I0420 17:46:33.873462 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0420 17:46:33.874115 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0420 17:46:33.874192 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0420 17:46:33.874620 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 17:46:33.877603 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0420 17:46:33.878319 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0420 17:46:33.878664 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0420 17:46:33.879389 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 17:46:33.907571 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0420 17:46:33.915113 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0420 17:46:33.915212 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0420 17:46:33.915333 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0420 17:46:33.916299 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0420 17:46:33.917098 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0420 17:46:33.917134 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0420 17:46:33.917188 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0420 17:46:33.918362 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0420 17:46:33.918406 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0420 17:46:33.919765 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0420 17:46:33.920700 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0420 17:46:33.920926 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0420 17:46:33.920943 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0420 17:46:33.921010 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0420 17:46:33.921427 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0420 17:46:33.925051 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0420 17:46:33.926104 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0420 17:46:33.926526 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0420 17:46:33.927242 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0420 17:46:33.928018 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0420 17:46:33.928625 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0420 17:46:33.929267 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0420 17:46:33.929645 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0420 17:46:33.930037 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0420 17:46:53.916385 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-20 17:46:53.916352016 +0000 UTC m=+20.090988576 I0420 17:46:53.932713 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:53.933132 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-20 17:46:53.933127526 +0000 UTC m=+20.107764086 I0420 17:46:53.932906 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-20 17:46:53.932897607 +0000 UTC m=+20.107534167 I0420 17:46:53.950245 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0420 17:46:53.950417 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:53.950443 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-20 17:46:53.950437014 +0000 UTC m=+20.125073574 E0420 17:46:53.950518 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0420 17:46:53.960819 1 controller.go:167] cert-manager/certificates-trigger "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0420 17:46:53.981992 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-20 17:46:53.981984231 +0000 UTC m=+20.156620791 I0420 17:46:53.996677 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:53.996712 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-20 17:46:53.996704096 +0000 UTC m=+20.171340656 I0420 17:46:53.996953 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-20 17:46:53.996937975 +0000 UTC m=+20.171574535 I0420 17:46:54.015034 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0420 17:46:54.015128 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-20 17:46:54.015120054 +0000 UTC m=+20.189756604 I0420 17:46:54.443967 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0420 17:46:54.482142 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-6ddwb" condition "Approved" to 2026-04-20 17:46:54.482131148 +0000 UTC m=+20.656767728 I0420 17:46:54.530555 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-6ddwb" condition "Ready" to 2026-04-20 17:46:54.530543157 +0000 UTC m=+20.705179717 I0420 17:46:54.561247 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-20 17:46:54.561207805 +0000 UTC m=+20.735844365 I0420 17:46:54.565706 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:54.565700058 +0000 UTC m=+20.740336618 I0420 17:46:54.595034 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:54.595031 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-20 17:46:54.595014856 +0000 UTC m=+20.769651416 I0420 17:46:54.595069 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-20 17:46:54.595062588 +0000 UTC m=+20.769699138 I0420 17:46:54.607438 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0420 17:46:54.630753 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0420 17:46:54.630827 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-20 17:46:54.63081939 +0000 UTC m=+20.805455940 I0420 17:46:54.723321 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0420 17:46:54.891249 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0420 17:46:54.957744 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-20 17:46:54.957717762 +0000 UTC m=+21.132354312 I0420 17:46:54.970532 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-vpklk" condition "Approved" to 2026-04-20 17:46:54.970178572 +0000 UTC m=+21.144815122 I0420 17:46:54.984919 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:54.984966 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-20 17:46:54.984955836 +0000 UTC m=+21.159592406 I0420 17:46:54.985423 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-20 17:46:54.985311509 +0000 UTC m=+21.159948059 I0420 17:46:55.053440 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0420 17:46:55.053521 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-20 17:46:55.053515144 +0000 UTC m=+21.228151694 I0420 17:46:55.059136 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-vpklk" condition "Ready" to 2026-04-20 17:46:55.059131035 +0000 UTC m=+21.233767585 I0420 17:46:55.312986 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:55.312963154 +0000 UTC m=+21.487599734 I0420 17:46:55.399582 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0420 17:46:55.407621 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0420 17:46:55.535938 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-zzhql" condition "Approved" to 2026-04-20 17:46:55.535926384 +0000 UTC m=+21.710562934 I0420 17:46:55.589245 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0420 17:46:55.594715 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-zzhql" condition "Ready" to 2026-04-20 17:46:55.594708155 +0000 UTC m=+21.769344695 I0420 17:46:55.605718 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-20 17:46:55.605706521 +0000 UTC m=+21.780343071 I0420 17:46:55.614891 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-20 17:46:55.61488362 +0000 UTC m=+21.789520170 I0420 17:46:55.614367 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:55.614981 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-20 17:46:55.614978794 +0000 UTC m=+21.789615334 I0420 17:46:55.740976 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0420 17:46:55.741038 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0420 17:46:55.741052 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-20 17:46:55.741048503 +0000 UTC m=+21.915685053 I0420 17:46:55.796774 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:55.796753684 +0000 UTC m=+21.971390274 I0420 17:46:55.965405 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0420 17:46:55.977897 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:55.968700171 +0000 UTC m=+22.143336721 I0420 17:46:56.148695 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:56.148672778 +0000 UTC m=+22.323309338 I0420 17:46:56.198020 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0420 17:46:56.239476 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0420 17:46:56.501243 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-p9bsn" condition "Approved" to 2026-04-20 17:46:56.501224871 +0000 UTC m=+22.675861461 I0420 17:46:56.814043 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-p9bsn" condition "Ready" to 2026-04-20 17:46:56.814027675 +0000 UTC m=+22.988664255 I0420 17:46:57.105322 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:57.105294799 +0000 UTC m=+23.279931379 I0420 17:46:57.189982 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0420 17:46:57.190230 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 17:46:57.190224815 +0000 UTC m=+23.364861365 I0420 17:46:57.390255 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0420 17:48:02.068456 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0420 17:48:02.119530 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-20 17:48:02.118872936 +0000 UTC m=+88.293509526 I0420 17:48:02.140307 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-20 17:48:02.140295064 +0000 UTC m=+88.314931624 E0420 17:48:04.351682 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0420 17:48:04.385473 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-20 17:48:04.385457442 +0000 UTC m=+90.560094002 I0420 17:48:04.411878 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-20 17:48:04.411859233 +0000 UTC m=+90.586495823 E0420 17:48:06.136865 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0420 17:48:06.179871 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-20 17:48:06.179847416 +0000 UTC m=+92.354483996 I0420 17:48:06.226784 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-20 17:48:06.226769048 +0000 UTC m=+92.401405628 E0420 17:48:08.009410 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0420 17:48:08.060969 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-20 17:48:08.060924764 +0000 UTC m=+94.235561324 I0420 17:48:08.081511 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-20 17:48:08.081493509 +0000 UTC m=+94.256130069