I0418 17:51:48.611497 1 serving.go:386] Generated self-signed cert in-memory I0418 17:51:48.983703 1 controllermanager.go:191] "Starting" version="v1.34.0" I0418 17:51:48.983746 1 controllermanager.go:193] "Golang settings" GOGC="" GOMAXPROCS="" GOTRACEBACK="" I0418 17:51:48.986341 1 dynamic_cafile_content.go:161] "Starting controller" name="request-header::/etc/kubernetes/pki/front-proxy-ca.crt" I0418 17:51:48.986344 1 dynamic_cafile_content.go:161] "Starting controller" name="client-ca-bundle::/etc/kubernetes/pki/ca.crt" I0418 17:51:48.987172 1 secure_serving.go:211] Serving securely on [::]:10257 I0418 17:51:48.987315 1 tlsconfig.go:243] "Starting DynamicServingCertificateController" I0418 17:51:48.987792 1 leaderelection.go:257] attempting to acquire leader lease kube-system/kube-controller-manager... E0418 17:51:49.245781 1 leaderelection.go:448] error retrieving resource lock kube-system/kube-controller-manager: leases.coordination.k8s.io "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get resource "leases" in API group "coordination.k8s.io" in the namespace "kube-system": RBAC: [role.rbac.authorization.k8s.io "system::leader-locking-kube-controller-manager" not found, role.rbac.authorization.k8s.io "extension-apiserver-authentication-reader" not found]