I0331 22:23:22.995634 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0331 22:23:22.995773 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0331 22:23:22.995873 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0331 22:23:23.000594 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0331 22:23:23.001129 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0331 22:23:23.001127 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0331 22:23:23.001237 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0331 22:23:23.004108 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0331 22:23:23.023779 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0331 22:23:23.033385 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0331 22:23:23.037417 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0331 22:23:23.040116 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0331 22:23:23.042771 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0331 22:23:23.044629 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0331 22:23:23.044660 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0331 22:23:23.046942 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0331 22:23:23.048717 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0331 22:23:23.054600 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0331 22:23:23.057479 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0331 22:23:23.057510 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0331 22:23:23.057543 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0331 22:23:23.060204 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0331 22:23:23.062702 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0331 22:23:23.064547 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0331 22:23:23.066659 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0331 22:23:23.068494 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0331 22:23:23.070371 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0331 22:23:23.070611 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0331 22:23:23.077804 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0331 22:23:23.077875 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0331 22:23:23.080664 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0331 22:23:23.080796 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0331 22:23:23.083411 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0331 22:23:23.086249 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.087007 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.087271 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.087591 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.087603 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.087949 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.088449 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.088993 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.089584 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:23.196018 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0331 22:23:36.731671 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-03-31 22:23:36.731654288 +0000 UTC m=+13.772597132 I0331 22:23:37.496959 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-03-31 22:23:37.496941707 +0000 UTC m=+14.537884551 I0331 22:23:37.497154 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:23:37.497374 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-31 22:23:37.497358819 +0000 UTC m=+14.538301723 E0331 22:23:37.510417 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0331 22:23:37.510737 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-03-31 22:23:37.510724882 +0000 UTC m=+14.551667736 E0331 22:23:37.510803 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0331 22:23:37.513578 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:23:37.513655 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:23:37.513679 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-03-31 22:23:37.513670086 +0000 UTC m=+14.554612930 E0331 22:23:37.522656 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0331 22:23:37.523295 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0331 22:23:37.523607 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0331 22:23:37.523794 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0331 22:23:37.547825 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:23:37.556303 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-b7rh2" condition "Approved" to 2026-03-31 22:23:37.556292506 +0000 UTC m=+14.597235340 I0331 22:23:37.569038 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-b7rh2" condition "Ready" to 2026-03-31 22:23:37.56902564 +0000 UTC m=+14.609968484 I0331 22:23:37.595863 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:23:37.595849707 +0000 UTC m=+14.636792551 I0331 22:23:37.613329 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:23:37.613575 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:23:37.613568495 +0000 UTC m=+14.654511339 I0331 22:23:37.624123 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:23:37.626191 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:23:37.626565 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:23:37.626536536 +0000 UTC m=+14.667479380 I0331 22:23:42.523326 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:23:42.523311449 +0000 UTC m=+19.564254323 I0331 22:24:03.719019 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-03-31 22:24:03.718971183 +0000 UTC m=+40.759914027 I0331 22:24:03.719079 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:24:03.719126 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-03-31 22:24:03.719115117 +0000 UTC m=+40.760057991 I0331 22:24:03.733817 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-03-31 22:24:03.733798824 +0000 UTC m=+40.774741668 I0331 22:24:03.749810 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:24:03.749926 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-03-31 22:24:03.749917448 +0000 UTC m=+40.790860282 I0331 22:24:03.949773 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:24:03.984808 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hd8b9" condition "Approved" to 2026-03-31 22:24:03.984788015 +0000 UTC m=+41.025730889 I0331 22:24:04.018666 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-hd8b9" condition "Ready" to 2026-03-31 22:24:04.018649257 +0000 UTC m=+41.059592101 I0331 22:24:04.072367 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:24:04.072349962 +0000 UTC m=+41.113292796 I0331 22:24:04.099135 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:24:04.166210 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:53.463522 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:25:53.463565 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-03-31 22:25:53.46354102 +0000 UTC m=+150.504483884 I0331 22:25:53.463611 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-03-31 22:25:53.463591652 +0000 UTC m=+150.504534516 I0331 22:25:53.482124 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" E0331 22:25:53.482195 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0331 22:25:53.482315 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:25:53.482380 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-03-31 22:25:53.482364648 +0000 UTC m=+150.523307482 I0331 22:25:53.482438 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0331 22:25:53.482418 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-03-31 22:25:53.482408219 +0000 UTC m=+150.523351083 I0331 22:25:53.517599 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-03-31 22:25:53.517579558 +0000 UTC m=+150.558522392 I0331 22:25:53.517780 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:25:53.521794 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-03-31 22:25:53.521785009 +0000 UTC m=+150.562727853 E0331 22:25:53.537724 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0331 22:25:53.537846 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0331 22:25:53.537877 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0331 22:25:53.537907 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0331 22:25:53.555036 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:53.555343 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-03-31 22:25:53.55511767 +0000 UTC m=+150.596060504 I0331 22:25:53.696656 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-rghv7" condition "Approved" to 2026-03-31 22:25:53.696637658 +0000 UTC m=+150.737580522 I0331 22:25:53.727554 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-rghv7" condition "Ready" to 2026-03-31 22:25:53.727539295 +0000 UTC m=+150.768482139 I0331 22:25:53.736957 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:53.767914 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:53.767897571 +0000 UTC m=+150.808840445 I0331 22:25:53.790283 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-r4dfp" condition "Approved" to 2026-03-31 22:25:53.790252112 +0000 UTC m=+150.831195006 I0331 22:25:53.795637 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:53.796147 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:53.796138987 +0000 UTC m=+150.837081831 I0331 22:25:53.809748 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-r4dfp" condition "Ready" to 2026-03-31 22:25:53.809729826 +0000 UTC m=+150.850672670 I0331 22:25:53.819108 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:58.539288 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:58.539272153 +0000 UTC m=+155.580215027 I0331 22:25:58.556133 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-r4dfp" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:58.556113467 +0000 UTC m=+155.597056331 I0331 22:25:58.586472 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:58.586453669 +0000 UTC m=+155.627396533 I0331 22:25:58.606660 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:58.607090 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:25:58.607081694 +0000 UTC m=+155.648024558 I0331 22:25:58.624456 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:25:58.627379 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:28:36.060015 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-61.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:28:36.060067 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-61.nip.io-tls" condition "Issuing" to 2026-03-31 22:28:36.06005355 +0000 UTC m=+313.100996414 I0331 22:28:36.061030 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-61.nip.io-tls" condition "Ready" to 2026-03-31 22:28:36.061001775 +0000 UTC m=+313.101944639 I0331 22:28:36.076703 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-61.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-61.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:28:36.076792 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-61.nip.io-tls" condition "Ready" to 2026-03-31 22:28:36.076780874 +0000 UTC m=+313.117723718 I0331 22:28:36.186794 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-61.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-61.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:28:36.228612 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-61.nip.io-tls-76czm" condition "Approved" to 2026-03-31 22:28:36.228594469 +0000 UTC m=+313.269537303 I0331 22:28:36.245319 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-61.nip.io-tls-76czm" condition "Ready" to 2026-03-31 22:28:36.245292572 +0000 UTC m=+313.286235446 I0331 22:28:36.274007 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-61.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:28:36.273988263 +0000 UTC m=+313.314931127 I0331 22:28:36.295452 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-61.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-61.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:29:46.662941 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-03-31 22:29:46.66292397 +0000 UTC m=+383.703867104 I0331 22:29:46.662958 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:29:46.663066 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-03-31 22:29:46.663039513 +0000 UTC m=+383.703982387 E0331 22:29:46.676574 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0331 22:29:46.676641 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-03-31 22:29:46.676626844 +0000 UTC m=+383.717569718 E0331 22:29:46.676739 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0331 22:29:46.678992 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:29:46.679188 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:29:46.679236 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-03-31 22:29:46.679222373 +0000 UTC m=+383.720165247 E0331 22:29:46.686852 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0331 22:29:46.687160 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0331 22:29:46.687237 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0331 22:29:46.687323 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0331 22:29:46.716832 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-24524" condition "Approved" to 2026-03-31 22:29:46.71681292 +0000 UTC m=+383.757755764 I0331 22:29:46.729553 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-24524" condition "Ready" to 2026-03-31 22:29:46.729536708 +0000 UTC m=+383.770479552 I0331 22:29:46.751614 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:29:46.751602173 +0000 UTC m=+383.792545037 I0331 22:29:46.770294 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:29:46.770804 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:29:46.770789243 +0000 UTC m=+383.811732107 I0331 22:29:46.778306 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:29:46.788598 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:29:51.688591 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:29:51.688554678 +0000 UTC m=+388.729497552 I0331 22:30:30.118845 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:30:30.119079 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-03-31 22:30:30.119070512 +0000 UTC m=+427.160013336 I0331 22:30:30.119698 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-03-31 22:30:30.119683248 +0000 UTC m=+427.160626092 I0331 22:30:30.146085 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:30:30.146153 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-03-31 22:30:30.146139859 +0000 UTC m=+427.187082703 I0331 22:30:30.146677 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-03-31 22:30:30.146670773 +0000 UTC m=+427.187613617 I0331 22:30:30.147925 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:30:30.147958 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-03-31 22:30:30.147951427 +0000 UTC m=+427.188894261 I0331 22:30:30.149011 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-03-31 22:30:30.149007255 +0000 UTC m=+427.189950089 I0331 22:30:30.160534 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.160642 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-03-31 22:30:30.160633763 +0000 UTC m=+427.201576627 I0331 22:30:30.169911 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.169984 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-03-31 22:30:30.169977121 +0000 UTC m=+427.210919955 I0331 22:30:30.179327 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.179386 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-03-31 22:30:30.179379699 +0000 UTC m=+427.220322533 I0331 22:30:30.343413 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.376582 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-xk6wc" condition "Approved" to 2026-03-31 22:30:30.376561592 +0000 UTC m=+427.417504456 I0331 22:30:30.404502 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-xk6wc" condition "Ready" to 2026-03-31 22:30:30.404488542 +0000 UTC m=+427.445431376 I0331 22:30:30.426617 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.430044 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.452015 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:30.452002741 +0000 UTC m=+427.492945575 I0331 22:30:30.477259 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.477692 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:30.477683371 +0000 UTC m=+427.518626235 I0331 22:30:30.483476 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:30.503081 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" E0331 22:30:30.687323 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-jjjrc\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0331 22:30:30.694496 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-kgnrf" condition "Approved" to 2026-03-31 22:30:30.694488514 +0000 UTC m=+427.735431338 I0331 22:30:30.714078 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-kgnrf" condition "Ready" to 2026-03-31 22:30:30.714066583 +0000 UTC m=+427.755009427 I0331 22:30:30.974539 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" E0331 22:30:31.009695 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-tc9fc\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0331 22:30:31.071517 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-fv9jh" condition "Approved" to 2026-03-31 22:30:31.071494661 +0000 UTC m=+428.112437525 I0331 22:30:31.487613 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-fv9jh" condition "Ready" to 2026-03-31 22:30:31.487592962 +0000 UTC m=+428.528535826 I0331 22:30:31.611961 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" resource_name="prometheus-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="prometheus-tls-kgnrf" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="prometheus-tls-jjjrc" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" E0331 22:30:32.008120 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"grafana-tls-7v4fb\" not found" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" I0331 22:30:32.072120 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-h5vk8" condition "Approved" to 2026-03-31 22:30:32.072095245 +0000 UTC m=+429.113038089 I0331 22:30:32.375083 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-h5vk8" condition "Ready" to 2026-03-31 22:30:32.37506086 +0000 UTC m=+429.416003734 I0331 22:30:32.560966 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" resource_name="grafana-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="grafana-tls-fv9jh" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="grafana-tls-vp9l4" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0331 22:30:32.769612 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:32.769593491 +0000 UTC m=+429.810536365 I0331 22:30:32.819890 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-gs4td" condition "Approved" to 2026-03-31 22:30:32.819859932 +0000 UTC m=+429.860802806 I0331 22:30:32.916323 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:32.916722 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:32.916715718 +0000 UTC m=+429.957658552 I0331 22:30:33.291434 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-gs4td" condition "Ready" to 2026-03-31 22:30:33.291412503 +0000 UTC m=+430.332355367 I0331 22:30:33.619964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:33.667213 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:33.667199316 +0000 UTC m=+430.708142150 I0331 22:30:33.817147 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:33.817661 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:33.817652871 +0000 UTC m=+430.858595705 I0331 22:30:34.065763 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:38.318008 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:30:38.318233 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" condition "Issuing" to 2026-03-31 22:30:38.318219025 +0000 UTC m=+435.359161929 I0331 22:30:38.318105 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" condition "Ready" to 2026-03-31 22:30:38.318083891 +0000 UTC m=+435.359026735 I0331 22:30:38.340774 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:38.340975 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:30:38.341057 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" condition "Issuing" to 2026-03-31 22:30:38.341044619 +0000 UTC m=+435.381987493 I0331 22:30:38.496059 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:38.504334 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-tk9fv-5w77r" condition "Approved" to 2026-03-31 22:30:38.504320124 +0000 UTC m=+435.545262988 I0331 22:30:38.522240 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-tk9fv-5w77r" condition "Ready" to 2026-03-31 22:30:38.522227699 +0000 UTC m=+435.563170553 I0331 22:30:38.549451 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:38.549431369 +0000 UTC m=+435.590374213 I0331 22:30:38.570320 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:38.570615 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:30:38.57060815 +0000 UTC m=+435.611550994 I0331 22:30:38.576895 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:30:38.596857 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-tk9fv-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:31:01.703773 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:31:01.703804 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-03-31 22:31:01.703796762 +0000 UTC m=+458.744739596 I0331 22:31:01.704046 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-03-31 22:31:01.704042298 +0000 UTC m=+458.744985132 I0331 22:31:01.721613 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:31:01.721727 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:31:01.721753 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-03-31 22:31:01.721746027 +0000 UTC m=+458.762688871 I0331 22:31:01.891507 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hrrxw" condition "Approved" to 2026-03-31 22:31:01.891489933 +0000 UTC m=+458.932432777 I0331 22:31:01.911385 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hrrxw" condition "Ready" to 2026-03-31 22:31:01.91136996 +0000 UTC m=+458.952312804 I0331 22:31:01.943728 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:31:01.943705457 +0000 UTC m=+458.984648301 I0331 22:31:01.993499 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:31:01.993806 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:31:01.993800713 +0000 UTC m=+459.034743547 I0331 22:31:02.039938 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:31:02.040346 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:31:02.040336725 +0000 UTC m=+459.081279549 I0331 22:34:25.598643 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-03-31 22:34:25.598627088 +0000 UTC m=+662.639569932 I0331 22:34:25.599222 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:34:25.599320 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-03-31 22:34:25.599310596 +0000 UTC m=+662.640253440 I0331 22:34:25.617487 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:34:25.617604 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:34:25.617637 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-03-31 22:34:25.61762852 +0000 UTC m=+662.658571364 I0331 22:34:25.972027 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-sctj8" condition "Approved" to 2026-03-31 22:34:25.972011904 +0000 UTC m=+663.012954748 I0331 22:34:25.993336 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-sctj8" condition "Ready" to 2026-03-31 22:34:25.993322906 +0000 UTC m=+663.034265770 I0331 22:34:26.026950 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:34:26.026936634 +0000 UTC m=+663.067879478 I0331 22:34:26.055445 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:36:57.881875 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:36:57.881894 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-03-31 22:36:57.881862947 +0000 UTC m=+814.922805811 I0331 22:36:57.881944 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-03-31 22:36:57.881936808 +0000 UTC m=+814.922879662 I0331 22:36:57.902389 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:36:57.902510 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:36:57.902563 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-03-31 22:36:57.902554451 +0000 UTC m=+814.943497285 I0331 22:36:58.229728 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:36:58.240399 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-7bqpd" condition "Approved" to 2026-03-31 22:36:58.240385965 +0000 UTC m=+815.281328809 I0331 22:36:58.262347 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-7bqpd" condition "Ready" to 2026-03-31 22:36:58.262332023 +0000 UTC m=+815.303274867 I0331 22:36:58.297436 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:36:58.297415406 +0000 UTC m=+815.338358300 I0331 22:36:58.319249 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:36:58.319821 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:36:58.319811366 +0000 UTC m=+815.360754210 I0331 22:36:58.343648 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:36:58.343979 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:36:58.343969052 +0000 UTC m=+815.384911906 I0331 22:36:58.349503 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:38:06.458424 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-03-31 22:38:06.458413193 +0000 UTC m=+883.499356027 I0331 22:38:06.458872 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:38:06.458929 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-03-31 22:38:06.458922477 +0000 UTC m=+883.499865341 I0331 22:38:06.473550 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:38:06.473644 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:38:06.473675 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-03-31 22:38:06.473668195 +0000 UTC m=+883.514611039 I0331 22:38:06.897706 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-fj646" condition "Approved" to 2026-03-31 22:38:06.897694108 +0000 UTC m=+883.938636952 I0331 22:38:06.918416 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-fj646" condition "Ready" to 2026-03-31 22:38:06.918403623 +0000 UTC m=+883.959346447 I0331 22:38:06.948654 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:38:06.948633189 +0000 UTC m=+883.989576063 I0331 22:38:06.975046 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:38:06.975497 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:38:06.975485796 +0000 UTC m=+884.016428640 I0331 22:38:06.994516 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:38:06.994823 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:38:06.994813325 +0000 UTC m=+884.035756149 I0331 22:38:06.997944 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:41:15.521164 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-03-31 22:41:15.521148914 +0000 UTC m=+1072.562091788 I0331 22:41:15.521328 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0331 22:41:15.521387 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-03-31 22:41:15.521380001 +0000 UTC m=+1072.562322865 I0331 22:41:15.540070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:41:15.540181 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-03-31 22:41:15.540169202 +0000 UTC m=+1072.581112046 I0331 22:41:15.725968 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:41:15.757506 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-l85f8" condition "Approved" to 2026-03-31 22:41:15.757488893 +0000 UTC m=+1072.798431757 I0331 22:41:15.779153 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-l85f8" condition "Ready" to 2026-03-31 22:41:15.779135939 +0000 UTC m=+1072.820078813 I0331 22:41:15.812296 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:41:15.812280527 +0000 UTC m=+1072.853223401 I0331 22:41:15.830578 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0331 22:41:15.831076 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-03-31 22:41:15.831065199 +0000 UTC m=+1072.872008043 I0331 22:41:15.857794 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"