I0514 10:18:38.802656 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0514 10:18:38.802823 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0514 10:18:38.802877 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0514 10:18:38.802954 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0514 10:18:38.804594 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0514 10:18:38.805042 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0514 10:18:38.805232 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0514 10:18:38.805744 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0514 10:18:38.821822 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0514 10:18:38.822936 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0514 10:18:38.823060 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0514 10:18:38.823704 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0514 10:18:38.824455 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0514 10:18:38.825039 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0514 10:18:38.825773 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0514 10:18:38.826424 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0514 10:18:38.828265 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0514 10:18:38.829115 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0514 10:18:38.829764 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0514 10:18:38.831049 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0514 10:18:38.831442 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0514 10:18:38.831458 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0514 10:18:38.831469 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0514 10:18:38.831479 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0514 10:18:38.831588 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0514 10:18:38.832316 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0514 10:18:38.833552 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0514 10:18:38.834829 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0514 10:18:38.835225 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0514 10:18:38.835714 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0514 10:18:38.835909 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0514 10:18:38.836040 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0514 10:18:38.837192 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0514 10:19:04.777364 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-05-14 10:19:04.776358255 +0000 UTC m=+26.010153495 I0514 10:19:04.791389 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:04.791300 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-14 10:19:04.791290475 +0000 UTC m=+26.025085705 I0514 10:19:04.791418 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-05-14 10:19:04.791412248 +0000 UTC m=+26.025207488 E0514 10:19:04.806486 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0514 10:19:04.807345 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18af6749deec9328", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"236b9041-f5fb-46b7-a27f-ef440ac01bc6", APIVersion:"cert-manager.io/v1", ResourceVersion:"1351", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.May, 14, 10, 19, 4, 804954920, time.Local), LastTimestamp:time.Date(2026, time.May, 14, 10, 19, 4, 804954920, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18af6749deec9328" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0514 10:19:04.808332 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0514 10:19:04.808433 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-05-14 10:19:04.808424022 +0000 UTC m=+26.042219292 E0514 10:19:04.820920 1 controller.go:167] cert-manager/certificates-readiness "msg"="re-queuing item due to error processing" "error"="certificates.cert-manager.io \"selfsigned-cert\" not found" "key"="cert-manager-test/selfsigned-cert" I0514 10:19:04.835621 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-14 10:19:04.835591819 +0000 UTC m=+26.069387059 I0514 10:19:04.847173 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-14 10:19:04.847157551 +0000 UTC m=+26.080952791 I0514 10:19:04.847206 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:04.847241 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-14 10:19:04.847235213 +0000 UTC m=+26.081030443 I0514 10:19:04.863678 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0514 10:19:04.863722 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:04.863754 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-05-14 10:19:04.863751062 +0000 UTC m=+26.097546292 E0514 10:19:05.106659 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0514 10:19:05.195568 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0514 10:19:05.212071 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-q4qtt" condition "Approved" to 2026-05-14 10:19:05.21206193 +0000 UTC m=+26.445857170 I0514 10:19:05.255532 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-q4qtt" condition "Ready" to 2026-05-14 10:19:05.255523548 +0000 UTC m=+26.489318778 I0514 10:19:05.292552 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:05.29253855 +0000 UTC m=+26.526333800 I0514 10:19:05.323373 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0514 10:19:05.404010 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-14 10:19:05.403995812 +0000 UTC m=+26.637791052 I0514 10:19:05.422709 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-14 10:19:05.422696419 +0000 UTC m=+26.656491659 I0514 10:19:05.422742 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:05.422761 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-05-14 10:19:05.42275478 +0000 UTC m=+26.656550010 I0514 10:19:05.483347 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0514 10:19:05.483553 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-14 10:19:05.483547569 +0000 UTC m=+26.717342799 I0514 10:19:05.710761 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-14 10:19:05.710751758 +0000 UTC m=+26.944546988 I0514 10:19:05.723267 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-14 10:19:05.723250672 +0000 UTC m=+26.957045922 I0514 10:19:05.724077 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:05.724107 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-14 10:19:05.724100894 +0000 UTC m=+26.957896124 I0514 10:19:05.776094 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0514 10:19:05.780468 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:05.780491 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-05-14 10:19:05.780486408 +0000 UTC m=+27.014281638 I0514 10:19:05.870302 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0514 10:19:05.925096 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-mt77g" condition "Approved" to 2026-05-14 10:19:05.925086702 +0000 UTC m=+27.158881952 I0514 10:19:05.965559 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-mt77g" condition "Ready" to 2026-05-14 10:19:05.965546263 +0000 UTC m=+27.199341493 I0514 10:19:06.029388 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:06.029377549 +0000 UTC m=+27.263172779 I0514 10:19:06.052200 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0514 10:19:06.052580 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:06.052573748 +0000 UTC m=+27.286368988 I0514 10:19:06.106937 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0514 10:19:06.107568 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0514 10:19:06.107742 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-14 10:19:06.107737446 +0000 UTC m=+27.341532676 I0514 10:19:06.116648 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:06.116636016 +0000 UTC m=+27.350431246 I0514 10:19:06.129698 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:06.130868 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-14 10:19:06.130862004 +0000 UTC m=+27.364657234 I0514 10:19:06.129720 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-14 10:19:06.129715753 +0000 UTC m=+27.363510983 I0514 10:19:06.181859 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0514 10:19:06.184486 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0514 10:19:06.184537 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-05-14 10:19:06.184531822 +0000 UTC m=+27.418327052 I0514 10:19:06.412556 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-nzzx7" condition "Approved" to 2026-05-14 10:19:06.41254396 +0000 UTC m=+27.646339190 I0514 10:19:06.441837 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-nzzx7" condition "Ready" to 2026-05-14 10:19:06.441826608 +0000 UTC m=+27.675621838 I0514 10:19:06.694942 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:06.694931235 +0000 UTC m=+27.928726465 I0514 10:19:06.888330 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0514 10:19:06.891375 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:06.891363936 +0000 UTC m=+28.125159186 I0514 10:19:07.249989 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-msw2b" condition "Approved" to 2026-05-14 10:19:07.24997814 +0000 UTC m=+28.483773360 I0514 10:19:07.288931 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0514 10:19:07.342420 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0514 10:19:07.412279 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-msw2b" condition "Ready" to 2026-05-14 10:19:07.412261573 +0000 UTC m=+28.646056813 I0514 10:19:07.953363 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:07.953345949 +0000 UTC m=+29.187141219 I0514 10:19:08.049601 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0514 10:19:08.050040 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-14 10:19:08.050035498 +0000 UTC m=+29.283830728 I0514 10:19:08.289055 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0514 10:19:08.494062 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" E0514 10:20:19.091262 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0514 10:20:19.134858 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-05-14 10:20:19.134843588 +0000 UTC m=+100.368638848 I0514 10:20:19.152917 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-05-14 10:20:19.15290482 +0000 UTC m=+100.386700060 E0514 10:20:21.145811 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0514 10:20:21.180217 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-05-14 10:20:21.180202656 +0000 UTC m=+102.413997926 I0514 10:20:21.196979 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-05-14 10:20:21.196969081 +0000 UTC m=+102.430764321 E0514 10:20:22.686380 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0514 10:20:22.728078 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-05-14 10:20:22.728060238 +0000 UTC m=+103.961855498 I0514 10:20:22.750252 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-05-14 10:20:22.750241561 +0000 UTC m=+103.984036801 E0514 10:20:24.596574 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0514 10:20:24.714971 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-05-14 10:20:24.714951172 +0000 UTC m=+105.948746452 I0514 10:20:24.814411 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-05-14 10:20:24.814400916 +0000 UTC m=+106.048196156