I0520 04:10:10.487664 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0520 04:10:10.487779 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0520 04:10:10.487859 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0520 04:10:10.491058 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0520 04:10:10.491480 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0520 04:10:10.491723 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0520 04:10:10.491768 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0520 04:10:10.494293 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0520 04:10:10.539881 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0520 04:10:10.540288 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0520 04:10:10.540334 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0520 04:10:10.544961 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0520 04:10:10.549223 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0520 04:10:10.553725 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0520 04:10:10.557820 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0520 04:10:10.560359 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0520 04:10:10.560440 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0520 04:10:10.563212 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0520 04:10:10.566844 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0520 04:10:10.571754 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0520 04:10:10.578201 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0520 04:10:10.578630 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0520 04:10:10.582713 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0520 04:10:10.587369 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0520 04:10:10.589078 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0520 04:10:10.590824 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0520 04:10:10.590850 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0520 04:10:10.590971 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0520 04:10:10.593127 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0520 04:10:10.595143 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0520 04:10:10.597334 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0520 04:10:10.603487 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0520 04:10:10.606504 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0520 04:10:10.610469 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.610900 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611143 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611236 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611387 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611471 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611568 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.611805 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.612093 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:10.758911 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0520 04:10:34.714185 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-20 04:10:34.714170991 +0000 UTC m=+24.262103715 I0520 04:10:37.691577 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-20 04:10:37.691563225 +0000 UTC m=+27.239495949 I0520 04:10:37.691726 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:37.691844 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-20 04:10:37.691833201 +0000 UTC m=+27.239765955 E0520 04:10:39.831629 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0520 04:10:39.831701 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-20 04:10:39.831690539 +0000 UTC m=+29.379623293 E0520 04:10:39.831765 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0520 04:10:39.836775 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:39.836892 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:39.836924 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-20 04:10:39.836914853 +0000 UTC m=+29.384847597 E0520 04:10:40.101426 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0520 04:10:40.101702 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0520 04:10:40.101778 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0520 04:10:40.101867 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0520 04:10:40.184264 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-t9wrw" condition "Approved" to 2026-05-20 04:10:40.184253123 +0000 UTC m=+29.732185847 I0520 04:10:40.397299 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-t9wrw" condition "Ready" to 2026-05-20 04:10:40.397286535 +0000 UTC m=+29.945219259 I0520 04:10:40.555171 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:40.555156015 +0000 UTC m=+30.103088739 I0520 04:10:40.580245 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:40.580521 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:40.580513704 +0000 UTC m=+30.128446428 I0520 04:10:41.246218 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:45.102485 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:45.102463179 +0000 UTC m=+34.650395923 I0520 04:10:51.915318 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-20 04:10:51.915304048 +0000 UTC m=+41.463236762 I0520 04:10:51.915428 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:51.915511 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-20 04:10:51.915495193 +0000 UTC m=+41.463427937 I0520 04:10:52.004505 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-20 04:10:52.00449184 +0000 UTC m=+41.552424564 I0520 04:10:52.007020 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:52.007078 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-20 04:10:52.007071026 +0000 UTC m=+41.555003750 I0520 04:10:52.589477 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-05-20 04:10:52.589463602 +0000 UTC m=+42.137396316 I0520 04:10:52.589566 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:52.589647 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-05-20 04:10:52.589638556 +0000 UTC m=+42.137571280 I0520 04:10:52.589886 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" E0520 04:10:52.632491 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0520 04:10:52.632565 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-05-20 04:10:52.632554875 +0000 UTC m=+42.180487599 I0520 04:10:52.632619 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0520 04:10:52.636877 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:52.636983 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:52.637018 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-05-20 04:10:52.637007988 +0000 UTC m=+42.184940742 E0520 04:10:52.680619 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0520 04:10:52.681206 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0520 04:10:52.681262 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0520 04:10:52.681341 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0520 04:10:52.681723 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-96bqz" condition "Approved" to 2026-05-20 04:10:52.681708943 +0000 UTC m=+42.229641687 I0520 04:10:52.719620 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-05-20 04:10:52.719606493 +0000 UTC m=+42.267539197 I0520 04:10:52.719890 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:52.719906 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-05-20 04:10:52.719903641 +0000 UTC m=+42.267836355 I0520 04:10:52.741668 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-96bqz" condition "Ready" to 2026-05-20 04:10:52.741657307 +0000 UTC m=+42.289590021 I0520 04:10:52.747104 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:52.747238 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:52.747280 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-05-20 04:10:52.747273631 +0000 UTC m=+42.295206355 I0520 04:10:52.888512 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:52.888496945 +0000 UTC m=+42.436429669 I0520 04:10:53.123084 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-vnc-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:53.123117 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Issuing" to 2026-05-20 04:10:53.12311049 +0000 UTC m=+42.671043204 I0520 04:10:53.123245 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-20 04:10:53.123227033 +0000 UTC m=+42.671159767 I0520 04:10:53.247368 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:53.451672 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:53.451751 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-20 04:10:53.451743781 +0000 UTC m=+42.999676495 I0520 04:10:53.735945 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:53.741084 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-sssh8" condition "Approved" to 2026-05-20 04:10:53.741074886 +0000 UTC m=+43.289007600 I0520 04:10:54.499430 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-rq7h9" condition "Approved" to 2026-05-20 04:10:54.499408715 +0000 UTC m=+44.047341469 I0520 04:10:54.504413 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:54.507455 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-sssh8" condition "Ready" to 2026-05-20 04:10:54.507447151 +0000 UTC m=+44.055379865 I0520 04:10:54.638348 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0520 04:10:54.638389 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-05-20 04:10:54.638380092 +0000 UTC m=+44.186312816 I0520 04:10:54.638799 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Ready" to 2026-05-20 04:10:54.638736781 +0000 UTC m=+44.186669555 I0520 04:10:54.640671 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-rq7h9" condition "Ready" to 2026-05-20 04:10:54.64066057 +0000 UTC m=+44.188593324 I0520 04:10:54.669832 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-g9zv2" condition "Approved" to 2026-05-20 04:10:54.669821537 +0000 UTC m=+44.217754261 I0520 04:10:54.672818 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:54.672863 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Ready" to 2026-05-20 04:10:54.672857424 +0000 UTC m=+44.220790148 I0520 04:10:54.679655 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:54.679640898 +0000 UTC m=+44.227573622 I0520 04:10:54.706380 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-g9zv2" condition "Ready" to 2026-05-20 04:10:54.706356792 +0000 UTC m=+44.254289556 I0520 04:10:54.709207 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:54.709604 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:54.709594405 +0000 UTC m=+44.257527159 I0520 04:10:54.714173 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:55.024075 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:55.024062263 +0000 UTC m=+44.571994977 I0520 04:10:55.302475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:55.304183 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:55.304241 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-ktckg" condition "Approved" to 2026-05-20 04:10:55.304228303 +0000 UTC m=+44.852161027 I0520 04:10:55.307740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:55.307982 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:55.30797767 +0000 UTC m=+44.855910394 I0520 04:10:55.372647 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-vnc" condition "Ready" to 2026-05-20 04:10:55.372633635 +0000 UTC m=+44.920566379 I0520 04:10:55.535969 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-ktckg" condition "Ready" to 2026-05-20 04:10:55.535949714 +0000 UTC m=+45.083882468 I0520 04:10:56.379503 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:56.379481584 +0000 UTC m=+45.927414338 I0520 04:10:56.702553 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:56.784784 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" E0520 04:10:56.877780 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"libvirt-api-ca\" not found" logger="cert-manager.issuers.setup" resource_name="libvirt-api" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0520 04:10:56.877844 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-api" condition "Ready" to 2026-05-20 04:10:56.877831918 +0000 UTC m=+46.425764663 I0520 04:10:56.877908 1 sync.go:62] "Error initializing issuer: secret \"libvirt-api-ca\" not found" logger="cert-manager.issuers" resource_name="libvirt-api" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0520 04:10:57.031614 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:57.031596644 +0000 UTC m=+46.579529388 E0520 04:10:57.093943 1 controller.go:167] "re-queuing item due to error processing" err="secret \"libvirt-api-ca\" not found" logger="cert-manager.issuers" key="openstack/libvirt-api" I0520 04:10:57.094156 1 conditions.go:85] Found status change for Issuer "libvirt-api" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:57.094149695 +0000 UTC m=+46.642082409 I0520 04:10:57.197539 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:57.197702 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:57.197697335 +0000 UTC m=+46.745630049 I0520 04:10:57.681216 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:57.681200278 +0000 UTC m=+47.229133032 I0520 04:10:57.802060 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-rq7h9" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:57.802045663 +0000 UTC m=+47.349978407 I0520 04:10:58.065020 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:58.065020 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0520 04:10:58.580428 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-20 04:10:58.580412452 +0000 UTC m=+48.128345196 I0520 04:10:59.519131 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" E0520 04:17:36.699870 1 leaderelection.go:369] Failed to update lock: etcdserver: request timed out E0520 04:17:58.837963 1 leaderelection.go:369] Failed to update lock: etcdserver: request timed out I0520 04:18:00.519099 1 leaderelection.go:285] failed to renew lease cert-manager/cert-manager-controller: timed out waiting for the condition E0520 04:18:06.258991 1 leaderelection.go:308] Failed to release lock: Operation cannot be fulfilled on leases.coordination.k8s.io "cert-manager-controller": the object has been modified; please apply your changes to the latest version and try again I0520 04:18:06.259262 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-ca" I0520 04:18:06.259621 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-venafi" I0520 04:18:06.259733 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.issuers" I0520 04:18:06.259760 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-selfsigned" I0520 04:18:06.259841 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-approver" I0520 04:18:06.260059 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-readiness" I0520 04:18:06.260044 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-metrics" I0520 04:18:06.260080 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-issuing" I0520 04:18:06.260098 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-acme" I0520 04:18:06.260100 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-revision-manager" I0520 04:18:06.260123 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.ingress-shim" I0520 04:18:06.260135 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.clusterissuers" I0520 04:18:06.260147 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.challenges" I0520 04:18:06.260160 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-request-manager" I0520 04:18:06.260174 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-key-manager" I0520 04:18:06.260184 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-vault" I0520 04:18:06.260194 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.orders" I0520 04:18:06.260204 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-trigger" E0520 04:18:06.260909 1 main.go:35] "error executing command" err="error starting controller: leader election lost" logger="cert-manager"