I0608 15:20:28.634169 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0608 15:20:28.634321 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0608 15:20:28.634374 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0608 15:20:28.634477 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0608 15:20:28.635924 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0608 15:20:28.636344 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0608 15:20:28.637740 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0608 15:20:28.637846 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0608 15:20:28.653301 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0608 15:20:28.655577 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0608 15:20:28.655608 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0608 15:20:28.655659 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0608 15:20:28.655683 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0608 15:20:28.656559 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0608 15:20:28.656782 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0608 15:20:28.656822 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0608 15:20:28.656833 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0608 15:20:28.657001 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0608 15:20:28.657690 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0608 15:20:28.658391 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0608 15:20:28.658446 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0608 15:20:28.659201 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0608 15:20:28.659832 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0608 15:20:28.660004 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0608 15:20:28.660546 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0608 15:20:28.661044 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0608 15:20:28.661440 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0608 15:20:28.661931 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0608 15:20:28.662726 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0608 15:20:28.662873 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0608 15:20:28.663423 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0608 15:20:28.663794 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0608 15:20:28.665935 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0608 15:20:53.964425 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-06-08 15:20:53.964377187 +0000 UTC m=+25.362357740 I0608 15:20:53.983548 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:53.983593 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-06-08 15:20:53.983586688 +0000 UTC m=+25.381567211 I0608 15:20:53.983768 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-06-08 15:20:53.983758653 +0000 UTC m=+25.381739196 E0608 15:20:54.005280 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18b724446fd36696", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"44635152-5db5-4b8b-ac19-37fde1d049c8", APIVersion:"cert-manager.io/v1", ResourceVersion:"1357", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.June, 8, 15, 20, 54, 821910, time.Local), LastTimestamp:time.Date(2026, time.June, 8, 15, 20, 54, 821910, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18b724446fd36696" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0608 15:20:54.006967 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0608 15:20:54.007029 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-06-08 15:20:54.007023703 +0000 UTC m=+25.405004226 E0608 15:20:54.013445 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0608 15:20:54.056803 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-06-08 15:20:54.056793136 +0000 UTC m=+25.454773659 I0608 15:20:54.079610 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:54.079648 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-06-08 15:20:54.079639807 +0000 UTC m=+25.477620350 I0608 15:20:54.079849 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-06-08 15:20:54.079843893 +0000 UTC m=+25.477824436 I0608 15:20:54.095833 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0608 15:20:54.095879 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-06-08 15:20:54.095872695 +0000 UTC m=+25.493853218 I0608 15:20:54.429571 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0608 15:20:54.478182 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-9qgnh" condition "Approved" to 2026-06-08 15:20:54.478173622 +0000 UTC m=+25.876154145 E0608 15:20:54.494168 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0608 15:20:54.514708 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-9qgnh" condition "Ready" to 2026-06-08 15:20:54.514699495 +0000 UTC m=+25.912680008 I0608 15:20:54.546524 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:54.54651884 +0000 UTC m=+25.944499353 I0608 15:20:54.573645 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0608 15:20:54.574198 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:54.574192024 +0000 UTC m=+25.972172537 I0608 15:20:54.593777 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0608 15:20:54.593988 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:54.593982225 +0000 UTC m=+25.991962738 I0608 15:20:54.748202 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-06-08 15:20:54.748190818 +0000 UTC m=+26.146171321 I0608 15:20:54.764765 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-06-08 15:20:54.764755345 +0000 UTC m=+26.162735868 I0608 15:20:54.765080 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:54.765092 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-06-08 15:20:54.765088095 +0000 UTC m=+26.163068618 I0608 15:20:54.781335 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0608 15:20:54.781416 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:54.781435 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-06-08 15:20:54.781429475 +0000 UTC m=+26.179409998 I0608 15:20:55.026542 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0608 15:20:55.031158 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-ng4cr" condition "Approved" to 2026-06-08 15:20:55.031146556 +0000 UTC m=+26.429127069 I0608 15:20:55.067742 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-ng4cr" condition "Ready" to 2026-06-08 15:20:55.06773318 +0000 UTC m=+26.465713693 I0608 15:20:55.122757 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:55.12274277 +0000 UTC m=+26.520723293 I0608 15:20:55.149744 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-06-08 15:20:55.149731064 +0000 UTC m=+26.547711587 I0608 15:20:55.153161 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0608 15:20:55.153398 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:55.153393671 +0000 UTC m=+26.551374194 I0608 15:20:55.161558 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0608 15:20:55.168930 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-06-08 15:20:55.168914832 +0000 UTC m=+26.566895345 I0608 15:20:55.168986 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:55.169006 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-06-08 15:20:55.169000684 +0000 UTC m=+26.566981197 I0608 15:20:55.179568 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0608 15:20:55.193232 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0608 15:20:55.193284 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:55.193298 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-06-08 15:20:55.193293241 +0000 UTC m=+26.591273764 I0608 15:20:55.534259 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-06-08 15:20:55.534250536 +0000 UTC m=+26.932231059 I0608 15:20:55.540057 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0608 15:20:55.551327 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-06-08 15:20:55.551315152 +0000 UTC m=+26.949295665 I0608 15:20:55.551977 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0608 15:20:55.552025 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-06-08 15:20:55.552016292 +0000 UTC m=+26.949996845 I0608 15:20:55.555859 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-bhd2k" condition "Approved" to 2026-06-08 15:20:55.555853083 +0000 UTC m=+26.953833596 I0608 15:20:55.565588 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0608 15:20:55.567810 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-06-08 15:20:55.567802901 +0000 UTC m=+26.965783424 I0608 15:20:55.697343 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-bhd2k" condition "Ready" to 2026-06-08 15:20:55.697335668 +0000 UTC m=+27.095316181 I0608 15:20:55.976688 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:55.97667005 +0000 UTC m=+27.374650573 I0608 15:20:56.072318 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0608 15:20:56.072640 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:56.072630039 +0000 UTC m=+27.470610562 I0608 15:20:56.322494 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0608 15:20:56.439288 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0608 15:20:56.579684 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-9lfs2" condition "Approved" to 2026-06-08 15:20:56.579671306 +0000 UTC m=+27.977651819 I0608 15:20:56.791194 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-9lfs2" condition "Ready" to 2026-06-08 15:20:56.79118184 +0000 UTC m=+28.189162393 I0608 15:20:57.179588 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:57.17957475 +0000 UTC m=+28.577555273 I0608 15:20:57.275712 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0608 15:20:57.276408 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-06-08 15:20:57.276395476 +0000 UTC m=+28.674376029 I0608 15:20:57.472473 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0608 15:22:03.350636 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0608 15:22:03.391019 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-06-08 15:22:03.39100694 +0000 UTC m=+94.788987463 I0608 15:22:03.410388 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-06-08 15:22:03.410378001 +0000 UTC m=+94.808358524 E0608 15:22:05.706258 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0608 15:22:05.759060 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-06-08 15:22:05.759047984 +0000 UTC m=+97.157028507 I0608 15:22:05.781118 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-06-08 15:22:05.781105252 +0000 UTC m=+97.179085785 E0608 15:22:07.490180 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0608 15:22:07.542226 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-06-08 15:22:07.542214254 +0000 UTC m=+98.940194767 I0608 15:22:07.567147 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-06-08 15:22:07.567131644 +0000 UTC m=+98.965112197 E0608 15:22:09.266206 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0608 15:22:09.307089 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-06-08 15:22:09.307069667 +0000 UTC m=+100.705050230 I0608 15:22:09.326587 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-06-08 15:22:09.326577188 +0000 UTC m=+100.724557741