I0427 16:34:21.635346 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0427 16:34:21.635640 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0427 16:34:21.635894 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0427 16:34:21.642711 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0427 16:34:21.643199 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0427 16:34:21.643301 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0427 16:34:21.643317 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0427 16:34:21.648708 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0427 16:34:21.666668 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0427 16:34:21.670070 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0427 16:34:21.670132 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0427 16:34:21.670161 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0427 16:34:21.670248 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0427 16:34:21.673627 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0427 16:34:21.677732 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0427 16:34:21.681348 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0427 16:34:21.681436 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0427 16:34:21.684029 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0427 16:34:21.686447 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0427 16:34:21.688814 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0427 16:34:21.691240 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0427 16:34:21.693755 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0427 16:34:21.696345 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0427 16:34:21.697260 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0427 16:34:21.702068 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0427 16:34:21.704694 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0427 16:34:21.706930 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0427 16:34:21.707096 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0427 16:34:21.709479 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0427 16:34:21.712273 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0427 16:34:21.714762 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0427 16:34:21.716510 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0427 16:34:21.719725 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0427 16:34:21.720250 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.720980 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.726665 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.741844 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.754580 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.775973 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.806377 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.816526 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.819465 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:21.841254 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0427 16:34:34.414641 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-27 16:34:34.414608974 +0000 UTC m=+12.811325715 I0427 16:34:35.129727 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-27 16:34:35.129712412 +0000 UTC m=+13.526429183 I0427 16:34:35.130123 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:34:35.131030 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-27 16:34:35.131008513 +0000 UTC m=+13.527725254 E0427 16:34:35.146185 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0427 16:34:35.146298 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-27 16:34:35.146288649 +0000 UTC m=+13.543005410 E0427 16:34:35.147057 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0427 16:34:35.148318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:34:35.148396 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:34:35.148423 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-27 16:34:35.14841604 +0000 UTC m=+13.545132801 E0427 16:34:35.160123 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0427 16:34:35.160703 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0427 16:34:35.160744 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0427 16:34:35.161033 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0427 16:34:35.190638 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-mglcw" condition "Approved" to 2026-04-27 16:34:35.190626983 +0000 UTC m=+13.587343724 I0427 16:34:35.207043 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-mglcw" condition "Ready" to 2026-04-27 16:34:35.207031857 +0000 UTC m=+13.603748608 I0427 16:34:35.231702 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:34:35.231693599 +0000 UTC m=+13.628410320 I0427 16:34:35.249203 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:34:35.249543 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:34:35.249536927 +0000 UTC m=+13.646253668 I0427 16:34:35.265196 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:34:35.265394 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:34:35.265387968 +0000 UTC m=+13.662104699 I0427 16:34:40.161332 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:34:40.16131903 +0000 UTC m=+18.558035791 E0427 16:34:47.167005 1 event.go:346] "Server rejected event (will not retry!)" err="etcdserver: request timed out" event="&Event{ObjectMeta:{atmosphere.18aa43eb24967af5 default 0 0001-01-01 00:00:00 +0000 UTC map[] map[] [] [] []},InvolvedObject:ObjectReference{Kind:ClusterIssuer,Namespace:,Name:atmosphere,UID:9cb5af29-cfb8-4274-b66d-d9693cd1411c,APIVersion:cert-manager.io/v1,ResourceVersion:1247,FieldPath:,},Reason:KeyPairVerified,Message:Signing CA verified,Source:EventSource{Component:cert-manager-clusterissuers,Host:,},FirstTimestamp:2026-04-27 16:34:40.161299189 +0000 UTC m=+18.558015950,LastTimestamp:2026-04-27 16:34:40.161299189 +0000 UTC m=+18.558015950,Count:1,Type:Normal,EventTime:0001-01-01 00:00:00 +0000 UTC,Series:nil,Action:,Related:nil,ReportingController:cert-manager-clusterissuers,ReportingInstance:,}" E0427 16:34:47.172820 1 controller.go:167] "re-queuing item due to error processing" err="etcdserver: request timed out" logger="cert-manager.clusterissuers" key="atmosphere" I0427 16:35:33.624153 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-27 16:35:33.624124189 +0000 UTC m=+72.020840930 I0427 16:35:33.624397 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:35:33.624527 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-27 16:35:33.624515088 +0000 UTC m=+72.021231899 I0427 16:35:33.635400 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-27 16:35:33.635386384 +0000 UTC m=+72.032103125 I0427 16:35:33.640428 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:35:33.640489 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:35:33.640512 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-27 16:35:33.64050787 +0000 UTC m=+72.037224611 I0427 16:35:33.770899 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4z4tf" condition "Approved" to 2026-04-27 16:35:33.770887958 +0000 UTC m=+72.167604699 I0427 16:35:33.804910 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-4z4tf" condition "Ready" to 2026-04-27 16:35:33.804898647 +0000 UTC m=+72.201615388 I0427 16:35:33.834384 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:35:33.834364933 +0000 UTC m=+72.231081704 I0427 16:35:33.853628 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:35:33.854079 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:35:33.854071318 +0000 UTC m=+72.250788059 I0427 16:35:33.871794 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:39:48.301092 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-153.nip.io-tls" condition "Ready" to 2026-04-27 16:39:48.301041484 +0000 UTC m=+326.697758245 I0427 16:39:48.301854 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-153.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:39:48.301893 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-153.nip.io-tls" condition "Issuing" to 2026-04-27 16:39:48.30188913 +0000 UTC m=+326.698605871 I0427 16:39:48.325511 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-153.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-153.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:39:48.325609 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-153.nip.io-tls" condition "Ready" to 2026-04-27 16:39:48.325598665 +0000 UTC m=+326.722315436 I0427 16:39:48.684781 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-153.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-153.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:39:48.706870 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-153.nip.io-tls-8rg5d" condition "Approved" to 2026-04-27 16:39:48.706855713 +0000 UTC m=+327.103572474 I0427 16:39:48.743412 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-153.nip.io-tls-8rg5d" condition "Ready" to 2026-04-27 16:39:48.743399953 +0000 UTC m=+327.140116694 I0427 16:39:48.776206 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-153.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:39:48.776194971 +0000 UTC m=+327.172911722 I0427 16:39:48.797758 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-153.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-153.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:39:48.844583 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-153.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-153.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:40:52.057884 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-27 16:40:52.057833595 +0000 UTC m=+390.454550366 I0427 16:40:52.057902 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:40:52.058161 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-27 16:40:52.058151621 +0000 UTC m=+390.454868392 I0427 16:40:52.068740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:40:52.068822 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-27 16:40:52.068815041 +0000 UTC m=+390.465531792 E0427 16:40:52.071172 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0427 16:40:52.071268 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-27 16:40:52.071260897 +0000 UTC m=+390.467977638 E0427 16:40:52.071361 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0427 16:40:52.082491 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0427 16:40:52.084439 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0427 16:40:52.084481 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0427 16:40:52.084535 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0427 16:40:52.085038 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:40:52.101006 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-n9z4d" condition "Approved" to 2026-04-27 16:40:52.100973392 +0000 UTC m=+390.497690163 I0427 16:40:52.112050 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-n9z4d" condition "Ready" to 2026-04-27 16:40:52.11204135 +0000 UTC m=+390.508758081 I0427 16:40:52.130384 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:40:52.130368353 +0000 UTC m=+390.527085114 I0427 16:40:52.148582 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:40:57.083497 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:40:57.083483983 +0000 UTC m=+395.480200754 I0427 16:41:36.361051 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-27 16:41:36.361006539 +0000 UTC m=+434.757723270 I0427 16:41:36.361583 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.361670 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-27 16:41:36.361660241 +0000 UTC m=+434.758377012 I0427 16:41:36.387370 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-27 16:41:36.387361996 +0000 UTC m=+434.784078727 I0427 16:41:36.387575 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.388116 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-27 16:41:36.38810325 +0000 UTC m=+434.784820001 I0427 16:41:36.399804 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-27 16:41:36.399793086 +0000 UTC m=+434.796509817 I0427 16:41:36.400123 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.400151 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-27 16:41:36.400136002 +0000 UTC m=+434.796852723 I0427 16:41:36.402245 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.402326 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.402358 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-27 16:41:36.402352753 +0000 UTC m=+434.799069484 I0427 16:41:36.421597 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.421678 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.421708 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-27 16:41:36.421701781 +0000 UTC m=+434.818418502 I0427 16:41:36.423759 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.423792 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:36.423804 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-27 16:41:36.423801399 +0000 UTC m=+434.820518130 I0427 16:41:36.786694 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-kb2t9" condition "Approved" to 2026-04-27 16:41:36.786686654 +0000 UTC m=+435.183403385 I0427 16:41:36.809752 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-kb2t9" condition "Ready" to 2026-04-27 16:41:36.809721149 +0000 UTC m=+435.206437880 I0427 16:41:36.846296 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:36.846280944 +0000 UTC m=+435.242997695 I0427 16:41:36.866304 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.866503 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:36.866498497 +0000 UTC m=+435.263215228 E0427 16:41:36.869318 1 controller.go:167] "re-queuing item due to error processing" err="secrets \"grafana-tls-4xpvf\" already exists" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" I0427 16:41:36.897427 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.909772 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:36.922900 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-qmxxn" condition "Approved" to 2026-04-27 16:41:36.922891179 +0000 UTC m=+435.319607910 I0427 16:41:36.952431 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-qmxxn" condition "Ready" to 2026-04-27 16:41:36.952421895 +0000 UTC m=+435.349138626 I0427 16:41:36.995123 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:36.995112914 +0000 UTC m=+435.391829645 I0427 16:41:37.019392 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:37.250609 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-s7th4" condition "Approved" to 2026-04-27 16:41:37.250589402 +0000 UTC m=+435.647306143 I0427 16:41:37.459579 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-s7th4" condition "Ready" to 2026-04-27 16:41:37.459567822 +0000 UTC m=+435.856284553 I0427 16:41:37.805130 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:37.805117654 +0000 UTC m=+436.201834375 I0427 16:41:37.896065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:37.896440 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:37.896430081 +0000 UTC m=+436.293146842 I0427 16:41:38.147697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:44.636068 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" condition "Ready" to 2026-04-27 16:41:44.636025039 +0000 UTC m=+443.032741820 I0427 16:41:44.636108 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:44.636628 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" condition "Issuing" to 2026-04-27 16:41:44.63661345 +0000 UTC m=+443.033330231 I0427 16:41:44.650581 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:44.650667 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" condition "Ready" to 2026-04-27 16:41:44.650660249 +0000 UTC m=+443.047376990 I0427 16:41:44.765201 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:44.793187 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-jdxnn-zn2xf" condition "Approved" to 2026-04-27 16:41:44.793173866 +0000 UTC m=+443.189890597 I0427 16:41:44.813202 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-jdxnn-zn2xf" condition "Ready" to 2026-04-27 16:41:44.813194455 +0000 UTC m=+443.209911176 I0427 16:41:44.841211 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:44.841199391 +0000 UTC m=+443.237916132 I0427 16:41:44.858119 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-jdxnn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:58.110221 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-27 16:41:58.110193079 +0000 UTC m=+456.506909810 I0427 16:41:58.110712 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:58.110762 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-27 16:41:58.110758879 +0000 UTC m=+456.507475610 I0427 16:41:58.129065 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:41:58.129197 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:41:58.129235 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-27 16:41:58.129225868 +0000 UTC m=+456.525942629 I0427 16:41:58.545145 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-d9jrt" condition "Approved" to 2026-04-27 16:41:58.545132347 +0000 UTC m=+456.941849088 I0427 16:41:58.561411 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-d9jrt" condition "Ready" to 2026-04-27 16:41:58.561400066 +0000 UTC m=+456.958116797 I0427 16:41:58.589417 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:41:58.58940607 +0000 UTC m=+456.986122801 I0427 16:41:58.608782 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:45:11.619812 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:45:11.619880 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-27 16:45:11.619873234 +0000 UTC m=+650.016589975 I0427 16:45:11.619855 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-27 16:45:11.619834483 +0000 UTC m=+650.016551244 I0427 16:45:11.658318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:45:11.658506 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0427 16:45:11.658582 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-27 16:45:11.65857317 +0000 UTC m=+650.055289941 I0427 16:45:12.023843 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-tss5x" condition "Approved" to 2026-04-27 16:45:12.023831904 +0000 UTC m=+650.420548635 I0427 16:45:12.062301 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-tss5x" condition "Ready" to 2026-04-27 16:45:12.062285556 +0000 UTC m=+650.459002317 I0427 16:45:12.101563 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:45:12.101551511 +0000 UTC m=+650.498268252 I0427 16:45:12.133762 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:45:12.134451 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:45:12.134446254 +0000 UTC m=+650.531162985 I0427 16:45:12.161999 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0427 16:45:12.162455 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-27 16:45:12.16244574 +0000 UTC m=+650.559162481 I0427 16:45:12.166914 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again"