I0420 11:53:25.239661 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0420 11:53:25.239766 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0420 11:53:25.239844 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 11:53:25.244082 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0420 11:53:25.244939 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0420 11:53:25.244973 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0420 11:53:25.244989 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0420 11:53:25.250262 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 11:53:25.267054 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0420 11:53:25.267415 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0420 11:53:25.273017 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0420 11:53:25.276246 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0420 11:53:25.276276 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0420 11:53:25.276291 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0420 11:53:25.276306 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0420 11:53:25.276315 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0420 11:53:25.279070 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0420 11:53:25.283630 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0420 11:53:25.289026 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0420 11:53:25.292082 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0420 11:53:25.294136 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0420 11:53:25.296077 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0420 11:53:25.297732 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0420 11:53:25.299890 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0420 11:53:25.302529 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0420 11:53:25.308691 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0420 11:53:25.312782 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0420 11:53:25.315430 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0420 11:53:25.318100 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0420 11:53:25.320123 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0420 11:53:25.320212 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0420 11:53:25.322228 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0420 11:53:25.325638 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0420 11:53:25.327830 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.329043 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.329265 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.329445 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.329704 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.330796 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.332200 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.332554 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.332639 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:25.417052 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 11:53:37.148072 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-20 11:53:37.14805419 +0000 UTC m=+11.945132460 I0420 11:53:37.884845 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-20 11:53:37.884831495 +0000 UTC m=+12.681909775 I0420 11:53:37.885998 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:53:37.886031 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 11:53:37.886021643 +0000 UTC m=+12.683099923 E0420 11:53:37.906836 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 11:53:37.906958 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-20 11:53:37.906945919 +0000 UTC m=+12.704024159 E0420 11:53:37.906985 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 11:53:37.907834 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:53:37.907994 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:53:37.908029 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 11:53:37.908018494 +0000 UTC m=+12.705096764 E0420 11:53:37.919800 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0420 11:53:37.920337 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 11:53:37.920363 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 11:53:37.920482 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0420 11:53:37.944564 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:53:37.950329 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-q2l5b" condition "Approved" to 2026-04-20 11:53:37.950294054 +0000 UTC m=+12.747372304 I0420 11:53:37.964552 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-q2l5b" condition "Ready" to 2026-04-20 11:53:37.964540138 +0000 UTC m=+12.761618398 I0420 11:53:37.986993 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:53:37.986972139 +0000 UTC m=+12.784050409 I0420 11:53:38.002667 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:53:38.005088 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:53:38.005078296 +0000 UTC m=+12.802156546 I0420 11:53:38.010988 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:53:38.021836 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:53:38.022110 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:53:38.022098836 +0000 UTC m=+12.819177106 I0420 11:53:42.920482 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:53:42.920467134 +0000 UTC m=+17.717545414 I0420 11:54:04.669867 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 11:54:04.669846184 +0000 UTC m=+39.466924434 I0420 11:54:04.670373 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:54:04.670488 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 11:54:04.67047807 +0000 UTC m=+39.467556350 I0420 11:54:04.687506 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-20 11:54:04.687496081 +0000 UTC m=+39.484574321 I0420 11:54:04.693936 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:54:04.694029 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:54:04.694058 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 11:54:04.694051819 +0000 UTC m=+39.491130069 I0420 11:54:04.926069 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:54:04.933620 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ph6qs" condition "Approved" to 2026-04-20 11:54:04.933612227 +0000 UTC m=+39.730690477 I0420 11:54:04.963417 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-ph6qs" condition "Ready" to 2026-04-20 11:54:04.963405616 +0000 UTC m=+39.760483866 I0420 11:54:04.996223 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:54:04.996208049 +0000 UTC m=+39.793286299 I0420 11:54:05.012065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.469090 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:55:38.469147 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-20 11:55:38.469135519 +0000 UTC m=+133.266213799 I0420 11:55:38.469091 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-20 11:55:38.469043607 +0000 UTC m=+133.266121877 E0420 11:55:38.486247 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 11:55:38.486293 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-04-20 11:55:38.486286671 +0000 UTC m=+133.283364921 I0420 11:55:38.486351 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 11:55:38.490811 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.490897 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-20 11:55:38.49088839 +0000 UTC m=+133.287966640 I0420 11:55:38.498559 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-20 11:55:38.498544055 +0000 UTC m=+133.295622315 I0420 11:55:38.498564 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:55:38.498670 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-20 11:55:38.498661477 +0000 UTC m=+133.295739737 E0420 11:55:38.499063 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0420 11:55:38.499249 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 11:55:38.499334 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0420 11:55:38.499412 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0420 11:55:38.514049 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.514122 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-20 11:55:38.514115789 +0000 UTC m=+133.311194039 I0420 11:55:38.603930 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.639635 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-vmnjn" condition "Approved" to 2026-04-20 11:55:38.63961386 +0000 UTC m=+133.436692140 I0420 11:55:38.671125 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-vmnjn" condition "Ready" to 2026-04-20 11:55:38.671110866 +0000 UTC m=+133.468189116 I0420 11:55:38.701709 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:38.701687389 +0000 UTC m=+133.498765659 I0420 11:55:38.718236 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.718864 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:38.718854992 +0000 UTC m=+133.515933272 I0420 11:55:38.742128 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.745100 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.782856 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:38.825385 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-tf7h4" condition "Approved" to 2026-04-20 11:55:38.825357687 +0000 UTC m=+133.622435927 I0420 11:55:38.844389 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-tf7h4" condition "Ready" to 2026-04-20 11:55:38.844371503 +0000 UTC m=+133.641449753 I0420 11:55:43.500446 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:43.500427262 +0000 UTC m=+138.297505542 I0420 11:55:43.518706 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-tf7h4" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:43.518688209 +0000 UTC m=+138.315766489 I0420 11:55:43.551377 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:43.551366764 +0000 UTC m=+138.348445044 I0420 11:55:43.574256 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:55:43.574479 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:55:43.574475528 +0000 UTC m=+138.371553768 I0420 11:55:43.597295 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:58:16.549284 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready" to 2026-04-20 11:58:16.549217458 +0000 UTC m=+291.346295728 I0420 11:58:16.549360 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-65.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:58:16.549416 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Issuing" to 2026-04-20 11:58:16.549402183 +0000 UTC m=+291.346480463 I0420 11:58:16.566533 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:58:16.566612 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready" to 2026-04-20 11:58:16.566603289 +0000 UTC m=+291.363681549 I0420 11:58:16.750668 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:58:16.781441 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-65.nip.io-tls-bs4tw" condition "Approved" to 2026-04-20 11:58:16.781427664 +0000 UTC m=+291.578505914 I0420 11:58:16.796147 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-65.nip.io-tls-bs4tw" condition "Ready" to 2026-04-20 11:58:16.79613865 +0000 UTC m=+291.593216900 I0420 11:58:16.824319 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:58:16.824304252 +0000 UTC m=+291.621382522 I0420 11:58:16.844309 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:58:16.844712 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:58:16.844705447 +0000 UTC m=+291.641783697 I0420 11:58:16.858836 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:58:16.859216 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:58:16.859207158 +0000 UTC m=+291.656285428 I0420 11:59:25.898843 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-20 11:59:25.898825964 +0000 UTC m=+360.695904214 I0420 11:59:25.899367 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:59:25.899426 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 11:59:25.899413408 +0000 UTC m=+360.696491688 E0420 11:59:25.909707 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 11:59:25.909749 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-20 11:59:25.909740938 +0000 UTC m=+360.706819188 E0420 11:59:25.909799 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 11:59:25.913343 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:59:25.913459 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 11:59:25.913494 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 11:59:25.913484848 +0000 UTC m=+360.710563128 E0420 11:59:25.918339 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0420 11:59:25.918463 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 11:59:25.918505 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 11:59:25.918556 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0420 11:59:25.953491 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-gnlqd" condition "Approved" to 2026-04-20 11:59:25.953477624 +0000 UTC m=+360.750555864 I0420 11:59:25.953659 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:59:25.966952 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-gnlqd" condition "Ready" to 2026-04-20 11:59:25.966932058 +0000 UTC m=+360.764010348 I0420 11:59:25.988422 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:59:25.988404557 +0000 UTC m=+360.785482827 I0420 11:59:26.003413 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:59:26.003720 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:59:26.003711376 +0000 UTC m=+360.800789626 I0420 11:59:26.018581 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 11:59:30.919507 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 11:59:30.919496181 +0000 UTC m=+365.716574411 I0420 12:00:08.331129 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 12:00:08.33107317 +0000 UTC m=+403.128151410 I0420 12:00:08.331455 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:08.335840 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-20 12:00:08.335814844 +0000 UTC m=+403.132893084 I0420 12:00:08.331513 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 12:00:08.33150864 +0000 UTC m=+403.128586880 I0420 12:00:08.331557 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:08.336247 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 12:00:08.336243574 +0000 UTC m=+403.133321814 I0420 12:00:08.344843 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-20 12:00:08.344824541 +0000 UTC m=+403.141902791 I0420 12:00:08.344869 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:08.344998 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 12:00:08.344985276 +0000 UTC m=+403.142063516 I0420 12:00:08.362805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.362894 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:08.362912 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 12:00:08.362907328 +0000 UTC m=+403.159985568 I0420 12:00:08.371310 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.371452 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:08.371492 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 12:00:08.371481915 +0000 UTC m=+403.168560185 I0420 12:00:08.372442 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.372537 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 12:00:08.37252678 +0000 UTC m=+403.169605030 I0420 12:00:08.565408 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-n9846" condition "Approved" to 2026-04-20 12:00:08.565394947 +0000 UTC m=+403.362473197 I0420 12:00:08.590467 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-n9846" condition "Ready" to 2026-04-20 12:00:08.590455342 +0000 UTC m=+403.387533592 I0420 12:00:08.595659 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.635205 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:08.635191752 +0000 UTC m=+403.432270002 I0420 12:00:08.655110 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.655573 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:08.655565354 +0000 UTC m=+403.452643604 I0420 12:00:08.676076 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.708915 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-m25fj" condition "Approved" to 2026-04-20 12:00:08.708901122 +0000 UTC m=+403.505979402 I0420 12:00:08.728560 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-m25fj" condition "Ready" to 2026-04-20 12:00:08.728540916 +0000 UTC m=+403.525619196 I0420 12:00:08.783102 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:08.783090954 +0000 UTC m=+403.580169194 I0420 12:00:08.816986 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:08.817373 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:08.817365651 +0000 UTC m=+403.614443901 I0420 12:00:09.015154 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:09.327495 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-f2h4t" condition "Approved" to 2026-04-20 12:00:09.327477988 +0000 UTC m=+404.124556268 I0420 12:00:09.678464 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-f2h4t" condition "Ready" to 2026-04-20 12:00:09.678447753 +0000 UTC m=+404.475526023 I0420 12:00:09.929764 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" resource_name="prometheus-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="prometheus-tls-f2h4t" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="prometheus-tls-zwdch" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" E0420 12:00:10.065558 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-zwdch\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0420 12:00:10.122534 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-tbhk5" condition "Approved" to 2026-04-20 12:00:10.122514695 +0000 UTC m=+404.919592975 I0420 12:00:10.425630 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-tbhk5" condition "Ready" to 2026-04-20 12:00:10.425618723 +0000 UTC m=+405.222696973 I0420 12:00:10.666721 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:10.666703474 +0000 UTC m=+405.463781714 I0420 12:00:10.818122 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:10.818657 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:10.818647224 +0000 UTC m=+405.615725494 I0420 12:00:11.065365 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:19.340266 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" condition "Ready" to 2026-04-20 12:00:19.340252127 +0000 UTC m=+414.137330377 I0420 12:00:19.340519 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:19.340556 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" condition "Issuing" to 2026-04-20 12:00:19.340545815 +0000 UTC m=+414.137624065 I0420 12:00:19.358978 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-brqtb-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:19.359061 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" condition "Ready" to 2026-04-20 12:00:19.359053021 +0000 UTC m=+414.156131281 I0420 12:00:19.616839 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-brqtb-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:19.644527 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-brqtb-b57ts" condition "Approved" to 2026-04-20 12:00:19.64451116 +0000 UTC m=+414.441589440 I0420 12:00:19.668063 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-brqtb-b57ts" condition "Ready" to 2026-04-20 12:00:19.668049909 +0000 UTC m=+414.465128179 I0420 12:00:19.695111 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:19.695097683 +0000 UTC m=+414.492175933 I0420 12:00:19.714954 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-brqtb-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:19.715397 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:19.715388573 +0000 UTC m=+414.512466813 I0420 12:00:19.742390 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-brqtb-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-brqtb-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:48.702861 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 12:00:48.702843357 +0000 UTC m=+443.499921627 I0420 12:00:48.703318 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:48.703345 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 12:00:48.703339139 +0000 UTC m=+443.500417409 I0420 12:00:48.718271 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:48.718458 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:00:48.718507 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 12:00:48.718499586 +0000 UTC m=+443.515577836 I0420 12:00:49.004531 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-wh6ff" condition "Approved" to 2026-04-20 12:00:49.004514007 +0000 UTC m=+443.801592287 I0420 12:00:49.024490 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-wh6ff" condition "Ready" to 2026-04-20 12:00:49.02447625 +0000 UTC m=+443.821554500 I0420 12:00:49.060667 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:49.060652184 +0000 UTC m=+443.857730434 I0420 12:00:49.089003 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:00:49.089268 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:00:49.089261126 +0000 UTC m=+443.886339366 I0420 12:00:49.112475 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:04:11.738639 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:04:11.738641 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-20 12:04:11.738589645 +0000 UTC m=+646.535667915 I0420 12:04:11.738671 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 12:04:11.738665127 +0000 UTC m=+646.535743367 I0420 12:04:11.757551 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:04:11.757610 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:04:11.757660 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 12:04:11.75765482 +0000 UTC m=+646.554733060 I0420 12:04:11.968973 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cz2z7" condition "Approved" to 2026-04-20 12:04:11.968953768 +0000 UTC m=+646.766031998 I0420 12:04:11.986218 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cz2z7" condition "Ready" to 2026-04-20 12:04:11.986200959 +0000 UTC m=+646.783279209 I0420 12:04:12.012006 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:04:12.011990669 +0000 UTC m=+646.809068919 I0420 12:04:12.032730 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:04:12.087421 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:06:45.159131 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-04-20 12:06:45.15908568 +0000 UTC m=+799.956163930 I0420 12:06:45.159137 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:06:45.159327 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-04-20 12:06:45.159314186 +0000 UTC m=+799.956392456 I0420 12:06:45.180335 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:06:45.180443 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:06:45.180477 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-04-20 12:06:45.18046699 +0000 UTC m=+799.977545250 I0420 12:06:45.320399 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-kwrt2" condition "Approved" to 2026-04-20 12:06:45.320374525 +0000 UTC m=+800.117452815 I0420 12:06:45.348973 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-kwrt2" condition "Ready" to 2026-04-20 12:06:45.348958119 +0000 UTC m=+800.146036369 I0420 12:06:45.375528 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:06:45.375509423 +0000 UTC m=+800.172587663 I0420 12:06:45.406867 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:06:45.466516 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:07:52.655711 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:07:52.655741 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-04-20 12:07:52.655725399 +0000 UTC m=+867.452803639 I0420 12:07:52.655751 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-04-20 12:07:52.655742129 +0000 UTC m=+867.452820379 I0420 12:07:52.670713 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:07:52.670781 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:07:52.670793 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-04-20 12:07:52.670789422 +0000 UTC m=+867.467867652 I0420 12:07:52.810925 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-bcd4j" condition "Approved" to 2026-04-20 12:07:52.810898365 +0000 UTC m=+867.607976635 I0420 12:07:52.828421 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-bcd4j" condition "Ready" to 2026-04-20 12:07:52.828408976 +0000 UTC m=+867.625487226 I0420 12:07:52.858811 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:07:52.858795947 +0000 UTC m=+867.655874197 I0420 12:07:52.882779 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:07:52.883044 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:07:52.88303448 +0000 UTC m=+867.680112730 I0420 12:07:52.885482 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:07:52.899821 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:10:53.498950 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-04-20 12:10:53.498834265 +0000 UTC m=+1048.295912535 I0420 12:10:53.498976 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:10:53.499057 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-04-20 12:10:53.49904499 +0000 UTC m=+1048.296123330 I0420 12:10:53.516278 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:10:53.516341 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 12:10:53.516361 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-04-20 12:10:53.516354667 +0000 UTC m=+1048.313432917 I0420 12:10:53.658069 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-pjc2k" condition "Approved" to 2026-04-20 12:10:53.65805824 +0000 UTC m=+1048.455136490 I0420 12:10:53.677620 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-pjc2k" condition "Ready" to 2026-04-20 12:10:53.677608839 +0000 UTC m=+1048.474687089 I0420 12:10:53.701521 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:10:53.701512244 +0000 UTC m=+1048.498590494 I0420 12:10:53.722699 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 12:10:53.722892 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 12:10:53.722886727 +0000 UTC m=+1048.519964967 I0420 12:10:53.749320 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"