I0423 15:46:31.624276 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0423 15:46:31.624558 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0423 15:46:31.624652 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0423 15:46:31.631433 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0423 15:46:31.632343 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0423 15:46:31.632399 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0423 15:46:31.632637 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0423 15:46:31.636830 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0423 15:46:31.649509 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0423 15:46:31.654073 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0423 15:46:31.656990 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0423 15:46:31.659894 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0423 15:46:31.665779 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0423 15:46:31.670407 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0423 15:46:31.674451 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0423 15:46:31.677751 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0423 15:46:31.680300 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0423 15:46:31.682892 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0423 15:46:31.685620 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0423 15:46:31.691890 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0423 15:46:31.695288 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0423 15:46:31.697970 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0423 15:46:31.700225 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0423 15:46:31.700360 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0423 15:46:31.702906 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0423 15:46:31.705576 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0423 15:46:31.707459 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0423 15:46:31.707480 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0423 15:46:31.707488 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0423 15:46:31.707496 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0423 15:46:31.707660 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0423 15:46:31.709579 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0423 15:46:31.709994 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0423 15:46:31.714334 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.715991 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.716677 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.721059 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.728887 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.783450 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.793988 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.811967 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.814817 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:31.831015 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0423 15:46:44.434332 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-23 15:46:44.434309594 +0000 UTC m=+12.846420552 I0423 15:46:45.173225 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-23 15:46:45.173203943 +0000 UTC m=+13.585314901 I0423 15:46:45.173278 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:46:45.173380 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-23 15:46:45.173365957 +0000 UTC m=+13.585476915 E0423 15:46:45.188946 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0423 15:46:45.189117 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-23 15:46:45.18910822 +0000 UTC m=+13.601219158 E0423 15:46:45.189142 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0423 15:46:45.191401 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:46:45.191458 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:46:45.191475 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-23 15:46:45.191471057 +0000 UTC m=+13.603581995 E0423 15:46:45.199119 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0423 15:46:45.199491 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0423 15:46:45.199532 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0423 15:46:45.199597 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0423 15:46:45.223702 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:46:45.228398 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-5xvfm" condition "Approved" to 2026-04-23 15:46:45.228382094 +0000 UTC m=+13.640493032 I0423 15:46:45.239625 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-5xvfm" condition "Ready" to 2026-04-23 15:46:45.239603337 +0000 UTC m=+13.651714275 I0423 15:46:45.263017 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:46:45.262997315 +0000 UTC m=+13.675108283 I0423 15:46:45.285390 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:46:45.285887 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:46:45.285878131 +0000 UTC m=+13.697989059 I0423 15:46:45.299964 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:46:45.300321 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:46:45.300307131 +0000 UTC m=+13.712418069 I0423 15:46:50.199858 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:46:50.19984223 +0000 UTC m=+18.611953188 I0423 15:47:15.937955 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:47:15.938025 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-23 15:47:15.938018265 +0000 UTC m=+44.350129193 I0423 15:47:15.938233 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-23 15:47:15.938220438 +0000 UTC m=+44.350331366 I0423 15:47:15.949225 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-23 15:47:15.949211843 +0000 UTC m=+44.361322781 I0423 15:47:15.974878 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:47:15.974946 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:47:15.974965 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-23 15:47:15.974959513 +0000 UTC m=+44.387070441 I0423 15:47:16.364112 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:47:16.373598 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-7hsgp" condition "Approved" to 2026-04-23 15:47:16.373586308 +0000 UTC m=+44.785697246 I0423 15:47:16.408602 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-7hsgp" condition "Ready" to 2026-04-23 15:47:16.408585415 +0000 UTC m=+44.820696373 I0423 15:47:16.443031 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:47:16.443018801 +0000 UTC m=+44.855129769 I0423 15:47:16.464527 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:47:16.465018 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:47:16.465009998 +0000 UTC m=+44.877120936 I0423 15:47:16.474705 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:47:16.492393 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:52:08.058811 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-38.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:52:08.058863 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-38.nip.io-tls" condition "Issuing" to 2026-04-23 15:52:08.058851539 +0000 UTC m=+336.470962507 I0423 15:52:08.059285 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-38.nip.io-tls" condition "Ready" to 2026-04-23 15:52:08.059259408 +0000 UTC m=+336.471370376 I0423 15:52:08.123504 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-38.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-38.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:52:08.123659 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-38.nip.io-tls" condition "Ready" to 2026-04-23 15:52:08.123643131 +0000 UTC m=+336.535754049 I0423 15:52:08.587011 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-38.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-38.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:52:08.625359 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-38.nip.io-tls-kvknh" condition "Approved" to 2026-04-23 15:52:08.625342647 +0000 UTC m=+337.037453605 I0423 15:52:08.650950 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-38.nip.io-tls-kvknh" condition "Ready" to 2026-04-23 15:52:08.650934297 +0000 UTC m=+337.063045235 I0423 15:52:08.682417 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-38.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:52:08.682398492 +0000 UTC m=+337.094509430 I0423 15:52:08.710361 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-38.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-38.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:53:14.334214 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:53:14.334314 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-23 15:53:14.334302429 +0000 UTC m=+402.746413367 I0423 15:53:14.334608 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-23 15:53:14.334067044 +0000 UTC m=+402.746177982 E0423 15:53:14.354482 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0423 15:53:14.354581 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-23 15:53:14.354569506 +0000 UTC m=+402.766680464 E0423 15:53:14.354616 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0423 15:53:14.360772 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:53:14.360933 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-23 15:53:14.360919208 +0000 UTC m=+402.773030176 E0423 15:53:14.367751 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0423 15:53:14.367847 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0423 15:53:14.367937 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0423 15:53:14.367964 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0423 15:53:14.373294 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:53:14.373529 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-23 15:53:14.37352038 +0000 UTC m=+402.785631308 I0423 15:53:14.386722 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-kchkl" condition "Approved" to 2026-04-23 15:53:14.386712862 +0000 UTC m=+402.798823800 I0423 15:53:14.400293 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-kchkl" condition "Ready" to 2026-04-23 15:53:14.400278572 +0000 UTC m=+402.812389500 I0423 15:53:14.428619 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:53:14.428601982 +0000 UTC m=+402.840712940 I0423 15:53:14.445297 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:53:19.368696 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:53:19.368679869 +0000 UTC m=+407.780790827 I0423 15:54:02.752927 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-23 15:54:02.752909163 +0000 UTC m=+451.165020101 I0423 15:54:02.753310 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.753336 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-23 15:54:02.753332139 +0000 UTC m=+451.165443077 I0423 15:54:02.806603 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.806994 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-23 15:54:02.806984571 +0000 UTC m=+451.219095519 I0423 15:54:02.807841 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-23 15:54:02.807836294 +0000 UTC m=+451.219947222 I0423 15:54:02.824573 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:02.824664 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.824690 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-23 15:54:02.824683421 +0000 UTC m=+451.236794349 I0423 15:54:02.831991 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-23 15:54:02.831973327 +0000 UTC m=+451.244084255 I0423 15:54:02.832285 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.832307 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-23 15:54:02.832304083 +0000 UTC m=+451.244415011 I0423 15:54:02.852288 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:02.852372 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.852396 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-23 15:54:02.852390001 +0000 UTC m=+451.264500929 I0423 15:54:02.862658 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:02.862712 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:02.862731 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-23 15:54:02.862727036 +0000 UTC m=+451.274837964 I0423 15:54:03.159218 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-smjrq" condition "Approved" to 2026-04-23 15:54:03.159204405 +0000 UTC m=+451.571315333 I0423 15:54:03.163456 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-gx825" condition "Approved" to 2026-04-23 15:54:03.163442881 +0000 UTC m=+451.575553809 I0423 15:54:03.187252 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-smjrq" condition "Ready" to 2026-04-23 15:54:03.187246079 +0000 UTC m=+451.599357007 I0423 15:54:03.193233 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-gx825" condition "Ready" to 2026-04-23 15:54:03.193218843 +0000 UTC m=+451.605329781 I0423 15:54:03.239112 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:03.239076479 +0000 UTC m=+451.651187397 I0423 15:54:03.239695 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:03.239680789 +0000 UTC m=+451.651791717 I0423 15:54:03.247807 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-9x2xf" condition "Approved" to 2026-04-23 15:54:03.247796847 +0000 UTC m=+451.659907775 I0423 15:54:03.282629 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:03.283614 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-9x2xf" condition "Ready" to 2026-04-23 15:54:03.283556654 +0000 UTC m=+451.695667602 I0423 15:54:03.288306 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:03.288509 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:03.288504282 +0000 UTC m=+451.700615210 E0423 15:54:03.804024 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"prometheus-tls-j9brp\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" I0423 15:54:03.846916 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" E0423 15:54:03.947144 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"alertmanager-tls-vhlzr\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" I0423 15:54:03.997366 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:03.997347918 +0000 UTC m=+452.409458856 I0423 15:54:04.250009 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:04.250668 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:04.250658873 +0000 UTC m=+452.662769811 I0423 15:54:04.547998 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:12.874382 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" condition "Ready" to 2026-04-23 15:54:12.874364954 +0000 UTC m=+461.286475892 I0423 15:54:12.874825 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:12.874883 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" condition "Issuing" to 2026-04-23 15:54:12.874871741 +0000 UTC m=+461.286982679 I0423 15:54:12.895635 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-md5lf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:12.895742 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" condition "Ready" to 2026-04-23 15:54:12.895729076 +0000 UTC m=+461.307840024 I0423 15:54:13.095766 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-md5lf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:13.127555 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-md5lf-4rhgc" condition "Approved" to 2026-04-23 15:54:13.127537023 +0000 UTC m=+461.539647981 I0423 15:54:13.152435 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-md5lf-4rhgc" condition "Ready" to 2026-04-23 15:54:13.15241858 +0000 UTC m=+461.564529538 I0423 15:54:13.186041 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:13.186021203 +0000 UTC m=+461.598132171 I0423 15:54:13.210986 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-md5lf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:13.211323 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:13.211313736 +0000 UTC m=+461.623424664 I0423 15:54:13.229430 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-md5lf-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-md5lf-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:26.851612 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-23 15:54:26.851580584 +0000 UTC m=+475.263691522 I0423 15:54:26.852150 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:26.852168 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-23 15:54:26.852164793 +0000 UTC m=+475.264275721 I0423 15:54:26.869418 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:26.869505 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:54:26.869523 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-23 15:54:26.869515816 +0000 UTC m=+475.281626754 I0423 15:54:27.216662 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-lqzwn" condition "Approved" to 2026-04-23 15:54:27.216639668 +0000 UTC m=+475.628750606 I0423 15:54:27.243815 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-lqzwn" condition "Ready" to 2026-04-23 15:54:27.24380277 +0000 UTC m=+475.655913698 I0423 15:54:27.288835 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:27.288816504 +0000 UTC m=+475.700927432 I0423 15:54:27.312009 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:27.312347 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:54:27.312337341 +0000 UTC m=+475.724448269 I0423 15:54:27.324388 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:54:27.344103 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:57:52.082408 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-23 15:57:52.082372615 +0000 UTC m=+680.494483543 I0423 15:57:52.082444 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:57:52.082725 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-23 15:57:52.082712179 +0000 UTC m=+680.494823147 I0423 15:57:52.102538 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:57:52.102597 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:57:52.102612 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-23 15:57:52.10260672 +0000 UTC m=+680.514717648 I0423 15:57:52.349773 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-qvdkj" condition "Approved" to 2026-04-23 15:57:52.34975689 +0000 UTC m=+680.761867818 I0423 15:57:52.380251 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-qvdkj" condition "Ready" to 2026-04-23 15:57:52.380240265 +0000 UTC m=+680.792351193 I0423 15:57:52.408700 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:57:52.408691694 +0000 UTC m=+680.820802622 I0423 15:57:52.427937 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:57:52.428189 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:57:52.42818385 +0000 UTC m=+680.840294778 I0423 15:57:52.448432 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:57:52.449040 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:57:52.449032913 +0000 UTC m=+680.861143841 I0423 15:58:37.375312 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-23 15:58:37.375266278 +0000 UTC m=+725.787377216 I0423 15:58:37.375358 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0423 15:58:37.375600 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-23 15:58:37.375577342 +0000 UTC m=+725.787688300 I0423 15:58:37.407737 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:58:37.407910 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-23 15:58:37.407877503 +0000 UTC m=+725.819988451 I0423 15:58:37.508641 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:58:37.549029 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-hsckn" condition "Approved" to 2026-04-23 15:58:37.549008759 +0000 UTC m=+725.961119687 I0423 15:58:37.564038 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-hsckn" condition "Ready" to 2026-04-23 15:58:37.564026485 +0000 UTC m=+725.976137413 I0423 15:58:37.594923 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:58:37.594907639 +0000 UTC m=+726.007018567 I0423 15:58:37.621622 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0423 15:58:37.621841 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-23 15:58:37.621835724 +0000 UTC m=+726.033946652 I0423 15:58:37.638074 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"