0650919 +0000 UTC m=+619.448328356 I0413 21:16:20.204683 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:16:20.232690 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-hj6tt" condition "Approved" to 2026-04-13 21:16:20.232673809 +0000 UTC m=+619.615910275 I0413 21:16:20.254136 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-hj6tt" condition "Ready" to 2026-04-13 21:16:20.254125217 +0000 UTC m=+619.637361683 I0413 21:16:20.291824 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:16:20.291809501 +0000 UTC m=+619.675045977 I0413 21:16:20.314338 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:16:20.314661 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:16:20.314653296 +0000 UTC m=+619.697889752 I0413 21:16:20.332594 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:16:20.332853 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:16:20.33284622 +0000 UTC m=+619.716082676 I0413 21:17:02.221763 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0413 21:17:02.221836 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-13 21:17:02.221828453 +0000 UTC m=+661.605064909 I0413 21:17:02.222385 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-13 21:17:02.222380383 +0000 UTC m=+661.605616829 I0413 21:17:02.246101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:17:02.246156 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-13 21:17:02.246150562 +0000 UTC m=+661.629387018 I0413 21:17:02.482337 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:17:02.510476 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-nbggv" condition "Approved" to 2026-04-13 21:17:02.510460761 +0000 UTC m=+661.893697257 I0413 21:17:02.533993 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-nbggv" condition "Ready" to 2026-04-13 21:17:02.533983764 +0000 UTC m=+661.917220230 I0413 21:17:02.562121 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-13 21:17:02.562112964 +0000 UTC m=+661.945349420 I0413 21:17:02.585126 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0413 21:17:02.637587 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"