Name: cert-manager-654dbb86b5-xpqs6 Namespace: cert-manager Priority: 0 Service Account: cert-manager Node: instance/199.19.213.96 Start Time: Mon, 30 Mar 2026 18:03:54 +0000 Labels: app=cert-manager app.kubernetes.io/component=controller app.kubernetes.io/instance=cert-manager app.kubernetes.io/managed-by=Helm app.kubernetes.io/name=cert-manager app.kubernetes.io/version=v1.15.5 helm.sh/chart=cert-manager-v1.15.5 pod-template-hash=654dbb86b5 Annotations: prometheus.io/path: /metrics prometheus.io/port: 9402 prometheus.io/scrape: true Status: Running SeccompProfile: RuntimeDefault IP: 10.0.0.189 IPs: IP: 10.0.0.189 Controlled By: ReplicaSet/cert-manager-654dbb86b5 Containers: cert-manager-controller: Container ID: containerd://e4fe9fbdc7334caf11e6b85311bc41eb144724ea20ed120c44c3f44054f2b3de Image: harbor.atmosphere.dev/quay.io/jetstack/cert-manager-controller:v1.12.10 Image ID: harbor.atmosphere.dev/quay.io/jetstack/cert-manager-controller@sha256:ff0817580fa47fa99be05cb22417cbbfdb5424fabf7ccb7bd9b9db255b0f3c0f Ports: 9402/TCP, 9403/TCP Host Ports: 0/TCP, 0/TCP Args: --v=2 --cluster-resource-namespace=$(POD_NAMESPACE) --leader-election-namespace=cert-manager --acme-http01-solver-image=harbor.atmosphere.dev/quay.io/jetstack/cert-manager-acmesolver:v1.12.10 --enable-gateway-api --max-concurrent-challenges=60 State: Waiting Reason: CrashLoopBackOff Last State: Terminated Reason: Error Exit Code: 1 Started: Mon, 30 Mar 2026 18:09:30 +0000 Finished: Mon, 30 Mar 2026 18:09:30 +0000 Ready: False Restart Count: 6 Liveness: http-get http://:http-healthz/livez delay=10s timeout=15s period=10s #success=1 #failure=8 Environment: POD_NAMESPACE: cert-manager (v1:metadata.namespace) Mounts: /etc/ssl/certs from etc-ssl-certs (ro) /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-pn8cz (ro) Conditions: Type Status Initialized True Ready False ContainersReady False PodScheduled True Volumes: etc-ssl-certs: Type: HostPath (bare host directory volume) Path: /etc/ssl/certs HostPathType: kube-api-access-pn8cz: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: DownwardAPI: true QoS Class: BestEffort Node-Selectors: kubernetes.io/os=linux openstack-control-plane=enabled Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 10m default-scheduler Successfully assigned cert-manager/cert-manager-654dbb86b5-xpqs6 to instance Normal Pulling 10m kubelet Pulling image "harbor.atmosphere.dev/quay.io/jetstack/cert-manager-controller:v1.12.10" Normal Pulled 10m kubelet Successfully pulled image "harbor.atmosphere.dev/quay.io/jetstack/cert-manager-controller:v1.12.10" in 1.152s (2.292s including waiting) Normal Created 9m13s (x5 over 10m) kubelet Created container cert-manager-controller Normal Started 9m13s (x5 over 10m) kubelet Started container cert-manager-controller Normal Pulled 9m13s (x4 over 10m) kubelet Container image "harbor.atmosphere.dev/quay.io/jetstack/cert-manager-controller:v1.12.10" already present on machine Warning BackOff 40s (x52 over 10m) kubelet Back-off restarting failed container cert-manager-controller in pod cert-manager-654dbb86b5-xpqs6_cert-manager(51a66309-586f-4373-b36c-bf82ba2080a3)