I0505 11:15:19.691896 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0505 11:15:19.692086 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0505 11:15:19.692189 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0505 11:15:19.698053 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0505 11:15:19.698537 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0505 11:15:19.698666 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0505 11:15:19.698795 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0505 11:15:19.701600 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0505 11:15:19.718673 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0505 11:15:19.722588 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0505 11:15:19.726289 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0505 11:15:19.737187 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0505 11:15:19.739841 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0505 11:15:19.742132 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0505 11:15:19.744078 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0505 11:15:19.746112 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0505 11:15:19.748154 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0505 11:15:19.750342 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0505 11:15:19.750410 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0505 11:15:19.750413 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0505 11:15:19.753256 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0505 11:15:19.759437 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0505 11:15:19.759481 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0505 11:15:19.764167 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0505 11:15:19.766772 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0505 11:15:19.766793 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0505 11:15:19.766892 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0505 11:15:19.768922 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0505 11:15:19.771020 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0505 11:15:19.772962 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0505 11:15:19.774937 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0505 11:15:19.775033 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0505 11:15:19.777612 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0505 11:15:19.781787 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.785088 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.786060 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.786988 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.787535 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.787886 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.788403 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.803922 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.826646 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:19.871969 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0505 11:15:29.875837 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-05 11:15:29.875820014 +0000 UTC m=+10.217731785 I0505 11:15:30.601662 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-05 11:15:30.60164501 +0000 UTC m=+10.943556781 I0505 11:15:30.602639 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:15:30.602761 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-05 11:15:30.6026758 +0000 UTC m=+10.944587541 E0505 11:15:30.613328 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 11:15:30.613427 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-05 11:15:30.613420012 +0000 UTC m=+10.955331753 E0505 11:15:30.613451 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 11:15:30.617753 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:30.617963 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:15:30.618073 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-05 11:15:30.617984869 +0000 UTC m=+10.959896610 E0505 11:15:30.627174 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0505 11:15:30.627721 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 11:15:30.627827 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 11:15:30.627924 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0505 11:15:30.669084 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-bfw9s" condition "Approved" to 2026-05-05 11:15:30.669071354 +0000 UTC m=+11.010983105 I0505 11:15:30.681793 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-bfw9s" condition "Ready" to 2026-05-05 11:15:30.681782975 +0000 UTC m=+11.023694716 I0505 11:15:30.700947 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:30.700932262 +0000 UTC m=+11.042844013 I0505 11:15:30.719980 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:30.720329 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:30.720320969 +0000 UTC m=+11.062232720 I0505 11:15:30.733167 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:35.627789 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:35.627778546 +0000 UTC m=+15.969690287 I0505 11:15:57.515657 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:15:57.515935 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 11:15:57.515915988 +0000 UTC m=+37.857827759 I0505 11:15:57.515930 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-05 11:15:57.515894998 +0000 UTC m=+37.857806729 I0505 11:15:57.535562 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-05 11:15:57.535137339 +0000 UTC m=+37.877049070 I0505 11:15:57.548973 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:57.549048 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:15:57.549081 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-05 11:15:57.549075113 +0000 UTC m=+37.890986844 I0505 11:15:57.927902 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-rjxzr" condition "Approved" to 2026-05-05 11:15:57.927892926 +0000 UTC m=+38.269804657 I0505 11:15:57.961903 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-rjxzr" condition "Ready" to 2026-05-05 11:15:57.961892641 +0000 UTC m=+38.303804392 I0505 11:15:57.991657 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:57.991634338 +0000 UTC m=+38.333546109 I0505 11:15:58.016732 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:58.017304 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:58.017297747 +0000 UTC m=+38.359209488 I0505 11:15:58.036602 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:15:58.036976 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:15:58.036947799 +0000 UTC m=+38.378859550 I0505 11:20:20.802809 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Ready" to 2026-05-05 11:20:20.802769652 +0000 UTC m=+301.144681423 I0505 11:20:20.803011 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-30.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:20:20.803093 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Issuing" to 2026-05-05 11:20:20.803082882 +0000 UTC m=+301.144994643 I0505 11:20:20.819958 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-30.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-30.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:20:20.820113 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-30.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:20:20.820167 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Issuing" to 2026-05-05 11:20:20.820160128 +0000 UTC m=+301.162071859 I0505 11:20:21.123073 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-30.nip.io-tls-jbc72" condition "Approved" to 2026-05-05 11:20:21.123062211 +0000 UTC m=+301.464973942 I0505 11:20:21.152526 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-30.nip.io-tls-jbc72" condition "Ready" to 2026-05-05 11:20:21.152516154 +0000 UTC m=+301.494427895 I0505 11:20:21.182039 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:20:21.181986496 +0000 UTC m=+301.523898247 I0505 11:20:21.201932 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-30.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-30.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:20:21.202765 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:20:21.202755871 +0000 UTC m=+301.544667632 I0505 11:20:21.220211 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-30.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-30.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:20:21.220907 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-30.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-30.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:20:21.221443 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-30.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:20:21.221432167 +0000 UTC m=+301.563343908 I0505 11:21:25.330764 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 11:21:25.330721614 +0000 UTC m=+365.672633385 I0505 11:21:25.331112 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:21:25.331157 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-05 11:21:25.331147603 +0000 UTC m=+365.673059354 E0505 11:21:25.345128 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 11:21:25.345175 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-05 11:21:25.34516525 +0000 UTC m=+365.687076991 E0505 11:21:25.345237 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0505 11:21:25.347751 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:21:25.347847 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-05 11:21:25.347839269 +0000 UTC m=+365.689751010 E0505 11:21:25.356550 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0505 11:21:25.356861 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 11:21:25.356950 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0505 11:21:25.357022 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0505 11:21:25.363226 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:21:25.388217 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-6ws42" condition "Approved" to 2026-05-05 11:21:25.388202469 +0000 UTC m=+365.730114210 I0505 11:21:25.423719 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-6ws42" condition "Ready" to 2026-05-05 11:21:25.42370599 +0000 UTC m=+365.765617751 I0505 11:21:25.465110 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:21:25.465096909 +0000 UTC m=+365.807008650 I0505 11:21:25.512450 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:21:25.571619 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:21:30.357841 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:21:30.357793837 +0000 UTC m=+370.699705608 I0505 11:22:10.932855 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:10.932946 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-05 11:22:10.932925162 +0000 UTC m=+411.274836903 I0505 11:22:10.933416 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-05 11:22:10.933411082 +0000 UTC m=+411.275322823 I0505 11:22:10.935833 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-05 11:22:10.935827051 +0000 UTC m=+411.277738792 I0505 11:22:10.936083 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:10.936145 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-05 11:22:10.936136661 +0000 UTC m=+411.278048392 I0505 11:22:10.949991 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:10.950025 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-05 11:22:10.950018437 +0000 UTC m=+411.291930168 I0505 11:22:10.950193 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-05 11:22:10.950180967 +0000 UTC m=+411.292092698 I0505 11:22:10.981039 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:10.981129 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-05 11:22:10.981121389 +0000 UTC m=+411.323033110 I0505 11:22:10.985317 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:10.985453 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-05 11:22:10.985445649 +0000 UTC m=+411.327357400 I0505 11:22:10.989002 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:10.989072 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-05 11:22:10.989065858 +0000 UTC m=+411.330977579 I0505 11:22:11.112170 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.143754 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7bqmm" condition "Approved" to 2026-05-05 11:22:11.143742118 +0000 UTC m=+411.485653879 I0505 11:22:11.173296 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-7bqmm" condition "Ready" to 2026-05-05 11:22:11.173285711 +0000 UTC m=+411.515197462 I0505 11:22:11.218058 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:11.21804003 +0000 UTC m=+411.559951801 I0505 11:22:11.254487 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.307715 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.325047 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.338878 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rr8dg" condition "Approved" to 2026-05-05 11:22:11.338869369 +0000 UTC m=+411.680781100 I0505 11:22:11.351059 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-rr8dg" condition "Ready" to 2026-05-05 11:22:11.351050515 +0000 UTC m=+411.692962256 I0505 11:22:11.391131 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:11.391118705 +0000 UTC m=+411.733030446 I0505 11:22:11.433114 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.629089 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:11.931616 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-tw9vn" condition "Approved" to 2026-05-05 11:22:11.931596958 +0000 UTC m=+412.273508749 I0505 11:22:11.981748 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:12.287341 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-tw9vn" condition "Ready" to 2026-05-05 11:22:12.287331897 +0000 UTC m=+412.629243628 I0505 11:22:12.526932 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:12.526882127 +0000 UTC m=+412.868793868 I0505 11:22:12.623459 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:12.624125 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:12.624113693 +0000 UTC m=+412.966025464 I0505 11:22:12.826385 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:18.868722 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" condition "Ready" to 2026-05-05 11:22:18.868706577 +0000 UTC m=+419.210618318 I0505 11:22:18.869175 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:18.869782 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" condition "Issuing" to 2026-05-05 11:22:18.869774226 +0000 UTC m=+419.211686007 I0505 11:22:18.884496 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:18.884796 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" condition "Ready" to 2026-05-05 11:22:18.884783343 +0000 UTC m=+419.226695104 I0505 11:22:19.080667 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:19.116923 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-ftlbp-t6bk6" condition "Approved" to 2026-05-05 11:22:19.116913623 +0000 UTC m=+419.458825354 I0505 11:22:19.139736 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-ftlbp-t6bk6" condition "Ready" to 2026-05-05 11:22:19.139724158 +0000 UTC m=+419.481635889 I0505 11:22:19.169147 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:19.16913516 +0000 UTC m=+419.511046901 I0505 11:22:19.187116 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:19.241235 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ftlbp-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:31.220617 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-05 11:22:31.220579109 +0000 UTC m=+431.562490870 I0505 11:22:31.220771 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:31.220812 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-05 11:22:31.220802849 +0000 UTC m=+431.562714610 I0505 11:22:31.241293 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:31.241371 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:22:31.241390 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-05 11:22:31.241384834 +0000 UTC m=+431.583296565 I0505 11:22:31.596180 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-bm22t" condition "Approved" to 2026-05-05 11:22:31.596170014 +0000 UTC m=+431.938081745 I0505 11:22:31.613440 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-bm22t" condition "Ready" to 2026-05-05 11:22:31.613430159 +0000 UTC m=+431.955341890 I0505 11:22:31.648382 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:22:31.648372051 +0000 UTC m=+431.990283772 I0505 11:22:31.670015 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:22:31.733123 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:25:41.488817 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:25:41.488941 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 11:25:41.488930176 +0000 UTC m=+621.830841947 I0505 11:25:41.489336 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-05 11:25:41.489319535 +0000 UTC m=+621.831231306 I0505 11:25:41.508101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:25:41.508288 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:25:41.508321 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-05 11:25:41.508315501 +0000 UTC m=+621.850227232 I0505 11:25:41.723541 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-k2s8t" condition "Approved" to 2026-05-05 11:25:41.723529206 +0000 UTC m=+622.065440937 I0505 11:25:41.743857 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-k2s8t" condition "Ready" to 2026-05-05 11:25:41.743845811 +0000 UTC m=+622.085757552 I0505 11:25:41.770406 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:25:41.770394935 +0000 UTC m=+622.112306666 I0505 11:25:41.790042 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:25:41.790649 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:25:41.790641959 +0000 UTC m=+622.132553700 I0505 11:25:41.808348 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:25:41.808630 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:25:41.808623504 +0000 UTC m=+622.150535235 I0505 11:26:23.733214 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-05 11:26:23.732912607 +0000 UTC m=+664.074824378 I0505 11:26:23.734217 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:26:23.734277 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 11:26:23.734270527 +0000 UTC m=+664.076182288 I0505 11:26:23.761014 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:26:23.761121 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 11:26:23.761145 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 11:26:23.761136931 +0000 UTC m=+664.103048692 I0505 11:26:24.294688 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 11:26:24.305472 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-tgltr" condition "Approved" to 2026-05-05 11:26:24.305456912 +0000 UTC m=+664.647368683 I0505 11:26:24.323697 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-tgltr" condition "Ready" to 2026-05-05 11:26:24.323686497 +0000 UTC m=+664.665598238 I0505 11:26:24.352129 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 11:26:24.352115979 +0000 UTC m=+664.694027720 I0505 11:26:24.371327 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"