I0318 13:14:16.837000 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0318 13:14:16.837175 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0318 13:14:16.837222 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0318 13:14:16.837344 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0318 13:14:16.839090 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0318 13:14:16.839539 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0318 13:14:16.839662 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0318 13:14:16.840232 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0318 13:14:16.855344 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0318 13:14:16.857437 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0318 13:14:16.858581 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0318 13:14:16.860860 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0318 13:14:16.860217 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0318 13:14:16.861241 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0318 13:14:16.861270 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0318 13:14:16.862789 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0318 13:14:16.862834 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0318 13:14:16.862844 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0318 13:14:16.862929 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0318 13:14:16.863136 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0318 13:14:16.863380 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0318 13:14:16.863850 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0318 13:14:16.864214 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0318 13:14:16.864274 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0318 13:14:16.864880 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0318 13:14:16.865343 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0318 13:14:16.865865 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0318 13:14:16.866536 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0318 13:14:16.867208 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0318 13:14:16.867938 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0318 13:14:16.867980 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0318 13:14:16.868994 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0318 13:14:16.869819 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0318 13:14:46.515093 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-03-18 13:14:46.515029151 +0000 UTC m=+29.711015742 I0318 13:14:46.528031 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:46.528087 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-03-18 13:14:46.528076658 +0000 UTC m=+29.724063259 I0318 13:14:46.528528 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-18 13:14:46.528515625 +0000 UTC m=+29.724502226 E0318 13:14:46.544069 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.189df1cbf4d9abad", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"33f4864d-e1a7-4024-929d-688a8f75bfd3", APIVersion:"cert-manager.io/v1", ResourceVersion:"1359", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.March, 18, 13, 14, 46, 542404525, time.Local), LastTimestamp:time.Date(2026, time.March, 18, 13, 14, 46, 542404525, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.189df1cbf4d9abad" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0318 13:14:46.545650 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0318 13:14:46.545707 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-03-18 13:14:46.545701544 +0000 UTC m=+29.741688135 E0318 13:14:46.547425 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" I0318 13:14:46.581470 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-18 13:14:46.581455025 +0000 UTC m=+29.777441626 I0318 13:14:46.593882 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:46.593915 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-03-18 13:14:46.593908603 +0000 UTC m=+29.789895204 I0318 13:14:46.594765 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-18 13:14:46.594747806 +0000 UTC m=+29.790734407 I0318 13:14:46.608995 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0318 13:14:46.609069 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-18 13:14:46.609060803 +0000 UTC m=+29.805047404 E0318 13:14:46.706985 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0318 13:14:46.978920 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0318 13:14:47.017713 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-tmvvz" condition "Approved" to 2026-03-18 13:14:47.017700289 +0000 UTC m=+30.213686920 I0318 13:14:47.059474 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-tmvvz" condition "Ready" to 2026-03-18 13:14:47.059462556 +0000 UTC m=+30.255449157 I0318 13:14:47.111554 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:47.111537909 +0000 UTC m=+30.307524540 I0318 13:14:47.121984 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-18 13:14:47.121973747 +0000 UTC m=+30.317960338 I0318 13:14:47.143316 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-18 13:14:47.143305777 +0000 UTC m=+30.339292378 I0318 13:14:47.143529 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:47.146675 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-03-18 13:14:47.143688784 +0000 UTC m=+30.339675395 I0318 13:14:47.150221 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0318 13:14:47.166050 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0318 13:14:47.166121 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-18 13:14:47.166113561 +0000 UTC m=+30.362100182 I0318 13:14:47.484905 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-18 13:14:47.484859533 +0000 UTC m=+30.680846164 I0318 13:14:47.626731 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:47.626742 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-18 13:14:47.626733637 +0000 UTC m=+30.822720228 I0318 13:14:47.626750 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-03-18 13:14:47.626746418 +0000 UTC m=+30.822733009 I0318 13:14:47.632447 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0318 13:14:47.658515 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0318 13:14:47.658570 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-18 13:14:47.658564196 +0000 UTC m=+30.854550787 I0318 13:14:47.675515 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-84nsz" condition "Approved" to 2026-03-18 13:14:47.67550392 +0000 UTC m=+30.871490521 I0318 13:14:47.755035 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-84nsz" condition "Ready" to 2026-03-18 13:14:47.755023147 +0000 UTC m=+30.951009748 I0318 13:14:47.977769 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0318 13:14:47.989175 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:47.989166298 +0000 UTC m=+31.185152889 I0318 13:14:48.018382 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0318 13:14:48.018844 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:48.018605769 +0000 UTC m=+31.214592360 I0318 13:14:48.052281 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0318 13:14:48.053630 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-x66zp" condition "Approved" to 2026-03-18 13:14:48.053623633 +0000 UTC m=+31.249610224 I0318 13:14:48.072317 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0318 13:14:48.082674 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-x66zp" condition "Ready" to 2026-03-18 13:14:48.082663478 +0000 UTC m=+31.278650079 I0318 13:14:48.205018 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-18 13:14:48.205006898 +0000 UTC m=+31.400993529 I0318 13:14:48.216651 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-18 13:14:48.216637583 +0000 UTC m=+31.412624184 I0318 13:14:48.216906 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:48.216931 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-18 13:14:48.216925317 +0000 UTC m=+31.412911918 I0318 13:14:48.480238 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0318 13:14:48.480314 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0318 13:14:48.480350 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-03-18 13:14:48.480345029 +0000 UTC m=+31.676331620 I0318 13:14:48.608203 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:48.608189781 +0000 UTC m=+31.804176362 I0318 13:14:48.687200 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0318 13:14:49.180089 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-mjct5" condition "Approved" to 2026-03-18 13:14:49.180076424 +0000 UTC m=+32.376063025 I0318 13:14:49.447483 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-mjct5" condition "Ready" to 2026-03-18 13:14:49.447472426 +0000 UTC m=+32.643459017 I0318 13:14:49.729599 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:49.729582846 +0000 UTC m=+32.925569477 I0318 13:14:49.876557 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0318 13:14:49.876871 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-18 13:14:49.876863758 +0000 UTC m=+33.072850359 I0318 13:14:50.136285 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0318 13:14:50.182410 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0318 13:16:32.176823 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0318 13:16:32.227895 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-03-18 13:16:32.227883386 +0000 UTC m=+135.423870007 I0318 13:16:32.253271 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-03-18 13:16:32.253259298 +0000 UTC m=+135.449245899 E0318 13:16:34.674088 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0318 13:16:34.704594 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-03-18 13:16:34.704579341 +0000 UTC m=+137.900565962 I0318 13:16:34.729013 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-03-18 13:16:34.729003881 +0000 UTC m=+137.924990472 E0318 13:16:37.176379 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0318 13:16:37.216140 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-03-18 13:16:37.216124764 +0000 UTC m=+140.412111375 I0318 13:16:37.331297 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-03-18 13:16:37.331280293 +0000 UTC m=+140.527266924 E0318 13:16:39.057519 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0318 13:16:39.104359 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-03-18 13:16:39.104340025 +0000 UTC m=+142.300326657 I0318 13:16:39.124574 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-03-18 13:16:39.124564609 +0000 UTC m=+142.320551210