[
{
    "branch": "main",
    "index": "0",
    "phase": "pre",
    "playbook": "github.com/vexxhost/zuul-config/playbooks/base/pre.yaml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:30:55.930214Z",
                    "start": "2026-07-29T18:30:53.468062Z"
                },
                "id": "0242ac17-0010-5787-ea30-000000000002",
                "name": "localhost"
            },
            "tasks": [
                {
                    "hosts": {
                        "localhost": {
                            "action": "gather_facts",
                            "ansible_facts": {
                                "ansible_apparmor": {
                                    "status": "disabled"
                                },
                                "ansible_architecture": "x86_64",
                                "ansible_bios_date": "NA",
                                "ansible_bios_vendor": "NA",
                                "ansible_bios_version": "NA",
                                "ansible_board_asset_tag": "NA",
                                "ansible_board_name": "NA",
                                "ansible_board_serial": "NA",
                                "ansible_board_vendor": "NA",
                                "ansible_board_version": "NA",
                                "ansible_chassis_asset_tag": "NA",
                                "ansible_chassis_serial": "NA",
                                "ansible_chassis_vendor": "NA",
                                "ansible_chassis_version": "NA",
                                "ansible_cmdline": {
                                    "BOOT_IMAGE": "/boot/vmlinuz-5.15.0-130-generic",
                                    "console": "ttyS0",
                                    "ro": true,
                                    "root": "UUID=5a569d86-b935-46dd-ae79-7a72a25b6a4c"
                                },
                                "ansible_date_time": {
                                    "date": "2026-07-29",
                                    "day": "29",
                                    "epoch": "1785349854",
                                    "epoch_int": "1785349854",
                                    "hour": "18",
                                    "iso8601": "2026-07-29T18:30:54Z",
                                    "iso8601_basic": "20260729T183054066661",
                                    "iso8601_basic_short": "20260729T183054",
                                    "iso8601_micro": "2026-07-29T18:30:54.066661Z",
                                    "minute": "30",
                                    "month": "07",
                                    "second": "54",
                                    "time": "18:30:54",
                                    "tz": "UTC",
                                    "tz_dst": "UTC",
                                    "tz_offset": "+0000",
                                    "weekday": "Wednesday",
                                    "weekday_number": "3",
                                    "weeknumber": "30",
                                    "year": "2026"
                                },
                                "ansible_devices": {},
                                "ansible_distribution": "Debian",
                                "ansible_distribution_major_version": "12",
                                "ansible_distribution_release": "bookworm",
                                "ansible_distribution_version": "12",
                                "ansible_dns": {
                                    "nameservers": [
                                        "127.0.0.11"
                                    ],
                                    "options": {
                                        "edns0": true,
                                        "ndots": "0",
                                        "trust-ad": true
                                    },
                                    "search": [
                                        "openstacklocal"
                                    ]
                                },
                                "ansible_domain": "",
                                "ansible_effective_group_id": 0,
                                "ansible_effective_user_id": 0,
                                "ansible_env": {
                                    "ANSIBLE_CONFIG": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/ansible/pre_playbook_0/ansible.cfg",
                                    "DEBIAN_FRONTEND": "noninteractive",
                                    "GPG_KEY": "A035C8C19219BA821ECEA86B64E628F8D684696D",
                                    "HOME": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work",
                                    "HOSTNAME": "2d72f0692154",
                                    "KUBECONFIG": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/kube/config",
                                    "LANG": "C.UTF-8",
                                    "PATH": "/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
                                    "PWD": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_0/github.com/vexxhost/zuul-config/playbooks/base",
                                    "PYTHONPATH": "/var/lib/zuul/ansible/9",
                                    "PYTHON_SHA256": "8d3ed8ec5c88c1c95f5e558612a725450d2452813ddad5e58fdb1a53b1209b78",
                                    "PYTHON_VERSION": "3.11.14",
                                    "SSH_AGENT_PID": "2107972",
                                    "SSH_AUTH_SOCK": "/tmp/ssh-JXx5AZD5946d/agent.2107971",
                                    "TMP": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/tmp",
                                    "ZUUL_ANSIBLE_SPLIT_STREAMS": "False",
                                    "ZUUL_JOBDIR": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e",
                                    "ZUUL_JOB_FAILURE_OUTPUT": "[]",
                                    "ZUUL_JOB_LOG_CONFIG": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/ansible/logging.json",
                                    "ZUUL_OUTPUT_MAX_BYTES": "1073741824"
                                },
                                "ansible_fibre_channel_wwn": [],
                                "ansible_fips": false,
                                "ansible_form_factor": "NA",
                                "ansible_fqdn": "2d72f0692154",
                                "ansible_hostname": "2d72f0692154",
                                "ansible_hostnqn": "",
                                "ansible_is_chroot": false,
                                "ansible_iscsi_iqn": "",
                                "ansible_kernel": "5.15.0-130-generic",
                                "ansible_kernel_version": "#140-Ubuntu SMP Wed Dec 18 17:59:53 UTC 2024",
                                "ansible_loadavg": {
                                    "15m": 3.51171875,
                                    "1m": 3.57763671875,
                                    "5m": 3.60888671875
                                },
                                "ansible_local": {},
                                "ansible_lsb": {},
                                "ansible_lvm": "N/A",
                                "ansible_machine": "x86_64",
                                "ansible_memfree_mb": 5705,
                                "ansible_memory_mb": {
                                    "nocache": {
                                        "free": 14247,
                                        "used": 17843
                                    },
                                    "real": {
                                        "free": 5705,
                                        "total": 32090,
                                        "used": 26385
                                    },
                                    "swap": {
                                        "cached": 0,
                                        "free": 0,
                                        "total": 0,
                                        "used": 0
                                    }
                                },
                                "ansible_memtotal_mb": 32090,
                                "ansible_mounts": [
                                    {
                                        "block_available": 8631087,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970493,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/etc/resolv.conf",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352932352,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631085,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970495,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/etc/hosts",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352924160,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631082,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970498,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work",
                                        "options": "rw,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352911872,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631079,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970501,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/ansible/9",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352899584,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631076,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970504,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/ansible",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352887296,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631075,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970505,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/kube",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352883200,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631062,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970518,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352829952,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631058,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970522,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352813568,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631055,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970525,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/ansible/pre_playbook_0",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352801280,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631053,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970527,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/etc/zuul/site-variables.yaml",
                                        "options": "ro,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352793088,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 76908212,
                                        "block_size": 4096,
                                        "block_total": 263940717,
                                        "block_used": 187032505,
                                        "device": "/dev/vdb",
                                        "fstype": "ext4",
                                        "inode_available": 35872291,
                                        "inode_total": 67108864,
                                        "inode_used": 31236573,
                                        "mount": "/srv/static/logs",
                                        "options": "rw,nosuid,nodev,relatime,discard",
                                        "size_available": 315016036352,
                                        "size_total": 1081101176832,
                                        "uuid": "N/A"
                                    },
                                    {
                                        "block_available": 8631048,
                                        "block_size": 4096,
                                        "block_total": 40601580,
                                        "block_used": 31970532,
                                        "device": "/dev/vda1",
                                        "fstype": "ext4",
                                        "inode_available": 16684657,
                                        "inode_total": 20643840,
                                        "inode_used": 3959183,
                                        "mount": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/.ansible",
                                        "options": "rw,nosuid,nodev,relatime,discard,errors=remount-ro,bind",
                                        "size_available": 35352772608,
                                        "size_total": 166304071680,
                                        "uuid": "N/A"
                                    }
                                ],
                                "ansible_nodename": "2d72f0692154",
                                "ansible_os_family": "Debian",
                                "ansible_pkg_mgr": "apt",
                                "ansible_proc_cmdline": {
                                    "BOOT_IMAGE": "/boot/vmlinuz-5.15.0-130-generic",
                                    "console": [
                                        "tty1",
                                        "ttyS0"
                                    ],
                                    "ro": true,
                                    "root": "UUID=5a569d86-b935-46dd-ae79-7a72a25b6a4c"
                                },
                                "ansible_processor": [
                                    "0",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "1",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "2",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "3",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "4",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "5",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "6",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "7",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "8",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "9",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "10",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "11",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "12",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "13",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "14",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor",
                                    "15",
                                    "AuthenticAMD",
                                    "AMD EPYC-Rome Processor"
                                ],
                                "ansible_processor_cores": 1,
                                "ansible_processor_count": 16,
                                "ansible_processor_nproc": 16,
                                "ansible_processor_threads_per_core": 1,
                                "ansible_processor_vcpus": 16,
                                "ansible_product_name": "NA",
                                "ansible_product_serial": "NA",
                                "ansible_product_uuid": "NA",
                                "ansible_product_version": "NA",
                                "ansible_python": {
                                    "executable": "/usr/local/lib/zuul/ansible/9/bin/python",
                                    "has_sslcontext": true,
                                    "type": "cpython",
                                    "version": {
                                        "major": 3,
                                        "micro": 14,
                                        "minor": 11,
                                        "releaselevel": "final",
                                        "serial": 0
                                    },
                                    "version_info": [
                                        3,
                                        11,
                                        14,
                                        "final",
                                        0
                                    ]
                                },
                                "ansible_python_version": "3.11.14",
                                "ansible_real_group_id": 0,
                                "ansible_real_user_id": 0,
                                "ansible_selinux": {
                                    "status": "disabled"
                                },
                                "ansible_selinux_python_present": true,
                                "ansible_service_mgr": "bwrap",
                                "ansible_swapfree_mb": 0,
                                "ansible_swaptotal_mb": 0,
                                "ansible_system": "Linux",
                                "ansible_system_capabilities": "N/A",
                                "ansible_system_capabilities_enforced": "N/A",
                                "ansible_system_vendor": "NA",
                                "ansible_uptime_seconds": 49013583,
                                "ansible_user_dir": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work",
                                "ansible_user_gecos": "root",
                                "ansible_user_gid": 0,
                                "ansible_user_id": "root",
                                "ansible_user_shell": "/bin/bash",
                                "ansible_user_uid": 0,
                                "ansible_userspace_architecture": "x86_64",
                                "ansible_userspace_bits": "64",
                                "ansible_virtualization_role": "host",
                                "ansible_virtualization_tech_guest": [],
                                "ansible_virtualization_tech_host": [
                                    "kvm"
                                ],
                                "ansible_virtualization_type": "kvm",
                                "gather_subset": [
                                    "all"
                                ],
                                "module_setup": true
                            },
                            "changed": false,
                            "deprecations": [],
                            "warnings": []
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:54.392864Z",
                            "start": "2026-07-29T18:30:53.479174Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000002a",
                        "name": "Gathering Facts"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "include_role",
                            "changed": false,
                            "include_args": {
                                "name": "set-zuul-log-path-fact"
                            }
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000006",
                        "name": "emit-job-header",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/emit-job-header"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:54.420826Z",
                            "start": "2026-07-29T18:30:54.398636Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000008",
                        "name": "Setup log path fact"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "set_fact",
                            "ansible_facts": {
                                "zuul_log_path": "df9/oss/df925605a75e40088f795833ad47c03e"
                            },
                            "changed": false
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000054",
                        "name": "set-zuul-log-path-fact",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/set-zuul-log-path-fact"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:54.467128Z",
                            "start": "2026-07-29T18:30:54.434908Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000056",
                        "name": "Set log path for a build"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "debug",
                            "changed": false,
                            "msg": "# Job Information\nAnsible Version: 2.16.18\nJob: atmosphere-common-molecule-secretgen-controller\nPipeline: check\nExecutor: 2d72f0692154\nTriggered by: https://github.com/vexxhost/atmosphere.common/pull/105\nEvent ID: 3d762ff0-8b7b-11f1-818d-d90a9db3412f\n"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000006",
                        "name": "emit-job-header",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/emit-job-header"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:54.523720Z",
                            "start": "2026-07-29T18:30:54.479891Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000009",
                        "name": "Print job information"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "debug",
                            "changed": false,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_item",
                                    "changed": false,
                                    "failed": false,
                                    "msg": "# Node Information\nInventory Hostname: controller\nHostname: np0000187452\nUsername: zuul\nDistro: Ubuntu 24.04\nProvider: yul1\nRegion: ca-ymq-1\nLabel: ubuntu-noble\nProduct Name: OpenStack Nova\nInterface IP: 199.19.213.139\n",
                                    "zj_item": "controller"
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000006",
                        "name": "emit-job-header",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/emit-job-header"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:54.640370Z",
                            "start": "2026-07-29T18:30:54.528564Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000000a",
                        "name": "Print node information"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": 493,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-00000000000d",
                        "name": "log-inventory",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/log-inventory"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:55.052748Z",
                            "start": "2026-07-29T18:30:54.649098Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000000f",
                        "name": "Ensure Zuul Ansible directory exists"
                    }
                },
                {
                    "hosts": {
                        "localhost": {
                            "action": "copy",
                            "changed": true,
                            "checksum": "343f67e66be64538cd48c172cb471469d311a570",
                            "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info/inventory.yaml",
                            "diff": [],
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_original_basename": "inventory.yaml",
                                    "attributes": null,
                                    "backup": false,
                                    "checksum": "343f67e66be64538cd48c172cb471469d311a570",
                                    "content": null,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/zuul-info",
                                    "directory_mode": null,
                                    "follow": false,
                                    "force": true,
                                    "group": null,
                                    "local_follow": null,
                                    "mode": 420,
                                    "owner": null,
                                    "remote_src": null,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/.ansible/tmp/ansible-tmp-1785349855.091195-84-182245676715560/source",
                                    "unsafe_writes": false,
                                    "validate": null
                                }
                            },
                            "md5sum": "b8249fd6b3e358de671df5157d471023",
                            "mode": "0644",
                            "owner": "root",
                            "size": 351328,
                            "src": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/.ansible/tmp/ansible-tmp-1785349855.091195-84-182245676715560/source",
                            "state": "file",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-00000000000d",
                        "name": "log-inventory",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/log-inventory"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:55.930214Z",
                            "start": "2026-07-29T18:30:55.059923Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000010",
                        "name": "Copy ansible inventory to logs dir"
                    }
                }
            ]
        },
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:31:03.360724Z",
                    "start": "2026-07-29T18:30:55.940365Z"
                },
                "id": "0242ac17-0010-5787-ea30-000000000011",
                "name": "all"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "stat",
                            "changed": false,
                            "failed_when_result": false,
                            "invocation": {
                                "module_args": {
                                    "checksum_algorithm": "sha1",
                                    "follow": false,
                                    "get_attributes": true,
                                    "get_checksum": true,
                                    "get_mime": true,
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa"
                                }
                            },
                            "stat": {
                                "exists": false
                            }
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:56.186457Z",
                            "start": "2026-07-29T18:30:55.948656Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000018",
                        "name": "Check to see if ssh key was already created for this build"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "include_tasks",
                            "changed": false,
                            "include": "create-key-and-replace.yaml",
                            "include_args": {}
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:56.228677Z",
                            "start": "2026-07-29T18:30:56.193148Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000019",
                        "name": "Create a new key in workspace based on build UUID"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "command",
                            "changed": true,
                            "cmd": [
                                "ssh-keygen",
                                "-t",
                                "rsa",
                                "-N",
                                "",
                                "-C",
                                "zuul-build-sshkey",
                                "-f",
                                "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa",
                                "-b",
                                "3072"
                            ],
                            "delta": "0:00:00.745511",
                            "end": "2026-07-29 18:30:57.356749",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "ssh-keygen -t rsa -N '' -C 'zuul-build-sshkey' -f /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa -b 3072",
                                    "_uses_shell": false,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": null,
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5787-ea30-00000000009c-0-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:30:56.611238",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "Generating public/private rsa key pair.\nYour identification has been saved in /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa\nYour public key has been saved in /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa.pub\nThe key fingerprint is:\nSHA256:DEnAWIcXthC5i6EUK1TRhF6FBp2xgvwoIgBlJgKZcLQ zuul-build-sshkey\nThe key's randomart image is:\n+---[RSA 3072]----+\n|O=BB%BXo         |\n|*Boo+%oo         |\n|ooE.o++          |\n|oo+.o  o         |\n|*o + .  S        |\n|= . .            |\n|                 |\n|                 |\n|                 |\n+----[SHA256]-----+",
                            "stdout_lines": [
                                "Generating public/private rsa key pair.",
                                "Your identification has been saved in /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa",
                                "Your public key has been saved in /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa.pub",
                                "The key fingerprint is:",
                                "SHA256:DEnAWIcXthC5i6EUK1TRhF6FBp2xgvwoIgBlJgKZcLQ zuul-build-sshkey",
                                "The key's randomart image is:",
                                "+---[RSA 3072]----+",
                                "|O=BB%BXo         |",
                                "|*Boo+%oo         |",
                                "|ooE.o++          |",
                                "|oo+.o  o         |",
                                "|*o + .  S        |",
                                "|= . .            |",
                                "|                 |",
                                "|                 |",
                                "|                 |",
                                "+----[SHA256]-----+"
                            ],
                            "zuul_log_id": "0242ac17-0010-5787-ea30-00000000009c-0-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:57.404123Z",
                            "start": "2026-07-29T18:30:56.250745Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000009c",
                        "name": "Create Temp SSH key"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "include_tasks",
                            "changed": false,
                            "include": "remote-linux.yaml",
                            "include_args": {}
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:57.445005Z",
                            "start": "2026-07-29T18:30:57.413083Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000009d",
                        "name": "Remote setup ssh keys (linux)"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "lineinfile",
                            "changed": false,
                            "false_condition": "zuul_build_sshkey_cleanup",
                            "skip_reason": "Conditional result was False",
                            "skipped": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:57.488693Z",
                            "start": "2026-07-29T18:30:57.464284Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000bc",
                        "name": "Remove previously added zuul-build-sshkey"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "authorized_key",
                            "changed": true,
                            "comment": null,
                            "exclusive": false,
                            "follow": false,
                            "invocation": {
                                "module_args": {
                                    "changed": true,
                                    "comment": null,
                                    "exclusive": false,
                                    "follow": false,
                                    "key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCmDHOdGrQeoRqhLHqTWhV3QHEYCvX9JXswHgsgu21Iv6EhFwZDzTwhIpA1Icc0Qb8U4/j3fg7R/Knr/oAq8CJxVK2gCJ0e/ucYK7kbnyNNdKhdL5nS8LEhsUaDqFC1vZC3v2BRcNo7ePVPygFCsxy0Zf/H6JI3BR47Z6C1n5nliH4cVvxvgJyzLJUCr6NtaAOCD+buWMRnuro5MU4a+Rxo2EQ3DK+3h7yhv+gKZRlwY2Mkbrhq30aVw8q9Lb1YhNxrgEIOqKTF0oInC/bpXavTQ7awjO47N2tTzJe3/nfMf3t+uA8lu+aAqZ6OzCbUtCosAedWur1vcLzyKpS+67IiMgIf49wAB2gM5CcdrmKjLJEY5vXBzMiRKgIIi0TiQzY0cCbBwuOOrhJOnlaAx8jS23wO8rZI3EdK2eBWxdrTs5gw3ZYncQwMMhHsX3UCe0QTIs1itz2I4B9WwdqsqYNh8tAB3FwzQcIklVzr/hcBDP+KWjfTPm8xB4jDYcQYiJc= zuul-build-sshkey",
                                    "key_options": null,
                                    "keyfile": "/home/zuul/.ssh/authorized_keys",
                                    "manage_dir": true,
                                    "path": null,
                                    "state": "present",
                                    "user": "zuul",
                                    "validate_certs": true
                                }
                            },
                            "key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCmDHOdGrQeoRqhLHqTWhV3QHEYCvX9JXswHgsgu21Iv6EhFwZDzTwhIpA1Icc0Qb8U4/j3fg7R/Knr/oAq8CJxVK2gCJ0e/ucYK7kbnyNNdKhdL5nS8LEhsUaDqFC1vZC3v2BRcNo7ePVPygFCsxy0Zf/H6JI3BR47Z6C1n5nliH4cVvxvgJyzLJUCr6NtaAOCD+buWMRnuro5MU4a+Rxo2EQ3DK+3h7yhv+gKZRlwY2Mkbrhq30aVw8q9Lb1YhNxrgEIOqKTF0oInC/bpXavTQ7awjO47N2tTzJe3/nfMf3t+uA8lu+aAqZ6OzCbUtCosAedWur1vcLzyKpS+67IiMgIf49wAB2gM5CcdrmKjLJEY5vXBzMiRKgIIi0TiQzY0cCbBwuOOrhJOnlaAx8jS23wO8rZI3EdK2eBWxdrTs5gw3ZYncQwMMhHsX3UCe0QTIs1itz2I4B9WwdqsqYNh8tAB3FwzQcIklVzr/hcBDP+KWjfTPm8xB4jDYcQYiJc= zuul-build-sshkey",
                            "key_options": null,
                            "keyfile": "/home/zuul/.ssh/authorized_keys",
                            "manage_dir": true,
                            "path": null,
                            "state": "present",
                            "user": "zuul",
                            "validate_certs": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:58.001492Z",
                            "start": "2026-07-29T18:30:57.498198Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000bd",
                        "name": "Enable access via build key on all nodes"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": false,
                            "diff": {
                                "after": {
                                    "path": "/home/zuul/.ssh"
                                },
                                "before": {
                                    "path": "/home/zuul/.ssh"
                                }
                            },
                            "gid": 1000,
                            "group": "zuul",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": 448,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/home/zuul/.ssh",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0700",
                            "owner": "zuul",
                            "path": "/home/zuul/.ssh",
                            "size": 4096,
                            "state": "directory",
                            "uid": 1000
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:58.232666Z",
                            "start": "2026-07-29T18:30:58.007627Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000be",
                        "name": "Make sure user has a .ssh"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "copy",
                            "changed": true,
                            "checksum": "0c383d7e81c6bb950023ee554f2889a3d85dcc01",
                            "dest": "/home/zuul/.ssh/id_rsa",
                            "diff": [],
                            "gid": 1000,
                            "group": "zuul",
                            "invocation": {
                                "module_args": {
                                    "_original_basename": "df925605a75e40088f795833ad47c03e_id_rsa",
                                    "attributes": null,
                                    "backup": false,
                                    "checksum": "0c383d7e81c6bb950023ee554f2889a3d85dcc01",
                                    "content": null,
                                    "dest": "/home/zuul/.ssh/id_rsa",
                                    "directory_mode": null,
                                    "follow": false,
                                    "force": false,
                                    "group": null,
                                    "local_follow": null,
                                    "mode": 384,
                                    "owner": null,
                                    "remote_src": null,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349858.2864475-190-229658670874206/source",
                                    "unsafe_writes": false,
                                    "validate": null
                                }
                            },
                            "md5sum": "cbd3f69baa05ee2e7ee09dd80dcc8f77",
                            "mode": "0600",
                            "owner": "zuul",
                            "size": 2602,
                            "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349858.2864475-190-229658670874206/source",
                            "state": "file",
                            "uid": 1000
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:58.799600Z",
                            "start": "2026-07-29T18:30:58.238679Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000bf",
                        "name": "Install build private key as SSH key on all nodes"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "copy",
                            "changed": true,
                            "checksum": "f9a9b2b8dc1f74b53db11af97489067d4225b640",
                            "dest": "/home/zuul/.ssh/id_rsa.pub",
                            "diff": [],
                            "gid": 1000,
                            "group": "zuul",
                            "invocation": {
                                "module_args": {
                                    "_original_basename": "df925605a75e40088f795833ad47c03e_id_rsa.pub",
                                    "attributes": null,
                                    "backup": false,
                                    "checksum": "f9a9b2b8dc1f74b53db11af97489067d4225b640",
                                    "content": null,
                                    "dest": "/home/zuul/.ssh/id_rsa.pub",
                                    "directory_mode": null,
                                    "follow": false,
                                    "force": false,
                                    "group": null,
                                    "local_follow": null,
                                    "mode": 420,
                                    "owner": null,
                                    "remote_src": null,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349858.8518217-200-121033156942045/source",
                                    "unsafe_writes": false,
                                    "validate": null
                                }
                            },
                            "md5sum": "5689f942f3ac328dfa032842ebef1622",
                            "mode": "0644",
                            "owner": "zuul",
                            "size": 571,
                            "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349858.8518217-200-121033156942045/source",
                            "state": "file",
                            "uid": 1000
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:59.359230Z",
                            "start": "2026-07-29T18:30:58.806462Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000c0",
                        "name": "Install build public key as SSH key on all nodes"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "include_tasks",
                            "changed": false,
                            "false_condition": "ansible_os_family == \"Windows\"",
                            "skip_reason": "Conditional result was False",
                            "skipped": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:59.392747Z",
                            "start": "2026-07-29T18:30:59.366124Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000009e",
                        "name": "Remote setup ssh keys (windows)"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "sshagent_remove_keys",
                            "changed": true,
                            "invocation": {
                                "module_args": {
                                    "remove": "^(?!\\(stdin\\)).*"
                                }
                            },
                            "removed": [
                                "/etc/zuul/id_rsa"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-0000000000a3",
                        "name": "remove-zuul-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/remove-zuul-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:30:59.776304Z",
                            "start": "2026-07-29T18:30:59.404295Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000a5",
                        "name": "Remove master key from local agent"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "command",
                            "changed": true,
                            "cmd": [
                                "ssh-add",
                                "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa"
                            ],
                            "delta": "0:00:00.012235",
                            "end": "2026-07-29 18:31:00.024785",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "ssh-add /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa",
                                    "_uses_shell": false,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": null,
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5787-ea30-0000000000ab-0-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:31:00.012550",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "Identity added: /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa (zuul-build-sshkey)",
                            "stdout_lines": [
                                "Identity added: /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/df925605a75e40088f795833ad47c03e_id_rsa (zuul-build-sshkey)"
                            ],
                            "zuul_log_id": "0242ac17-0010-5787-ea30-0000000000ab-0-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:00.070918Z",
                            "start": "2026-07-29T18:30:59.790526Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000ab",
                        "name": "Add back temp key"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "ping",
                            "changed": false,
                            "invocation": {
                                "module_args": {
                                    "data": "pong"
                                }
                            },
                            "ping": "pong"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:00.427939Z",
                            "start": "2026-07-29T18:31:00.076665Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000ac",
                        "name": "Verify we can still SSH to all nodes"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "command",
                            "changed": false,
                            "false_condition": "ansible_os_family == \"Windows\"",
                            "skip_reason": "Conditional result was False",
                            "skipped": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000016",
                        "name": "add-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/add-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:00.463227Z",
                            "start": "2026-07-29T18:31:00.436439Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-0000000000ad",
                        "name": "Verify we can still SSH to all nodes (windows)"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "zuul_console",
                            "changed": false,
                            "invocation": {
                                "module_args": {
                                    "path": "/tmp/console-{log_uuid}.log",
                                    "port": 19885,
                                    "state": "present"
                                }
                            }
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-00000000001b",
                        "name": "prepare-workspace",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/prepare-workspace"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:00.883585Z",
                            "start": "2026-07-29T18:31:00.480760Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000001d",
                        "name": "Start zuul_console daemon."
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result",
                            "changed": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-00000000001b",
                        "name": "prepare-workspace",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/prepare-workspace"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:02.102573Z",
                            "start": "2026-07-29T18:31:00.890699Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-00000000001e",
                        "name": "Synchronize src repos to workspace directory."
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": false,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": null,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/logs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "absent",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "path": "/home/zuul/zuul-output/logs",
                                    "state": "absent",
                                    "zj_output_dir": "logs"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": null,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/artifacts",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "absent",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "path": "/home/zuul/zuul-output/artifacts",
                                    "state": "absent",
                                    "zj_output_dir": "artifacts"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": null,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/docs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "absent",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "path": "/home/zuul/zuul-output/docs",
                                    "state": "absent",
                                    "zj_output_dir": "docs"
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000020",
                        "name": "ensure-output-dirs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/ensure-output-dirs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:02.725143Z",
                            "start": "2026-07-29T18:31:02.115113Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000022",
                        "name": "Empty Zuul Output directories by removing them"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "mode": "0755",
                                            "path": "/home/zuul/zuul-output/logs",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "mode": "0775",
                                            "path": "/home/zuul/zuul-output/logs",
                                            "state": "absent"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 1000,
                                    "group": "zuul",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/logs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "zuul",
                                    "path": "/home/zuul/zuul-output/logs",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 1000,
                                    "zj_output_dir": "logs"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "mode": "0755",
                                            "path": "/home/zuul/zuul-output/artifacts",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "mode": "0775",
                                            "path": "/home/zuul/zuul-output/artifacts",
                                            "state": "absent"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 1000,
                                    "group": "zuul",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/artifacts",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "zuul",
                                    "path": "/home/zuul/zuul-output/artifacts",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 1000,
                                    "zj_output_dir": "artifacts"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "mode": "0755",
                                            "path": "/home/zuul/zuul-output/docs",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "mode": "0775",
                                            "path": "/home/zuul/zuul-output/docs",
                                            "state": "absent"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 1000,
                                    "group": "zuul",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/home/zuul/zuul-output/docs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "zuul",
                                    "path": "/home/zuul/zuul-output/docs",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 1000,
                                    "zj_output_dir": "docs"
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5787-ea30-000000000020",
                        "name": "ensure-output-dirs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/ensure-output-dirs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:03.360724Z",
                            "start": "2026-07-29T18:31:02.734191Z"
                        },
                        "id": "0242ac17-0010-5787-ea30-000000000024",
                        "name": "Ensure Zuul Output directories exist"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 8,
            "failures": 0,
            "ignored": 0,
            "ok": 15,
            "rescued": 0,
            "skipped": 3,
            "unreachable": 0
        },
        "localhost": {
            "changed": 2,
            "failures": 0,
            "ignored": 0,
            "ok": 6,
            "rescued": 0,
            "skipped": 0,
            "unreachable": 0
        }
    },
    "trusted": true
},
{
    "branch": "main",
    "index": "1",
    "phase": "pre",
    "playbook": "github.com/vexxhost/zuul-jobs/playbooks/molecule/pre.yaml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:31:07.561380Z",
                    "start": "2026-07-29T18:31:04.210844Z"
                },
                "id": "0242ac17-0010-37e0-b0c9-000000000002",
                "name": "all"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.unarchive",
                            "changed": true,
                            "dest": "/usr/local/bin",
                            "extract_results": {
                                "cmd": [
                                    "/usr/bin/tar",
                                    "--extract",
                                    "-C",
                                    "/usr/local/bin",
                                    "-z",
                                    "--show-transformed-names",
                                    "--strip-components=1",
                                    "-f",
                                    "/home/zuul/.ansible/tmp/ansible-tmp-1785349864.2707846-5-277822073919956/uv-x86_64-unknown-linux-gnursh18mhn.tar.gz"
                                ],
                                "err": "",
                                "out": "",
                                "rc": 0
                            },
                            "gid": 0,
                            "group": "root",
                            "handler": "TgzArchive",
                            "invocation": {
                                "module_args": {
                                    "attributes": null,
                                    "copy": true,
                                    "creates": "/usr/local/bin/uv",
                                    "decrypt": true,
                                    "dest": "/usr/local/bin",
                                    "exclude": [],
                                    "extra_opts": [
                                        "--strip-components=1"
                                    ],
                                    "group": null,
                                    "include": [],
                                    "io_buffer_size": 65536,
                                    "keep_newer": false,
                                    "list_files": false,
                                    "mode": null,
                                    "owner": null,
                                    "remote_src": true,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": "https://github.com/astral-sh/uv/releases/download/0.8.13/uv-x86_64-unknown-linux-gnu.tar.gz",
                                    "unsafe_writes": false,
                                    "validate_certs": true
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "size": 4096,
                            "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349864.2707846-5-277822073919956/uv-x86_64-unknown-linux-gnursh18mhn.tar.gz",
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-37e0-b0c9-000000000005",
                        "name": "setup-uv",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_0/github.com/vexxhost/zuul-jobs/roles/setup-uv"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:06.594349Z",
                            "start": "2026-07-29T18:31:04.222940Z"
                        },
                        "id": "0242ac17-0010-37e0-b0c9-000000000007",
                        "name": "Extract archive"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.command",
                            "changed": true,
                            "cmd": [
                                "/usr/local/bin/uv",
                                "--version"
                            ],
                            "delta": "0:00:00.013627",
                            "end": "2026-07-29 18:31:07.001882",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "/usr/local/bin/uv --version",
                                    "_uses_shell": false,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": null,
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-37e0-b0c9-000000000008-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:31:06.988255",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "uv 0.8.13",
                            "stdout_lines": [
                                "uv 0.8.13"
                            ],
                            "zuul_log_id": "0242ac17-0010-37e0-b0c9-000000000008-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-37e0-b0c9-000000000005",
                        "name": "setup-uv",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_0/github.com/vexxhost/zuul-jobs/roles/setup-uv"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:07.145443Z",
                            "start": "2026-07-29T18:31:06.626953Z"
                        },
                        "id": "0242ac17-0010-37e0-b0c9-000000000008",
                        "name": "Print version"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "molecule_install_galaxy_sibling_collections",
                            "changed": false,
                            "checkouts": [],
                            "installed": [],
                            "invocation": {
                                "module_args": {
                                    "build_refs": [
                                        {
                                            "branch": "main",
                                            "change": "105",
                                            "change_message": "chore(deps): update helm release cert-manager to v1.21.1\n\n> \u2139\ufe0f **Note**\n> \n> This PR body was truncated due to platform limits.\n\nThis PR contains the following updates:\n\n| Package | Update | Change |\n|---|---|---|\n| [cert-manager](https://cert-manager.io) ([source](https://redirect.github.com/cert-manager/cert-manager)) | minor | `1.18.2` \u2192 `1.21.1` |\n\n---\n\n### Release Notes\n\n<details>\n<summary>cert-manager/cert-manager (cert-manager)</summary>\n\n### [`v1.21.1`](https://redirect.github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1)\n\n### [`v1.21.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.21.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.3...v1.21.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\ncert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values \u2014 review them carefully before upgrading.\n\n#### Known Issues\n\n- **Controller crash-loops when a Certificate sets `renewal.policy: Disabled`**: the new Certificate renewal policies feature ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258)) causes a nil pointer dereference panic in the trigger controller whenever a Certificate's `spec.renewal.policy` is set to `Disabled` \u2014 `pki.RenewalTime()` returns `(nil, nil)` for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. **Workaround**: do not set `renewal.policy: Disabled` on any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See [#&#8203;9031](https://redirect.github.com/cert-manager/cert-manager/issues/9031) for details.\n- **Log spam for non-cert-manager-labelled Secret events**: the typed predicates refactoring ([#&#8203;8407](https://redirect.github.com/cert-manager/cert-manager/issues/8407)) causes `filteredEventHandler` type assertion failures (`\"OnAdd missing Object\"`, `\"OnUpdate missing ObjectOld\"`, `\"OnDelete missing Object\"`) for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. **This is cosmetic only** \u2014 the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See [#&#8203;8994](https://redirect.github.com/cert-manager/cert-manager/issues/8994) for details.\n- **Issuer/ClusterIssuer can get stuck at `Ready: False, Reason: InvalidSolver` and never self-correct**: new eager validation of ACME solver Secrets ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255)) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly report `Ready: False`, but creating the missing Secret afterwards does not trigger re-reconciliation \u2014 the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. **Workaround**: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See [#&#8203;9036](https://redirect.github.com/cert-manager/cert-manager/issues/9036) for details and a fix proposal.\n\n#### Major Themes\n\n##### Default `tokenrequest` RBAC removed from Helm chart\n\n> \u26a0\ufe0f Breaking change\n\nThe Helm chart no longer creates a default `Role` and `RoleBinding` granting the cert-manager controller permission to create tokens for its own ServiceAccount (`serviceaccounts/token: create`). No documented workflow requires this RBAC \u2014 the Route53 docs section that motivated it was removed in 2024.\n\nIf you use `serviceAccountRef.name` pointing at the controller ServiceAccount, you must now either create your own `Role`/`RoleBinding` granting `serviceaccounts/token: create`, or migrate to a dedicated ServiceAccount (recommended \u2014 see the [Vault](https://cert-manager.io/docs/configuration/vault/) or [Route53](https://cert-manager.io/docs/configuration/acme/dns01/route53/) documentation).\n\n##### Restrict Challenge and Order RBAC in `cert-manager-edit` ClusterRole\n\n> \u26a0\ufe0f Potentially breaking change\n\nThe `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io` ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). These resources are internal to cert-manager's ACME workflow. Challenge `patch` and `update` are retained because users may need them to remove stuck finalizers.\n\nThis change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly.\n\n##### Metrics port name and path Helm values removed\n\n> \u26a0\ufe0f Breaking change\n\nThe Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path` have been removed. The controller Service metrics port has been renamed from `tcp-prometheus-servicemonitor` to `http-metrics`. Because the Helm values schema uses `additionalProperties: false`, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade \u2014 remove them before upgrading. ([#&#8203;8952](https://redirect.github.com/cert-manager/cert-manager/issues/8952))\n\n##### ACME and Certificate Management\n\n- **ACME Renewal Information (ARI)**: experimental support for [RFC 9773](https://www.rfc-editor.org/rfc/rfc9773) behind the `ACMEUseARI` feature gate. When enabled, cert-manager queries the ACME server's `renewalInfo` endpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. ([#&#8203;8798](https://redirect.github.com/cert-manager/cert-manager/issues/8798))\n- **`waitInsteadOfSelfCheck` solver option**: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See [configuration details](https://cert-manager.io/docs/configuration/acme/#skip-the-self-check-with-waitinsteadofselfcheck). ([#&#8203;8858](https://redirect.github.com/cert-manager/cert-manager/issues/8858))\n- **AWS IAM authentication for Vault**: the Vault issuer now supports IRSA, EKS Pod Identity, and ambient EC2/ECS credentials, removing the need for long-lived AWS Secrets. ([#&#8203;8422](https://redirect.github.com/cert-manager/cert-manager/issues/8422))\n- **Certificate renewal policies**: a new `renewalPolicies` field on the Certificate API provides more expressive control over renewal scheduling, complementing `renewBefore` and `renewBeforePercentage`. ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258))\n- **Configurable CertificateRequest retry backoff**: the new `--certificate-request-maximum-backoff-duration` flag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. ([#&#8203;8893](https://redirect.github.com/cert-manager/cert-manager/issues/8893))\n- **Modern2026 [PKCS#12](https://redirect.github.com/PKCS/cert-manager/issues/12) profile**: a new FIPS 140-3 compatible encoding profile using AES-256 + SHA-256 KDFs instead of legacy 3DES/RC2. ([#&#8203;8841](https://redirect.github.com/cert-manager/cert-manager/issues/8841))\n- **Webhook certificate renewal after system suspend**: the webhook now detects missed certificate renewals after system suspend (S3/S4) or VM live migration by polling wall-clock time, recovering within one minute of resume. ([#&#8203;8464](https://redirect.github.com/cert-manager/cert-manager/issues/8464))\n\n##### Gateway API and cainjector\n\n- **HTTP01 ListenerSet parentRef fallback**: the `acme.cert-manager.io/http01-parentreffallback: \"true\"` annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. ([#&#8203;8749](https://redirect.github.com/cert-manager/cert-manager/issues/8749))\n- **`cert-manager.io/ignore-tls-listeners` annotation**: exclude specific Gateway TLS listeners from certificate management. ([#&#8203;8727](https://redirect.github.com/cert-manager/cert-manager/issues/8727))\n- **Additional listener protocols**: configurable listener protocols beyond the default set. ([#&#8203;8683](https://redirect.github.com/cert-manager/cert-manager/issues/8683))\n- **`enableGatewayAPI` configuration restructure**: `enableGatewayAPI` and `enableGatewayAPIListenerSet` are deprecated in favor of `gatewayAPI.enabled` / `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://redirect.github.com/cert-manager/cert-manager/issues/8732))\n- **`CAInjectorMerging` promoted to GA**: unconditionally enabled; will be removed in a future release. ([#&#8203;8583](https://redirect.github.com/cert-manager/cert-manager/issues/8583))\n- **cainjector server-side apply unconditional**: the `ServerSideApply` feature gate is deprecated. ([#&#8203;8692](https://redirect.github.com/cert-manager/cert-manager/issues/8692))\n- **cainjector `--ignore-namespaces` flag**: skip specified namespaces when watching Secrets for injection. ([#&#8203;8614](https://redirect.github.com/cert-manager/cert-manager/issues/8614))\n\n##### Deployment and Observability\n\n- **Venafi OAuth token observability**: a new `AuthFailed` Issuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. ([#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808), [#&#8203;8779](https://redirect.github.com/cert-manager/cert-manager/issues/8779))\n- **`runtimeClassName` support**: configurable for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://redirect.github.com/cert-manager/cert-manager/issues/8791), [#&#8203;8976](https://redirect.github.com/cert-manager/cert-manager/issues/8976))\n- **`startupapicheck.ttlSecondsAfterFinished`**: opt-in automatic cleanup of the startupapicheck Job. ([#&#8203;8523](https://redirect.github.com/cert-manager/cert-manager/issues/8523))\n- **`--acme-http01-solver-extra-labels`**: propagate `global.commonLabels` to dynamically-created ACME HTTP01 solver resources. ([#&#8203;8761](https://redirect.github.com/cert-manager/cert-manager/issues/8761))\n\n##### Notable Bug Fixes\n\n- **Integer overflow in `renewBeforePercentage`**: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. ([#&#8203;8947](https://redirect.github.com/cert-manager/cert-manager/issues/8947))\n- **Infinite re-issuance loop**: cert-manager no longer loops when an issuer returns an already-expired certificate. ([#&#8203;8610](https://redirect.github.com/cert-manager/cert-manager/issues/8610))\n- **ACME transient network errors**: challenges no longer permanently fail on TLS handshake timeouts, DNS resolution failures, or context cancellation during nonce fetches and authorization waits. ([#&#8203;8760](https://redirect.github.com/cert-manager/cert-manager/issues/8760))\n- **DNS-over-HTTPS response body cap**: response body reads are now bounded at 128 KB to prevent potential OOM. ([#&#8203;8803](https://redirect.github.com/cert-manager/cert-manager/issues/8803))\n- **Vault path traversal**: the Vault issuer webhook now rejects `..` path segments, preventing `path.Join` from silently resolving relative segments. ([#&#8203;8930](https://redirect.github.com/cert-manager/cert-manager/issues/8930))\n- **DNS issuer secrets validated before ready**: prevents silent misconfiguration. ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255))\n\n#### Community\n\nAs always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.\n\nA special thanks to:\n\n- [@&#8203;Copilot](https://redirect.github.com/Copilot)\n- [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps)\n- [@&#8203;Peac36](https://redirect.github.com/Peac36)\n- [@&#8203;SebTardif](https://redirect.github.com/SebTardif)\n- [@&#8203;apkatsikas](https://redirect.github.com/apkatsikas)\n- [@&#8203;bitloi](https://redirect.github.com/bitloi)\n- [@&#8203;dap0am](https://redirect.github.com/dap0am)\n- [@&#8203;figaw](https://redirect.github.com/figaw)\n- [@&#8203;immanuwell](https://redirect.github.com/immanuwell)\n- [@&#8203;jabbrwcky](https://redirect.github.com/jabbrwcky)\n- [@&#8203;jnohlgard](https://redirect.github.com/jnohlgard)\n- [@&#8203;jsoref](https://redirect.github.com/jsoref)\n- [@&#8203;ltwongaa](https://redirect.github.com/ltwongaa)\n- [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite)\n- [@&#8203;mateenali66](https://redirect.github.com/mateenali66)\n- [@&#8203;onurmicoogullari](https://redirect.github.com/onurmicoogullari)\n- [@&#8203;putongyong](https://redirect.github.com/putongyong)\n- [@&#8203;seanorama](https://redirect.github.com/seanorama)\n- [@&#8203;texasich](https://redirect.github.com/texasich)\n\nfor their contributions, comments and support!\n\nAlso, thanks to the cert-manager maintainer team for their help in this release:\n\n- [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish)\n- [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot)\n- [@&#8203;erikgb](https://redirect.github.com/erikgb)\n- [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123)\n- [@&#8203;inteon](https://redirect.github.com/inteon)\n- [@&#8203;maelvls](https://redirect.github.com/maelvls)\n- [@&#8203;munnerz](https://redirect.github.com/munnerz)\n- [@&#8203;wallrj](https://redirect.github.com/wallrj)\n- [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark)\n\nAnd finally, thanks to the cert-manager steering committee for their feedback in this release cycle:\n\n- [@&#8203;FlorianLiebhart](https://redirect.github.com/FlorianLiebhart)\n- [@&#8203;TrilokGeer](https://redirect.github.com/TrilokGeer)\n- [@&#8203;ianarsenault](https://redirect.github.com/ianarsenault)\n- [@&#8203;ssyno](https://redirect.github.com/ssyno)\n\n#### Changes since v1.20.0\n\n##### Feature\n\n- Add Venafi OAuth token request observability and a new `AuthFailed` Issuer condition reason to distinguish bad credentials from transient infrastructure errors. ([#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Add `certificateRequestMaximumBackoffDuration` controller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file, `--certificate-request-maximum-backoff-duration` CLI flag, or Helm value `config.certificateRequestMaximumBackoffDuration`. Defaults to 32 hours for backward compatibility. ([#&#8203;8893](https://redirect.github.com/cert-manager/cert-manager/issues/8893), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Add an optional `waitInsteadOfSelfCheck` field to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. ([#&#8203;8858](https://redirect.github.com/cert-manager/cert-manager/issues/8858), [@&#8203;wallrj](https://redirect.github.com/wallrj))\n- Add configurable `runtimeClassName` support for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://redirect.github.com/cert-manager/cert-manager/issues/8791), [@&#8203;jsoref](https://redirect.github.com/jsoref))\n- Add direct configurable `runtimeClassName` support for ACME HTTP01 solver pods via the `acmesolver.runtimeClassName` Helm value. ([#&#8203;8976](https://redirect.github.com/cert-manager/cert-manager/issues/8976), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Add new controller flag `--acme-http01-solver-extra-labels`, allowing Helm's `global.commonLabels` to propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). ([#&#8203;8761](https://redirect.github.com/cert-manager/cert-manager/issues/8761), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Add opt-in `startupapicheck.ttlSecondsAfterFinished` Helm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. ([#&#8203;8523](https://redirect.github.com/cert-manager/cert-manager/issues/8523), [@&#8203;dap0am](https://redirect.github.com/dap0am))\n- Added ARI support through the ACMEUseARI feature gate. ([#&#8203;8798](https://redirect.github.com/cert-manager/cert-manager/issues/8798), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). ([#&#8203;8422](https://redirect.github.com/cert-manager/cert-manager/issues/8422), [@&#8203;bitloi](https://redirect.github.com/bitloi))\n- Added `cert-manager.io/ignore-tls-listeners` annotation for ignoring gwapi listeners. ([#&#8203;8727](https://redirect.github.com/cert-manager/cert-manager/issues/8727), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. ([#&#8203;8683](https://redirect.github.com/cert-manager/cert-manager/issues/8683), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3 ([#&#8203;8841](https://redirect.github.com/cert-manager/cert-manager/issues/8841), [@&#8203;seanorama](https://redirect.github.com/seanorama))\n- Cainjector: A new flag `--ignore-namespaces` was added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. ([#&#8203;8614](https://redirect.github.com/cert-manager/cert-manager/issues/8614), [@&#8203;figaw](https://redirect.github.com/figaw))\n- Disabled client side rate-limiting if AP\\&F is enabled. ([#&#8203;8757](https://redirect.github.com/cert-manager/cert-manager/issues/8757), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Extend the Venafi/CyberArk integration to also support PANW NGTS. ([#&#8203;8779](https://redirect.github.com/cert-manager/cert-manager/issues/8779), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Adding certificate renewal policies ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate ([#&#8203;8692](https://redirect.github.com/cert-manager/cert-manager/issues/8692), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Processed annotations `cert-manager.io/alt-names`, `cert-manager.io/ip-sans` to Certificates generated from ingress like objects in cert-shim controllers. ([#&#8203;8927](https://redirect.github.com/cert-manager/cert-manager/issues/8927), [@&#8203;jabbrwcky](https://redirect.github.com/jabbrwcky))\n- Promote the CAInjectorMerging feature gate to GA ([#&#8203;8583](https://redirect.github.com/cert-manager/cert-manager/issues/8583), [@&#8203;Copilot](https://redirect.github.com/Copilot))\n- When using ACME HTTP-01 with a ListenerSet, setting the annotation `acme.cert-manager.io/http01-parentreffallback: \"true\"` causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. ([#&#8203;8749](https://redirect.github.com/cert-manager/cert-manager/issues/8749), [@&#8203;apkatsikas](https://redirect.github.com/apkatsikas))\n\n##### Bug or Regression\n\n- **BREAKING**: The Helm chart no longer ships a default `Role` and `RoleBinding` granting the cert-manager controller ServiceAccount permission to create tokens for itself (`serviceaccounts/token: create`). This RBAC was added in v1.16 ([#&#8203;7213](https://redirect.github.com/cert-manager/cert-manager/issues/7213)) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely on `serviceAccountRef.name` pointing at the controller ServiceAccount (an undocumented pattern), you must now create your own `Role` and `RoleBinding` granting `serviceaccounts/token: create` on that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). ([#&#8203;8931](https://redirect.github.com/cert-manager/cert-manager/issues/8931), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- ACME challenges no longer terminally fail on transient network errors (TLS handshake timeouts, DNS failures, context cancellation) during nonce fetches and authorization waits. The challenge controller returns the error and lets the workqueue retry with backoff. ([#&#8203;8760](https://redirect.github.com/cert-manager/cert-manager/issues/8760), [@&#8203;texasich](https://redirect.github.com/texasich))\n- Add dns issuer secrets validation before marking it as ready ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Add missing issuer finalizer RBAC to the order controller to support owner references ([#&#8203;8654](https://redirect.github.com/cert-manager/cert-manager/issues/8654), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- ClusterIssuer metrics collector now correctly respects the enabled-controllers configuration, avoiding a redundant startup when only operating within a namespace. ([#&#8203;8822](https://redirect.github.com/cert-manager/cert-manager/issues/8822), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Fix Venafi TPP issuer setup and signing regression on master: restore authentication of the vcert connector in the client constructor, which was removed in [#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808). ([#&#8203;8843](https://redirect.github.com/cert-manager/cert-manager/issues/8843), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Fix a performance issue in the certificateRequestApproval webhook where CertificateRequests referencing a GroupKind whose CRD is not yet installed would trigger repeated API server discovery queries on every admission request. Negative results are now cached for 30 seconds. ([#&#8203;8651](https://redirect.github.com/cert-manager/cert-manager/issues/8651), [@&#8203;mateenali66](https://redirect.github.com/mateenali66))\n- Fix webhook serving certificate not being renewed after system suspend. ([#&#8203;8464](https://redirect.github.com/cert-manager/cert-manager/issues/8464), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Fixed a rare panic in the trigger controller when a Certificate is deleted from the informer cache while a reconcile is in progress (e.g. during namespace teardown). ([#&#8203;8962](https://redirect.github.com/cert-manager/cert-manager/issues/8962), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Fixed an integer overflow in `renewBeforePercentage` calculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. ([#&#8203;8947](https://redirect.github.com/cert-manager/cert-manager/issues/8947), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8619](https://redirect.github.com/cert-manager/cert-manager/issues/8619), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Fixed infinite re-issuance loop when issuer returns an already expired certificate ([#&#8203;8610](https://redirect.github.com/cert-manager/cert-manager/issues/8610), [@&#8203;onurmicoogullari](https://redirect.github.com/onurmicoogullari))\n- Fixed local `e2e-setup-samplewebhook` installation to use the samplewebhook image repository and tag from the saved image tarball manifest. ([#&#8203;8821](https://redirect.github.com/cert-manager/cert-manager/issues/8821), [@&#8203;wallrj](https://redirect.github.com/wallrj))\n- Fixed potential OOM in DNS-over-HTTPS client by bounding response body read with io.LimitReader (128 KB cap). ([#&#8203;8803](https://redirect.github.com/cert-manager/cert-manager/issues/8803), [@&#8203;SebTardif](https://redirect.github.com/SebTardif))\n- Fixed validation of timezone-prefixed renewal window cron specs without a schedule. ([#&#8203;8813](https://redirect.github.com/cert-manager/cert-manager/issues/8813), [@&#8203;immanuwell](https://redirect.github.com/immanuwell))\n- Helm chart bugfix: rename image helper to avoid umbrella chart conflicts ([#&#8203;8753](https://redirect.github.com/cert-manager/cert-manager/issues/8753), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8664](https://redirect.github.com/cert-manager/cert-manager/issues/8664), [@&#8203;jnohlgard](https://redirect.github.com/jnohlgard))\n- Remove ACME Challenge `create` and Order `create`/`patch`/`update` from the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). ([#&#8203;8958](https://redirect.github.com/cert-manager/cert-manager/issues/8958), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8743](https://redirect.github.com/cert-manager/cert-manager/issues/8743), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Update logic to identify and preserve the secret matching nextPrivateKeySecretName ([#&#8203;8577](https://redirect.github.com/cert-manager/cert-manager/issues/8577), [@&#8203;putongyong](https://redirect.github.com/putongyong))\n- Vault Issuer webhook validation now rejects `..` path segments in `spec.vault.path` and auth mount path fields, preventing `path.Join` from silently resolving relative segments before constructing the Vault API request. ([#&#8203;8930](https://redirect.github.com/cert-manager/cert-manager/issues/8930), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n##### Other (Cleanup or Flake)\n\n- API cleanup: removed deprecated ObjectReference ([#&#8203;8625](https://redirect.github.com/cert-manager/cert-manager/issues/8625), [@&#8203;inteon](https://redirect.github.com/inteon))\n- Remove Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path`. The metrics path is always `/metrics` and the target port is always `http-metrics`. Rename the controller service metrics port from `tcp-prometheus-servicemonitor` to `http-metrics` for consistency with other workloads. Users must remove these keys from their value overrides before upgrading. ([#&#8203;8952](https://redirect.github.com/cert-manager/cert-manager/issues/8952), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- The `enableGatewayAPI` and `enableGatewayAPIListenerSet` fields on `ControllerConfiguration` are deprecated and moved into the `gatewayAPI` sub-struct as `gatewayAPI.enabled` and `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://redirect.github.com/cert-manager/cert-manager/issues/8732), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Update base images to Debian 13 ([#&#8203;8849](https://redirect.github.com/cert-manager/cert-manager/issues/8849), [@&#8203;ltwongaa](https://redirect.github.com/ltwongaa))\n\n### [`v1.20.3`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.3)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.2...v1.20.3)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.\n\nThis release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.\n\nAll users should upgrade.\n\n> \\[!WARNING]\n> **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate \u2192 CertificateRequest \u2192 Order \u2192 Challenge flow), you will need to grant those permissions explicitly.\n\n#### Changes by Kind\n\n##### Bug or Regression\n\n- Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8940](https://redirect.github.com/cert-manager/cert-manager/issues/8940), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8759](https://redirect.github.com/cert-manager/cert-manager/issues/8759), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Bump go to 1.26.3, other deps to fix several govulncheck issues ([#&#8203;8789](https://redirect.github.com/cert-manager/cert-manager/issues/8789), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.26.4` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8926](https://redirect.github.com/cert-manager/cert-manager/issues/8926), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n### [`v1.20.2`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.2)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.1...v1.20.2)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.2 fixes invalid YAML generated in the Helm chart when both `webhook.config`\nand `webhook.volumes` are defined, and bumps Go to 1.26.2 along with dependencies\nto address reported vulnerabilities.\n\n#### Changes by Kind\n\n##### Bug or Regression\n\n- Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8665](https://redirect.github.com/cert-manager/cert-manager/issues/8665), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Bump go dependencies with reported vulnerabilities ([#&#8203;8704](https://redirect.github.com/cert-manager/cert-manager/issues/8704), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump go to 1.26.2 ([#&#8203;8703](https://redirect.github.com/cert-manager/cert-manager/issues/8703), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.20.1`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.0...v1.20.1)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate `parentRef` bug when both issuer config and annotations are present (Gateway API).\n\n##### Bug or Regression\n\n- Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8658](https://redirect.github.com/cert-manager/cert-manager/issues/8658), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Add missing issuer finalizer RBAC to the order controller to support owner references. This was preventing OpenShift users from being able to upgrade to v1.20.0. ([#&#8203;8655](https://redirect.github.com/cert-manager/cert-manager/issues/8655), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump google.golang.org/grpc to fix vulnerability reported by scanners. This isn't a vulnerability that affects cert-manager, but we are bumping it because it is reported by scanners. ([#&#8203;8657](https://redirect.github.com/cert-manager/cert-manager/issues/8657), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.20.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.6...v1.20.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.\n\n##### Changes by Kind\n\n##### Feature\n\n- Added a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. ([#&#8203;8370](https://redirect.github.com/cert-manager/cert-manager/issues/8370), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- Added selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} ([#&#8203;8256](https://redirect.github.com/cert-manager/cert-manager/issues/8256), [@&#8203;tareksha](https://redirect.github.com/tareksha))\n- Added support for specifying `imagePullSecrets` in the `startupapicheck-job` Helm template to enable pulling images from private registries. ([#&#8203;8186](https://redirect.github.com/cert-manager/cert-manager/issues/8186), [@&#8203;mathieu-clnk](https://redirect.github.com/mathieu-clnk))\n- Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. ([#&#8203;8355](https://redirect.github.com/cert-manager/cert-manager/issues/8355), [@&#8203;dancmeyers](https://redirect.github.com/dancmeyers))\n- Added `parentRef` override annotations on the Certificate resource. ([#&#8203;8518](https://redirect.github.com/cert-manager/cert-manager/issues/8518), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added support for azure private zones for dns01 issuer. ([#&#8203;8494](https://redirect.github.com/cert-manager/cert-manager/issues/8494), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. ([#&#8203;7642](https://redirect.github.com/cert-manager/cert-manager/issues/7642), [@&#8203;robertlestak](https://redirect.github.com/robertlestak))\n- Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget ([#&#8203;7728](https://redirect.github.com/cert-manager/cert-manager/issues/7728), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- For Venafi provider, read `venafi.cert-manager.io/custom-fields` annotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. ([#&#8203;8301](https://redirect.github.com/cert-manager/cert-manager/issues/8301), [@&#8203;k0da](https://redirect.github.com/k0da))\n- Improve error message when CA issuers are misconfigured to use a clashing secret name ([#&#8203;8374](https://redirect.github.com/cert-manager/cert-manager/issues/8374), [@&#8203;majiayu000](https://redirect.github.com/majiayu000))\n- Introduce a new Ingress annotation `acme.cert-manager.io/http01-ingress-ingressclassname` to override `http01.ingress.ingressClassName` field in HTTP-01 challenge solvers. ([#&#8203;8244](https://redirect.github.com/cert-manager/cert-manager/issues/8244), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8195](https://redirect.github.com/cert-manager/cert-manager/issues/8195), [@&#8203;StingRayZA](https://redirect.github.com/StingRayZA))\n- Vault issuers will now include the Vault server address as one of the default audiences on generated service account tokens. ([#&#8203;8228](https://redirect.github.com/cert-manager/cert-manager/issues/8228), [@&#8203;terinjokes](https://redirect.github.com/terinjokes))\n- Added experimental `XListenerSets` feature gate ([#&#8203;8394](https://redirect.github.com/cert-manager/cert-manager/issues/8394), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n\n##### Documentation\n\n- Add GWAPI documentation to NOTES.TXT in helm chart ([#&#8203;8353](https://redirect.github.com/cert-manager/cert-manager/issues/8353), [@&#8203;jaxels10](https://redirect.github.com/jaxels10))\n\n##### Bug or Regression\n\n- Adds logs for cases when acme server returns us a fatal error in the order controller ([#&#8203;8199](https://redirect.github.com/cert-manager/cert-manager/issues/8199), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Fixed an issue where kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed ([#&#8203;8160](https://redirect.github.com/cert-manager/cert-manager/issues/8160), [@&#8203;inteon](https://redirect.github.com/inteon))\n- Changes to the Duration and RenewBefore annotations on ingress and gateway-api resources will now trigger certificate updates. ([#&#8203;8232](https://redirect.github.com/cert-manager/cert-manager/issues/8232), [@&#8203;eleanor-merry](https://redirect.github.com/eleanor-merry))\n- Fix an issue where ACME challenge TXT records are not cleaned up when there are many resource records in CloudDNS. ([#&#8203;8456](https://redirect.github.com/cert-manager/cert-manager/issues/8456), [@&#8203;tkna](https://redirect.github.com/tkna))\n- Fix unregulated retries with the DigitalOcean DNS-01 solver\n  Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging ([#&#8203;8221](https://redirect.github.com/cert-manager/cert-manager/issues/8221), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8403](https://redirect.github.com/cert-manager/cert-manager/issues/8403), [@&#8203;calm329](https://redirect.github.com/calm329))\n- Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8424](https://redirect.github.com/cert-manager/cert-manager/issues/8424), [@&#8203;SlashNephy](https://redirect.github.com/SlashNephy))\n- Fixed the HTTP-01 Gateway solver creating invalid HTTPRoutes by not setting spec.hostnames when the challenge DNSName is an IP address. ([#&#8203;8443](https://redirect.github.com/cert-manager/cert-manager/issues/8443), [@&#8203;alviss7](https://redirect.github.com/alviss7))\n- Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8173](https://redirect.github.com/cert-manager/cert-manager/issues/8173), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8469](https://redirect.github.com/cert-manager/cert-manager/issues/8469), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8290](https://redirect.github.com/cert-manager/cert-manager/issues/8290), [@&#8203;octo-sts](https://redirect.github.com/octo-sts)\\[bot])\n- When Prometheus monitoring is enabled, the metrics label is now set to the intended value of `cert-manager`. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). ([#&#8203;8162](https://redirect.github.com/cert-manager/cert-manager/issues/8162), [@&#8203;LiquidPL](https://redirect.github.com/LiquidPL))\n\n##### Other (Cleanup or Flake)\n\n- Promoted the OtherNames feature to Beta and enabled it by default ([#&#8203;8288](https://redirect.github.com/cert-manager/cert-manager/issues/8288), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Promoting `XListenerSets` feature gate to `ListenerSets` ([#&#8203;8501](https://redirect.github.com/cert-manager/cert-manager/issues/8501), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Rebranding of the Venafi Issuer to CyberArk ([#&#8203;8215](https://redirect.github.com/cert-manager/cert-manager/issues/8215), [@&#8203;iossifbenbassat123](https://redirect.github.com/iossifbenbassat123))\n- Switched to SSA for challenge finalizer updates ([#&#8203;8519](https://redirect.github.com/cert-manager/cert-manager/issues/8519), [@&#8203;inteon](https://redirect.github.com/inteon))\n- The default container user (UID) is now 65532 (previously 1000) and the default container group (GID) is now 65532 (previously 0) ([#&#8203;8408](https://redirect.github.com/cert-manager/cert-manager/issues/8408), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- The feature-gate DefaultPrivateKeyRotationPolicyAlways moved from Beta to GA and can no longer be disabled. ([#&#8203;8287](https://redirect.github.com/cert-manager/cert-manager/issues/8287), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Update cert-manager's ACME client, forked from golang/x/crypto ([#&#8203;8268](https://redirect.github.com/cert-manager/cert-manager/issues/8268), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Use the latest version of Kyverno (1.16.2) in the best-practice installation tests ([#&#8203;8389](https://redirect.github.com/cert-manager/cert-manager/issues/8389), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- We stopped testing with Coutour due to it not supporting the new XListenerSet resource, and moved to kgateway. ([#&#8203;8426](https://redirect.github.com/cert-manager/cert-manager/issues/8426), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n\n### [`v1.19.6`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.6)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.5...v1.19.6)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.\n\nThis release also includes Go version bumps to address reported CVEs. All users should upgrade.\n\n> \\[!WARNING]\n> **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate \u2192 CertificateRequest \u2192 Order \u2192 Challenge flow), you will need to grant those permissions explicitly.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8941](https://redirect.github.com/cert-manager/cert-manager/pull/8941), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n##### Other (Cleanup or Flake)\n\n- Update Go to `v1.25.11` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8925](https://redirect.github.com/cert-manager/cert-manager/pull/8925), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Upgrade Go to 1.25.10 to fix reported vulnerabilities, along with other dependency bumps ([#&#8203;8788](https://redirect.github.com/cert-manager/cert-manager/pull/8788), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.5`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.5)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.4...v1.19.5)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.\n\n##### Changes by Kind\n\n##### Other (Cleanup or Flake)\n\n- Bump go dependencies with reported vulnerabilities ([#&#8203;8706](https://redirect.github.com/cert-manager/cert-manager/pull/8706), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump go to 1.25.8 to address several reported vulnerabilities ([#&#8203;8628](https://redirect.github.com/cert-manager/cert-manager/pull/8628), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Bump go to 1.25.9 ([#&#8203;8705](https://redirect.github.com/cert-manager/cert-manager/pull/8705), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.19.4`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.4)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.3...v1.19.4)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Bump go to address CVE-2025-68121 ([#&#8203;8526](https://redirect.github.com/cert-manager/cert-manager/issues/8526), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Bump otel SDK to address GO-2026-4394 ([#&#8203;8531](https://redirect.github.com/cert-manager/cert-manager/issues/8531), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.3`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.3)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.2...v1.19.3)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8415](https://redirect.github.com/cert-manager/cert-manager/issues/8415), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Fixed an issue where HTTP-01 challenges failed when the Host header contained an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8436](https://redirect.github.com/cert-manager/cert-manager/issues/8436), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8468](https://redirect.github.com/cert-manager/cert-manager/issues/8468), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n##### Other (Cleanup or Flake)\n\n- Bump go to 1.25.6 ([#&#8203;8459](https://redirect.github.com/cert-manager/cert-manager/issues/8459), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.2`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.2)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.1...v1.19.2)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nWe updated Go to fix some vulnerabilities in the standard library.\n\n> \ud83d\udcd6 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading.\n\n#### Changes since `v1.19.1`\n\n##### Bug or Regression\n\n- Address false positive vulnerabilities `CVE-2025-47914` and `CVE-2025-58181` which were reported by Trivy. ([#&#8203;8283](https://redirect.github.com/cert-manager/cert-manager/issues/8283), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8294](https://redirect.github.com/cert-manager/cert-manager/issues/8294), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8233](https://redirect.github.com/cert-manager/cert-manager/issues/8233), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Update cert-manager's ACME client, forked from `golang/x/crypto` ([#&#8203;8270](https://redirect.github.com/cert-manager/cert-manager/issues/8270), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Updated Debian 12 distroless base images ([#&#8203;8326](https://redirect.github.com/cert-manager/cert-manager/issues/8326), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n### [`v1.19.1`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.0...v1.19.1)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nWe reverted the CRD-based API defaults for `Certificate.Spec.IssuerRef` and `CertificateRequest.Spec.IssuerRef` after they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager `1.20`.\nWe fixed a bug that caused certificates to be re-issued unexpectedly if the `issuerRef` kind or group was changed to one of the \"runtime\" default values.\nWe upgraded Go to `1.25.3` to address the following security vulnerabilities: `CVE-2025-61724`, `CVE-2025-58187`, `CVE-2025-47912`, `CVE-2025-58183`, `CVE-2025-61723`, `CVE-2025-58186`, `CVE-2025-58185`, `CVE-2025-58188`, and `CVE-2025-61725`.\n\n> \ud83d\udcd6 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading.\n\nChanges since `v1.19.0`:\n\n##### Bug or Regression\n\n- BUGFIX: in case kind or group in the `issuerRef` of a Certificate was omitted, upgrading to `1.19.x` incorrectly caused the certificate to be renewed ([#&#8203;8175](https://redirect.github.com/cert-manager/cert-manager/issues/8175), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Bump Go to 1.25.3 to fix a backwards incompatible change to the validation of DNS names in X.509 SAN fields which prevented the use of DNS names with a trailing dot ([#&#8203;8177](https://redirect.github.com/cert-manager/cert-manager/issues/8177), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8178](https://redirect.github.com/cert-manager/cert-manager/issues/8178), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n### [`v1.19.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.18.6...v1.19.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\n> \u26a0\ufe0f **Known issues**: The following known issues are fixed in [v1.19.1](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.1):\n>\n> - [Unexpected certificate renewal after upgrading to 1.19.0](https://redirect.github.com/cert-manager/cert-manager/issues/8158)\n\nThis release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues.\n\n> \ud83d\udcd6  Read the full release notes at cert-manager.io: <https://cert-manager.io/docs/releases/release-notes/release-notes-1.19>\n\nChanges since `v1.18.0`:\n\n##### Feature\n\n- Add IPv6 rules to the default network policy ([#&#8203;7726](https://redirect.github.com/cert-manager/cert-manager/issues/7726), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- Add `global.nodeSelector` to helm chart to allow for a single `nodeSelector` to be set across all services. ([#&#8203;7818](https://redirect.github.com/cert-manager/cert-manager/issues/7818), [@&#8203;StingRayZA](https://redirect.github.com/StingRayZA))\n- Add a feature gate to default to Ingress `pathType` `Exact` in ACME HTTP01 Ingress challenge solvers. ([#&#8203;7795](https://redirect.github.com/cert-manager/cert-manager/issues/7795), [@&#8203;sspreitzer](https://redirect.github.com/sspreitzer))\n- Add generated `applyconfigurations` allowing clients to make type-safe server-side apply requests for cert-manager resources. ([#&#8203;7866](https://redirect.github.com/cert-manager/cert-manager/issues/7866), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). ([#&#8203;7414](https://redirect.github.com/cert-manager/cert-manager/issues/7414), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Added `certmanager_certificate_challenge_status` Prometheus metric. ([#&#8203;7736](https://re\n\n> \u2702 **Note**\n> \n> PR body was truncated to here.\n\n\n</details>\n\n---\n\n### Configuration\n\n\ud83d\udcc5 **Schedule**: (UTC)\n\n- Branch creation\n  - At any time (no schedule defined)\n- Automerge\n  - At any time (no schedule defined)\n\n\ud83d\udea6 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.\n\n\u267b **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.\n\n\ud83d\udd15 **Ignore**: Close this PR and you won't be reminded about this update again.\n\n---\n\n - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/vexxhost/atmosphere.common).\n<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMzEuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->\n",
                                            "change_url": "https://github.com/vexxhost/atmosphere.common/pull/105",
                                            "commit_id": "4ab174a72079e89cc7e61a674221eb9e91158c0c",
                                            "patchset": "4ab174a72079e89cc7e61a674221eb9e91158c0c",
                                            "project": {
                                                "canonical_hostname": "github.com",
                                                "canonical_name": "github.com/vexxhost/atmosphere.common",
                                                "name": "vexxhost/atmosphere.common",
                                                "short_name": "atmosphere.common",
                                                "src_dir": "src/github.com/vexxhost/atmosphere.common"
                                            },
                                            "src_dir": "src/github.com/vexxhost/atmosphere.common",
                                            "topic": null
                                        },
                                        {
                                            "branch": "main",
                                            "change": "105",
                                            "change_message": "chore(deps): update helm release cert-manager to v1.21.1\n\n> \u2139\ufe0f **Note**\n> \n> This PR body was truncated due to platform limits.\n\nThis PR contains the following updates:\n\n| Package | Update | Change |\n|---|---|---|\n| [cert-manager](https://cert-manager.io) ([source](https://redirect.github.com/cert-manager/cert-manager)) | minor | `1.18.2` \u2192 `1.21.1` |\n\n---\n\n### Release Notes\n\n<details>\n<summary>cert-manager/cert-manager (cert-manager)</summary>\n\n### [`v1.21.1`](https://redirect.github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1)\n\n### [`v1.21.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.21.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.3...v1.21.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\ncert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values \u2014 review them carefully before upgrading.\n\n#### Known Issues\n\n- **Controller crash-loops when a Certificate sets `renewal.policy: Disabled`**: the new Certificate renewal policies feature ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258)) causes a nil pointer dereference panic in the trigger controller whenever a Certificate's `spec.renewal.policy` is set to `Disabled` \u2014 `pki.RenewalTime()` returns `(nil, nil)` for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. **Workaround**: do not set `renewal.policy: Disabled` on any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See [#&#8203;9031](https://redirect.github.com/cert-manager/cert-manager/issues/9031) for details.\n- **Log spam for non-cert-manager-labelled Secret events**: the typed predicates refactoring ([#&#8203;8407](https://redirect.github.com/cert-manager/cert-manager/issues/8407)) causes `filteredEventHandler` type assertion failures (`\"OnAdd missing Object\"`, `\"OnUpdate missing ObjectOld\"`, `\"OnDelete missing Object\"`) for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. **This is cosmetic only** \u2014 the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See [#&#8203;8994](https://redirect.github.com/cert-manager/cert-manager/issues/8994) for details.\n- **Issuer/ClusterIssuer can get stuck at `Ready: False, Reason: InvalidSolver` and never self-correct**: new eager validation of ACME solver Secrets ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255)) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly report `Ready: False`, but creating the missing Secret afterwards does not trigger re-reconciliation \u2014 the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. **Workaround**: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See [#&#8203;9036](https://redirect.github.com/cert-manager/cert-manager/issues/9036) for details and a fix proposal.\n\n#### Major Themes\n\n##### Default `tokenrequest` RBAC removed from Helm chart\n\n> \u26a0\ufe0f Breaking change\n\nThe Helm chart no longer creates a default `Role` and `RoleBinding` granting the cert-manager controller permission to create tokens for its own ServiceAccount (`serviceaccounts/token: create`). No documented workflow requires this RBAC \u2014 the Route53 docs section that motivated it was removed in 2024.\n\nIf you use `serviceAccountRef.name` pointing at the controller ServiceAccount, you must now either create your own `Role`/`RoleBinding` granting `serviceaccounts/token: create`, or migrate to a dedicated ServiceAccount (recommended \u2014 see the [Vault](https://cert-manager.io/docs/configuration/vault/) or [Route53](https://cert-manager.io/docs/configuration/acme/dns01/route53/) documentation).\n\n##### Restrict Challenge and Order RBAC in `cert-manager-edit` ClusterRole\n\n> \u26a0\ufe0f Potentially breaking change\n\nThe `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io` ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). These resources are internal to cert-manager's ACME workflow. Challenge `patch` and `update` are retained because users may need them to remove stuck finalizers.\n\nThis change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly.\n\n##### Metrics port name and path Helm values removed\n\n> \u26a0\ufe0f Breaking change\n\nThe Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path` have been removed. The controller Service metrics port has been renamed from `tcp-prometheus-servicemonitor` to `http-metrics`. Because the Helm values schema uses `additionalProperties: false`, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade \u2014 remove them before upgrading. ([#&#8203;8952](https://redirect.github.com/cert-manager/cert-manager/issues/8952))\n\n##### ACME and Certificate Management\n\n- **ACME Renewal Information (ARI)**: experimental support for [RFC 9773](https://www.rfc-editor.org/rfc/rfc9773) behind the `ACMEUseARI` feature gate. When enabled, cert-manager queries the ACME server's `renewalInfo` endpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. ([#&#8203;8798](https://redirect.github.com/cert-manager/cert-manager/issues/8798))\n- **`waitInsteadOfSelfCheck` solver option**: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See [configuration details](https://cert-manager.io/docs/configuration/acme/#skip-the-self-check-with-waitinsteadofselfcheck). ([#&#8203;8858](https://redirect.github.com/cert-manager/cert-manager/issues/8858))\n- **AWS IAM authentication for Vault**: the Vault issuer now supports IRSA, EKS Pod Identity, and ambient EC2/ECS credentials, removing the need for long-lived AWS Secrets. ([#&#8203;8422](https://redirect.github.com/cert-manager/cert-manager/issues/8422))\n- **Certificate renewal policies**: a new `renewalPolicies` field on the Certificate API provides more expressive control over renewal scheduling, complementing `renewBefore` and `renewBeforePercentage`. ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258))\n- **Configurable CertificateRequest retry backoff**: the new `--certificate-request-maximum-backoff-duration` flag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. ([#&#8203;8893](https://redirect.github.com/cert-manager/cert-manager/issues/8893))\n- **Modern2026 [PKCS#12](https://redirect.github.com/PKCS/cert-manager/issues/12) profile**: a new FIPS 140-3 compatible encoding profile using AES-256 + SHA-256 KDFs instead of legacy 3DES/RC2. ([#&#8203;8841](https://redirect.github.com/cert-manager/cert-manager/issues/8841))\n- **Webhook certificate renewal after system suspend**: the webhook now detects missed certificate renewals after system suspend (S3/S4) or VM live migration by polling wall-clock time, recovering within one minute of resume. ([#&#8203;8464](https://redirect.github.com/cert-manager/cert-manager/issues/8464))\n\n##### Gateway API and cainjector\n\n- **HTTP01 ListenerSet parentRef fallback**: the `acme.cert-manager.io/http01-parentreffallback: \"true\"` annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. ([#&#8203;8749](https://redirect.github.com/cert-manager/cert-manager/issues/8749))\n- **`cert-manager.io/ignore-tls-listeners` annotation**: exclude specific Gateway TLS listeners from certificate management. ([#&#8203;8727](https://redirect.github.com/cert-manager/cert-manager/issues/8727))\n- **Additional listener protocols**: configurable listener protocols beyond the default set. ([#&#8203;8683](https://redirect.github.com/cert-manager/cert-manager/issues/8683))\n- **`enableGatewayAPI` configuration restructure**: `enableGatewayAPI` and `enableGatewayAPIListenerSet` are deprecated in favor of `gatewayAPI.enabled` / `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://redirect.github.com/cert-manager/cert-manager/issues/8732))\n- **`CAInjectorMerging` promoted to GA**: unconditionally enabled; will be removed in a future release. ([#&#8203;8583](https://redirect.github.com/cert-manager/cert-manager/issues/8583))\n- **cainjector server-side apply unconditional**: the `ServerSideApply` feature gate is deprecated. ([#&#8203;8692](https://redirect.github.com/cert-manager/cert-manager/issues/8692))\n- **cainjector `--ignore-namespaces` flag**: skip specified namespaces when watching Secrets for injection. ([#&#8203;8614](https://redirect.github.com/cert-manager/cert-manager/issues/8614))\n\n##### Deployment and Observability\n\n- **Venafi OAuth token observability**: a new `AuthFailed` Issuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. ([#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808), [#&#8203;8779](https://redirect.github.com/cert-manager/cert-manager/issues/8779))\n- **`runtimeClassName` support**: configurable for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://redirect.github.com/cert-manager/cert-manager/issues/8791), [#&#8203;8976](https://redirect.github.com/cert-manager/cert-manager/issues/8976))\n- **`startupapicheck.ttlSecondsAfterFinished`**: opt-in automatic cleanup of the startupapicheck Job. ([#&#8203;8523](https://redirect.github.com/cert-manager/cert-manager/issues/8523))\n- **`--acme-http01-solver-extra-labels`**: propagate `global.commonLabels` to dynamically-created ACME HTTP01 solver resources. ([#&#8203;8761](https://redirect.github.com/cert-manager/cert-manager/issues/8761))\n\n##### Notable Bug Fixes\n\n- **Integer overflow in `renewBeforePercentage`**: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. ([#&#8203;8947](https://redirect.github.com/cert-manager/cert-manager/issues/8947))\n- **Infinite re-issuance loop**: cert-manager no longer loops when an issuer returns an already-expired certificate. ([#&#8203;8610](https://redirect.github.com/cert-manager/cert-manager/issues/8610))\n- **ACME transient network errors**: challenges no longer permanently fail on TLS handshake timeouts, DNS resolution failures, or context cancellation during nonce fetches and authorization waits. ([#&#8203;8760](https://redirect.github.com/cert-manager/cert-manager/issues/8760))\n- **DNS-over-HTTPS response body cap**: response body reads are now bounded at 128 KB to prevent potential OOM. ([#&#8203;8803](https://redirect.github.com/cert-manager/cert-manager/issues/8803))\n- **Vault path traversal**: the Vault issuer webhook now rejects `..` path segments, preventing `path.Join` from silently resolving relative segments. ([#&#8203;8930](https://redirect.github.com/cert-manager/cert-manager/issues/8930))\n- **DNS issuer secrets validated before ready**: prevents silent misconfiguration. ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255))\n\n#### Community\n\nAs always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.\n\nA special thanks to:\n\n- [@&#8203;Copilot](https://redirect.github.com/Copilot)\n- [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps)\n- [@&#8203;Peac36](https://redirect.github.com/Peac36)\n- [@&#8203;SebTardif](https://redirect.github.com/SebTardif)\n- [@&#8203;apkatsikas](https://redirect.github.com/apkatsikas)\n- [@&#8203;bitloi](https://redirect.github.com/bitloi)\n- [@&#8203;dap0am](https://redirect.github.com/dap0am)\n- [@&#8203;figaw](https://redirect.github.com/figaw)\n- [@&#8203;immanuwell](https://redirect.github.com/immanuwell)\n- [@&#8203;jabbrwcky](https://redirect.github.com/jabbrwcky)\n- [@&#8203;jnohlgard](https://redirect.github.com/jnohlgard)\n- [@&#8203;jsoref](https://redirect.github.com/jsoref)\n- [@&#8203;ltwongaa](https://redirect.github.com/ltwongaa)\n- [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite)\n- [@&#8203;mateenali66](https://redirect.github.com/mateenali66)\n- [@&#8203;onurmicoogullari](https://redirect.github.com/onurmicoogullari)\n- [@&#8203;putongyong](https://redirect.github.com/putongyong)\n- [@&#8203;seanorama](https://redirect.github.com/seanorama)\n- [@&#8203;texasich](https://redirect.github.com/texasich)\n\nfor their contributions, comments and support!\n\nAlso, thanks to the cert-manager maintainer team for their help in this release:\n\n- [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish)\n- [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot)\n- [@&#8203;erikgb](https://redirect.github.com/erikgb)\n- [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123)\n- [@&#8203;inteon](https://redirect.github.com/inteon)\n- [@&#8203;maelvls](https://redirect.github.com/maelvls)\n- [@&#8203;munnerz](https://redirect.github.com/munnerz)\n- [@&#8203;wallrj](https://redirect.github.com/wallrj)\n- [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark)\n\nAnd finally, thanks to the cert-manager steering committee for their feedback in this release cycle:\n\n- [@&#8203;FlorianLiebhart](https://redirect.github.com/FlorianLiebhart)\n- [@&#8203;TrilokGeer](https://redirect.github.com/TrilokGeer)\n- [@&#8203;ianarsenault](https://redirect.github.com/ianarsenault)\n- [@&#8203;ssyno](https://redirect.github.com/ssyno)\n\n#### Changes since v1.20.0\n\n##### Feature\n\n- Add Venafi OAuth token request observability and a new `AuthFailed` Issuer condition reason to distinguish bad credentials from transient infrastructure errors. ([#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Add `certificateRequestMaximumBackoffDuration` controller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file, `--certificate-request-maximum-backoff-duration` CLI flag, or Helm value `config.certificateRequestMaximumBackoffDuration`. Defaults to 32 hours for backward compatibility. ([#&#8203;8893](https://redirect.github.com/cert-manager/cert-manager/issues/8893), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Add an optional `waitInsteadOfSelfCheck` field to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. ([#&#8203;8858](https://redirect.github.com/cert-manager/cert-manager/issues/8858), [@&#8203;wallrj](https://redirect.github.com/wallrj))\n- Add configurable `runtimeClassName` support for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://redirect.github.com/cert-manager/cert-manager/issues/8791), [@&#8203;jsoref](https://redirect.github.com/jsoref))\n- Add direct configurable `runtimeClassName` support for ACME HTTP01 solver pods via the `acmesolver.runtimeClassName` Helm value. ([#&#8203;8976](https://redirect.github.com/cert-manager/cert-manager/issues/8976), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Add new controller flag `--acme-http01-solver-extra-labels`, allowing Helm's `global.commonLabels` to propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). ([#&#8203;8761](https://redirect.github.com/cert-manager/cert-manager/issues/8761), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Add opt-in `startupapicheck.ttlSecondsAfterFinished` Helm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. ([#&#8203;8523](https://redirect.github.com/cert-manager/cert-manager/issues/8523), [@&#8203;dap0am](https://redirect.github.com/dap0am))\n- Added ARI support through the ACMEUseARI feature gate. ([#&#8203;8798](https://redirect.github.com/cert-manager/cert-manager/issues/8798), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). ([#&#8203;8422](https://redirect.github.com/cert-manager/cert-manager/issues/8422), [@&#8203;bitloi](https://redirect.github.com/bitloi))\n- Added `cert-manager.io/ignore-tls-listeners` annotation for ignoring gwapi listeners. ([#&#8203;8727](https://redirect.github.com/cert-manager/cert-manager/issues/8727), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. ([#&#8203;8683](https://redirect.github.com/cert-manager/cert-manager/issues/8683), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3 ([#&#8203;8841](https://redirect.github.com/cert-manager/cert-manager/issues/8841), [@&#8203;seanorama](https://redirect.github.com/seanorama))\n- Cainjector: A new flag `--ignore-namespaces` was added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. ([#&#8203;8614](https://redirect.github.com/cert-manager/cert-manager/issues/8614), [@&#8203;figaw](https://redirect.github.com/figaw))\n- Disabled client side rate-limiting if AP\\&F is enabled. ([#&#8203;8757](https://redirect.github.com/cert-manager/cert-manager/issues/8757), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Extend the Venafi/CyberArk integration to also support PANW NGTS. ([#&#8203;8779](https://redirect.github.com/cert-manager/cert-manager/issues/8779), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Adding certificate renewal policies ([#&#8203;8258](https://redirect.github.com/cert-manager/cert-manager/issues/8258), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate ([#&#8203;8692](https://redirect.github.com/cert-manager/cert-manager/issues/8692), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Processed annotations `cert-manager.io/alt-names`, `cert-manager.io/ip-sans` to Certificates generated from ingress like objects in cert-shim controllers. ([#&#8203;8927](https://redirect.github.com/cert-manager/cert-manager/issues/8927), [@&#8203;jabbrwcky](https://redirect.github.com/jabbrwcky))\n- Promote the CAInjectorMerging feature gate to GA ([#&#8203;8583](https://redirect.github.com/cert-manager/cert-manager/issues/8583), [@&#8203;Copilot](https://redirect.github.com/Copilot))\n- When using ACME HTTP-01 with a ListenerSet, setting the annotation `acme.cert-manager.io/http01-parentreffallback: \"true\"` causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. ([#&#8203;8749](https://redirect.github.com/cert-manager/cert-manager/issues/8749), [@&#8203;apkatsikas](https://redirect.github.com/apkatsikas))\n\n##### Bug or Regression\n\n- **BREAKING**: The Helm chart no longer ships a default `Role` and `RoleBinding` granting the cert-manager controller ServiceAccount permission to create tokens for itself (`serviceaccounts/token: create`). This RBAC was added in v1.16 ([#&#8203;7213](https://redirect.github.com/cert-manager/cert-manager/issues/7213)) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely on `serviceAccountRef.name` pointing at the controller ServiceAccount (an undocumented pattern), you must now create your own `Role` and `RoleBinding` granting `serviceaccounts/token: create` on that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). ([#&#8203;8931](https://redirect.github.com/cert-manager/cert-manager/issues/8931), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- ACME challenges no longer terminally fail on transient network errors (TLS handshake timeouts, DNS failures, context cancellation) during nonce fetches and authorization waits. The challenge controller returns the error and lets the workqueue retry with backoff. ([#&#8203;8760](https://redirect.github.com/cert-manager/cert-manager/issues/8760), [@&#8203;texasich](https://redirect.github.com/texasich))\n- Add dns issuer secrets validation before marking it as ready ([#&#8203;8255](https://redirect.github.com/cert-manager/cert-manager/issues/8255), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Add missing issuer finalizer RBAC to the order controller to support owner references ([#&#8203;8654](https://redirect.github.com/cert-manager/cert-manager/issues/8654), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- ClusterIssuer metrics collector now correctly respects the enabled-controllers configuration, avoiding a redundant startup when only operating within a namespace. ([#&#8203;8822](https://redirect.github.com/cert-manager/cert-manager/issues/8822), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Fix Venafi TPP issuer setup and signing regression on master: restore authentication of the vcert connector in the client constructor, which was removed in [#&#8203;8808](https://redirect.github.com/cert-manager/cert-manager/issues/8808). ([#&#8203;8843](https://redirect.github.com/cert-manager/cert-manager/issues/8843), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Fix a performance issue in the certificateRequestApproval webhook where CertificateRequests referencing a GroupKind whose CRD is not yet installed would trigger repeated API server discovery queries on every admission request. Negative results are now cached for 30 seconds. ([#&#8203;8651](https://redirect.github.com/cert-manager/cert-manager/issues/8651), [@&#8203;mateenali66](https://redirect.github.com/mateenali66))\n- Fix webhook serving certificate not being renewed after system suspend. ([#&#8203;8464](https://redirect.github.com/cert-manager/cert-manager/issues/8464), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Fixed a rare panic in the trigger controller when a Certificate is deleted from the informer cache while a reconcile is in progress (e.g. during namespace teardown). ([#&#8203;8962](https://redirect.github.com/cert-manager/cert-manager/issues/8962), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Fixed an integer overflow in `renewBeforePercentage` calculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. ([#&#8203;8947](https://redirect.github.com/cert-manager/cert-manager/issues/8947), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8619](https://redirect.github.com/cert-manager/cert-manager/issues/8619), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Fixed infinite re-issuance loop when issuer returns an already expired certificate ([#&#8203;8610](https://redirect.github.com/cert-manager/cert-manager/issues/8610), [@&#8203;onurmicoogullari](https://redirect.github.com/onurmicoogullari))\n- Fixed local `e2e-setup-samplewebhook` installation to use the samplewebhook image repository and tag from the saved image tarball manifest. ([#&#8203;8821](https://redirect.github.com/cert-manager/cert-manager/issues/8821), [@&#8203;wallrj](https://redirect.github.com/wallrj))\n- Fixed potential OOM in DNS-over-HTTPS client by bounding response body read with io.LimitReader (128 KB cap). ([#&#8203;8803](https://redirect.github.com/cert-manager/cert-manager/issues/8803), [@&#8203;SebTardif](https://redirect.github.com/SebTardif))\n- Fixed validation of timezone-prefixed renewal window cron specs without a schedule. ([#&#8203;8813](https://redirect.github.com/cert-manager/cert-manager/issues/8813), [@&#8203;immanuwell](https://redirect.github.com/immanuwell))\n- Helm chart bugfix: rename image helper to avoid umbrella chart conflicts ([#&#8203;8753](https://redirect.github.com/cert-manager/cert-manager/issues/8753), [@&#8203;FelixPhipps](https://redirect.github.com/FelixPhipps))\n- Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8664](https://redirect.github.com/cert-manager/cert-manager/issues/8664), [@&#8203;jnohlgard](https://redirect.github.com/jnohlgard))\n- Remove ACME Challenge `create` and Order `create`/`patch`/`update` from the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). ([#&#8203;8958](https://redirect.github.com/cert-manager/cert-manager/issues/8958), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8743](https://redirect.github.com/cert-manager/cert-manager/issues/8743), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Update logic to identify and preserve the secret matching nextPrivateKeySecretName ([#&#8203;8577](https://redirect.github.com/cert-manager/cert-manager/issues/8577), [@&#8203;putongyong](https://redirect.github.com/putongyong))\n- Vault Issuer webhook validation now rejects `..` path segments in `spec.vault.path` and auth mount path fields, preventing `path.Join` from silently resolving relative segments before constructing the Vault API request. ([#&#8203;8930](https://redirect.github.com/cert-manager/cert-manager/issues/8930), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n##### Other (Cleanup or Flake)\n\n- API cleanup: removed deprecated ObjectReference ([#&#8203;8625](https://redirect.github.com/cert-manager/cert-manager/issues/8625), [@&#8203;inteon](https://redirect.github.com/inteon))\n- Remove Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path`. The metrics path is always `/metrics` and the target port is always `http-metrics`. Rename the controller service metrics port from `tcp-prometheus-servicemonitor` to `http-metrics` for consistency with other workloads. Users must remove these keys from their value overrides before upgrading. ([#&#8203;8952](https://redirect.github.com/cert-manager/cert-manager/issues/8952), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- The `enableGatewayAPI` and `enableGatewayAPIListenerSet` fields on `ControllerConfiguration` are deprecated and moved into the `gatewayAPI` sub-struct as `gatewayAPI.enabled` and `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://redirect.github.com/cert-manager/cert-manager/issues/8732), [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))\n- Update base images to Debian 13 ([#&#8203;8849](https://redirect.github.com/cert-manager/cert-manager/issues/8849), [@&#8203;ltwongaa](https://redirect.github.com/ltwongaa))\n\n### [`v1.20.3`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.3)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.2...v1.20.3)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.\n\nThis release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.\n\nAll users should upgrade.\n\n> \\[!WARNING]\n> **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate \u2192 CertificateRequest \u2192 Order \u2192 Challenge flow), you will need to grant those permissions explicitly.\n\n#### Changes by Kind\n\n##### Bug or Regression\n\n- Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8940](https://redirect.github.com/cert-manager/cert-manager/issues/8940), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8759](https://redirect.github.com/cert-manager/cert-manager/issues/8759), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Bump go to 1.26.3, other deps to fix several govulncheck issues ([#&#8203;8789](https://redirect.github.com/cert-manager/cert-manager/issues/8789), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.26.4` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8926](https://redirect.github.com/cert-manager/cert-manager/issues/8926), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n### [`v1.20.2`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.2)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.1...v1.20.2)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.2 fixes invalid YAML generated in the Helm chart when both `webhook.config`\nand `webhook.volumes` are defined, and bumps Go to 1.26.2 along with dependencies\nto address reported vulnerabilities.\n\n#### Changes by Kind\n\n##### Bug or Regression\n\n- Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8665](https://redirect.github.com/cert-manager/cert-manager/issues/8665), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Bump go dependencies with reported vulnerabilities ([#&#8203;8704](https://redirect.github.com/cert-manager/cert-manager/issues/8704), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump go to 1.26.2 ([#&#8203;8703](https://redirect.github.com/cert-manager/cert-manager/issues/8703), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.20.1`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.20.0...v1.20.1)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate `parentRef` bug when both issuer config and annotations are present (Gateway API).\n\n##### Bug or Regression\n\n- Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8658](https://redirect.github.com/cert-manager/cert-manager/issues/8658), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Add missing issuer finalizer RBAC to the order controller to support owner references. This was preventing OpenShift users from being able to upgrade to v1.20.0. ([#&#8203;8655](https://redirect.github.com/cert-manager/cert-manager/issues/8655), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump google.golang.org/grpc to fix vulnerability reported by scanners. This isn't a vulnerability that affects cert-manager, but we are bumping it because it is reported by scanners. ([#&#8203;8657](https://redirect.github.com/cert-manager/cert-manager/issues/8657), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.20.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.20.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.6...v1.20.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.\n\n##### Changes by Kind\n\n##### Feature\n\n- Added a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. ([#&#8203;8370](https://redirect.github.com/cert-manager/cert-manager/issues/8370), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- Added selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} ([#&#8203;8256](https://redirect.github.com/cert-manager/cert-manager/issues/8256), [@&#8203;tareksha](https://redirect.github.com/tareksha))\n- Added support for specifying `imagePullSecrets` in the `startupapicheck-job` Helm template to enable pulling images from private registries. ([#&#8203;8186](https://redirect.github.com/cert-manager/cert-manager/issues/8186), [@&#8203;mathieu-clnk](https://redirect.github.com/mathieu-clnk))\n- Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. ([#&#8203;8355](https://redirect.github.com/cert-manager/cert-manager/issues/8355), [@&#8203;dancmeyers](https://redirect.github.com/dancmeyers))\n- Added `parentRef` override annotations on the Certificate resource. ([#&#8203;8518](https://redirect.github.com/cert-manager/cert-manager/issues/8518), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added support for azure private zones for dns01 issuer. ([#&#8203;8494](https://redirect.github.com/cert-manager/cert-manager/issues/8494), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. ([#&#8203;7642](https://redirect.github.com/cert-manager/cert-manager/issues/7642), [@&#8203;robertlestak](https://redirect.github.com/robertlestak))\n- Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget ([#&#8203;7728](https://redirect.github.com/cert-manager/cert-manager/issues/7728), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- For Venafi provider, read `venafi.cert-manager.io/custom-fields` annotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. ([#&#8203;8301](https://redirect.github.com/cert-manager/cert-manager/issues/8301), [@&#8203;k0da](https://redirect.github.com/k0da))\n- Improve error message when CA issuers are misconfigured to use a clashing secret name ([#&#8203;8374](https://redirect.github.com/cert-manager/cert-manager/issues/8374), [@&#8203;majiayu000](https://redirect.github.com/majiayu000))\n- Introduce a new Ingress annotation `acme.cert-manager.io/http01-ingress-ingressclassname` to override `http01.ingress.ingressClassName` field in HTTP-01 challenge solvers. ([#&#8203;8244](https://redirect.github.com/cert-manager/cert-manager/issues/8244), [@&#8203;lunarwhite](https://redirect.github.com/lunarwhite))\n- Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8195](https://redirect.github.com/cert-manager/cert-manager/issues/8195), [@&#8203;StingRayZA](https://redirect.github.com/StingRayZA))\n- Vault issuers will now include the Vault server address as one of the default audiences on generated service account tokens. ([#&#8203;8228](https://redirect.github.com/cert-manager/cert-manager/issues/8228), [@&#8203;terinjokes](https://redirect.github.com/terinjokes))\n- Added experimental `XListenerSets` feature gate ([#&#8203;8394](https://redirect.github.com/cert-manager/cert-manager/issues/8394), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n\n##### Documentation\n\n- Add GWAPI documentation to NOTES.TXT in helm chart ([#&#8203;8353](https://redirect.github.com/cert-manager/cert-manager/issues/8353), [@&#8203;jaxels10](https://redirect.github.com/jaxels10))\n\n##### Bug or Regression\n\n- Adds logs for cases when acme server returns us a fatal error in the order controller ([#&#8203;8199](https://redirect.github.com/cert-manager/cert-manager/issues/8199), [@&#8203;Peac36](https://redirect.github.com/Peac36))\n- Fixed an issue where kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed ([#&#8203;8160](https://redirect.github.com/cert-manager/cert-manager/issues/8160), [@&#8203;inteon](https://redirect.github.com/inteon))\n- Changes to the Duration and RenewBefore annotations on ingress and gateway-api resources will now trigger certificate updates. ([#&#8203;8232](https://redirect.github.com/cert-manager/cert-manager/issues/8232), [@&#8203;eleanor-merry](https://redirect.github.com/eleanor-merry))\n- Fix an issue where ACME challenge TXT records are not cleaned up when there are many resource records in CloudDNS. ([#&#8203;8456](https://redirect.github.com/cert-manager/cert-manager/issues/8456), [@&#8203;tkna](https://redirect.github.com/tkna))\n- Fix unregulated retries with the DigitalOcean DNS-01 solver\n  Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging ([#&#8203;8221](https://redirect.github.com/cert-manager/cert-manager/issues/8221), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8403](https://redirect.github.com/cert-manager/cert-manager/issues/8403), [@&#8203;calm329](https://redirect.github.com/calm329))\n- Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8424](https://redirect.github.com/cert-manager/cert-manager/issues/8424), [@&#8203;SlashNephy](https://redirect.github.com/SlashNephy))\n- Fixed the HTTP-01 Gateway solver creating invalid HTTPRoutes by not setting spec.hostnames when the challenge DNSName is an IP address. ([#&#8203;8443](https://redirect.github.com/cert-manager/cert-manager/issues/8443), [@&#8203;alviss7](https://redirect.github.com/alviss7))\n- Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8173](https://redirect.github.com/cert-manager/cert-manager/issues/8173), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8469](https://redirect.github.com/cert-manager/cert-manager/issues/8469), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8290](https://redirect.github.com/cert-manager/cert-manager/issues/8290), [@&#8203;octo-sts](https://redirect.github.com/octo-sts)\\[bot])\n- When Prometheus monitoring is enabled, the metrics label is now set to the intended value of `cert-manager`. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). ([#&#8203;8162](https://redirect.github.com/cert-manager/cert-manager/issues/8162), [@&#8203;LiquidPL](https://redirect.github.com/LiquidPL))\n\n##### Other (Cleanup or Flake)\n\n- Promoted the OtherNames feature to Beta and enabled it by default ([#&#8203;8288](https://redirect.github.com/cert-manager/cert-manager/issues/8288), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Promoting `XListenerSets` feature gate to `ListenerSets` ([#&#8203;8501](https://redirect.github.com/cert-manager/cert-manager/issues/8501), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n- Rebranding of the Venafi Issuer to CyberArk ([#&#8203;8215](https://redirect.github.com/cert-manager/cert-manager/issues/8215), [@&#8203;iossifbenbassat123](https://redirect.github.com/iossifbenbassat123))\n- Switched to SSA for challenge finalizer updates ([#&#8203;8519](https://redirect.github.com/cert-manager/cert-manager/issues/8519), [@&#8203;inteon](https://redirect.github.com/inteon))\n- The default container user (UID) is now 65532 (previously 1000) and the default container group (GID) is now 65532 (previously 0) ([#&#8203;8408](https://redirect.github.com/cert-manager/cert-manager/issues/8408), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- The feature-gate DefaultPrivateKeyRotationPolicyAlways moved from Beta to GA and can no longer be disabled. ([#&#8203;8287](https://redirect.github.com/cert-manager/cert-manager/issues/8287), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Update cert-manager's ACME client, forked from golang/x/crypto ([#&#8203;8268](https://redirect.github.com/cert-manager/cert-manager/issues/8268), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Use the latest version of Kyverno (1.16.2) in the best-practice installation tests ([#&#8203;8389](https://redirect.github.com/cert-manager/cert-manager/issues/8389), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- We stopped testing with Coutour due to it not supporting the new XListenerSet resource, and moved to kgateway. ([#&#8203;8426](https://redirect.github.com/cert-manager/cert-manager/issues/8426), [@&#8203;hjoshi123](https://redirect.github.com/hjoshi123))\n\n### [`v1.19.6`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.6)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.5...v1.19.6)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.\n\nThis release also includes Go version bumps to address reported CVEs. All users should upgrade.\n\n> \\[!WARNING]\n> **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate \u2192 CertificateRequest \u2192 Order \u2192 Challenge flow), you will need to grant those permissions explicitly.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8941](https://redirect.github.com/cert-manager/cert-manager/pull/8941), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n##### Other (Cleanup or Flake)\n\n- Update Go to `v1.25.11` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8925](https://redirect.github.com/cert-manager/cert-manager/pull/8925), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Upgrade Go to 1.25.10 to fix reported vulnerabilities, along with other dependency bumps ([#&#8203;8788](https://redirect.github.com/cert-manager/cert-manager/pull/8788), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.5`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.5)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.4...v1.19.5)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.\n\n##### Changes by Kind\n\n##### Other (Cleanup or Flake)\n\n- Bump go dependencies with reported vulnerabilities ([#&#8203;8706](https://redirect.github.com/cert-manager/cert-manager/pull/8706), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Bump go to 1.25.8 to address several reported vulnerabilities ([#&#8203;8628](https://redirect.github.com/cert-manager/cert-manager/pull/8628), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Bump go to 1.25.9 ([#&#8203;8705](https://redirect.github.com/cert-manager/cert-manager/pull/8705), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n\n### [`v1.19.4`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.4)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.3...v1.19.4)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nv1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Bump go to address CVE-2025-68121 ([#&#8203;8526](https://redirect.github.com/cert-manager/cert-manager/issues/8526), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Bump otel SDK to address GO-2026-4394 ([#&#8203;8531](https://redirect.github.com/cert-manager/cert-manager/issues/8531), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.3`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.3)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.2...v1.19.3)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nThis release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.\n\n##### Changes by Kind\n\n##### Bug or Regression\n\n- Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8415](https://redirect.github.com/cert-manager/cert-manager/issues/8415), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Fixed an issue where HTTP-01 challenges failed when the Host header contained an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8436](https://redirect.github.com/cert-manager/cert-manager/issues/8436), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8468](https://redirect.github.com/cert-manager/cert-manager/issues/8468), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n##### Other (Cleanup or Flake)\n\n- Bump go to 1.25.6 ([#&#8203;8459](https://redirect.github.com/cert-manager/cert-manager/issues/8459), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n\n### [`v1.19.2`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.2)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.1...v1.19.2)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nWe updated Go to fix some vulnerabilities in the standard library.\n\n> \ud83d\udcd6 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading.\n\n#### Changes since `v1.19.1`\n\n##### Bug or Regression\n\n- Address false positive vulnerabilities `CVE-2025-47914` and `CVE-2025-58181` which were reported by Trivy. ([#&#8203;8283](https://redirect.github.com/cert-manager/cert-manager/issues/8283), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8294](https://redirect.github.com/cert-manager/cert-manager/issues/8294), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8233](https://redirect.github.com/cert-manager/cert-manager/issues/8233), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n##### Other (Cleanup or Flake)\n\n- Update cert-manager's ACME client, forked from `golang/x/crypto` ([#&#8203;8270](https://redirect.github.com/cert-manager/cert-manager/issues/8270), [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))\n- Updated Debian 12 distroless base images ([#&#8203;8326](https://redirect.github.com/cert-manager/cert-manager/issues/8326), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n\n### [`v1.19.1`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.1)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.19.0...v1.19.1)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\nWe reverted the CRD-based API defaults for `Certificate.Spec.IssuerRef` and `CertificateRequest.Spec.IssuerRef` after they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager `1.20`.\nWe fixed a bug that caused certificates to be re-issued unexpectedly if the `issuerRef` kind or group was changed to one of the \"runtime\" default values.\nWe upgraded Go to `1.25.3` to address the following security vulnerabilities: `CVE-2025-61724`, `CVE-2025-58187`, `CVE-2025-47912`, `CVE-2025-58183`, `CVE-2025-61723`, `CVE-2025-58186`, `CVE-2025-58185`, `CVE-2025-58188`, and `CVE-2025-61725`.\n\n> \ud83d\udcd6 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading.\n\nChanges since `v1.19.0`:\n\n##### Bug or Regression\n\n- BUGFIX: in case kind or group in the `issuerRef` of a Certificate was omitted, upgrading to `1.19.x` incorrectly caused the certificate to be renewed ([#&#8203;8175](https://redirect.github.com/cert-manager/cert-manager/issues/8175), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n- Bump Go to 1.25.3 to fix a backwards incompatible change to the validation of DNS names in X.509 SAN fields which prevented the use of DNS names with a trailing dot ([#&#8203;8177](https://redirect.github.com/cert-manager/cert-manager/issues/8177), [@&#8203;wallrj-cyberark](https://redirect.github.com/wallrj-cyberark))\n- Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8178](https://redirect.github.com/cert-manager/cert-manager/issues/8178), [@&#8203;cert-manager-bot](https://redirect.github.com/cert-manager-bot))\n\n### [`v1.19.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.0)\n\n[Compare Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.18.6...v1.19.0)\n\ncert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.\n\n> \u26a0\ufe0f **Known issues**: The following known issues are fixed in [v1.19.1](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.19.1):\n>\n> - [Unexpected certificate renewal after upgrading to 1.19.0](https://redirect.github.com/cert-manager/cert-manager/issues/8158)\n\nThis release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues.\n\n> \ud83d\udcd6  Read the full release notes at cert-manager.io: <https://cert-manager.io/docs/releases/release-notes/release-notes-1.19>\n\nChanges since `v1.18.0`:\n\n##### Feature\n\n- Add IPv6 rules to the default network policy ([#&#8203;7726](https://redirect.github.com/cert-manager/cert-manager/issues/7726), [@&#8203;jcpunk](https://redirect.github.com/jcpunk))\n- Add `global.nodeSelector` to helm chart to allow for a single `nodeSelector` to be set across all services. ([#&#8203;7818](https://redirect.github.com/cert-manager/cert-manager/issues/7818), [@&#8203;StingRayZA](https://redirect.github.com/StingRayZA))\n- Add a feature gate to default to Ingress `pathType` `Exact` in ACME HTTP01 Ingress challenge solvers. ([#&#8203;7795](https://redirect.github.com/cert-manager/cert-manager/issues/7795), [@&#8203;sspreitzer](https://redirect.github.com/sspreitzer))\n- Add generated `applyconfigurations` allowing clients to make type-safe server-side apply requests for cert-manager resources. ([#&#8203;7866](https://redirect.github.com/cert-manager/cert-manager/issues/7866), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). ([#&#8203;7414](https://redirect.github.com/cert-manager/cert-manager/issues/7414), [@&#8203;erikgb](https://redirect.github.com/erikgb))\n- Added `certmanager_certificate_challenge_status` Prometheus metric. ([#&#8203;7736](https://re\n\n> \u2702 **Note**\n> \n> PR body was truncated to here.\n\n\n</details>\n\n---\n\n### Configuration\n\n\ud83d\udcc5 **Schedule**: (UTC)\n\n- Branch creation\n  - At any time (no schedule defined)\n- Automerge\n  - At any time (no schedule defined)\n\n\ud83d\udea6 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.\n\n\u267b **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.\n\n\ud83d\udd15 **Ignore**: Close this PR and you won't be reminded about this update again.\n\n---\n\n - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/vexxhost/atmosphere.common).\n<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMzEuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->\n",
                                            "change_url": "https://github.com/vexxhost/atmosphere.common/pull/105",
                                            "commit_id": "4ab174a72079e89cc7e61a674221eb9e91158c0c",
                                            "patchset": "4ab174a72079e89cc7e61a674221eb9e91158c0c",
                                            "project": {
                                                "canonical_hostname": "github.com",
                                                "canonical_name": "github.com/vexxhost/atmosphere.common",
                                                "name": "vexxhost/atmosphere.common",
                                                "short_name": "atmosphere.common",
                                                "src_dir": "src/github.com/vexxhost/atmosphere.common"
                                            },
                                            "topic": null
                                        }
                                    ],
                                    "collections_path": "/home/zuul/.ansible/collections",
                                    "executable": "uv",
                                    "project_dir": "src/github.com/vexxhost/atmosphere.common",
                                    "projects": [
                                        {
                                            "canonical_hostname": "github.com",
                                            "canonical_name": "github.com/vexxhost/atmosphere.common",
                                            "checkout": "main",
                                            "checkout_description": "zuul branch",
                                            "commit": "efc39c0f1736643f058dfcd25f6e7e04f89f1840",
                                            "name": "vexxhost/atmosphere.common",
                                            "required": false,
                                            "short_name": "atmosphere.common",
                                            "src_dir": "src/github.com/vexxhost/atmosphere.common"
                                        }
                                    ],
                                    "workspace_dir": "/home/zuul"
                                }
                            },
                            "log": [
                                "Skipping kubernetes.core: no checked-out sibling",
                                "Skipping openstack.cloud: no checked-out sibling",
                                "Skipping vexxhost.kubernetes: no checked-out sibling"
                            ],
                            "msg": "Skipping kubernetes.core: no checked-out sibling\nSkipping openstack.cloud: no checked-out sibling\nSkipping vexxhost.kubernetes: no checked-out sibling"
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:07.561380Z",
                            "start": "2026-07-29T18:31:07.157000Z"
                        },
                        "id": "0242ac17-0010-37e0-b0c9-00000000000a",
                        "name": "Install Ansible collection siblings"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 2,
            "failures": 0,
            "ignored": 0,
            "ok": 3,
            "rescued": 0,
            "skipped": 0,
            "unreachable": 0
        }
    },
    "trusted": false
},
{
    "branch": "main",
    "index": "2",
    "phase": "pre",
    "playbook": "github.com/vexxhost/atmosphere.common/test-playbooks/molecule/pre.yml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:31:16.770997Z",
                    "start": "2026-07-29T18:31:08.325351Z"
                },
                "id": "0242ac17-0010-4326-8b81-000000000002",
                "name": "Prepare Molecule log collection"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.apt",
                            "cache_update_time": 1785349873,
                            "cache_updated": true,
                            "changed": true,
                            "diff": {},
                            "invocation": {
                                "module_args": {
                                    "allow_change_held_packages": false,
                                    "allow_downgrade": false,
                                    "allow_unauthenticated": false,
                                    "autoclean": false,
                                    "autoremove": false,
                                    "cache_valid_time": 0,
                                    "clean": false,
                                    "deb": null,
                                    "default_release": null,
                                    "dpkg_options": "force-confdef,force-confold",
                                    "fail_on_autoremove": false,
                                    "force": false,
                                    "force_apt_get": false,
                                    "install_recommends": null,
                                    "lock_timeout": 60,
                                    "name": "jq",
                                    "only_upgrade": false,
                                    "package": [
                                        "jq"
                                    ],
                                    "policy_rc_d": null,
                                    "purge": false,
                                    "state": "present",
                                    "update_cache": true,
                                    "update_cache_retries": 5,
                                    "update_cache_retry_max_delay": 12,
                                    "upgrade": null
                                }
                            },
                            "stderr": "debconf: delaying package configuration, since apt-utils is not installed\n",
                            "stderr_lines": [
                                "debconf: delaying package configuration, since apt-utils is not installed"
                            ],
                            "stdout": "Reading package lists...\nBuilding dependency tree...\nReading state information...\nThe following additional packages will be installed:\n  libjq1 libonig5\nThe following NEW packages will be installed:\n  jq libjq1 libonig5\n0 upgraded, 3 newly installed, 0 to remove and 7 not upgraded.\nNeed to get 380 kB of archives.\nAfter this operation, 1127 kB of additional disk space will be used.\nGet:1 http://nova.clouds.archive.ubuntu.com/ubuntu noble/main amd64 libonig5 amd64 6.9.9-1build1 [172 kB]\nGet:2 http://nova.clouds.archive.ubuntu.com/ubuntu noble-updates/main amd64 libjq1 amd64 1.7.1-3ubuntu0.24.04.2 [142 kB]\nGet:3 http://nova.clouds.archive.ubuntu.com/ubuntu noble-updates/main amd64 jq amd64 1.7.1-3ubuntu0.24.04.2 [65.7 kB]\nFetched 380 kB in 1s (578 kB/s)\nSelecting previously unselected package libonig5:amd64.\r\n(Reading database ... \r(Reading database ... 5%\r(Reading database ... 10%\r(Reading database ... 15%\r(Reading database ... 20%\r(Reading database ... 25%\r(Reading database ... 30%\r(Reading database ... 35%\r(Reading database ... 40%\r(Reading database ... 45%\r(Reading database ... 50%\r(Reading database ... 55%\r(Reading database ... 60%\r(Reading database ... 65%\r(Reading database ... 70%\r(Reading database ... 75%\r(Reading database ... 80%\r(Reading database ... 85%\r(Reading database ... 90%\r(Reading database ... 95%\r(Reading database ... 100%\r(Reading database ... 31295 files and directories currently installed.)\r\nPreparing to unpack .../libonig5_6.9.9-1build1_amd64.deb ...\r\nUnpacking libonig5:amd64 (6.9.9-1build1) ...\r\nSelecting previously unselected package libjq1:amd64.\r\nPreparing to unpack .../libjq1_1.7.1-3ubuntu0.24.04.2_amd64.deb ...\r\nUnpacking libjq1:amd64 (1.7.1-3ubuntu0.24.04.2) ...\r\nSelecting previously unselected package jq.\r\nPreparing to unpack .../jq_1.7.1-3ubuntu0.24.04.2_amd64.deb ...\r\nUnpacking jq (1.7.1-3ubuntu0.24.04.2) ...\r\nSetting up libonig5:amd64 (6.9.9-1build1) ...\r\nSetting up libjq1:amd64 (1.7.1-3ubuntu0.24.04.2) ...\r\nSetting up jq (1.7.1-3ubuntu0.24.04.2) ...\r\nProcessing triggers for libc-bin (2.39-0ubuntu8.7) ...\r\n",
                            "stdout_lines": [
                                "Reading package lists...",
                                "Building dependency tree...",
                                "Reading state information...",
                                "The following additional packages will be installed:",
                                "  libjq1 libonig5",
                                "The following NEW packages will be installed:",
                                "  jq libjq1 libonig5",
                                "0 upgraded, 3 newly installed, 0 to remove and 7 not upgraded.",
                                "Need to get 380 kB of archives.",
                                "After this operation, 1127 kB of additional disk space will be used.",
                                "Get:1 http://nova.clouds.archive.ubuntu.com/ubuntu noble/main amd64 libonig5 amd64 6.9.9-1build1 [172 kB]",
                                "Get:2 http://nova.clouds.archive.ubuntu.com/ubuntu noble-updates/main amd64 libjq1 amd64 1.7.1-3ubuntu0.24.04.2 [142 kB]",
                                "Get:3 http://nova.clouds.archive.ubuntu.com/ubuntu noble-updates/main amd64 jq amd64 1.7.1-3ubuntu0.24.04.2 [65.7 kB]",
                                "Fetched 380 kB in 1s (578 kB/s)",
                                "Selecting previously unselected package libonig5:amd64.",
                                "(Reading database ... ",
                                "(Reading database ... 5%",
                                "(Reading database ... 10%",
                                "(Reading database ... 15%",
                                "(Reading database ... 20%",
                                "(Reading database ... 25%",
                                "(Reading database ... 30%",
                                "(Reading database ... 35%",
                                "(Reading database ... 40%",
                                "(Reading database ... 45%",
                                "(Reading database ... 50%",
                                "(Reading database ... 55%",
                                "(Reading database ... 60%",
                                "(Reading database ... 65%",
                                "(Reading database ... 70%",
                                "(Reading database ... 75%",
                                "(Reading database ... 80%",
                                "(Reading database ... 85%",
                                "(Reading database ... 90%",
                                "(Reading database ... 95%",
                                "(Reading database ... 100%",
                                "(Reading database ... 31295 files and directories currently installed.)",
                                "Preparing to unpack .../libonig5_6.9.9-1build1_amd64.deb ...",
                                "Unpacking libonig5:amd64 (6.9.9-1build1) ...",
                                "Selecting previously unselected package libjq1:amd64.",
                                "Preparing to unpack .../libjq1_1.7.1-3ubuntu0.24.04.2_amd64.deb ...",
                                "Unpacking libjq1:amd64 (1.7.1-3ubuntu0.24.04.2) ...",
                                "Selecting previously unselected package jq.",
                                "Preparing to unpack .../jq_1.7.1-3ubuntu0.24.04.2_amd64.deb ...",
                                "Unpacking jq (1.7.1-3ubuntu0.24.04.2) ...",
                                "Setting up libonig5:amd64 (6.9.9-1build1) ...",
                                "Setting up libjq1:amd64 (1.7.1-3ubuntu0.24.04.2) ...",
                                "Setting up jq (1.7.1-3ubuntu0.24.04.2) ...",
                                "Processing triggers for libc-bin (2.39-0ubuntu8.7) ..."
                            ]
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:16.770997Z",
                            "start": "2026-07-29T18:31:08.336619Z"
                        },
                        "id": "0242ac17-0010-4326-8b81-000000000004",
                        "name": "Install jq for log collection"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 1,
            "failures": 0,
            "ignored": 0,
            "ok": 1,
            "rescued": 0,
            "skipped": 0,
            "unreachable": 0
        }
    },
    "trusted": false
},
{
    "branch": "main",
    "index": "0",
    "phase": "run",
    "playbook": "github.com/vexxhost/zuul-jobs/playbooks/molecule/run.yaml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:35:53.575273Z",
                    "start": "2026-07-29T18:31:17.474763Z"
                },
                "id": "0242ac17-0010-1989-7ad7-000000000002",
                "name": "all"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.stat",
                            "changed": false,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "checksum_algorithm": "sha1",
                                            "follow": true,
                                            "get_attributes": true,
                                            "get_checksum": true,
                                            "get_mime": true,
                                            "path": "src/github.com/vexxhost/atmosphere.common"
                                        }
                                    },
                                    "item": "src/github.com/vexxhost/atmosphere.common",
                                    "stat": {
                                        "atime": 1785349861.9658697,
                                        "attr_flags": "e",
                                        "attributes": [
                                            "extents"
                                        ],
                                        "block_size": 4096,
                                        "blocks": 8,
                                        "charset": "unknown",
                                        "ctime": 1785349861.986871,
                                        "dev": 64769,
                                        "device_type": 0,
                                        "executable": true,
                                        "exists": true,
                                        "gid": 1000,
                                        "gr_name": "zuul",
                                        "inode": 1023520,
                                        "isblk": false,
                                        "ischr": false,
                                        "isdir": true,
                                        "isfifo": false,
                                        "isgid": false,
                                        "islnk": false,
                                        "isreg": false,
                                        "issock": false,
                                        "isuid": false,
                                        "mimetype": "unknown",
                                        "mode": "0755",
                                        "mtime": 1785349844.6832364,
                                        "nlink": 10,
                                        "path": "src/github.com/vexxhost/atmosphere.common",
                                        "pw_name": "zuul",
                                        "readable": true,
                                        "rgrp": true,
                                        "roth": true,
                                        "rusr": true,
                                        "size": 4096,
                                        "uid": 1000,
                                        "version": "426589368",
                                        "wgrp": false,
                                        "woth": false,
                                        "writeable": true,
                                        "wusr": true,
                                        "xgrp": true,
                                        "xoth": true,
                                        "xusr": true
                                    }
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "checksum_algorithm": "sha1",
                                            "follow": true,
                                            "get_attributes": true,
                                            "get_checksum": true,
                                            "get_mime": true,
                                            "path": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory"
                                        }
                                    },
                                    "item": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory",
                                    "stat": {
                                        "exists": false
                                    }
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "checksum_algorithm": "sha1",
                                            "follow": true,
                                            "get_attributes": true,
                                            "get_checksum": true,
                                            "get_mime": true,
                                            "path": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory"
                                        }
                                    },
                                    "item": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory",
                                    "stat": {
                                        "exists": false
                                    }
                                }
                            ]
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:18.227285Z",
                            "start": "2026-07-29T18:31:17.486221Z"
                        },
                        "id": "0242ac17-0010-1989-7ad7-000000000004",
                        "name": "Check inventory directories"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.copy",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "item",
                                    "changed": true,
                                    "checksum": "343f67e66be64538cd48c172cb471469d311a570",
                                    "dest": "src/github.com/vexxhost/atmosphere.common/inventory.yaml",
                                    "diff": [],
                                    "failed": false,
                                    "gid": 1000,
                                    "group": "zuul",
                                    "invocation": {
                                        "module_args": {
                                            "_original_basename": "inventory.yaml",
                                            "attributes": null,
                                            "backup": false,
                                            "checksum": "343f67e66be64538cd48c172cb471469d311a570",
                                            "content": null,
                                            "dest": "src/github.com/vexxhost/atmosphere.common",
                                            "directory_mode": null,
                                            "follow": false,
                                            "force": true,
                                            "group": null,
                                            "local_follow": null,
                                            "mode": "0644",
                                            "owner": null,
                                            "remote_src": null,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349878.2947528-9-71122444013686/source",
                                            "unsafe_writes": false,
                                            "validate": null
                                        }
                                    },
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common",
                                        "stat": {
                                            "atime": 1785349861.9658697,
                                            "attr_flags": "e",
                                            "attributes": [
                                                "extents"
                                            ],
                                            "block_size": 4096,
                                            "blocks": 8,
                                            "charset": "unknown",
                                            "ctime": 1785349861.986871,
                                            "dev": 64769,
                                            "device_type": 0,
                                            "executable": true,
                                            "exists": true,
                                            "gid": 1000,
                                            "gr_name": "zuul",
                                            "inode": 1023520,
                                            "isblk": false,
                                            "ischr": false,
                                            "isdir": true,
                                            "isfifo": false,
                                            "isgid": false,
                                            "islnk": false,
                                            "isreg": false,
                                            "issock": false,
                                            "isuid": false,
                                            "mimetype": "unknown",
                                            "mode": "0755",
                                            "mtime": 1785349844.6832364,
                                            "nlink": 10,
                                            "path": "src/github.com/vexxhost/atmosphere.common",
                                            "pw_name": "zuul",
                                            "readable": true,
                                            "rgrp": true,
                                            "roth": true,
                                            "rusr": true,
                                            "size": 4096,
                                            "uid": 1000,
                                            "version": "426589368",
                                            "wgrp": false,
                                            "woth": false,
                                            "writeable": true,
                                            "wusr": true,
                                            "xgrp": true,
                                            "xoth": true,
                                            "xusr": true
                                        }
                                    },
                                    "md5sum": "b8249fd6b3e358de671df5157d471023",
                                    "mode": "0644",
                                    "owner": "zuul",
                                    "size": 351328,
                                    "src": "/home/zuul/.ansible/tmp/ansible-tmp-1785349878.2947528-9-71122444013686/source",
                                    "state": "file",
                                    "uid": 1000
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "false_condition": "item.stat.isdir | default(false)",
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory",
                                        "stat": {
                                            "exists": false
                                        }
                                    },
                                    "skip_reason": "Conditional result was False",
                                    "skipped": true
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "false_condition": "item.stat.isdir | default(false)",
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory",
                                        "stat": {
                                            "exists": false
                                        }
                                    },
                                    "skip_reason": "Conditional result was False",
                                    "skipped": true
                                }
                            ]
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:19.187928Z",
                            "start": "2026-07-29T18:31:18.235418Z"
                        },
                        "id": "0242ac17-0010-1989-7ad7-000000000005",
                        "name": "Copy inventory file for Zuul"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.replace",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "item",
                                    "changed": true,
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "after": null,
                                            "attributes": null,
                                            "backup": false,
                                            "before": null,
                                            "encoding": "utf-8",
                                            "group": null,
                                            "mode": null,
                                            "owner": null,
                                            "path": "src/github.com/vexxhost/atmosphere.common/inventory.yaml",
                                            "regexp": "(^\\s*ansible_host:\\s*).*$",
                                            "replace": "\\1\"{{ nodepool.private_ipv4 }}\"",
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "unsafe_writes": false,
                                            "validate": null
                                        }
                                    },
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common",
                                        "stat": {
                                            "atime": 1785349861.9658697,
                                            "attr_flags": "e",
                                            "attributes": [
                                                "extents"
                                            ],
                                            "block_size": 4096,
                                            "blocks": 8,
                                            "charset": "unknown",
                                            "ctime": 1785349861.986871,
                                            "dev": 64769,
                                            "device_type": 0,
                                            "executable": true,
                                            "exists": true,
                                            "gid": 1000,
                                            "gr_name": "zuul",
                                            "inode": 1023520,
                                            "isblk": false,
                                            "ischr": false,
                                            "isdir": true,
                                            "isfifo": false,
                                            "isgid": false,
                                            "islnk": false,
                                            "isreg": false,
                                            "issock": false,
                                            "isuid": false,
                                            "mimetype": "unknown",
                                            "mode": "0755",
                                            "mtime": 1785349844.6832364,
                                            "nlink": 10,
                                            "path": "src/github.com/vexxhost/atmosphere.common",
                                            "pw_name": "zuul",
                                            "readable": true,
                                            "rgrp": true,
                                            "roth": true,
                                            "rusr": true,
                                            "size": 4096,
                                            "uid": 1000,
                                            "version": "426589368",
                                            "wgrp": false,
                                            "woth": false,
                                            "writeable": true,
                                            "wusr": true,
                                            "xgrp": true,
                                            "xoth": true,
                                            "xusr": true
                                        }
                                    },
                                    "msg": "1 replacements made",
                                    "rc": 0
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "false_condition": "item.stat.isdir | default(false)",
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common/molecule/secretgen-controller/inventory",
                                        "stat": {
                                            "exists": false
                                        }
                                    },
                                    "skip_reason": "Conditional result was False",
                                    "skipped": true
                                },
                                {
                                    "ansible_loop_var": "item",
                                    "changed": false,
                                    "false_condition": "item.stat.isdir | default(false)",
                                    "item": {
                                        "ansible_loop_var": "item",
                                        "changed": false,
                                        "failed": false,
                                        "invocation": {
                                            "module_args": {
                                                "checksum_algorithm": "sha1",
                                                "follow": true,
                                                "get_attributes": true,
                                                "get_checksum": true,
                                                "get_mime": true,
                                                "path": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory"
                                            }
                                        },
                                        "item": "src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/inventory",
                                        "stat": {
                                            "exists": false
                                        }
                                    },
                                    "skip_reason": "Conditional result was False",
                                    "skipped": true
                                }
                            ]
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:31:19.633474Z",
                            "start": "2026-07-29T18:31:19.195694Z"
                        },
                        "id": "0242ac17-0010-1989-7ad7-000000000006",
                        "name": "Switch \"ansible_host\" to private IP"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "ansible.builtin.command",
                            "changed": true,
                            "cmd": [
                                "uv",
                                "run",
                                "molecule",
                                "test",
                                "--destroy",
                                "never",
                                "-s",
                                "secretgen-controller"
                            ],
                            "delta": "0:04:32.764326",
                            "end": "2026-07-29 18:35:52.803919",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "uv run molecule test --destroy never -s secretgen-controller",
                                    "_uses_shell": false,
                                    "argv": null,
                                    "chdir": "src/github.com/vexxhost/atmosphere.common",
                                    "creates": null,
                                    "executable": null,
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-1989-7ad7-000000000007-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:31:20.039593",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "Using CPython 3.12.3 interpreter at: /usr/bin/python3\nCreating virtual environment at: .venv\nwarning: No `requires-python` value found in the workspace. Defaulting to `>=3.12`.\nDownloading cryptography (4.3MiB)\nDownloading pygments (1.2MiB)\nDownloading kubernetes (1.9MiB)\nDownloading pydantic-core (2.0MiB)\nDownloading ansible-core (2.1MiB)\n Downloading pydantic-core\n Downloading cryptography\n Downloading pygments\n Downloading kubernetes\n Downloading ansible-core\nInstalled 52 packages in 46ms\nINFO     Collection 'atmosphere.common' detected.\nINFO     Scenarios will be used from 'extensions/molecule'\nINFO     [secretgen-controller > discovery] scenario test matrix: dependency, cleanup, destroy, syntax, create, prepare, converge, idempotence, side_effect, verify, cleanup, destroy\nINFO     [secretgen-controller > prerun] Performing prerun with role_name_check=0...\nINFO     [secretgen-controller > dependency] Executing\nWARNING  [secretgen-controller > dependency] Missing roles requirements file: requirements.yml\nWARNING  [secretgen-controller > dependency] Missing collections requirements file: collections.yml\nWARNING  [secretgen-controller > dependency] Executed: 2 missing (Remove from test_sequence to suppress)\nINFO     [secretgen-controller > cleanup] Executing\nWARNING  [secretgen-controller > cleanup] Executed: Missing playbook (Remove from test_sequence to suppress)\nINFO     [secretgen-controller > destroy] Executing\nWARNING  [secretgen-controller > destroy] Skipping, '--destroy=never' requested.\nINFO     [secretgen-controller > destroy] Executed: Successful\nINFO     [secretgen-controller > syntax] Executing\n\nplaybook: /home/zuul/src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/converge.yml\nINFO     [secretgen-controller > syntax] Executed: Successful\nINFO     [secretgen-controller > create] Executing\nWARNING  [secretgen-controller > create] Executed: Missing playbook (Remove from test_sequence to suppress)\nINFO     [secretgen-controller > prepare] Executing\n\nPLAY [Prepare] *****************************************************************\n\nTASK [Gathering Facts] *********************************************************\nWednesday 29 July 2026  18:32:51 +0000 (0:00:00.034)       0:00:00.034 ********\n[WARNING]: Platform linux on host controller is using the discovered Python\ninterpreter at /usr/bin/python3.12, but future installation of another Python\ninterpreter could change the meaning of that path. See\nhttps://docs.ansible.com/ansible-\ncore/2.18/reference_appendices/interpreter_discovery.html for more information.\nok: [controller]\n\nTASK [Install Debian packages] *************************************************\nWednesday 29 July 2026  18:32:52 +0000 (0:00:01.291)       0:00:01.325 ********\nok: [controller]\n\nPLAY [Configure Kubernetes VIP] ************************************************\n\nTASK [Gathering Facts] *********************************************************\nWednesday 29 July 2026  18:32:55 +0000 (0:00:02.346)       0:00:03.671 ********\nok: [controller]\n\nTASK [vexxhost.containers.directory : Create directory (/etc/kubernetes/manifests)] ***\nWednesday 29 July 2026  18:32:55 +0000 (0:00:00.785)       0:00:04.457 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Uninstall legacy HA stack] ****************\nWednesday 29 July 2026  18:32:56 +0000 (0:00:00.336)       0:00:04.794 ********\nok: [controller] => (item=/etc/keepalived/keepalived.conf)\nok: [controller] => (item=/etc/keepalived/check_apiserver.sh)\nok: [controller] => (item=/etc/kubernetes/manifests/keepalived.yaml)\nok: [controller] => (item=/etc/haproxy/haproxy.cfg)\nok: [controller] => (item=/etc/kubernetes/manifests/haproxy.yaml)\n\nTASK [vexxhost.kubernetes.kube_vip : Switch API server to run on port 6443] ****\nWednesday 29 July 2026  18:32:57 +0000 (0:00:01.066)       0:00:05.860 ********\nfailed: [controller] (item=/etc/kubernetes/manifests/kube-apiserver.yaml) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/manifests/kube-apiserver.yaml\", \"msg\": \"Path /etc/kubernetes/manifests/kube-apiserver.yaml does not exist !\", \"rc\": 257}\nfailed: [controller] (item=/etc/kubernetes/controller-manager.conf) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/controller-manager.conf\", \"msg\": \"Path /etc/kubernetes/controller-manager.conf does not exist !\", \"rc\": 257}\nfailed: [controller] (item=/etc/kubernetes/scheduler.conf) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/scheduler.conf\", \"msg\": \"Path /etc/kubernetes/scheduler.conf does not exist !\", \"rc\": 257}\n...ignoring\n\nTASK [vexxhost.kubernetes.kube_vip : Check if super-admin.conf exists] *********\nWednesday 29 July 2026  18:32:57 +0000 (0:00:00.688)       0:00:06.548 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Check if kubeadm has already run] *********\nWednesday 29 July 2026  18:32:58 +0000 (0:00:00.314)       0:00:06.863 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Set fact with KUBECONFIG path] ************\nWednesday 29 July 2026  18:32:58 +0000 (0:00:00.224)       0:00:07.088 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Set fact with KUBECONFIG path (with super-admin.conf)] ***\nWednesday 29 July 2026  18:32:58 +0000 (0:00:00.030)       0:00:07.118 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Upload Kubernetes manifest] ***************\nWednesday 29 July 2026  18:32:58 +0000 (0:00:00.035)       0:00:07.153 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Ensure kube-vip configuration file] *******\nWednesday 29 July 2026  18:32:59 +0000 (0:00:00.778)       0:00:07.932 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kube_vip : Flush handlers] ***************************\nWednesday 29 July 2026  18:32:59 +0000 (0:00:00.243)       0:00:08.176 ********\n\nPLAY [Install Kubernetes] ******************************************************\n\nTASK [Gathering Facts] *********************************************************\nWednesday 29 July 2026  18:32:59 +0000 (0:00:00.048)       0:00:08.224 ********\nok: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:00 +0000 (0:00:00.800)       0:00:09.024 ********\nok: [controller]\n\nTASK [vexxhost.containers.package : Update state for tar] **********************\nWednesday 29 July 2026  18:33:00 +0000 (0:00:00.255)       0:00:09.280 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.directory : Create directory (/var/lib/downloads)] ***\nWednesday 29 July 2026  18:33:00 +0000 (0:00:00.037)       0:00:09.317 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:00 +0000 (0:00:00.242)       0:00:09.560 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/opencontainers/runc/releases/download/v1.4.2/runc.amd64\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:00 +0000 (0:00:00.082)       0:00:09.643 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:01 +0000 (0:00:00.854)       0:00:10.497 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:01 +0000 (0:00:00.035)       0:00:10.533 ********\nok: [controller]\n\nTASK [vexxhost.containers.package : Update state for tar] **********************\nWednesday 29 July 2026  18:33:02 +0000 (0:00:00.242)       0:00:10.775 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:03 +0000 (0:00:00.892)       0:00:11.668 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/containerd/containerd/releases/download/v2.3.2/containerd-2.3.2-linux-amd64.tar.gz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:03 +0000 (0:00:00.067)       0:00:11.735 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:04 +0000 (0:00:01.004)       0:00:12.740 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.containerd : Install SELinux packages] ***************\nWednesday 29 July 2026  18:33:06 +0000 (0:00:02.926)       0:00:15.666 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Set SELinux to permissive at runtime] ***\nWednesday 29 July 2026  18:33:07 +0000 (0:00:00.026)       0:00:15.693 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Persist SELinux permissive mode] ********\nWednesday 29 July 2026  18:33:07 +0000 (0:00:00.032)       0:00:15.725 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Install AppArmor packages] **************\nWednesday 29 July 2026  18:33:07 +0000 (0:00:00.029)       0:00:15.755 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.containerd : Create systemd service file for containerd] ***\nWednesday 29 July 2026  18:33:14 +0000 (0:00:07.116)       0:00:22.871 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.containerd : Create folders for configuration] *******\nWednesday 29 July 2026  18:33:14 +0000 (0:00:00.538)       0:00:23.410 ********\nchanged: [controller] => (item={'path': '/etc/containerd'})\nchanged: [controller] => (item={'path': '/var/lib/containerd', 'mode': '0o700'})\nchanged: [controller] => (item={'path': '/run/containerd', 'mode': '0o711'})\nchanged: [controller] => (item={'path': '/run/containerd/io.containerd.grpc.v1.cri', 'mode': '0o700'})\nchanged: [controller] => (item={'path': '/run/containerd/io.containerd.sandbox.controller.v1.shim', 'mode': '0o700'})\n\nTASK [vexxhost.containers.containerd : Create containerd config file] **********\nWednesday 29 July 2026  18:33:15 +0000 (0:00:01.159)       0:00:24.570 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.containerd : Force any restarts if necessary] ********\nWednesday 29 July 2026  18:33:16 +0000 (0:00:00.666)       0:00:25.236 ********\n\nRUNNING HANDLER [vexxhost.containers.containerd : Restart containerd] **********\nWednesday 29 July 2026  18:33:16 +0000 (0:00:00.007)       0:00:25.244 ********\nchanged: [controller]\n\nRUNNING HANDLER [vexxhost.kubernetes.kubelet : Reload systemd] *****************\nWednesday 29 July 2026  18:33:17 +0000 (0:00:00.746)       0:00:25.990 ********\nok: [controller]\n\nTASK [vexxhost.containers.containerd : Enable and start service] ***************\nWednesday 29 July 2026  18:33:18 +0000 (0:00:00.868)       0:00:26.859 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Retrieve the \"kubeadm-config\" ConfigMap] ***\nWednesday 29 July 2026  18:33:19 +0000 (0:00:01.668)       0:00:28.528 ********\nfatal: [controller]: FAILED! => {\"changed\": false, \"msg\": \"Failed to import the required Python library (kubernetes) on np0000187452's Python /usr/bin/python3.12. Please read the module documentation and install it in the appropriate location. If the required library is installed, but Ansible is using the wrong Python interpreter, please consult the documentation on ansible_python_interpreter\"}\n...ignoring\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Parse the ClusterConfiguration] ***\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.590)       0:00:29.118 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Retrieve the current Kubernetes version] ***\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.036)       0:00:29.155 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Extract major, minor, and patch versions] ***\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.032)       0:00:29.187 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Fail if we're jumping more than one minor version] ***\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.222 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes_upgrade_check : Set fact if we need to upgrade] ***\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.256 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.033)       0:00:29.290 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.249)       0:00:29.540 ********\nok: [controller] => {\n    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubeadm\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.574 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:22 +0000 (0:00:01.261)       0:00:30.835 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:22 +0000 (0:00:00.039)       0:00:30.875 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:22 +0000 (0:00:00.236)       0:00:31.111 ********\nok: [controller] => {\n    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubectl\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:22 +0000 (0:00:00.040)       0:00:31.152 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:23 +0000 (0:00:00.886)       0:00:32.039 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Install SELinux packages] ***************\nWednesday 29 July 2026  18:33:23 +0000 (0:00:00.045)       0:00:32.084 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Set SELinux to permissive at runtime] ***\nWednesday 29 July 2026  18:33:23 +0000 (0:00:00.031)       0:00:32.116 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Persist SELinux permissive mode] ********\nWednesday 29 July 2026  18:33:23 +0000 (0:00:00.033)       0:00:32.150 ********\nskipping: [controller]\n\nTASK [vexxhost.containers.containerd : Install AppArmor packages] **************\nWednesday 29 July 2026  18:33:23 +0000 (0:00:00.034)       0:00:32.185 ********\nok: [controller]\n\nTASK [vexxhost.containers.containerd : Create systemd service file for containerd] ***\nWednesday 29 July 2026  18:33:24 +0000 (0:00:00.922)       0:00:33.107 ********\nok: [controller]\n\nTASK [vexxhost.containers.containerd : Create folders for configuration] *******\nWednesday 29 July 2026  18:33:24 +0000 (0:00:00.525)       0:00:33.633 ********\nok: [controller] => (item={'path': '/etc/containerd'})\nok: [controller] => (item={'path': '/var/lib/containerd', 'mode': '0o700'})\nok: [controller] => (item={'path': '/run/containerd', 'mode': '0o711'})\nok: [controller] => (item={'path': '/run/containerd/io.containerd.grpc.v1.cri', 'mode': '0o700'})\nok: [controller] => (item={'path': '/run/containerd/io.containerd.sandbox.controller.v1.shim', 'mode': '0o700'})\n\nTASK [vexxhost.containers.containerd : Create containerd config file] **********\nWednesday 29 July 2026  18:33:26 +0000 (0:00:01.099)       0:00:34.732 ********\nok: [controller]\n\nTASK [vexxhost.containers.containerd : Force any restarts if necessary] ********\nWednesday 29 July 2026  18:33:26 +0000 (0:00:00.623)       0:00:35.356 ********\n\nTASK [vexxhost.containers.containerd : Enable and start service] ***************\nWednesday 29 July 2026  18:33:26 +0000 (0:00:00.005)       0:00:35.362 ********\nok: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:27 +0000 (0:00:00.419)       0:00:35.782 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:27 +0000 (0:00:00.235)       0:00:36.018 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/kubernetes-sigs/cri-tools/releases/download/v1.36.0/crictl-v1.36.0-linux-amd64.tar.gz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:27 +0000 (0:00:00.058)       0:00:36.076 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:28 +0000 (0:00:00.799)       0:00:36.876 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:29 +0000 (0:00:01.517)       0:00:38.393 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/kubernetes-sigs/cri-tools/releases/download/v1.36.0/critest-v1.36.0-linux-amd64.tar.gz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:29 +0000 (0:00:00.061)       0:00:38.455 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:30 +0000 (0:00:01.020)       0:00:39.476 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.cri_tools : Create crictl config] ********************\nWednesday 29 July 2026  18:33:32 +0000 (0:00:01.542)       0:00:41.019 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.directory : Create directory (/opt/cni/bin)] *********\nWednesday 29 July 2026  18:33:32 +0000 (0:00:00.547)       0:00:41.566 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:33 +0000 (0:00:00.245)       0:00:41.811 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:33 +0000 (0:00:00.241)       0:00:42.053 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/containernetworking/plugins/releases/download/v1.9.1/cni-plugins-linux-amd64-v1.9.1.tgz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:33 +0000 (0:00:00.059)       0:00:42.113 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:34 +0000 (0:00:01.061)       0:00:43.174 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.cni_plugins : Gather variables for each operating system] ***\nWednesday 29 July 2026  18:33:37 +0000 (0:00:02.797)       0:00:45.972 ********\nok: [controller] => (item=/home/zuul/.ansible/collections/ansible_collections/vexxhost/containers/roles/cni_plugins/vars/debian.yml)\n\nTASK [vexxhost.containers.cni_plugins : Install additional packages] ***********\nWednesday 29 July 2026  18:33:37 +0000 (0:00:00.050)       0:00:46.022 ********\nok: [controller]\n\nTASK [vexxhost.containers.cni_plugins : Ensure IPv6 is enabled] ****************\nWednesday 29 July 2026  18:33:38 +0000 (0:00:00.873)       0:00:46.896 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.cni_plugins : Enable kernel modules on-boot] *********\nWednesday 29 July 2026  18:33:38 +0000 (0:00:00.327)       0:00:47.224 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.cni_plugins : Enable kernel modules in runtime] ******\nWednesday 29 July 2026  18:33:39 +0000 (0:00:00.550)       0:00:47.775 ********\nchanged: [controller] => (item=br_netfilter)\nok: [controller] => (item=ip_tables)\nchanged: [controller] => (item=ip6_tables)\nchanged: [controller] => (item=nf_conntrack)\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:33:40 +0000 (0:00:01.022)       0:00:48.798 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:33:40 +0000 (0:00:00.232)       0:00:49.031 ********\nok: [controller] => {\n    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubelet\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:33:40 +0000 (0:00:00.044)       0:00:49.075 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:33:41 +0000 (0:00:01.414)       0:00:50.490 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Gather variables for each operating system] ***\nWednesday 29 July 2026  18:33:41 +0000 (0:00:00.034)       0:00:50.524 ********\nok: [controller] => (item=/home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubelet/vars/debian.yml)\n\nTASK [vexxhost.kubernetes.kubelet : Install coreutils] *************************\nWednesday 29 July 2026  18:33:41 +0000 (0:00:00.050)       0:00:50.574 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Install additional packages] ***************\nWednesday 29 July 2026  18:33:41 +0000 (0:00:00.025)       0:00:50.600 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Configure sysctl values] *******************\nWednesday 29 July 2026  18:33:45 +0000 (0:00:03.103)       0:00:53.703 ********\nchanged: [controller] => (item={'name': 'net.ipv4.ip_forward', 'value': 1})\nchanged: [controller] => (item={'name': 'net.bridge.bridge-nf-call-iptables', 'value': 1})\nchanged: [controller] => (item={'name': 'net.bridge.bridge-nf-call-ip6tables', 'value': 1})\nchanged: [controller] => (item={'name': 'net.ipv4.conf.all.rp_filter', 'value': 0})\nchanged: [controller] => (item={'name': 'fs.inotify.max_queued_events', 'value': 1048576})\nchanged: [controller] => (item={'name': 'fs.inotify.max_user_instances', 'value': 8192})\nchanged: [controller] => (item={'name': 'fs.inotify.max_user_watches', 'value': 1048576})\n\nTASK [vexxhost.kubernetes.kubelet : Create folders for kubernetes configuration] ***\nWednesday 29 July 2026  18:33:46 +0000 (0:00:01.604)       0:00:55.307 ********\nchanged: [controller] => (item=/etc/systemd/system/kubelet.service.d)\nok: [controller] => (item=/etc/kubernetes)\nok: [controller] => (item=/etc/kubernetes/manifests)\n\nTASK [vexxhost.kubernetes.kubelet : Add kubelet systemd service config] ********\nWednesday 29 July 2026  18:33:47 +0000 (0:00:00.674)       0:00:55.982 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Add kubeadm dropin for kubelet systemd service config] ***\nWednesday 29 July 2026  18:33:47 +0000 (0:00:00.548)       0:00:56.530 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Check swap status] *************************\nWednesday 29 July 2026  18:33:48 +0000 (0:00:00.552)       0:00:57.083 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Disable swap] ******************************\nWednesday 29 July 2026  18:33:48 +0000 (0:00:00.330)       0:00:57.414 ********\n[DEPRECATION WARNING]: Conditional result at location /home/zuul/.ansible/colle\nctions/ansible_collections/vexxhost/kubernetes/roles/kubelet/tasks/main.yml\n91:11 was of type 'AnsibleUnsafeText'. Conditional results should only be True\nor False. The result was interpreted as False. This feature will be removed in\nversion 2.19. Deprecation warnings can be disabled by setting\ndeprecation_warnings=False in ansible.cfg.\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Remove swapfile from /etc/fstab] ***********\nWednesday 29 July 2026  18:33:48 +0000 (0:00:00.035)       0:00:57.450 ********\nok: [controller] => (item=swap)\nok: [controller] => (item=none)\n\nTASK [vexxhost.kubernetes.kubelet : Create noswap systemd service config file] ***\nWednesday 29 July 2026  18:33:49 +0000 (0:00:00.539)       0:00:57.989 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Enable noswap service] *********************\nWednesday 29 July 2026  18:33:49 +0000 (0:00:00.561)       0:00:58.551 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Force any restarts if necessary] ***********\nWednesday 29 July 2026  18:33:50 +0000 (0:00:00.684)       0:00:59.236 ********\n\nRUNNING HANDLER [vexxhost.kubernetes.kubelet : Reload systemd] *****************\nWednesday 29 July 2026  18:33:50 +0000 (0:00:00.005)       0:00:59.241 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Enable and start kubelet service] **********\nWednesday 29 July 2026  18:33:51 +0000 (0:00:00.861)       0:01:00.103 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Ensure availability of dbus on Debian] *****\nWednesday 29 July 2026  18:33:52 +0000 (0:00:00.710)       0:01:00.813 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Configure short hostname] ******************\nWednesday 29 July 2026  18:33:53 +0000 (0:00:00.924)       0:01:01.738 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubelet : Ensure hostname inside hosts file] *********\nWednesday 29 July 2026  18:33:55 +0000 (0:00:02.277)       0:01:04.016 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Remove kubernetes repository] ***********\nWednesday 29 July 2026  18:33:55 +0000 (0:00:00.338)       0:01:04.354 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Setup control plane] ********************\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.477)       0:01:04.831 ********\nincluded: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubernetes/tasks/control-plane.yml for controller\n\nTASK [vexxhost.kubernetes.kubernetes : Bootstrap cluster] **********************\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.071)       0:01:04.903 ********\nincluded: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubernetes/tasks/bootstrap-cluster.yml for controller\n\nTASK [vexxhost.kubernetes.kubernetes : Check if any control plane is bootstrapped] ***\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.074)       0:01:04.978 ********\nok: [controller] => (item=controller)\n\nTASK [vexxhost.kubernetes.kubernetes : Pick node from pre-existing cluster] ****\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.245)       0:01:05.223 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Select first node to initialize cluster] ***\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.039)       0:01:05.263 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Print selected bootstrap node] **********\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.048)       0:01:05.311 ********\nok: [controller] => {\n    \"msg\": \"controller\"\n}\n\nTASK [vexxhost.kubernetes.kubernetes : Upload cluster configuration for bootstrap node] ***\nWednesday 29 July 2026  18:33:56 +0000 (0:00:00.040)       0:01:05.352 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create pki folder] **********************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.571)       0:01:05.924 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create kubernetes ca key] ***************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.032)       0:01:05.956 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create kubernetes ca cert] **************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.034)       0:01:05.990 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create etcd-ca key] *********************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.024)       0:01:06.014 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create etcd-ca cert] ********************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.036)       0:01:06.051 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create front-proxy-ca key] **************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.030)       0:01:06.082 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create front-proxy-ca cert] *************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.035)       0:01:06.117 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Initialize cluster] *********************\nWednesday 29 July 2026  18:33:57 +0000 (0:00:00.031)       0:01:06.149 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Check if the node is already part of the cluster] ***\nWednesday 29 July 2026  18:34:43 +0000 (0:00:46.148)       0:01:52.297 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Join cluster] ***************************\nWednesday 29 July 2026  18:34:43 +0000 (0:00:00.252)       0:01:52.549 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Create folder for admin configuration] ***\nWednesday 29 July 2026  18:34:43 +0000 (0:00:00.035)       0:01:52.585 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Creating a symlink for admin configuration file] ***\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.253)       0:01:52.838 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Add bash autocomplete for kubectl] ******\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.251)       0:01:53.090 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Install PIP] ****************************\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.237)       0:01:53.327 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Install Kubernetes Python package using pip on supported systems] ***\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.041)       0:01:53.369 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Enable EPEL repository] *****************\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.043)       0:01:53.412 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Install Kubernetes Python package using package manager on supported systems] ***\nWednesday 29 July 2026  18:34:44 +0000 (0:00:00.048)       0:01:53.460 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Allow workload on control plane node] ***\nWednesday 29 July 2026  18:34:52 +0000 (0:00:07.745)       0:02:01.205 ********\n[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not\nwork.\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Remove kube-proxy resources] ************\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.737)       0:02:01.943 ********\nskipping: [controller] => (item=DaemonSet)\nskipping: [controller] => (item=ConfigMap)\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Start an upgrade] ***********************\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.036)       0:02:01.980 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Check if the Kubernetes API services is up to date] ***\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.034)       0:02:02.015 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Trigger an upgrade of the Kubernetes API services] ***\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.037)       0:02:02.053 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Setup nodes] ****************************\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.035)       0:02:02.088 ********\nskipping: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Upgrade & restart Kubelet node for upgrade (if needed)] ***\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.031)       0:02:02.120 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.kubernetes : Set node selector for CoreDNS components] ***\nWednesday 29 July 2026  18:34:53 +0000 (0:00:00.476)       0:02:02.596 ********\nchanged: [controller]\n\nPLAY [Install control-plane components] ****************************************\n\nTASK [Gathering Facts] *********************************************************\nWednesday 29 July 2026  18:34:54 +0000 (0:00:00.923)       0:02:03.520 ********\nok: [controller]\n\nTASK [vexxhost.containers.forget_package : Forget package] *********************\nWednesday 29 July 2026  18:34:55 +0000 (0:00:00.795)       0:02:04.316 ********\nok: [controller]\n\nTASK [vexxhost.containers.package : Update state for tar] **********************\nWednesday 29 July 2026  18:34:55 +0000 (0:00:00.234)       0:02:04.551 ********\nok: [controller]\n\nTASK [vexxhost.containers.directory : Create directory (/var/lib/downloads)] ***\nWednesday 29 July 2026  18:34:56 +0000 (0:00:00.904)       0:02:05.455 ********\nok: [controller]\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:34:57 +0000 (0:00:00.259)       0:02:05.714 ********\nok: [controller] => {\n    \"msg\": \"https://get.helm.sh/helm-v3.11.2-linux-amd64.tar.gz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:34:57 +0000 (0:00:00.038)       0:02:05.753 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:34:57 +0000 (0:00:00.861)       0:02:06.614 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.helm : Remove Helm repository] ***********************\nWednesday 29 July 2026  18:34:59 +0000 (0:00:01.663)       0:02:08.278 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.helm : Add bash autocomplete for helm] ***************\nWednesday 29 July 2026  18:34:59 +0000 (0:00:00.378)       0:02:08.656 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.helm : Get Helm plugins dir] *************************\nWednesday 29 July 2026  18:35:00 +0000 (0:00:00.225)       0:02:08.881 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.helm : Create Helm plugins directory if it does not exist] ***\nWednesday 29 July 2026  18:35:00 +0000 (0:00:00.347)       0:02:09.229 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.helm : Remove Helm diff plugin installed by kubernetes.core.helm_plugin] ***\nWednesday 29 July 2026  18:35:00 +0000 (0:00:00.237)       0:02:09.466 ********\nok: [controller]\n\nTASK [Install plugin] **********************************************************\nWednesday 29 July 2026  18:35:01 +0000 (0:00:00.224)       0:02:09.690 ********\nincluded: vexxhost.containers.download_artifact for controller\n\nTASK [vexxhost.containers.download_artifact : Starting download of file] *******\nWednesday 29 July 2026  18:35:01 +0000 (0:00:00.040)       0:02:09.731 ********\nok: [controller] => {\n    \"msg\": \"https://github.com/databus23/helm-diff/releases/download/v3.8.1/helm-diff-linux-amd64.tgz\"\n}\n\nTASK [vexxhost.containers.download_artifact : Download item] *******************\nWednesday 29 July 2026  18:35:01 +0000 (0:00:00.037)       0:02:09.768 ********\nchanged: [controller]\n\nTASK [vexxhost.containers.download_artifact : Extract archive] *****************\nWednesday 29 July 2026  18:35:01 +0000 (0:00:00.832)       0:02:10.600 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.upload_helm_chart : Include help chart upload method tasks] ***\nWednesday 29 July 2026  18:35:03 +0000 (0:00:01.946)       0:02:12.547 ********\nincluded: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/upload_helm_chart/tasks/synchronize.yml for controller\n\nTASK [vexxhost.kubernetes.upload_helm_chart : Upload Helm chart] ***************\nWednesday 29 July 2026  18:35:03 +0000 (0:00:00.029)       0:02:12.576 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.cilium : Get current Kubernetes version] *************\nWednesday 29 July 2026  18:35:04 +0000 (0:00:00.628)       0:02:13.205 ********\nok: [controller]\n\nTASK [vexxhost.kubernetes.cilium : Deploy Helm chart] **************************\nWednesday 29 July 2026  18:35:05 +0000 (0:00:00.840)       0:02:14.045 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.upload_helm_chart : Include help chart upload method tasks] ***\nWednesday 29 July 2026  18:35:07 +0000 (0:00:02.194)       0:02:16.240 ********\nincluded: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/upload_helm_chart/tasks/synchronize.yml for controller\n\nTASK [vexxhost.kubernetes.upload_helm_chart : Upload Helm chart] ***************\nWednesday 29 July 2026  18:35:07 +0000 (0:00:00.031)       0:02:16.271 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.envoy_gateway : Deploy Helm chart] *******************\nWednesday 29 July 2026  18:35:08 +0000 (0:00:00.535)       0:02:16.806 ********\nchanged: [controller]\n\nTASK [vexxhost.kubernetes.envoy_gateway : Create GatewayClass] *****************\nWednesday 29 July 2026  18:35:42 +0000 (0:00:34.682)       0:02:51.489 ********\nchanged: [controller]\n\nPLAY RECAP *********************************************************************\ncontroller                 : ok=117  changed=54   unreachable=0    failed=0    skipped=35   rescued=0    ignored=2\n\n\nTASKS RECAP ********************************************************************\nWednesday 29 July 2026  18:35:43 +0000 (0:00:00.836)       0:02:52.325 ********\n===============================================================================\nvexxhost.kubernetes.kubernetes : Initialize cluster -------------------- 46.15s\nvexxhost.kubernetes.envoy_gateway : Deploy Helm chart ------------------ 34.68s\nvexxhost.kubernetes.kubernetes : Install Kubernetes Python package using package manager on supported systems --- 7.75s\nvexxhost.containers.containerd : Install AppArmor packages -------------- 7.12s\nvexxhost.kubernetes.kubelet : Install additional packages --------------- 3.10s\nvexxhost.containers.download_artifact : Extract archive ----------------- 2.93s\nvexxhost.containers.download_artifact : Extract archive ----------------- 2.80s\nInstall Debian packages ------------------------------------------------- 2.35s\nvexxhost.kubernetes.kubelet : Configure short hostname ------------------ 2.28s\nvexxhost.kubernetes.cilium : Deploy Helm chart -------------------------- 2.19s\nvexxhost.containers.download_artifact : Extract archive ----------------- 1.95s\nvexxhost.kubernetes.kubelet : Reload systemd ---------------------------- 1.73s\nvexxhost.containers.containerd : Enable and start service --------------- 1.67s\nvexxhost.containers.download_artifact : Extract archive ----------------- 1.66s\nvexxhost.kubernetes.kubelet : Configure sysctl values ------------------- 1.60s\nvexxhost.containers.download_artifact : Extract archive ----------------- 1.54s\nvexxhost.containers.download_artifact : Extract archive ----------------- 1.52s\nvexxhost.containers.download_artifact : Download item ------------------- 1.41s\nGathering Facts --------------------------------------------------------- 1.29s\nvexxhost.containers.download_artifact : Download item ------------------- 1.26s\nINFO     [secretgen-controller > prepare] Executed: Successful\nINFO     [secretgen-controller > converge] Executing\n\nPLAY [Deploy \"secretgen-controller\"] *******************************************\n\nTASK [atmosphere.common.secretgen_controller : Deploy secretgen-controller] ****\nWednesday 29 July 2026  18:35:44 +0000 (0:00:00.046)       0:00:00.046 ********\n[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not\nwork.\n[WARNING]: Platform linux on host controller is using the discovered Python\ninterpreter at /usr/bin/python3.12, but future installation of another Python\ninterpreter could change the meaning of that path. See\nhttps://docs.ansible.com/ansible-\ncore/2.18/reference_appendices/interpreter_discovery.html for more information.\nchanged: [controller]\n\nPLAY RECAP *********************************************************************\ncontroller                 : ok=1    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0\n\n\nTASKS RECAP ********************************************************************\nWednesday 29 July 2026  18:35:45 +0000 (0:00:01.351)       0:00:01.398 ********\n===============================================================================\natmosphere.common.secretgen_controller : Deploy secretgen-controller ---- 1.35s\nINFO     [secretgen-controller > converge] Executed: Successful\nINFO     [secretgen-controller > idempotence] Executing\n\nPLAY [Deploy \"secretgen-controller\"] *******************************************\n\nTASK [atmosphere.common.secretgen_controller : Deploy secretgen-controller] ****\nWednesday 29 July 2026  18:35:46 +0000 (0:00:00.045)       0:00:00.045 ********\n[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not\nwork.\n[WARNING]: Platform linux on host controller is using the discovered Python\ninterpreter at /usr/bin/python3.12, but future installation of another Python\ninterpreter could change the meaning of that path. See\nhttps://docs.ansible.com/ansible-\ncore/2.18/reference_appendices/interpreter_discovery.html for more information.\nok: [controller]\n\nPLAY RECAP *********************************************************************\ncontroller                 : ok=1    changed=0    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0\n\n\nTASKS RECAP ********************************************************************\nWednesday 29 July 2026  18:35:48 +0000 (0:00:01.337)       0:00:01.382 ********\n===============================================================================\natmosphere.common.secretgen_controller : Deploy secretgen-controller ---- 1.34s\nINFO     [secretgen-controller > idempotence] Executed: Successful\nINFO     [secretgen-controller > side_effect] Executing\nWARNING  [secretgen-controller > side_effect] Executed: Missing playbook (Remove from test_sequence to suppress)\nINFO     [secretgen-controller > verify] Executing\n\nPLAY [Verify] ******************************************************************\n\nTASK [Gathering Facts] *********************************************************\nWednesday 29 July 2026  18:35:48 +0000 (0:00:00.042)       0:00:00.042 ********\n[WARNING]: Platform linux on host controller is using the discovered Python\ninterpreter at /usr/bin/python3.12, but future installation of another Python\ninterpreter could change the meaning of that path. See\nhttps://docs.ansible.com/ansible-\ncore/2.18/reference_appendices/interpreter_discovery.html for more information.\nok: [controller]\n\nTASK [Wait for secretgen-controller deployment to be available] ****************\nWednesday 29 July 2026  18:35:50 +0000 (0:00:01.280)       0:00:01.322 ********\n[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not\nwork.\nok: [controller]\n\nTASK [Create a test Password resource] *****************************************\nWednesday 29 July 2026  18:35:51 +0000 (0:00:00.841)       0:00:02.163 ********\nchanged: [controller]\n\nTASK [Wait for test-password secret to be generated] ***************************\nWednesday 29 July 2026  18:35:51 +0000 (0:00:00.882)       0:00:03.046 ********\nok: [controller]\n\nPLAY RECAP *********************************************************************\ncontroller                 : ok=4    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0\n\n\nTASKS RECAP ********************************************************************\nWednesday 29 July 2026  18:35:52 +0000 (0:00:00.705)       0:00:03.752 ********\n===============================================================================\nGathering Facts --------------------------------------------------------- 1.28s\nCreate a test Password resource ----------------------------------------- 0.88s\nWait for secretgen-controller deployment to be available ---------------- 0.84s\nWait for test-password secret to be generated --------------------------- 0.71s\nINFO     [secretgen-controller > verify] Executed: Successful\nINFO     [secretgen-controller > cleanup] Executing\nWARNING  [secretgen-controller > cleanup] Executed: Missing playbook (Remove from test_sequence to suppress)\nINFO     [secretgen-controller > destroy] Executing\nWARNING  [secretgen-controller > destroy] Skipping, '--destroy=never' requested.\nINFO     [secretgen-controller > destroy] Executed: Successful\nWARNING  Molecule executed 1 scenario (1 missing files)",
                            "stdout_lines": [
                                "Using CPython 3.12.3 interpreter at: /usr/bin/python3",
                                "Creating virtual environment at: .venv",
                                "warning: No `requires-python` value found in the workspace. Defaulting to `>=3.12`.",
                                "Downloading cryptography (4.3MiB)",
                                "Downloading pygments (1.2MiB)",
                                "Downloading kubernetes (1.9MiB)",
                                "Downloading pydantic-core (2.0MiB)",
                                "Downloading ansible-core (2.1MiB)",
                                " Downloading pydantic-core",
                                " Downloading cryptography",
                                " Downloading pygments",
                                " Downloading kubernetes",
                                " Downloading ansible-core",
                                "Installed 52 packages in 46ms",
                                "INFO     Collection 'atmosphere.common' detected.",
                                "INFO     Scenarios will be used from 'extensions/molecule'",
                                "INFO     [secretgen-controller > discovery] scenario test matrix: dependency, cleanup, destroy, syntax, create, prepare, converge, idempotence, side_effect, verify, cleanup, destroy",
                                "INFO     [secretgen-controller > prerun] Performing prerun with role_name_check=0...",
                                "INFO     [secretgen-controller > dependency] Executing",
                                "WARNING  [secretgen-controller > dependency] Missing roles requirements file: requirements.yml",
                                "WARNING  [secretgen-controller > dependency] Missing collections requirements file: collections.yml",
                                "WARNING  [secretgen-controller > dependency] Executed: 2 missing (Remove from test_sequence to suppress)",
                                "INFO     [secretgen-controller > cleanup] Executing",
                                "WARNING  [secretgen-controller > cleanup] Executed: Missing playbook (Remove from test_sequence to suppress)",
                                "INFO     [secretgen-controller > destroy] Executing",
                                "WARNING  [secretgen-controller > destroy] Skipping, '--destroy=never' requested.",
                                "INFO     [secretgen-controller > destroy] Executed: Successful",
                                "INFO     [secretgen-controller > syntax] Executing",
                                "",
                                "playbook: /home/zuul/src/github.com/vexxhost/atmosphere.common/extensions/molecule/secretgen-controller/converge.yml",
                                "INFO     [secretgen-controller > syntax] Executed: Successful",
                                "INFO     [secretgen-controller > create] Executing",
                                "WARNING  [secretgen-controller > create] Executed: Missing playbook (Remove from test_sequence to suppress)",
                                "INFO     [secretgen-controller > prepare] Executing",
                                "",
                                "PLAY [Prepare] *****************************************************************",
                                "",
                                "TASK [Gathering Facts] *********************************************************",
                                "Wednesday 29 July 2026  18:32:51 +0000 (0:00:00.034)       0:00:00.034 ********",
                                "[WARNING]: Platform linux on host controller is using the discovered Python",
                                "interpreter at /usr/bin/python3.12, but future installation of another Python",
                                "interpreter could change the meaning of that path. See",
                                "https://docs.ansible.com/ansible-",
                                "core/2.18/reference_appendices/interpreter_discovery.html for more information.",
                                "ok: [controller]",
                                "",
                                "TASK [Install Debian packages] *************************************************",
                                "Wednesday 29 July 2026  18:32:52 +0000 (0:00:01.291)       0:00:01.325 ********",
                                "ok: [controller]",
                                "",
                                "PLAY [Configure Kubernetes VIP] ************************************************",
                                "",
                                "TASK [Gathering Facts] *********************************************************",
                                "Wednesday 29 July 2026  18:32:55 +0000 (0:00:02.346)       0:00:03.671 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.directory : Create directory (/etc/kubernetes/manifests)] ***",
                                "Wednesday 29 July 2026  18:32:55 +0000 (0:00:00.785)       0:00:04.457 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Uninstall legacy HA stack] ****************",
                                "Wednesday 29 July 2026  18:32:56 +0000 (0:00:00.336)       0:00:04.794 ********",
                                "ok: [controller] => (item=/etc/keepalived/keepalived.conf)",
                                "ok: [controller] => (item=/etc/keepalived/check_apiserver.sh)",
                                "ok: [controller] => (item=/etc/kubernetes/manifests/keepalived.yaml)",
                                "ok: [controller] => (item=/etc/haproxy/haproxy.cfg)",
                                "ok: [controller] => (item=/etc/kubernetes/manifests/haproxy.yaml)",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Switch API server to run on port 6443] ****",
                                "Wednesday 29 July 2026  18:32:57 +0000 (0:00:01.066)       0:00:05.860 ********",
                                "failed: [controller] (item=/etc/kubernetes/manifests/kube-apiserver.yaml) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/manifests/kube-apiserver.yaml\", \"msg\": \"Path /etc/kubernetes/manifests/kube-apiserver.yaml does not exist !\", \"rc\": 257}",
                                "failed: [controller] (item=/etc/kubernetes/controller-manager.conf) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/controller-manager.conf\", \"msg\": \"Path /etc/kubernetes/controller-manager.conf does not exist !\", \"rc\": 257}",
                                "failed: [controller] (item=/etc/kubernetes/scheduler.conf) => {\"ansible_loop_var\": \"item\", \"changed\": false, \"item\": \"/etc/kubernetes/scheduler.conf\", \"msg\": \"Path /etc/kubernetes/scheduler.conf does not exist !\", \"rc\": 257}",
                                "...ignoring",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Check if super-admin.conf exists] *********",
                                "Wednesday 29 July 2026  18:32:57 +0000 (0:00:00.688)       0:00:06.548 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Check if kubeadm has already run] *********",
                                "Wednesday 29 July 2026  18:32:58 +0000 (0:00:00.314)       0:00:06.863 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Set fact with KUBECONFIG path] ************",
                                "Wednesday 29 July 2026  18:32:58 +0000 (0:00:00.224)       0:00:07.088 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Set fact with KUBECONFIG path (with super-admin.conf)] ***",
                                "Wednesday 29 July 2026  18:32:58 +0000 (0:00:00.030)       0:00:07.118 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Upload Kubernetes manifest] ***************",
                                "Wednesday 29 July 2026  18:32:58 +0000 (0:00:00.035)       0:00:07.153 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Ensure kube-vip configuration file] *******",
                                "Wednesday 29 July 2026  18:32:59 +0000 (0:00:00.778)       0:00:07.932 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kube_vip : Flush handlers] ***************************",
                                "Wednesday 29 July 2026  18:32:59 +0000 (0:00:00.243)       0:00:08.176 ********",
                                "",
                                "PLAY [Install Kubernetes] ******************************************************",
                                "",
                                "TASK [Gathering Facts] *********************************************************",
                                "Wednesday 29 July 2026  18:32:59 +0000 (0:00:00.048)       0:00:08.224 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:00 +0000 (0:00:00.800)       0:00:09.024 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.package : Update state for tar] **********************",
                                "Wednesday 29 July 2026  18:33:00 +0000 (0:00:00.255)       0:00:09.280 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.directory : Create directory (/var/lib/downloads)] ***",
                                "Wednesday 29 July 2026  18:33:00 +0000 (0:00:00.037)       0:00:09.317 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:00 +0000 (0:00:00.242)       0:00:09.560 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/opencontainers/runc/releases/download/v1.4.2/runc.amd64\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:00 +0000 (0:00:00.082)       0:00:09.643 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:01 +0000 (0:00:00.854)       0:00:10.497 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:01 +0000 (0:00:00.035)       0:00:10.533 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.package : Update state for tar] **********************",
                                "Wednesday 29 July 2026  18:33:02 +0000 (0:00:00.242)       0:00:10.775 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:03 +0000 (0:00:00.892)       0:00:11.668 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/containerd/containerd/releases/download/v2.3.2/containerd-2.3.2-linux-amd64.tar.gz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:03 +0000 (0:00:00.067)       0:00:11.735 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:04 +0000 (0:00:01.004)       0:00:12.740 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Install SELinux packages] ***************",
                                "Wednesday 29 July 2026  18:33:06 +0000 (0:00:02.926)       0:00:15.666 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Set SELinux to permissive at runtime] ***",
                                "Wednesday 29 July 2026  18:33:07 +0000 (0:00:00.026)       0:00:15.693 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Persist SELinux permissive mode] ********",
                                "Wednesday 29 July 2026  18:33:07 +0000 (0:00:00.032)       0:00:15.725 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Install AppArmor packages] **************",
                                "Wednesday 29 July 2026  18:33:07 +0000 (0:00:00.029)       0:00:15.755 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Create systemd service file for containerd] ***",
                                "Wednesday 29 July 2026  18:33:14 +0000 (0:00:07.116)       0:00:22.871 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Create folders for configuration] *******",
                                "Wednesday 29 July 2026  18:33:14 +0000 (0:00:00.538)       0:00:23.410 ********",
                                "changed: [controller] => (item={'path': '/etc/containerd'})",
                                "changed: [controller] => (item={'path': '/var/lib/containerd', 'mode': '0o700'})",
                                "changed: [controller] => (item={'path': '/run/containerd', 'mode': '0o711'})",
                                "changed: [controller] => (item={'path': '/run/containerd/io.containerd.grpc.v1.cri', 'mode': '0o700'})",
                                "changed: [controller] => (item={'path': '/run/containerd/io.containerd.sandbox.controller.v1.shim', 'mode': '0o700'})",
                                "",
                                "TASK [vexxhost.containers.containerd : Create containerd config file] **********",
                                "Wednesday 29 July 2026  18:33:15 +0000 (0:00:01.159)       0:00:24.570 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Force any restarts if necessary] ********",
                                "Wednesday 29 July 2026  18:33:16 +0000 (0:00:00.666)       0:00:25.236 ********",
                                "",
                                "RUNNING HANDLER [vexxhost.containers.containerd : Restart containerd] **********",
                                "Wednesday 29 July 2026  18:33:16 +0000 (0:00:00.007)       0:00:25.244 ********",
                                "changed: [controller]",
                                "",
                                "RUNNING HANDLER [vexxhost.kubernetes.kubelet : Reload systemd] *****************",
                                "Wednesday 29 July 2026  18:33:17 +0000 (0:00:00.746)       0:00:25.990 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Enable and start service] ***************",
                                "Wednesday 29 July 2026  18:33:18 +0000 (0:00:00.868)       0:00:26.859 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Retrieve the \"kubeadm-config\" ConfigMap] ***",
                                "Wednesday 29 July 2026  18:33:19 +0000 (0:00:01.668)       0:00:28.528 ********",
                                "fatal: [controller]: FAILED! => {\"changed\": false, \"msg\": \"Failed to import the required Python library (kubernetes) on np0000187452's Python /usr/bin/python3.12. Please read the module documentation and install it in the appropriate location. If the required library is installed, but Ansible is using the wrong Python interpreter, please consult the documentation on ansible_python_interpreter\"}",
                                "...ignoring",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Parse the ClusterConfiguration] ***",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.590)       0:00:29.118 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Retrieve the current Kubernetes version] ***",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.036)       0:00:29.155 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Extract major, minor, and patch versions] ***",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.032)       0:00:29.187 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Fail if we're jumping more than one minor version] ***",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.222 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes_upgrade_check : Set fact if we need to upgrade] ***",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.256 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.033)       0:00:29.290 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.249)       0:00:29.540 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubeadm\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:20 +0000 (0:00:00.034)       0:00:29.574 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:22 +0000 (0:00:01.261)       0:00:30.835 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:22 +0000 (0:00:00.039)       0:00:30.875 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:22 +0000 (0:00:00.236)       0:00:31.111 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubectl\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:22 +0000 (0:00:00.040)       0:00:31.152 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:23 +0000 (0:00:00.886)       0:00:32.039 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Install SELinux packages] ***************",
                                "Wednesday 29 July 2026  18:33:23 +0000 (0:00:00.045)       0:00:32.084 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Set SELinux to permissive at runtime] ***",
                                "Wednesday 29 July 2026  18:33:23 +0000 (0:00:00.031)       0:00:32.116 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Persist SELinux permissive mode] ********",
                                "Wednesday 29 July 2026  18:33:23 +0000 (0:00:00.033)       0:00:32.150 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Install AppArmor packages] **************",
                                "Wednesday 29 July 2026  18:33:23 +0000 (0:00:00.034)       0:00:32.185 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Create systemd service file for containerd] ***",
                                "Wednesday 29 July 2026  18:33:24 +0000 (0:00:00.922)       0:00:33.107 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Create folders for configuration] *******",
                                "Wednesday 29 July 2026  18:33:24 +0000 (0:00:00.525)       0:00:33.633 ********",
                                "ok: [controller] => (item={'path': '/etc/containerd'})",
                                "ok: [controller] => (item={'path': '/var/lib/containerd', 'mode': '0o700'})",
                                "ok: [controller] => (item={'path': '/run/containerd', 'mode': '0o711'})",
                                "ok: [controller] => (item={'path': '/run/containerd/io.containerd.grpc.v1.cri', 'mode': '0o700'})",
                                "ok: [controller] => (item={'path': '/run/containerd/io.containerd.sandbox.controller.v1.shim', 'mode': '0o700'})",
                                "",
                                "TASK [vexxhost.containers.containerd : Create containerd config file] **********",
                                "Wednesday 29 July 2026  18:33:26 +0000 (0:00:01.099)       0:00:34.732 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.containerd : Force any restarts if necessary] ********",
                                "Wednesday 29 July 2026  18:33:26 +0000 (0:00:00.623)       0:00:35.356 ********",
                                "",
                                "TASK [vexxhost.containers.containerd : Enable and start service] ***************",
                                "Wednesday 29 July 2026  18:33:26 +0000 (0:00:00.005)       0:00:35.362 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:27 +0000 (0:00:00.419)       0:00:35.782 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:27 +0000 (0:00:00.235)       0:00:36.018 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/kubernetes-sigs/cri-tools/releases/download/v1.36.0/crictl-v1.36.0-linux-amd64.tar.gz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:27 +0000 (0:00:00.058)       0:00:36.076 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:28 +0000 (0:00:00.799)       0:00:36.876 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:29 +0000 (0:00:01.517)       0:00:38.393 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/kubernetes-sigs/cri-tools/releases/download/v1.36.0/critest-v1.36.0-linux-amd64.tar.gz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:29 +0000 (0:00:00.061)       0:00:38.455 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:30 +0000 (0:00:01.020)       0:00:39.476 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.cri_tools : Create crictl config] ********************",
                                "Wednesday 29 July 2026  18:33:32 +0000 (0:00:01.542)       0:00:41.019 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.directory : Create directory (/opt/cni/bin)] *********",
                                "Wednesday 29 July 2026  18:33:32 +0000 (0:00:00.547)       0:00:41.566 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:33 +0000 (0:00:00.245)       0:00:41.811 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:33 +0000 (0:00:00.241)       0:00:42.053 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/containernetworking/plugins/releases/download/v1.9.1/cni-plugins-linux-amd64-v1.9.1.tgz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:33 +0000 (0:00:00.059)       0:00:42.113 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:34 +0000 (0:00:01.061)       0:00:43.174 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.cni_plugins : Gather variables for each operating system] ***",
                                "Wednesday 29 July 2026  18:33:37 +0000 (0:00:02.797)       0:00:45.972 ********",
                                "ok: [controller] => (item=/home/zuul/.ansible/collections/ansible_collections/vexxhost/containers/roles/cni_plugins/vars/debian.yml)",
                                "",
                                "TASK [vexxhost.containers.cni_plugins : Install additional packages] ***********",
                                "Wednesday 29 July 2026  18:33:37 +0000 (0:00:00.050)       0:00:46.022 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.cni_plugins : Ensure IPv6 is enabled] ****************",
                                "Wednesday 29 July 2026  18:33:38 +0000 (0:00:00.873)       0:00:46.896 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.cni_plugins : Enable kernel modules on-boot] *********",
                                "Wednesday 29 July 2026  18:33:38 +0000 (0:00:00.327)       0:00:47.224 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.cni_plugins : Enable kernel modules in runtime] ******",
                                "Wednesday 29 July 2026  18:33:39 +0000 (0:00:00.550)       0:00:47.775 ********",
                                "changed: [controller] => (item=br_netfilter)",
                                "ok: [controller] => (item=ip_tables)",
                                "changed: [controller] => (item=ip6_tables)",
                                "changed: [controller] => (item=nf_conntrack)",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:33:40 +0000 (0:00:01.022)       0:00:48.798 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:33:40 +0000 (0:00:00.232)       0:00:49.031 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://dl.k8s.io/release/v1.28.13/bin/linux/amd64/kubelet\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:33:40 +0000 (0:00:00.044)       0:00:49.075 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:33:41 +0000 (0:00:01.414)       0:00:50.490 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Gather variables for each operating system] ***",
                                "Wednesday 29 July 2026  18:33:41 +0000 (0:00:00.034)       0:00:50.524 ********",
                                "ok: [controller] => (item=/home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubelet/vars/debian.yml)",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Install coreutils] *************************",
                                "Wednesday 29 July 2026  18:33:41 +0000 (0:00:00.050)       0:00:50.574 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Install additional packages] ***************",
                                "Wednesday 29 July 2026  18:33:41 +0000 (0:00:00.025)       0:00:50.600 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Configure sysctl values] *******************",
                                "Wednesday 29 July 2026  18:33:45 +0000 (0:00:03.103)       0:00:53.703 ********",
                                "changed: [controller] => (item={'name': 'net.ipv4.ip_forward', 'value': 1})",
                                "changed: [controller] => (item={'name': 'net.bridge.bridge-nf-call-iptables', 'value': 1})",
                                "changed: [controller] => (item={'name': 'net.bridge.bridge-nf-call-ip6tables', 'value': 1})",
                                "changed: [controller] => (item={'name': 'net.ipv4.conf.all.rp_filter', 'value': 0})",
                                "changed: [controller] => (item={'name': 'fs.inotify.max_queued_events', 'value': 1048576})",
                                "changed: [controller] => (item={'name': 'fs.inotify.max_user_instances', 'value': 8192})",
                                "changed: [controller] => (item={'name': 'fs.inotify.max_user_watches', 'value': 1048576})",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Create folders for kubernetes configuration] ***",
                                "Wednesday 29 July 2026  18:33:46 +0000 (0:00:01.604)       0:00:55.307 ********",
                                "changed: [controller] => (item=/etc/systemd/system/kubelet.service.d)",
                                "ok: [controller] => (item=/etc/kubernetes)",
                                "ok: [controller] => (item=/etc/kubernetes/manifests)",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Add kubelet systemd service config] ********",
                                "Wednesday 29 July 2026  18:33:47 +0000 (0:00:00.674)       0:00:55.982 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Add kubeadm dropin for kubelet systemd service config] ***",
                                "Wednesday 29 July 2026  18:33:47 +0000 (0:00:00.548)       0:00:56.530 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Check swap status] *************************",
                                "Wednesday 29 July 2026  18:33:48 +0000 (0:00:00.552)       0:00:57.083 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Disable swap] ******************************",
                                "Wednesday 29 July 2026  18:33:48 +0000 (0:00:00.330)       0:00:57.414 ********",
                                "[DEPRECATION WARNING]: Conditional result at location /home/zuul/.ansible/colle",
                                "ctions/ansible_collections/vexxhost/kubernetes/roles/kubelet/tasks/main.yml",
                                "91:11 was of type 'AnsibleUnsafeText'. Conditional results should only be True",
                                "or False. The result was interpreted as False. This feature will be removed in",
                                "version 2.19. Deprecation warnings can be disabled by setting",
                                "deprecation_warnings=False in ansible.cfg.",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Remove swapfile from /etc/fstab] ***********",
                                "Wednesday 29 July 2026  18:33:48 +0000 (0:00:00.035)       0:00:57.450 ********",
                                "ok: [controller] => (item=swap)",
                                "ok: [controller] => (item=none)",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Create noswap systemd service config file] ***",
                                "Wednesday 29 July 2026  18:33:49 +0000 (0:00:00.539)       0:00:57.989 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Enable noswap service] *********************",
                                "Wednesday 29 July 2026  18:33:49 +0000 (0:00:00.561)       0:00:58.551 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Force any restarts if necessary] ***********",
                                "Wednesday 29 July 2026  18:33:50 +0000 (0:00:00.684)       0:00:59.236 ********",
                                "",
                                "RUNNING HANDLER [vexxhost.kubernetes.kubelet : Reload systemd] *****************",
                                "Wednesday 29 July 2026  18:33:50 +0000 (0:00:00.005)       0:00:59.241 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Enable and start kubelet service] **********",
                                "Wednesday 29 July 2026  18:33:51 +0000 (0:00:00.861)       0:01:00.103 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Ensure availability of dbus on Debian] *****",
                                "Wednesday 29 July 2026  18:33:52 +0000 (0:00:00.710)       0:01:00.813 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Configure short hostname] ******************",
                                "Wednesday 29 July 2026  18:33:53 +0000 (0:00:00.924)       0:01:01.738 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubelet : Ensure hostname inside hosts file] *********",
                                "Wednesday 29 July 2026  18:33:55 +0000 (0:00:02.277)       0:01:04.016 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Remove kubernetes repository] ***********",
                                "Wednesday 29 July 2026  18:33:55 +0000 (0:00:00.338)       0:01:04.354 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Setup control plane] ********************",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.477)       0:01:04.831 ********",
                                "included: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubernetes/tasks/control-plane.yml for controller",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Bootstrap cluster] **********************",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.071)       0:01:04.903 ********",
                                "included: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/kubernetes/tasks/bootstrap-cluster.yml for controller",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Check if any control plane is bootstrapped] ***",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.074)       0:01:04.978 ********",
                                "ok: [controller] => (item=controller)",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Pick node from pre-existing cluster] ****",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.245)       0:01:05.223 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Select first node to initialize cluster] ***",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.039)       0:01:05.263 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Print selected bootstrap node] **********",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.048)       0:01:05.311 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"controller\"",
                                "}",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Upload cluster configuration for bootstrap node] ***",
                                "Wednesday 29 July 2026  18:33:56 +0000 (0:00:00.040)       0:01:05.352 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create pki folder] **********************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.571)       0:01:05.924 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create kubernetes ca key] ***************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.032)       0:01:05.956 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create kubernetes ca cert] **************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.034)       0:01:05.990 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create etcd-ca key] *********************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.024)       0:01:06.014 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create etcd-ca cert] ********************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.036)       0:01:06.051 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create front-proxy-ca key] **************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.030)       0:01:06.082 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create front-proxy-ca cert] *************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.035)       0:01:06.117 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Initialize cluster] *********************",
                                "Wednesday 29 July 2026  18:33:57 +0000 (0:00:00.031)       0:01:06.149 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Check if the node is already part of the cluster] ***",
                                "Wednesday 29 July 2026  18:34:43 +0000 (0:00:46.148)       0:01:52.297 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Join cluster] ***************************",
                                "Wednesday 29 July 2026  18:34:43 +0000 (0:00:00.252)       0:01:52.549 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Create folder for admin configuration] ***",
                                "Wednesday 29 July 2026  18:34:43 +0000 (0:00:00.035)       0:01:52.585 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Creating a symlink for admin configuration file] ***",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.253)       0:01:52.838 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Add bash autocomplete for kubectl] ******",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.251)       0:01:53.090 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Install PIP] ****************************",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.237)       0:01:53.327 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Install Kubernetes Python package using pip on supported systems] ***",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.041)       0:01:53.369 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Enable EPEL repository] *****************",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.043)       0:01:53.412 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Install Kubernetes Python package using package manager on supported systems] ***",
                                "Wednesday 29 July 2026  18:34:44 +0000 (0:00:00.048)       0:01:53.460 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Allow workload on control plane node] ***",
                                "Wednesday 29 July 2026  18:34:52 +0000 (0:00:07.745)       0:02:01.205 ********",
                                "[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not",
                                "work.",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Remove kube-proxy resources] ************",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.737)       0:02:01.943 ********",
                                "skipping: [controller] => (item=DaemonSet)",
                                "skipping: [controller] => (item=ConfigMap)",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Start an upgrade] ***********************",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.036)       0:02:01.980 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Check if the Kubernetes API services is up to date] ***",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.034)       0:02:02.015 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Trigger an upgrade of the Kubernetes API services] ***",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.037)       0:02:02.053 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Setup nodes] ****************************",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.035)       0:02:02.088 ********",
                                "skipping: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Upgrade & restart Kubelet node for upgrade (if needed)] ***",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.031)       0:02:02.120 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.kubernetes : Set node selector for CoreDNS components] ***",
                                "Wednesday 29 July 2026  18:34:53 +0000 (0:00:00.476)       0:02:02.596 ********",
                                "changed: [controller]",
                                "",
                                "PLAY [Install control-plane components] ****************************************",
                                "",
                                "TASK [Gathering Facts] *********************************************************",
                                "Wednesday 29 July 2026  18:34:54 +0000 (0:00:00.923)       0:02:03.520 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.forget_package : Forget package] *********************",
                                "Wednesday 29 July 2026  18:34:55 +0000 (0:00:00.795)       0:02:04.316 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.package : Update state for tar] **********************",
                                "Wednesday 29 July 2026  18:34:55 +0000 (0:00:00.234)       0:02:04.551 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.directory : Create directory (/var/lib/downloads)] ***",
                                "Wednesday 29 July 2026  18:34:56 +0000 (0:00:00.904)       0:02:05.455 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:34:57 +0000 (0:00:00.259)       0:02:05.714 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://get.helm.sh/helm-v3.11.2-linux-amd64.tar.gz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:34:57 +0000 (0:00:00.038)       0:02:05.753 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:34:57 +0000 (0:00:00.861)       0:02:06.614 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.helm : Remove Helm repository] ***********************",
                                "Wednesday 29 July 2026  18:34:59 +0000 (0:00:01.663)       0:02:08.278 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.helm : Add bash autocomplete for helm] ***************",
                                "Wednesday 29 July 2026  18:34:59 +0000 (0:00:00.378)       0:02:08.656 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.helm : Get Helm plugins dir] *************************",
                                "Wednesday 29 July 2026  18:35:00 +0000 (0:00:00.225)       0:02:08.881 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.helm : Create Helm plugins directory if it does not exist] ***",
                                "Wednesday 29 July 2026  18:35:00 +0000 (0:00:00.347)       0:02:09.229 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.helm : Remove Helm diff plugin installed by kubernetes.core.helm_plugin] ***",
                                "Wednesday 29 July 2026  18:35:00 +0000 (0:00:00.237)       0:02:09.466 ********",
                                "ok: [controller]",
                                "",
                                "TASK [Install plugin] **********************************************************",
                                "Wednesday 29 July 2026  18:35:01 +0000 (0:00:00.224)       0:02:09.690 ********",
                                "included: vexxhost.containers.download_artifact for controller",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Starting download of file] *******",
                                "Wednesday 29 July 2026  18:35:01 +0000 (0:00:00.040)       0:02:09.731 ********",
                                "ok: [controller] => {",
                                "    \"msg\": \"https://github.com/databus23/helm-diff/releases/download/v3.8.1/helm-diff-linux-amd64.tgz\"",
                                "}",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Download item] *******************",
                                "Wednesday 29 July 2026  18:35:01 +0000 (0:00:00.037)       0:02:09.768 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.containers.download_artifact : Extract archive] *****************",
                                "Wednesday 29 July 2026  18:35:01 +0000 (0:00:00.832)       0:02:10.600 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.upload_helm_chart : Include help chart upload method tasks] ***",
                                "Wednesday 29 July 2026  18:35:03 +0000 (0:00:01.946)       0:02:12.547 ********",
                                "included: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/upload_helm_chart/tasks/synchronize.yml for controller",
                                "",
                                "TASK [vexxhost.kubernetes.upload_helm_chart : Upload Helm chart] ***************",
                                "Wednesday 29 July 2026  18:35:03 +0000 (0:00:00.029)       0:02:12.576 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.cilium : Get current Kubernetes version] *************",
                                "Wednesday 29 July 2026  18:35:04 +0000 (0:00:00.628)       0:02:13.205 ********",
                                "ok: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.cilium : Deploy Helm chart] **************************",
                                "Wednesday 29 July 2026  18:35:05 +0000 (0:00:00.840)       0:02:14.045 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.upload_helm_chart : Include help chart upload method tasks] ***",
                                "Wednesday 29 July 2026  18:35:07 +0000 (0:00:02.194)       0:02:16.240 ********",
                                "included: /home/zuul/.ansible/collections/ansible_collections/vexxhost/kubernetes/roles/upload_helm_chart/tasks/synchronize.yml for controller",
                                "",
                                "TASK [vexxhost.kubernetes.upload_helm_chart : Upload Helm chart] ***************",
                                "Wednesday 29 July 2026  18:35:07 +0000 (0:00:00.031)       0:02:16.271 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.envoy_gateway : Deploy Helm chart] *******************",
                                "Wednesday 29 July 2026  18:35:08 +0000 (0:00:00.535)       0:02:16.806 ********",
                                "changed: [controller]",
                                "",
                                "TASK [vexxhost.kubernetes.envoy_gateway : Create GatewayClass] *****************",
                                "Wednesday 29 July 2026  18:35:42 +0000 (0:00:34.682)       0:02:51.489 ********",
                                "changed: [controller]",
                                "",
                                "PLAY RECAP *********************************************************************",
                                "controller                 : ok=117  changed=54   unreachable=0    failed=0    skipped=35   rescued=0    ignored=2",
                                "",
                                "",
                                "TASKS RECAP ********************************************************************",
                                "Wednesday 29 July 2026  18:35:43 +0000 (0:00:00.836)       0:02:52.325 ********",
                                "===============================================================================",
                                "vexxhost.kubernetes.kubernetes : Initialize cluster -------------------- 46.15s",
                                "vexxhost.kubernetes.envoy_gateway : Deploy Helm chart ------------------ 34.68s",
                                "vexxhost.kubernetes.kubernetes : Install Kubernetes Python package using package manager on supported systems --- 7.75s",
                                "vexxhost.containers.containerd : Install AppArmor packages -------------- 7.12s",
                                "vexxhost.kubernetes.kubelet : Install additional packages --------------- 3.10s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 2.93s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 2.80s",
                                "Install Debian packages ------------------------------------------------- 2.35s",
                                "vexxhost.kubernetes.kubelet : Configure short hostname ------------------ 2.28s",
                                "vexxhost.kubernetes.cilium : Deploy Helm chart -------------------------- 2.19s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 1.95s",
                                "vexxhost.kubernetes.kubelet : Reload systemd ---------------------------- 1.73s",
                                "vexxhost.containers.containerd : Enable and start service --------------- 1.67s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 1.66s",
                                "vexxhost.kubernetes.kubelet : Configure sysctl values ------------------- 1.60s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 1.54s",
                                "vexxhost.containers.download_artifact : Extract archive ----------------- 1.52s",
                                "vexxhost.containers.download_artifact : Download item ------------------- 1.41s",
                                "Gathering Facts --------------------------------------------------------- 1.29s",
                                "vexxhost.containers.download_artifact : Download item ------------------- 1.26s",
                                "INFO     [secretgen-controller > prepare] Executed: Successful",
                                "INFO     [secretgen-controller > converge] Executing",
                                "",
                                "PLAY [Deploy \"secretgen-controller\"] *******************************************",
                                "",
                                "TASK [atmosphere.common.secretgen_controller : Deploy secretgen-controller] ****",
                                "Wednesday 29 July 2026  18:35:44 +0000 (0:00:00.046)       0:00:00.046 ********",
                                "[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not",
                                "work.",
                                "[WARNING]: Platform linux on host controller is using the discovered Python",
                                "interpreter at /usr/bin/python3.12, but future installation of another Python",
                                "interpreter could change the meaning of that path. See",
                                "https://docs.ansible.com/ansible-",
                                "core/2.18/reference_appendices/interpreter_discovery.html for more information.",
                                "changed: [controller]",
                                "",
                                "PLAY RECAP *********************************************************************",
                                "controller                 : ok=1    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0",
                                "",
                                "",
                                "TASKS RECAP ********************************************************************",
                                "Wednesday 29 July 2026  18:35:45 +0000 (0:00:01.351)       0:00:01.398 ********",
                                "===============================================================================",
                                "atmosphere.common.secretgen_controller : Deploy secretgen-controller ---- 1.35s",
                                "INFO     [secretgen-controller > converge] Executed: Successful",
                                "INFO     [secretgen-controller > idempotence] Executing",
                                "",
                                "PLAY [Deploy \"secretgen-controller\"] *******************************************",
                                "",
                                "TASK [atmosphere.common.secretgen_controller : Deploy secretgen-controller] ****",
                                "Wednesday 29 July 2026  18:35:46 +0000 (0:00:00.045)       0:00:00.045 ********",
                                "[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not",
                                "work.",
                                "[WARNING]: Platform linux on host controller is using the discovered Python",
                                "interpreter at /usr/bin/python3.12, but future installation of another Python",
                                "interpreter could change the meaning of that path. See",
                                "https://docs.ansible.com/ansible-",
                                "core/2.18/reference_appendices/interpreter_discovery.html for more information.",
                                "ok: [controller]",
                                "",
                                "PLAY RECAP *********************************************************************",
                                "controller                 : ok=1    changed=0    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0",
                                "",
                                "",
                                "TASKS RECAP ********************************************************************",
                                "Wednesday 29 July 2026  18:35:48 +0000 (0:00:01.337)       0:00:01.382 ********",
                                "===============================================================================",
                                "atmosphere.common.secretgen_controller : Deploy secretgen-controller ---- 1.34s",
                                "INFO     [secretgen-controller > idempotence] Executed: Successful",
                                "INFO     [secretgen-controller > side_effect] Executing",
                                "WARNING  [secretgen-controller > side_effect] Executed: Missing playbook (Remove from test_sequence to suppress)",
                                "INFO     [secretgen-controller > verify] Executing",
                                "",
                                "PLAY [Verify] ******************************************************************",
                                "",
                                "TASK [Gathering Facts] *********************************************************",
                                "Wednesday 29 July 2026  18:35:48 +0000 (0:00:00.042)       0:00:00.042 ********",
                                "[WARNING]: Platform linux on host controller is using the discovered Python",
                                "interpreter at /usr/bin/python3.12, but future installation of another Python",
                                "interpreter could change the meaning of that path. See",
                                "https://docs.ansible.com/ansible-",
                                "core/2.18/reference_appendices/interpreter_discovery.html for more information.",
                                "ok: [controller]",
                                "",
                                "TASK [Wait for secretgen-controller deployment to be available] ****************",
                                "Wednesday 29 July 2026  18:35:50 +0000 (0:00:01.280)       0:00:01.322 ********",
                                "[WARNING]: kubernetes<24.2.0 is not supported or tested. Some features may not",
                                "work.",
                                "ok: [controller]",
                                "",
                                "TASK [Create a test Password resource] *****************************************",
                                "Wednesday 29 July 2026  18:35:51 +0000 (0:00:00.841)       0:00:02.163 ********",
                                "changed: [controller]",
                                "",
                                "TASK [Wait for test-password secret to be generated] ***************************",
                                "Wednesday 29 July 2026  18:35:51 +0000 (0:00:00.882)       0:00:03.046 ********",
                                "ok: [controller]",
                                "",
                                "PLAY RECAP *********************************************************************",
                                "controller                 : ok=4    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0",
                                "",
                                "",
                                "TASKS RECAP ********************************************************************",
                                "Wednesday 29 July 2026  18:35:52 +0000 (0:00:00.705)       0:00:03.752 ********",
                                "===============================================================================",
                                "Gathering Facts --------------------------------------------------------- 1.28s",
                                "Create a test Password resource ----------------------------------------- 0.88s",
                                "Wait for secretgen-controller deployment to be available ---------------- 0.84s",
                                "Wait for test-password secret to be generated --------------------------- 0.71s",
                                "INFO     [secretgen-controller > verify] Executed: Successful",
                                "INFO     [secretgen-controller > cleanup] Executing",
                                "WARNING  [secretgen-controller > cleanup] Executed: Missing playbook (Remove from test_sequence to suppress)",
                                "INFO     [secretgen-controller > destroy] Executing",
                                "WARNING  [secretgen-controller > destroy] Skipping, '--destroy=never' requested.",
                                "INFO     [secretgen-controller > destroy] Executed: Successful",
                                "WARNING  Molecule executed 1 scenario (1 missing files)"
                            ],
                            "zuul_log_id": "0242ac17-0010-1989-7ad7-000000000007-1-controller"
                        }
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:35:53.575273Z",
                            "start": "2026-07-29T18:31:19.666141Z"
                        },
                        "id": "0242ac17-0010-1989-7ad7-000000000007",
                        "name": "Run Molecule scenario"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 3,
            "failures": 0,
            "ignored": 0,
            "ok": 4,
            "rescued": 0,
            "skipped": 0,
            "unreachable": 0
        }
    },
    "trusted": false
},
{
    "branch": "main",
    "index": "0",
    "phase": "post",
    "playbook": "github.com/vexxhost/atmosphere.common/test-playbooks/molecule/post.yml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:36:53.229682Z",
                    "start": "2026-07-29T18:36:02.975029Z"
                },
                "id": "0242ac17-0010-5d7d-c0aa-000000000002",
                "name": "Collect Molecule logs"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/system",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/system",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/system",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/system",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000a",
                        "name": "gather-host-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-host-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:04.628582Z",
                            "start": "2026-07-29T18:36:03.064584Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000c",
                        "name": "creating directory for system status"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -x\nsystemd-cgls --full --all --no-pager > /tmp/logs/system/systemd-cgls.txt\nip addr > /tmp/logs/system/ip-addr.txt\nip route > /tmp/logs/system/ip-route.txt\nlsblk > /tmp/logs/system/lsblk.txt\nmount > /tmp/logs/system/mount.txt\ndocker images > /tmp/logs/system/docker-images.txt\nbrctl show > /tmp/logs/system/brctl-show.txt\nps aux --sort=-%mem > /tmp/logs/system/ps.txt\ndpkg -l > /tmp/logs/system/packages.txt\nCONTAINERS=($(docker ps -a --format '{{ .Names }}' --filter label=zuul))\nif [ ! -z \"$CONTAINERS\" ]; then\n  mkdir -p \"/tmp/logs/system/containers\"\n  for CONTAINER in ${CONTAINERS}; do\n    docker logs \"${CONTAINER}\" > \"/tmp/logs/system/containers/${CONTAINER}.txt\"\n  done\nfi",
                            "delta": "0:00:00.090599",
                            "end": "2026-07-29 18:36:05.280135",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -x\nsystemd-cgls --full --all --no-pager > /tmp/logs/system/systemd-cgls.txt\nip addr > /tmp/logs/system/ip-addr.txt\nip route > /tmp/logs/system/ip-route.txt\nlsblk > /tmp/logs/system/lsblk.txt\nmount > /tmp/logs/system/mount.txt\ndocker images > /tmp/logs/system/docker-images.txt\nbrctl show > /tmp/logs/system/brctl-show.txt\nps aux --sort=-%mem > /tmp/logs/system/ps.txt\ndpkg -l > /tmp/logs/system/packages.txt\nCONTAINERS=($(docker ps -a --format '{{ .Names }}' --filter label=zuul))\nif [ ! -z \"$CONTAINERS\" ]; then\n  mkdir -p \"/tmp/logs/system/containers\"\n  for CONTAINER in ${CONTAINERS}; do\n    docker logs \"${CONTAINER}\" > \"/tmp/logs/system/containers/${CONTAINER}.txt\"\n  done\nfi",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000000d-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:05.189536",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "+ systemd-cgls --full --all --no-pager\n+ ip addr\n+ ip route\n+ lsblk\n+ mount\n+ docker images\n/bin/bash: line 7: docker: command not found\n+ brctl show\n/bin/bash: line 8: brctl: command not found\n+ ps aux --sort=-%mem\n+ dpkg -l\n+ CONTAINERS=($(docker ps -a --format '{{ .Names }}' --filter label=zuul))\n++ docker ps -a --format '{{ .Names }}' --filter label=zuul\n/bin/bash: line 11: docker: command not found\n+ '[' '!' -z '' ']'",
                            "stdout_lines": [
                                "+ systemd-cgls --full --all --no-pager",
                                "+ ip addr",
                                "+ ip route",
                                "+ lsblk",
                                "+ mount",
                                "+ docker images",
                                "/bin/bash: line 7: docker: command not found",
                                "+ brctl show",
                                "/bin/bash: line 8: brctl: command not found",
                                "+ ps aux --sort=-%mem",
                                "+ dpkg -l",
                                "+ CONTAINERS=($(docker ps -a --format '{{ .Names }}' --filter label=zuul))",
                                "++ docker ps -a --format '{{ .Names }}' --filter label=zuul",
                                "/bin/bash: line 11: docker: command not found",
                                "+ '[' '!' -z '' ']'"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000000d-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000a",
                        "name": "gather-host-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-host-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:05.715597Z",
                            "start": "2026-07-29T18:36:04.696493Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000d",
                        "name": "Get logs for each host"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/system /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/system",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "created directory /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller\ncd+++++++++ system/\n>f+++++++++ system/brctl-show.txt\n>f+++++++++ system/docker-images.txt\n>f+++++++++ system/ip-addr.txt\n>f+++++++++ system/ip-route.txt\n>f+++++++++ system/lsblk.txt\n>f+++++++++ system/mount.txt\n>f+++++++++ system/packages.txt\n>f+++++++++ system/ps.txt\n>f+++++++++ system/systemd-cgls.txt\n",
                            "rc": 0,
                            "stdout_lines": [
                                "created directory /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                "cd+++++++++ system/",
                                ">f+++++++++ system/brctl-show.txt",
                                ">f+++++++++ system/docker-images.txt",
                                ">f+++++++++ system/ip-addr.txt",
                                ">f+++++++++ system/ip-route.txt",
                                ">f+++++++++ system/lsblk.txt",
                                ">f+++++++++ system/mount.txt",
                                ">f+++++++++ system/packages.txt",
                                ">f+++++++++ system/ps.txt",
                                ">f+++++++++ system/systemd-cgls.txt"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000a",
                        "name": "gather-host-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-host-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:07.756197Z",
                            "start": "2026-07-29T18:36:05.722997Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000000e",
                        "name": "Downloads logs to executor"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "directory",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "path": "/tmp/logs/helm/values",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "path": "/tmp/logs/helm/values",
                                            "state": "absent"
                                        }
                                    },
                                    "directory": "values",
                                    "failed": false,
                                    "gid": 0,
                                    "group": "root",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": null,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/tmp/logs/helm/values",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "root",
                                    "path": "/tmp/logs/helm/values",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 0
                                },
                                {
                                    "ansible_loop_var": "directory",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "path": "/tmp/logs/helm/releases",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "path": "/tmp/logs/helm/releases",
                                            "state": "absent"
                                        }
                                    },
                                    "directory": "releases",
                                    "failed": false,
                                    "gid": 0,
                                    "group": "root",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": null,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/tmp/logs/helm/releases",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "root",
                                    "path": "/tmp/logs/helm/releases",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 0
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000010",
                        "name": "helm-release-status",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/helm-release-status"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:08.222112Z",
                            "start": "2026-07-29T18:36:07.766472Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000012",
                        "name": "creating directory for helm release status"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\n\nfor namespace in $(kubectl get namespaces --no-headers --output custom-columns=\":metadata.name\"); do\n      # get all Helm releases including pending and failed releases\n      for release in $(helm list --all --short --namespace $namespace); do\n              # Make respective directories only when a Helm release actually exists in the namespace\n              # to prevent uploading a bunch of empty directories for namespaces without a Helm release.\n              mkdir -p /tmp/logs/helm/releases/$namespace\n              mkdir -p /tmp/logs/helm/values/$namespace\n\n              helm status $release --namespace $namespace >> /tmp/logs/helm/releases/$namespace/$release.txt\n              helm get values $release --namespace $namespace --all >> /tmp/logs/helm/values/$namespace/$release.yaml\n      done\ndone",
                            "delta": "0:00:01.358325",
                            "end": "2026-07-29 18:36:09.835980",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\n\nfor namespace in $(kubectl get namespaces --no-headers --output custom-columns=\":metadata.name\"); do\n      # get all Helm releases including pending and failed releases\n      for release in $(helm list --all --short --namespace $namespace); do\n              # Make respective directories only when a Helm release actually exists in the namespace\n              # to prevent uploading a bunch of empty directories for namespaces without a Helm release.\n              mkdir -p /tmp/logs/helm/releases/$namespace\n              mkdir -p /tmp/logs/helm/values/$namespace\n\n              helm status $release --namespace $namespace >> /tmp/logs/helm/releases/$namespace/$release.txt\n              helm get values $release --namespace $namespace --all >> /tmp/logs/helm/values/$namespace/$release.yaml\n      done\ndone",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000014-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:08.477655",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "",
                            "stdout_lines": [],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000014-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000010",
                        "name": "helm-release-status",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/helm-release-status"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:10.277673Z",
                            "start": "2026-07-29T18:36:08.257731Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000014",
                        "name": "Gather get release status for helm charts"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/helm /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/helm",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "cd+++++++++ helm/\ncd+++++++++ helm/releases/\ncd+++++++++ helm/releases/envoy-gateway-system/\n>f+++++++++ helm/releases/envoy-gateway-system/envoy-gateway.txt\ncd+++++++++ helm/releases/kube-system/\n>f+++++++++ helm/releases/kube-system/cilium.txt\ncd+++++++++ helm/values/\ncd+++++++++ helm/values/envoy-gateway-system/\n>f+++++++++ helm/values/envoy-gateway-system/envoy-gateway.yaml\ncd+++++++++ helm/values/kube-system/\n>f+++++++++ helm/values/kube-system/cilium.yaml\n",
                            "rc": 0,
                            "stdout_lines": [
                                "cd+++++++++ helm/",
                                "cd+++++++++ helm/releases/",
                                "cd+++++++++ helm/releases/envoy-gateway-system/",
                                ">f+++++++++ helm/releases/envoy-gateway-system/envoy-gateway.txt",
                                "cd+++++++++ helm/releases/kube-system/",
                                ">f+++++++++ helm/releases/kube-system/cilium.txt",
                                "cd+++++++++ helm/values/",
                                "cd+++++++++ helm/values/envoy-gateway-system/",
                                ">f+++++++++ helm/values/envoy-gateway-system/envoy-gateway.yaml",
                                "cd+++++++++ helm/values/kube-system/",
                                ">f+++++++++ helm/values/kube-system/cilium.yaml"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000010",
                        "name": "helm-release-status",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/helm-release-status"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:10.797990Z",
                            "start": "2026-07-29T18:36:10.284088Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000015",
                        "name": "Downloads logs to executor"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/objects/cluster",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/objects/cluster",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/objects/cluster",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/objects/cluster",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000017",
                        "name": "describe-kubernetes-objects",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/describe-kubernetes-objects"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:11.071556Z",
                            "start": "2026-07-29T18:36:10.811619Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000019",
                        "name": "creating directory for cluster scoped objects"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nexport OBJECT_TYPE=node,clusterrole,clusterrolebinding,storageclass,namespace\nexport PARALLELISM_FACTOR=2\n\nfunction list_objects () {\n  printf ${OBJECT_TYPE} | xargs -d ',' -I {} -P1 -n1 bash -c 'echo \"$@\"' _ {}\n}\nexport -f list_objects\n\nfunction name_objects () {\n  export OBJECT=$1\n  kubectl get ${OBJECT} -o name | xargs -L1 -I {} -P1 -n1 bash -c 'echo \"${OBJECT} ${1#*/}\"' _ {}\n}\nexport -f name_objects\n\nfunction get_objects () {\n  input=($1)\n  export OBJECT=${input[0]}\n  export NAME=${input[1]#*/}\n  echo \"${OBJECT}/${NAME}\"\n  DIR=\"/tmp/logs/objects/cluster/${OBJECT}\"\n  mkdir -p ${DIR}\n  kubectl get ${OBJECT} ${NAME} -o yaml > \"${DIR}/${NAME}.yaml\"\n  kubectl describe ${OBJECT} ${NAME} > \"${DIR}/${NAME}.txt\"\n}\nexport -f get_objects\n\nlist_objects |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'name_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'get_objects \"$@\"' _ {}",
                            "delta": "0:00:12.259486",
                            "end": "2026-07-29 18:36:23.618306",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nexport OBJECT_TYPE=node,clusterrole,clusterrolebinding,storageclass,namespace\nexport PARALLELISM_FACTOR=2\n\nfunction list_objects () {\n  printf ${OBJECT_TYPE} | xargs -d ',' -I {} -P1 -n1 bash -c 'echo \"$@\"' _ {}\n}\nexport -f list_objects\n\nfunction name_objects () {\n  export OBJECT=$1\n  kubectl get ${OBJECT} -o name | xargs -L1 -I {} -P1 -n1 bash -c 'echo \"${OBJECT} ${1#*/}\"' _ {}\n}\nexport -f name_objects\n\nfunction get_objects () {\n  input=($1)\n  export OBJECT=${input[0]}\n  export NAME=${input[1]#*/}\n  echo \"${OBJECT}/${NAME}\"\n  DIR=\"/tmp/logs/objects/cluster/${OBJECT}\"\n  mkdir -p ${DIR}\n  kubectl get ${OBJECT} ${NAME} -o yaml > \"${DIR}/${NAME}.yaml\"\n  kubectl describe ${OBJECT} ${NAME} > \"${DIR}/${NAME}.txt\"\n}\nexport -f get_objects\n\nlist_objects |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'name_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'get_objects \"$@\"' _ {}",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000001a-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:11.358820",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value\nxargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nnode/controller\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nclusterrole/admin\nclusterrole/cilium\nclusterrole/cilium-operator\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nclusterrole/cluster-admin\nclusterrole/edit\nclusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system\nclusterrole/envoy-gateway-gateway-helm-envoy-gateway-role\nclusterrole/kubeadm:get-nodes\nclusterrole/secretgen-controller-cluster-role\nclusterrole/system:aggregate-to-admin\nclusterrole/system:aggregate-to-edit\nclusterrole/system:aggregate-to-view\nclusterrole/system:auth-delegator\nclusterrole/system:basic-user\nclusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient\nclusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient\nclusterrole/system:certificates.k8s.io:kube-apiserver-client-approver\nclusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver\nclusterrole/system:certificates.k8s.io:kubelet-serving-approver\nclusterrole/system:certificates.k8s.io:legacy-unknown-approver\nclusterrole/system:controller:attachdetach-controller\nclusterrole/system:controller:certificate-controller\nclusterrole/system:controller:clusterrole-aggregation-controller\nclusterrole/system:controller:cronjob-controller\nclusterrolebinding/cilium\nclusterrole/system:controller:daemon-set-controller\nclusterrolebinding/cilium-operator\nclusterrole/system:controller:deployment-controller\nclusterrolebinding/cluster-admin\nclusterrole/system:controller:disruption-controller\nclusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system\nclusterrole/system:controller:endpoint-controller\nclusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding\nclusterrole/system:controller:endpointslice-controller\nclusterrole/system:controller:endpointslicemirroring-controller\nclusterrolebinding/kubeadm:get-nodes\nclusterrole/system:controller:ephemeral-volume-controller\nclusterrolebinding/kubeadm:kubelet-bootstrap\nclusterrole/system:controller:expand-controller\nclusterrolebinding/kubeadm:node-autoapprove-bootstrap\nclusterrole/system:controller:generic-garbage-collector\nclusterrolebinding/kubeadm:node-autoapprove-certificate-rotation\nclusterrole/system:controller:horizontal-pod-autoscaler\nclusterrolebinding/kubeadm:node-proxier\nclusterrole/system:controller:job-controller\nclusterrolebinding/secretgen-controller-cluster-role-binding\nclusterrole/system:controller:namespace-controller\nclusterrolebinding/system:basic-user\nclusterrole/system:controller:node-controller\nclusterrolebinding/system:controller:attachdetach-controller\nclusterrole/system:controller:persistent-volume-binder\nclusterrolebinding/system:controller:certificate-controller\nclusterrole/system:controller:pod-garbage-collector\nclusterrolebinding/system:controller:clusterrole-aggregation-controller\nclusterrole/system:controller:pv-protection-controller\nclusterrolebinding/system:controller:cronjob-controller\nclusterrolebinding/system:controller:daemon-set-controller\nclusterrole/system:controller:pvc-protection-controller\nclusterrolebinding/system:controller:deployment-controller\nclusterrole/system:controller:replicaset-controller\nclusterrolebinding/system:controller:disruption-controller\nclusterrole/system:controller:replication-controller\nclusterrolebinding/system:controller:endpoint-controller\nclusterrole/system:controller:resourcequota-controller\nclusterrolebinding/system:controller:endpointslice-controller\nclusterrole/system:controller:root-ca-cert-publisher\nclusterrolebinding/system:controller:endpointslicemirroring-controller\nclusterrole/system:controller:route-controller\nclusterrolebinding/system:controller:ephemeral-volume-controller\nclusterrole/system:controller:service-account-controller\nclusterrolebinding/system:controller:expand-controller\nclusterrole/system:controller:service-controller\nclusterrolebinding/system:controller:generic-garbage-collector\nclusterrole/system:controller:statefulset-controller\nclusterrolebinding/system:controller:horizontal-pod-autoscaler\nclusterrole/system:controller:ttl-after-finished-controller\nclusterrolebinding/system:controller:job-controller\nclusterrole/system:controller:ttl-controller\nclusterrole/system:coredns\nclusterrolebinding/system:controller:namespace-controller\nclusterrole/system:discovery\nclusterrolebinding/system:controller:node-controller\nclusterrole/system:heapster\nclusterrolebinding/system:controller:persistent-volume-binder\nclusterrole/system:kube-aggregator\nclusterrolebinding/system:controller:pod-garbage-collector\nclusterrole/system:kube-controller-manager\nclusterrolebinding/system:controller:pv-protection-controller\nclusterrole/system:kube-dns\nclusterrolebinding/system:controller:pvc-protection-controller\nclusterrole/system:kube-scheduler\nclusterrolebinding/system:controller:replicaset-controller\nclusterrole/system:kubelet-api-admin\nclusterrole/system:monitoring\nclusterrolebinding/system:controller:replication-controller\nclusterrole/system:node\nclusterrole/system:node-bootstrapper\nclusterrolebinding/system:controller:resourcequota-controller\nclusterrole/system:node-problem-detector\nclusterrolebinding/system:controller:root-ca-cert-publisher\nclusterrole/system:node-proxier\nclusterrolebinding/system:controller:route-controller\nclusterrole/system:persistent-volume-provisioner\nclusterrolebinding/system:controller:service-account-controller\nclusterrolebinding/system:controller:service-controller\nclusterrole/system:public-info-viewer\nclusterrolebinding/system:controller:statefulset-controller\nclusterrole/system:service-account-issuer-discovery\nclusterrolebinding/system:controller:ttl-after-finished-controller\nclusterrolebinding/system:controller:ttl-controller\nclusterrolebinding/system:coredns\nclusterrole/system:volume-scheduler\nclusterrolebinding/system:discovery\nclusterrole/view\nclusterrolebinding/system:kube-controller-manager\nclusterrolebinding/system:kube-dns\nclusterrolebinding/system:kube-scheduler\nclusterrolebinding/system:monitoring\nclusterrolebinding/system:node\nclusterrolebinding/system:node-proxier\nclusterrolebinding/system:public-info-viewer\nclusterrolebinding/system:service-account-issuer-discovery\nclusterrolebinding/system:volume-scheduler\nnamespace/default\nnamespace/envoy-gateway-system\nnamespace/kube-node-lease\nnamespace/kube-public\nnamespace/kube-system\nnamespace/secretgen-controller",
                            "stdout_lines": [
                                "xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value",
                                "xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "node/controller",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "clusterrole/admin",
                                "clusterrole/cilium",
                                "clusterrole/cilium-operator",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "clusterrole/cluster-admin",
                                "clusterrole/edit",
                                "clusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system",
                                "clusterrole/envoy-gateway-gateway-helm-envoy-gateway-role",
                                "clusterrole/kubeadm:get-nodes",
                                "clusterrole/secretgen-controller-cluster-role",
                                "clusterrole/system:aggregate-to-admin",
                                "clusterrole/system:aggregate-to-edit",
                                "clusterrole/system:aggregate-to-view",
                                "clusterrole/system:auth-delegator",
                                "clusterrole/system:basic-user",
                                "clusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient",
                                "clusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient",
                                "clusterrole/system:certificates.k8s.io:kube-apiserver-client-approver",
                                "clusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver",
                                "clusterrole/system:certificates.k8s.io:kubelet-serving-approver",
                                "clusterrole/system:certificates.k8s.io:legacy-unknown-approver",
                                "clusterrole/system:controller:attachdetach-controller",
                                "clusterrole/system:controller:certificate-controller",
                                "clusterrole/system:controller:clusterrole-aggregation-controller",
                                "clusterrole/system:controller:cronjob-controller",
                                "clusterrolebinding/cilium",
                                "clusterrole/system:controller:daemon-set-controller",
                                "clusterrolebinding/cilium-operator",
                                "clusterrole/system:controller:deployment-controller",
                                "clusterrolebinding/cluster-admin",
                                "clusterrole/system:controller:disruption-controller",
                                "clusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system",
                                "clusterrole/system:controller:endpoint-controller",
                                "clusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding",
                                "clusterrole/system:controller:endpointslice-controller",
                                "clusterrole/system:controller:endpointslicemirroring-controller",
                                "clusterrolebinding/kubeadm:get-nodes",
                                "clusterrole/system:controller:ephemeral-volume-controller",
                                "clusterrolebinding/kubeadm:kubelet-bootstrap",
                                "clusterrole/system:controller:expand-controller",
                                "clusterrolebinding/kubeadm:node-autoapprove-bootstrap",
                                "clusterrole/system:controller:generic-garbage-collector",
                                "clusterrolebinding/kubeadm:node-autoapprove-certificate-rotation",
                                "clusterrole/system:controller:horizontal-pod-autoscaler",
                                "clusterrolebinding/kubeadm:node-proxier",
                                "clusterrole/system:controller:job-controller",
                                "clusterrolebinding/secretgen-controller-cluster-role-binding",
                                "clusterrole/system:controller:namespace-controller",
                                "clusterrolebinding/system:basic-user",
                                "clusterrole/system:controller:node-controller",
                                "clusterrolebinding/system:controller:attachdetach-controller",
                                "clusterrole/system:controller:persistent-volume-binder",
                                "clusterrolebinding/system:controller:certificate-controller",
                                "clusterrole/system:controller:pod-garbage-collector",
                                "clusterrolebinding/system:controller:clusterrole-aggregation-controller",
                                "clusterrole/system:controller:pv-protection-controller",
                                "clusterrolebinding/system:controller:cronjob-controller",
                                "clusterrolebinding/system:controller:daemon-set-controller",
                                "clusterrole/system:controller:pvc-protection-controller",
                                "clusterrolebinding/system:controller:deployment-controller",
                                "clusterrole/system:controller:replicaset-controller",
                                "clusterrolebinding/system:controller:disruption-controller",
                                "clusterrole/system:controller:replication-controller",
                                "clusterrolebinding/system:controller:endpoint-controller",
                                "clusterrole/system:controller:resourcequota-controller",
                                "clusterrolebinding/system:controller:endpointslice-controller",
                                "clusterrole/system:controller:root-ca-cert-publisher",
                                "clusterrolebinding/system:controller:endpointslicemirroring-controller",
                                "clusterrole/system:controller:route-controller",
                                "clusterrolebinding/system:controller:ephemeral-volume-controller",
                                "clusterrole/system:controller:service-account-controller",
                                "clusterrolebinding/system:controller:expand-controller",
                                "clusterrole/system:controller:service-controller",
                                "clusterrolebinding/system:controller:generic-garbage-collector",
                                "clusterrole/system:controller:statefulset-controller",
                                "clusterrolebinding/system:controller:horizontal-pod-autoscaler",
                                "clusterrole/system:controller:ttl-after-finished-controller",
                                "clusterrolebinding/system:controller:job-controller",
                                "clusterrole/system:controller:ttl-controller",
                                "clusterrole/system:coredns",
                                "clusterrolebinding/system:controller:namespace-controller",
                                "clusterrole/system:discovery",
                                "clusterrolebinding/system:controller:node-controller",
                                "clusterrole/system:heapster",
                                "clusterrolebinding/system:controller:persistent-volume-binder",
                                "clusterrole/system:kube-aggregator",
                                "clusterrolebinding/system:controller:pod-garbage-collector",
                                "clusterrole/system:kube-controller-manager",
                                "clusterrolebinding/system:controller:pv-protection-controller",
                                "clusterrole/system:kube-dns",
                                "clusterrolebinding/system:controller:pvc-protection-controller",
                                "clusterrole/system:kube-scheduler",
                                "clusterrolebinding/system:controller:replicaset-controller",
                                "clusterrole/system:kubelet-api-admin",
                                "clusterrole/system:monitoring",
                                "clusterrolebinding/system:controller:replication-controller",
                                "clusterrole/system:node",
                                "clusterrole/system:node-bootstrapper",
                                "clusterrolebinding/system:controller:resourcequota-controller",
                                "clusterrole/system:node-problem-detector",
                                "clusterrolebinding/system:controller:root-ca-cert-publisher",
                                "clusterrole/system:node-proxier",
                                "clusterrolebinding/system:controller:route-controller",
                                "clusterrole/system:persistent-volume-provisioner",
                                "clusterrolebinding/system:controller:service-account-controller",
                                "clusterrolebinding/system:controller:service-controller",
                                "clusterrole/system:public-info-viewer",
                                "clusterrolebinding/system:controller:statefulset-controller",
                                "clusterrole/system:service-account-issuer-discovery",
                                "clusterrolebinding/system:controller:ttl-after-finished-controller",
                                "clusterrolebinding/system:controller:ttl-controller",
                                "clusterrolebinding/system:coredns",
                                "clusterrole/system:volume-scheduler",
                                "clusterrolebinding/system:discovery",
                                "clusterrole/view",
                                "clusterrolebinding/system:kube-controller-manager",
                                "clusterrolebinding/system:kube-dns",
                                "clusterrolebinding/system:kube-scheduler",
                                "clusterrolebinding/system:monitoring",
                                "clusterrolebinding/system:node",
                                "clusterrolebinding/system:node-proxier",
                                "clusterrolebinding/system:public-info-viewer",
                                "clusterrolebinding/system:service-account-issuer-discovery",
                                "clusterrolebinding/system:volume-scheduler",
                                "namespace/default",
                                "namespace/envoy-gateway-system",
                                "namespace/kube-node-lease",
                                "namespace/kube-public",
                                "namespace/kube-system",
                                "namespace/secretgen-controller"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000001a-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000017",
                        "name": "describe-kubernetes-objects",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/describe-kubernetes-objects"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:23.676496Z",
                            "start": "2026-07-29T18:36:11.126071Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001a",
                        "name": "Gathering descriptions for cluster scoped objects"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/objects/namespaced",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/objects/namespaced",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/objects/namespaced",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/objects/namespaced",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000017",
                        "name": "describe-kubernetes-objects",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/describe-kubernetes-objects"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:24.466126Z",
                            "start": "2026-07-29T18:36:23.684942Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001b",
                        "name": "creating directory for namespace scoped objects"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nexport OBJECT_TYPE=configmaps,cronjobs,daemonsets,deployment,endpoints,ingresses,jobs,networkpolicies,pods,podsecuritypolicies,persistentvolumeclaims,rolebindings,roles,secrets,serviceaccounts,services,statefulsets\nexport PARALLELISM_FACTOR=2\nfunction get_namespaces () {\n  kubectl get namespaces -o name | awk -F '/' '{ print $NF }'\n}\n\nfunction list_namespaced_objects () {\n  export NAMESPACE=$1\n  printf ${OBJECT_TYPE} | xargs -d ',' -I {} -P1 -n1 bash -c 'echo \"${NAMESPACE} $@\"' _ {}\n}\nexport -f list_namespaced_objects\n\nfunction name_objects () {\n  input=($1)\n  export NAMESPACE=${input[0]}\n  export OBJECT=${input[1]}\n  kubectl get -n ${NAMESPACE} ${OBJECT} -o name | xargs -L1 -I {} -P1 -n1 bash -c 'echo \"${NAMESPACE} ${OBJECT} $@\"' _ {}\n}\nexport -f name_objects\n\nfunction get_objects () {\n  input=($1)\n  export NAMESPACE=${input[0]}\n  export OBJECT=${input[1]}\n  export NAME=${input[2]#*/}\n  echo \"${NAMESPACE}/${OBJECT}/${NAME}\"\n  DIR=\"/tmp/logs/objects/namespaced/${NAMESPACE}/${OBJECT}\"\n  mkdir -p ${DIR}\n  kubectl get -n ${NAMESPACE} ${OBJECT} ${NAME} -o yaml > \"${DIR}/${NAME}.yaml\"\n  kubectl describe -n ${NAMESPACE} ${OBJECT} ${NAME} > \"${DIR}/${NAME}.txt\"\n}\nexport -f get_objects\n\nget_namespaces |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'list_namespaced_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'name_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'get_objects \"$@\"' _ {}",
                            "delta": "0:00:14.357360",
                            "end": "2026-07-29 18:36:39.081814",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nexport OBJECT_TYPE=configmaps,cronjobs,daemonsets,deployment,endpoints,ingresses,jobs,networkpolicies,pods,podsecuritypolicies,persistentvolumeclaims,rolebindings,roles,secrets,serviceaccounts,services,statefulsets\nexport PARALLELISM_FACTOR=2\nfunction get_namespaces () {\n  kubectl get namespaces -o name | awk -F '/' '{ print $NF }'\n}\n\nfunction list_namespaced_objects () {\n  export NAMESPACE=$1\n  printf ${OBJECT_TYPE} | xargs -d ',' -I {} -P1 -n1 bash -c 'echo \"${NAMESPACE} $@\"' _ {}\n}\nexport -f list_namespaced_objects\n\nfunction name_objects () {\n  input=($1)\n  export NAMESPACE=${input[0]}\n  export OBJECT=${input[1]}\n  kubectl get -n ${NAMESPACE} ${OBJECT} -o name | xargs -L1 -I {} -P1 -n1 bash -c 'echo \"${NAMESPACE} ${OBJECT} $@\"' _ {}\n}\nexport -f name_objects\n\nfunction get_objects () {\n  input=($1)\n  export NAMESPACE=${input[0]}\n  export OBJECT=${input[1]}\n  export NAME=${input[2]#*/}\n  echo \"${NAMESPACE}/${OBJECT}/${NAME}\"\n  DIR=\"/tmp/logs/objects/namespaced/${NAMESPACE}/${OBJECT}\"\n  mkdir -p ${DIR}\n  kubectl get -n ${NAMESPACE} ${OBJECT} ${NAME} -o yaml > \"${DIR}/${NAME}.yaml\"\n  kubectl describe -n ${NAMESPACE} ${OBJECT} ${NAME} > \"${DIR}/${NAME}.txt\"\n}\nexport -f get_objects\n\nget_namespaces |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'list_namespaced_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'name_objects \"$@\"' _ {} |  xargs -r -n 1 -P ${PARALLELISM_FACTOR} -I {} bash -c 'get_objects \"$@\"' _ {}",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000001c-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:24.724454",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value\nxargs: xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args valuewarning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value\n\nxargs: xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines valuewarning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\n\nenvoy-gateway-system/configmaps/envoy-gateway-config\nenvoy-gateway-system/configmaps/kube-root-ca.crt\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\ndefault/configmaps/kube-root-ca.crt\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/deployment/envoy-gateway\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/endpoints/envoy-gateway\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\ndefault/endpoints/kubernetes\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen\nenvoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding\nenvoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager\nenvoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\ndefault/secrets/test-password\nenvoy-gateway-system/serviceaccounts/default\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/serviceaccounts/envoy-gateway\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/secrets/envoy\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/secrets/envoy-gateway\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/secrets/envoy-oidc-hmac\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/secrets/envoy-rate-limit\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nenvoy-gateway-system/services/envoy-gateway\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\ndefault/serviceaccounts/default\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\ndefault/services/kubernetes\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-node-lease/configmaps/kube-root-ca.crt\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-public/configmaps/cluster-info\nkube-public/configmaps/kube-root-ca.crt\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo\nkube-public/rolebindings/system:controller:bootstrap-signer\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-node-lease/serviceaccounts/default\nkube-public/roles/kubeadm:bootstrap-signer-clusterinfo\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-public/roles/system:controller:bootstrap-signer\nkube-public/serviceaccounts/default\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/cilium-config\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/coredns\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/extension-apiserver-authentication\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nkube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/kube-proxy\nkube-system/configmaps/kube-root-ca.crt\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nerror: the server doesn't have a resource type \"podsecuritypolicies\"\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/kubeadm-config\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/configmaps/kubelet-config\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nsecretgen-controller/configmaps/kube-root-ca.crt\nkube-system/daemonsets/cilium\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/daemonsets/kube-proxy\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/deployment/cilium-operator\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nxargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value\nkube-system/deployment/coredns\nsecretgen-controller/deployment/secretgen-controller\nkube-system/endpoints/kube-dns\nkube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb\nkube-system/pods/cilium-p2q6r\nkube-system/pods/coredns-5dd5756b68-bwt9r\nkube-system/pods/coredns-77cccfdc44-6r6vb\nkube-system/pods/coredns-77cccfdc44-ksw4v\nkube-system/pods/etcd-controller\nkube-system/pods/kube-apiserver-controller\nkube-system/pods/kube-controller-manager-controller\nkube-system/pods/kube-proxy-nbcfs\nkube-system/pods/kube-scheduler-controller\nkube-system/pods/kube-vip-controller\nsecretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh\nkube-system/rolebindings/cilium-config-agent\nkube-system/rolebindings/kube-proxy\nkube-system/rolebindings/kubeadm:kubeadm-certs\nkube-system/rolebindings/kubeadm:kubelet-config\nkube-system/rolebindings/kubeadm:nodes-kubeadm-config\nkube-system/rolebindings/system::extension-apiserver-authentication-reader\nkube-system/rolebindings/system::leader-locking-kube-controller-manager\nkube-system/rolebindings/system::leader-locking-kube-scheduler\nkube-system/rolebindings/system:controller:bootstrap-signer\nkube-system/rolebindings/system:controller:cloud-provider\nkube-system/rolebindings/system:controller:token-cleaner\nkube-system/roles/cilium-config-agent\nkube-system/roles/extension-apiserver-authentication-reader\nkube-system/roles/kube-proxy\nkube-system/roles/kubeadm:kubeadm-certs\nkube-system/roles/kubeadm:kubelet-config\nkube-system/roles/kubeadm:nodes-kubeadm-config\nkube-system/roles/system::leader-locking-kube-controller-manager\nkube-system/roles/system::leader-locking-kube-scheduler\nkube-system/roles/system:controller:bootstrap-signer\nkube-system/roles/system:controller:cloud-provider\nkube-system/roles/system:controller:token-cleaner\nkube-system/secrets/bootstrap-token-83g3cy\nkube-system/secrets/bootstrap-token-goja43\nkube-system/secrets/kubeadm-certs\nkube-system/secrets/sh.helm.release.v1.cilium.v1\nkube-system/serviceaccounts/attachdetach-controller\nkube-system/serviceaccounts/bootstrap-signer\nkube-system/serviceaccounts/certificate-controller\nkube-system/serviceaccounts/cilium\nkube-system/serviceaccounts/cilium-operator\nkube-system/serviceaccounts/clusterrole-aggregation-controller\nkube-system/serviceaccounts/coredns\nkube-system/serviceaccounts/cronjob-controller\nkube-system/serviceaccounts/daemon-set-controller\nkube-system/serviceaccounts/default\nkube-system/serviceaccounts/deployment-controller\nkube-system/serviceaccounts/disruption-controller\nkube-system/serviceaccounts/endpoint-controller\nkube-system/serviceaccounts/endpointslice-controller\nkube-system/serviceaccounts/endpointslicemirroring-controller\nkube-system/serviceaccounts/ephemeral-volume-controller\nkube-system/serviceaccounts/expand-controller\nkube-system/serviceaccounts/generic-garbage-collector\nkube-system/serviceaccounts/horizontal-pod-autoscaler\nkube-system/serviceaccounts/job-controller\nkube-system/serviceaccounts/kube-proxy\nkube-system/serviceaccounts/namespace-controller\nkube-system/serviceaccounts/node-controller\nkube-system/serviceaccounts/persistent-volume-binder\nkube-system/serviceaccounts/pod-garbage-collector\nkube-system/serviceaccounts/pv-protection-controller\nkube-system/serviceaccounts/pvc-protection-controller\nkube-system/serviceaccounts/replicaset-controller\nkube-system/serviceaccounts/replication-controller\nkube-system/serviceaccounts/resourcequota-controller\nkube-system/serviceaccounts/root-ca-cert-publisher\nkube-system/serviceaccounts/service-account-controller\nkube-system/serviceaccounts/service-controller\nkube-system/serviceaccounts/statefulset-controller\nkube-system/serviceaccounts/token-cleaner\nkube-system/serviceaccounts/ttl-after-finished-controller\nkube-system/serviceaccounts/ttl-controller\nkube-system/services/kube-dns\nsecretgen-controller/serviceaccounts/default\nsecretgen-controller/serviceaccounts/secretgen-controller-sa",
                            "stdout_lines": [
                                "xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value",
                                "xargs: xargs: warning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args valuewarning: options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value",
                                "",
                                "xargs: xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines valuewarning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "",
                                "envoy-gateway-system/configmaps/envoy-gateway-config",
                                "envoy-gateway-system/configmaps/kube-root-ca.crt",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "default/configmaps/kube-root-ca.crt",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/deployment/envoy-gateway",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/endpoints/envoy-gateway",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "default/endpoints/kubernetes",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen",
                                "envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding",
                                "envoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager",
                                "envoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "default/secrets/test-password",
                                "envoy-gateway-system/serviceaccounts/default",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/serviceaccounts/envoy-gateway",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/secrets/envoy",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/secrets/envoy-gateway",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/secrets/envoy-oidc-hmac",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/secrets/envoy-rate-limit",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "envoy-gateway-system/services/envoy-gateway",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "default/serviceaccounts/default",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "default/services/kubernetes",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-node-lease/configmaps/kube-root-ca.crt",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-public/configmaps/cluster-info",
                                "kube-public/configmaps/kube-root-ca.crt",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo",
                                "kube-public/rolebindings/system:controller:bootstrap-signer",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-node-lease/serviceaccounts/default",
                                "kube-public/roles/kubeadm:bootstrap-signer-clusterinfo",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-public/roles/system:controller:bootstrap-signer",
                                "kube-public/serviceaccounts/default",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/cilium-config",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/coredns",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/extension-apiserver-authentication",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "kube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/kube-proxy",
                                "kube-system/configmaps/kube-root-ca.crt",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "error: the server doesn't have a resource type \"podsecuritypolicies\"",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/kubeadm-config",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/configmaps/kubelet-config",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "secretgen-controller/configmaps/kube-root-ca.crt",
                                "kube-system/daemonsets/cilium",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/daemonsets/kube-proxy",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/deployment/cilium-operator",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "xargs: warning: options --max-lines and --replace/-I/-i are mutually exclusive, ignoring previous --max-lines value",
                                "kube-system/deployment/coredns",
                                "secretgen-controller/deployment/secretgen-controller",
                                "kube-system/endpoints/kube-dns",
                                "kube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb",
                                "kube-system/pods/cilium-p2q6r",
                                "kube-system/pods/coredns-5dd5756b68-bwt9r",
                                "kube-system/pods/coredns-77cccfdc44-6r6vb",
                                "kube-system/pods/coredns-77cccfdc44-ksw4v",
                                "kube-system/pods/etcd-controller",
                                "kube-system/pods/kube-apiserver-controller",
                                "kube-system/pods/kube-controller-manager-controller",
                                "kube-system/pods/kube-proxy-nbcfs",
                                "kube-system/pods/kube-scheduler-controller",
                                "kube-system/pods/kube-vip-controller",
                                "secretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh",
                                "kube-system/rolebindings/cilium-config-agent",
                                "kube-system/rolebindings/kube-proxy",
                                "kube-system/rolebindings/kubeadm:kubeadm-certs",
                                "kube-system/rolebindings/kubeadm:kubelet-config",
                                "kube-system/rolebindings/kubeadm:nodes-kubeadm-config",
                                "kube-system/rolebindings/system::extension-apiserver-authentication-reader",
                                "kube-system/rolebindings/system::leader-locking-kube-controller-manager",
                                "kube-system/rolebindings/system::leader-locking-kube-scheduler",
                                "kube-system/rolebindings/system:controller:bootstrap-signer",
                                "kube-system/rolebindings/system:controller:cloud-provider",
                                "kube-system/rolebindings/system:controller:token-cleaner",
                                "kube-system/roles/cilium-config-agent",
                                "kube-system/roles/extension-apiserver-authentication-reader",
                                "kube-system/roles/kube-proxy",
                                "kube-system/roles/kubeadm:kubeadm-certs",
                                "kube-system/roles/kubeadm:kubelet-config",
                                "kube-system/roles/kubeadm:nodes-kubeadm-config",
                                "kube-system/roles/system::leader-locking-kube-controller-manager",
                                "kube-system/roles/system::leader-locking-kube-scheduler",
                                "kube-system/roles/system:controller:bootstrap-signer",
                                "kube-system/roles/system:controller:cloud-provider",
                                "kube-system/roles/system:controller:token-cleaner",
                                "kube-system/secrets/bootstrap-token-83g3cy",
                                "kube-system/secrets/bootstrap-token-goja43",
                                "kube-system/secrets/kubeadm-certs",
                                "kube-system/secrets/sh.helm.release.v1.cilium.v1",
                                "kube-system/serviceaccounts/attachdetach-controller",
                                "kube-system/serviceaccounts/bootstrap-signer",
                                "kube-system/serviceaccounts/certificate-controller",
                                "kube-system/serviceaccounts/cilium",
                                "kube-system/serviceaccounts/cilium-operator",
                                "kube-system/serviceaccounts/clusterrole-aggregation-controller",
                                "kube-system/serviceaccounts/coredns",
                                "kube-system/serviceaccounts/cronjob-controller",
                                "kube-system/serviceaccounts/daemon-set-controller",
                                "kube-system/serviceaccounts/default",
                                "kube-system/serviceaccounts/deployment-controller",
                                "kube-system/serviceaccounts/disruption-controller",
                                "kube-system/serviceaccounts/endpoint-controller",
                                "kube-system/serviceaccounts/endpointslice-controller",
                                "kube-system/serviceaccounts/endpointslicemirroring-controller",
                                "kube-system/serviceaccounts/ephemeral-volume-controller",
                                "kube-system/serviceaccounts/expand-controller",
                                "kube-system/serviceaccounts/generic-garbage-collector",
                                "kube-system/serviceaccounts/horizontal-pod-autoscaler",
                                "kube-system/serviceaccounts/job-controller",
                                "kube-system/serviceaccounts/kube-proxy",
                                "kube-system/serviceaccounts/namespace-controller",
                                "kube-system/serviceaccounts/node-controller",
                                "kube-system/serviceaccounts/persistent-volume-binder",
                                "kube-system/serviceaccounts/pod-garbage-collector",
                                "kube-system/serviceaccounts/pv-protection-controller",
                                "kube-system/serviceaccounts/pvc-protection-controller",
                                "kube-system/serviceaccounts/replicaset-controller",
                                "kube-system/serviceaccounts/replication-controller",
                                "kube-system/serviceaccounts/resourcequota-controller",
                                "kube-system/serviceaccounts/root-ca-cert-publisher",
                                "kube-system/serviceaccounts/service-account-controller",
                                "kube-system/serviceaccounts/service-controller",
                                "kube-system/serviceaccounts/statefulset-controller",
                                "kube-system/serviceaccounts/token-cleaner",
                                "kube-system/serviceaccounts/ttl-after-finished-controller",
                                "kube-system/serviceaccounts/ttl-controller",
                                "kube-system/services/kube-dns",
                                "secretgen-controller/serviceaccounts/default",
                                "secretgen-controller/serviceaccounts/secretgen-controller-sa"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000001c-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000017",
                        "name": "describe-kubernetes-objects",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/describe-kubernetes-objects"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:39.532032Z",
                            "start": "2026-07-29T18:36:24.501511Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001c",
                        "name": "Gathering descriptions for namespace scoped objects"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/objects /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/objects",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "cd+++++++++ objects/\ncd+++++++++ objects/cluster/\ncd+++++++++ objects/cluster/clusterrole/\n>f+++++++++ objects/cluster/clusterrole/admin.txt\n>f+++++++++ objects/cluster/clusterrole/admin.yaml\n>f+++++++++ objects/cluster/clusterrole/cilium-operator.txt\n>f+++++++++ objects/cluster/clusterrole/cilium-operator.yaml\n>f+++++++++ objects/cluster/clusterrole/cilium.txt\n>f+++++++++ objects/cluster/clusterrole/cilium.yaml\n>f+++++++++ objects/cluster/clusterrole/cluster-admin.txt\n>f+++++++++ objects/cluster/clusterrole/cluster-admin.yaml\n>f+++++++++ objects/cluster/clusterrole/edit.txt\n>f+++++++++ objects/cluster/clusterrole/edit.yaml\n>f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.txt\n>f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.yaml\n>f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-envoy-gateway-role.txt\n>f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-envoy-gateway-role.yaml\n>f+++++++++ objects/cluster/clusterrole/kubeadm:get-nodes.txt\n>f+++++++++ objects/cluster/clusterrole/kubeadm:get-nodes.yaml\n>f+++++++++ objects/cluster/clusterrole/secretgen-controller-cluster-role.txt\n>f+++++++++ objects/cluster/clusterrole/secretgen-controller-cluster-role.yaml\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-admin.txt\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-admin.yaml\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-edit.txt\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-edit.yaml\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-view.txt\n>f+++++++++ objects/cluster/clusterrole/system:aggregate-to-view.yaml\n>f+++++++++ objects/cluster/clusterrole/system:auth-delegator.txt\n>f+++++++++ objects/cluster/clusterrole/system:auth-delegator.yaml\n>f+++++++++ objects/cluster/clusterrole/system:basic-user.txt\n>f+++++++++ objects/cluster/clusterrole/system:basic-user.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-approver.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-approver.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kubelet-serving-approver.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kubelet-serving-approver.yaml\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:legacy-unknown-approver.txt\n>f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:legacy-unknown-approver.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:attachdetach-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:attachdetach-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:certificate-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:certificate-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:clusterrole-aggregation-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:clusterrole-aggregation-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:cronjob-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:cronjob-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:daemon-set-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:daemon-set-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:deployment-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:deployment-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:disruption-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:disruption-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpoint-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpoint-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpointslice-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpointslice-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpointslicemirroring-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:endpointslicemirroring-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:ephemeral-volume-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:ephemeral-volume-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:expand-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:expand-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:generic-garbage-collector.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:generic-garbage-collector.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:horizontal-pod-autoscaler.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:horizontal-pod-autoscaler.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:job-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:job-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:namespace-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:namespace-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:node-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:node-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:persistent-volume-binder.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:persistent-volume-binder.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:pod-garbage-collector.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:pod-garbage-collector.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:pv-protection-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:pv-protection-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:pvc-protection-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:pvc-protection-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:replicaset-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:replicaset-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:replication-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:replication-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:resourcequota-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:resourcequota-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:root-ca-cert-publisher.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:root-ca-cert-publisher.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:route-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:route-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:service-account-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:service-account-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:service-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:service-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:statefulset-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:statefulset-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:ttl-after-finished-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:ttl-after-finished-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:controller:ttl-controller.txt\n>f+++++++++ objects/cluster/clusterrole/system:controller:ttl-controller.yaml\n>f+++++++++ objects/cluster/clusterrole/system:coredns.txt\n>f+++++++++ objects/cluster/clusterrole/system:coredns.yaml\n>f+++++++++ objects/cluster/clusterrole/system:discovery.txt\n>f+++++++++ objects/cluster/clusterrole/system:discovery.yaml\n>f+++++++++ objects/cluster/clusterrole/system:heapster.txt\n>f+++++++++ objects/cluster/clusterrole/system:heapster.yaml\n>f+++++++++ objects/cluster/clusterrole/system:kube-aggregator.txt\n>f+++++++++ objects/cluster/clusterrole/system:kube-aggregator.yaml\n>f+++++++++ objects/cluster/clusterrole/system:kube-controller-manager.txt\n>f+++++++++ objects/cluster/clusterrole/system:kube-controller-manager.yaml\n>f+++++++++ objects/cluster/clusterrole/system:kube-dns.txt\n>f+++++++++ objects/cluster/clusterrole/system:kube-dns.yaml\n>f+++++++++ objects/cluster/clusterrole/system:kube-scheduler.txt\n>f+++++++++ objects/cluster/clusterrole/system:kube-scheduler.yaml\n>f+++++++++ objects/cluster/clusterrole/system:kubelet-api-admin.txt\n>f+++++++++ objects/cluster/clusterrole/system:kubelet-api-admin.yaml\n>f+++++++++ objects/cluster/clusterrole/system:monitoring.txt\n>f+++++++++ objects/cluster/clusterrole/system:monitoring.yaml\n>f+++++++++ objects/cluster/clusterrole/system:node-bootstrapper.txt\n>f+++++++++ objects/cluster/clusterrole/system:node-bootstrapper.yaml\n>f+++++++++ objects/cluster/clusterrole/system:node-problem-detector.txt\n>f+++++++++ objects/cluster/clusterrole/system:node-problem-detector.yaml\n>f+++++++++ objects/cluster/clusterrole/system:node-proxier.txt\n>f+++++++++ objects/cluster/clusterrole/system:node-proxier.yaml\n>f+++++++++ objects/cluster/clusterrole/system:node.txt\n>f+++++++++ objects/cluster/clusterrole/system:node.yaml\n>f+++++++++ objects/cluster/clusterrole/system:persistent-volume-provisioner.txt\n>f+++++++++ objects/cluster/clusterrole/system:persistent-volume-provisioner.yaml\n>f+++++++++ objects/cluster/clusterrole/system:public-info-viewer.txt\n>f+++++++++ objects/cluster/clusterrole/system:public-info-viewer.yaml\n>f+++++++++ objects/cluster/clusterrole/system:service-account-issuer-discovery.txt\n>f+++++++++ objects/cluster/clusterrole/system:service-account-issuer-discovery.yaml\n>f+++++++++ objects/cluster/clusterrole/system:volume-scheduler.txt\n>f+++++++++ objects/cluster/clusterrole/system:volume-scheduler.yaml\n>f+++++++++ objects/cluster/clusterrole/view.txt\n>f+++++++++ objects/cluster/clusterrole/view.yaml\ncd+++++++++ objects/cluster/clusterrolebinding/\n>f+++++++++ objects/cluster/clusterrolebinding/cilium-operator.txt\n>f+++++++++ objects/cluster/clusterrolebinding/cilium-operator.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/cilium.txt\n>f+++++++++ objects/cluster/clusterrolebinding/cilium.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/cluster-admin.txt\n>f+++++++++ objects/cluster/clusterrolebinding/cluster-admin.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.txt\n>f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding.txt\n>f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:get-nodes.txt\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:get-nodes.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:kubelet-bootstrap.txt\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:kubelet-bootstrap.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-bootstrap.txt\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-bootstrap.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-certificate-rotation.txt\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-certificate-rotation.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-proxier.txt\n>f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-proxier.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/secretgen-controller-cluster-role-binding.txt\n>f+++++++++ objects/cluster/clusterrolebinding/secretgen-controller-cluster-role-binding.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:basic-user.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:basic-user.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:attachdetach-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:attachdetach-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:certificate-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:certificate-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:clusterrole-aggregation-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:clusterrole-aggregation-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:cronjob-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:cronjob-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:daemon-set-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:daemon-set-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:deployment-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:deployment-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:disruption-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:disruption-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpoint-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpoint-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslice-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslice-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslicemirroring-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslicemirroring-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ephemeral-volume-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ephemeral-volume-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:expand-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:expand-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:generic-garbage-collector.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:generic-garbage-collector.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:horizontal-pod-autoscaler.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:horizontal-pod-autoscaler.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:job-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:job-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:namespace-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:namespace-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:node-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:node-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:persistent-volume-binder.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:persistent-volume-binder.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pod-garbage-collector.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pod-garbage-collector.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pv-protection-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pv-protection-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pvc-protection-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:pvc-protection-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:replicaset-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:replicaset-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:replication-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:replication-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:resourcequota-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:resourcequota-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:root-ca-cert-publisher.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:root-ca-cert-publisher.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:route-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:route-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-account-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-account-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:statefulset-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:statefulset-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-after-finished-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-after-finished-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-controller.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-controller.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:coredns.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:coredns.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:discovery.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:discovery.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-controller-manager.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-controller-manager.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-dns.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-dns.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-scheduler.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:kube-scheduler.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:monitoring.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:monitoring.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:node-proxier.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:node-proxier.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:node.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:node.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:public-info-viewer.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:public-info-viewer.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:service-account-issuer-discovery.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:service-account-issuer-discovery.yaml\n>f+++++++++ objects/cluster/clusterrolebinding/system:volume-scheduler.txt\n>f+++++++++ objects/cluster/clusterrolebinding/system:volume-scheduler.yaml\ncd+++++++++ objects/cluster/namespace/\n>f+++++++++ objects/cluster/namespace/default.txt\n>f+++++++++ objects/cluster/namespace/default.yaml\n>f+++++++++ objects/cluster/namespace/envoy-gateway-system.txt\n>f+++++++++ objects/cluster/namespace/envoy-gateway-system.yaml\n>f+++++++++ objects/cluster/namespace/kube-node-lease.txt\n>f+++++++++ objects/cluster/namespace/kube-node-lease.yaml\n>f+++++++++ objects/cluster/namespace/kube-public.txt\n>f+++++++++ objects/cluster/namespace/kube-public.yaml\n>f+++++++++ objects/cluster/namespace/kube-system.txt\n>f+++++++++ objects/cluster/namespace/kube-system.yaml\n>f+++++++++ objects/cluster/namespace/secretgen-controller.txt\n>f+++++++++ objects/cluster/namespace/secretgen-controller.yaml\ncd+++++++++ objects/cluster/node/\n>f+++++++++ objects/cluster/node/controller.txt\n>f+++++++++ objects/cluster/node/controller.yaml\ncd+++++++++ objects/namespaced/\ncd+++++++++ objects/namespaced/default/\ncd+++++++++ objects/namespaced/default/configmaps/\n>f+++++++++ objects/namespaced/default/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/default/configmaps/kube-root-ca.crt.yaml\ncd+++++++++ objects/namespaced/default/endpoints/\n>f+++++++++ objects/namespaced/default/endpoints/kubernetes.txt\n>f+++++++++ objects/namespaced/default/endpoints/kubernetes.yaml\ncd+++++++++ objects/namespaced/default/secrets/\n>f+++++++++ objects/namespaced/default/secrets/test-password.txt\n>f+++++++++ objects/namespaced/default/secrets/test-password.yaml\ncd+++++++++ objects/namespaced/default/serviceaccounts/\n>f+++++++++ objects/namespaced/default/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/default/serviceaccounts/default.yaml\ncd+++++++++ objects/namespaced/default/services/\n>f+++++++++ objects/namespaced/default/services/kubernetes.txt\n>f+++++++++ objects/namespaced/default/services/kubernetes.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/\ncd+++++++++ objects/namespaced/envoy-gateway-system/configmaps/\n>f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/envoy-gateway-config.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/envoy-gateway-config.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/kube-root-ca.crt.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/deployment/\n>f+++++++++ objects/namespaced/envoy-gateway-system/deployment/envoy-gateway.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/deployment/envoy-gateway.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/endpoints/\n>f+++++++++ objects/namespaced/envoy-gateway-system/endpoints/envoy-gateway.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/endpoints/envoy-gateway.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/pods/\n>f+++++++++ objects/namespaced/envoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/roles/\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/secrets/\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-gateway.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-gateway.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-oidc-hmac.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-oidc-hmac.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-rate-limit.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-rate-limit.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/default.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen.yaml\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway.yaml\ncd+++++++++ objects/namespaced/envoy-gateway-system/services/\n>f+++++++++ objects/namespaced/envoy-gateway-system/services/envoy-gateway.txt\n>f+++++++++ objects/namespaced/envoy-gateway-system/services/envoy-gateway.yaml\ncd+++++++++ objects/namespaced/kube-node-lease/\ncd+++++++++ objects/namespaced/kube-node-lease/configmaps/\n>f+++++++++ objects/namespaced/kube-node-lease/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/kube-node-lease/configmaps/kube-root-ca.crt.yaml\ncd+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/\n>f+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/default.yaml\ncd+++++++++ objects/namespaced/kube-public/\ncd+++++++++ objects/namespaced/kube-public/configmaps/\n>f+++++++++ objects/namespaced/kube-public/configmaps/cluster-info.txt\n>f+++++++++ objects/namespaced/kube-public/configmaps/cluster-info.yaml\n>f+++++++++ objects/namespaced/kube-public/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/kube-public/configmaps/kube-root-ca.crt.yaml\ncd+++++++++ objects/namespaced/kube-public/rolebindings/\n>f+++++++++ objects/namespaced/kube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo.txt\n>f+++++++++ objects/namespaced/kube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo.yaml\n>f+++++++++ objects/namespaced/kube-public/rolebindings/system:controller:bootstrap-signer.txt\n>f+++++++++ objects/namespaced/kube-public/rolebindings/system:controller:bootstrap-signer.yaml\ncd+++++++++ objects/namespaced/kube-public/roles/\n>f+++++++++ objects/namespaced/kube-public/roles/kubeadm:bootstrap-signer-clusterinfo.txt\n>f+++++++++ objects/namespaced/kube-public/roles/kubeadm:bootstrap-signer-clusterinfo.yaml\n>f+++++++++ objects/namespaced/kube-public/roles/system:controller:bootstrap-signer.txt\n>f+++++++++ objects/namespaced/kube-public/roles/system:controller:bootstrap-signer.yaml\ncd+++++++++ objects/namespaced/kube-public/serviceaccounts/\n>f+++++++++ objects/namespaced/kube-public/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/kube-public/serviceaccounts/default.yaml\ncd+++++++++ objects/namespaced/kube-system/\ncd+++++++++ objects/namespaced/kube-system/configmaps/\n>f+++++++++ objects/namespaced/kube-system/configmaps/cilium-config.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/cilium-config.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/coredns.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/coredns.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/extension-apiserver-authentication.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/extension-apiserver-authentication.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-proxy.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-proxy.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/kube-root-ca.crt.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/kubeadm-config.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/kubeadm-config.yaml\n>f+++++++++ objects/namespaced/kube-system/configmaps/kubelet-config.txt\n>f+++++++++ objects/namespaced/kube-system/configmaps/kubelet-config.yaml\ncd+++++++++ objects/namespaced/kube-system/daemonsets/\n>f+++++++++ objects/namespaced/kube-system/daemonsets/cilium.txt\n>f+++++++++ objects/namespaced/kube-system/daemonsets/cilium.yaml\n>f+++++++++ objects/namespaced/kube-system/daemonsets/kube-proxy.txt\n>f+++++++++ objects/namespaced/kube-system/daemonsets/kube-proxy.yaml\ncd+++++++++ objects/namespaced/kube-system/deployment/\n>f+++++++++ objects/namespaced/kube-system/deployment/cilium-operator.txt\n>f+++++++++ objects/namespaced/kube-system/deployment/cilium-operator.yaml\n>f+++++++++ objects/namespaced/kube-system/deployment/coredns.txt\n>f+++++++++ objects/namespaced/kube-system/deployment/coredns.yaml\ncd+++++++++ objects/namespaced/kube-system/endpoints/\n>f+++++++++ objects/namespaced/kube-system/endpoints/kube-dns.txt\n>f+++++++++ objects/namespaced/kube-system/endpoints/kube-dns.yaml\ncd+++++++++ objects/namespaced/kube-system/pods/\n>f+++++++++ objects/namespaced/kube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb.txt\n>f+++++++++ objects/namespaced/kube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/cilium-p2q6r.txt\n>f+++++++++ objects/namespaced/kube-system/pods/cilium-p2q6r.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-5dd5756b68-bwt9r.txt\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-5dd5756b68-bwt9r.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-6r6vb.txt\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-6r6vb.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-ksw4v.txt\n>f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-ksw4v.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/etcd-controller.txt\n>f+++++++++ objects/namespaced/kube-system/pods/etcd-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/kube-apiserver-controller.txt\n>f+++++++++ objects/namespaced/kube-system/pods/kube-apiserver-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/kube-controller-manager-controller.txt\n>f+++++++++ objects/namespaced/kube-system/pods/kube-controller-manager-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/kube-proxy-nbcfs.txt\n>f+++++++++ objects/namespaced/kube-system/pods/kube-proxy-nbcfs.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/kube-scheduler-controller.txt\n>f+++++++++ objects/namespaced/kube-system/pods/kube-scheduler-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/pods/kube-vip-controller.txt\n>f+++++++++ objects/namespaced/kube-system/pods/kube-vip-controller.yaml\ncd+++++++++ objects/namespaced/kube-system/rolebindings/\n>f+++++++++ objects/namespaced/kube-system/rolebindings/cilium-config-agent.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/cilium-config-agent.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kube-proxy.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kube-proxy.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubeadm-certs.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubeadm-certs.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubelet-config.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubelet-config.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:nodes-kubeadm-config.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:nodes-kubeadm-config.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::extension-apiserver-authentication-reader.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::extension-apiserver-authentication-reader.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-controller-manager.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-controller-manager.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-scheduler.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-scheduler.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:bootstrap-signer.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:bootstrap-signer.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:cloud-provider.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:cloud-provider.yaml\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:token-cleaner.txt\n>f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:token-cleaner.yaml\ncd+++++++++ objects/namespaced/kube-system/roles/\n>f+++++++++ objects/namespaced/kube-system/roles/cilium-config-agent.txt\n>f+++++++++ objects/namespaced/kube-system/roles/cilium-config-agent.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/extension-apiserver-authentication-reader.txt\n>f+++++++++ objects/namespaced/kube-system/roles/extension-apiserver-authentication-reader.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/kube-proxy.txt\n>f+++++++++ objects/namespaced/kube-system/roles/kube-proxy.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubeadm-certs.txt\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubeadm-certs.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubelet-config.txt\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubelet-config.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:nodes-kubeadm-config.txt\n>f+++++++++ objects/namespaced/kube-system/roles/kubeadm:nodes-kubeadm-config.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-controller-manager.txt\n>f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-controller-manager.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-scheduler.txt\n>f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-scheduler.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:bootstrap-signer.txt\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:bootstrap-signer.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:cloud-provider.txt\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:cloud-provider.yaml\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:token-cleaner.txt\n>f+++++++++ objects/namespaced/kube-system/roles/system:controller:token-cleaner.yaml\ncd+++++++++ objects/namespaced/kube-system/secrets/\n>f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-83g3cy.txt\n>f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-83g3cy.yaml\n>f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-goja43.txt\n>f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-goja43.yaml\n>f+++++++++ objects/namespaced/kube-system/secrets/kubeadm-certs.txt\n>f+++++++++ objects/namespaced/kube-system/secrets/kubeadm-certs.yaml\n>f+++++++++ objects/namespaced/kube-system/secrets/sh.helm.release.v1.cilium.v1.txt\n>f+++++++++ objects/namespaced/kube-system/secrets/sh.helm.release.v1.cilium.v1.yaml\ncd+++++++++ objects/namespaced/kube-system/serviceaccounts/\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/attachdetach-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/attachdetach-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/bootstrap-signer.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/bootstrap-signer.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/certificate-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/certificate-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium-operator.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium-operator.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/clusterrole-aggregation-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/clusterrole-aggregation-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/coredns.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/coredns.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cronjob-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/cronjob-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/daemon-set-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/daemon-set-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/default.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/deployment-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/deployment-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/disruption-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/disruption-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpoint-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpoint-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslice-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslice-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslicemirroring-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslicemirroring-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ephemeral-volume-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ephemeral-volume-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/expand-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/expand-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/generic-garbage-collector.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/generic-garbage-collector.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/horizontal-pod-autoscaler.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/horizontal-pod-autoscaler.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/job-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/job-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/kube-proxy.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/kube-proxy.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/namespace-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/namespace-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/node-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/node-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/persistent-volume-binder.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/persistent-volume-binder.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pod-garbage-collector.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pod-garbage-collector.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pv-protection-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pv-protection-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pvc-protection-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/pvc-protection-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/replicaset-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/replicaset-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/replication-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/replication-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/resourcequota-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/resourcequota-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/root-ca-cert-publisher.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/root-ca-cert-publisher.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-account-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-account-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/statefulset-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/statefulset-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/token-cleaner.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/token-cleaner.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-after-finished-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-after-finished-controller.yaml\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-controller.txt\n>f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-controller.yaml\ncd+++++++++ objects/namespaced/kube-system/services/\n>f+++++++++ objects/namespaced/kube-system/services/kube-dns.txt\n>f+++++++++ objects/namespaced/kube-system/services/kube-dns.yaml\ncd+++++++++ objects/namespaced/secretgen-controller/\ncd+++++++++ objects/namespaced/secretgen-controller/configmaps/\n>f+++++++++ objects/namespaced/secretgen-controller/configmaps/kube-root-ca.crt.txt\n>f+++++++++ objects/namespaced/secretgen-controller/configmaps/kube-root-ca.crt.yaml\ncd+++++++++ objects/namespaced/secretgen-controller/deployment/\n>f+++++++++ objects/namespaced/secretgen-controller/deployment/secretgen-controller.txt\n>f+++++++++ objects/namespaced/secretgen-controller/deployment/secretgen-controller.yaml\ncd+++++++++ objects/namespaced/secretgen-controller/pods/\n>f+++++++++ objects/namespaced/secretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh.txt\n>f+++++++++ objects/namespaced/secretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh.yaml\ncd+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/\n>f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/default.txt\n>f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/default.yaml\n>f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/secretgen-controller-sa.txt\n>f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/secretgen-controller-sa.yaml\n",
                            "rc": 0,
                            "stdout_lines": [
                                "cd+++++++++ objects/",
                                "cd+++++++++ objects/cluster/",
                                "cd+++++++++ objects/cluster/clusterrole/",
                                ">f+++++++++ objects/cluster/clusterrole/admin.txt",
                                ">f+++++++++ objects/cluster/clusterrole/admin.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/cilium-operator.txt",
                                ">f+++++++++ objects/cluster/clusterrole/cilium-operator.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/cilium.txt",
                                ">f+++++++++ objects/cluster/clusterrole/cilium.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/cluster-admin.txt",
                                ">f+++++++++ objects/cluster/clusterrole/cluster-admin.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/edit.txt",
                                ">f+++++++++ objects/cluster/clusterrole/edit.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.txt",
                                ">f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-envoy-gateway-role.txt",
                                ">f+++++++++ objects/cluster/clusterrole/envoy-gateway-gateway-helm-envoy-gateway-role.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/kubeadm:get-nodes.txt",
                                ">f+++++++++ objects/cluster/clusterrole/kubeadm:get-nodes.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/secretgen-controller-cluster-role.txt",
                                ">f+++++++++ objects/cluster/clusterrole/secretgen-controller-cluster-role.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-admin.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-admin.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-edit.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-edit.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-view.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:aggregate-to-view.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:auth-delegator.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:auth-delegator.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:basic-user.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:basic-user.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:nodeclient.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-approver.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-approver.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kubelet-serving-approver.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:kubelet-serving-approver.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:legacy-unknown-approver.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:certificates.k8s.io:legacy-unknown-approver.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:attachdetach-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:attachdetach-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:certificate-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:certificate-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:clusterrole-aggregation-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:clusterrole-aggregation-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:cronjob-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:cronjob-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:daemon-set-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:daemon-set-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:deployment-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:deployment-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:disruption-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:disruption-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpoint-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpoint-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpointslice-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpointslice-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpointslicemirroring-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:endpointslicemirroring-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ephemeral-volume-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ephemeral-volume-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:expand-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:expand-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:generic-garbage-collector.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:generic-garbage-collector.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:horizontal-pod-autoscaler.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:horizontal-pod-autoscaler.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:job-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:job-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:namespace-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:namespace-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:node-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:node-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:persistent-volume-binder.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:persistent-volume-binder.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pod-garbage-collector.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pod-garbage-collector.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pv-protection-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pv-protection-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pvc-protection-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:pvc-protection-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:replicaset-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:replicaset-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:replication-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:replication-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:resourcequota-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:resourcequota-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:root-ca-cert-publisher.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:root-ca-cert-publisher.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:route-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:route-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:service-account-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:service-account-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:service-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:service-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:statefulset-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:statefulset-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ttl-after-finished-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ttl-after-finished-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ttl-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:controller:ttl-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:coredns.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:coredns.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:discovery.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:discovery.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:heapster.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:heapster.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-aggregator.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-aggregator.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-controller-manager.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-controller-manager.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-dns.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-dns.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-scheduler.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:kube-scheduler.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:kubelet-api-admin.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:kubelet-api-admin.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:monitoring.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:monitoring.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-bootstrapper.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-bootstrapper.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-problem-detector.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-problem-detector.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-proxier.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:node-proxier.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:node.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:node.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:persistent-volume-provisioner.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:persistent-volume-provisioner.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:public-info-viewer.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:public-info-viewer.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:service-account-issuer-discovery.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:service-account-issuer-discovery.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/system:volume-scheduler.txt",
                                ">f+++++++++ objects/cluster/clusterrole/system:volume-scheduler.yaml",
                                ">f+++++++++ objects/cluster/clusterrole/view.txt",
                                ">f+++++++++ objects/cluster/clusterrole/view.yaml",
                                "cd+++++++++ objects/cluster/clusterrolebinding/",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cilium-operator.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cilium-operator.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cilium.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cilium.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cluster-admin.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/cluster-admin.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-certgen:envoy-gateway-system.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/envoy-gateway-gateway-helm-envoy-gateway-rolebinding.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:get-nodes.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:get-nodes.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:kubelet-bootstrap.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:kubelet-bootstrap.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-bootstrap.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-bootstrap.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-certificate-rotation.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-autoapprove-certificate-rotation.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-proxier.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/kubeadm:node-proxier.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/secretgen-controller-cluster-role-binding.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/secretgen-controller-cluster-role-binding.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:basic-user.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:basic-user.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:attachdetach-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:attachdetach-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:certificate-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:certificate-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:clusterrole-aggregation-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:clusterrole-aggregation-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:cronjob-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:cronjob-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:daemon-set-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:daemon-set-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:deployment-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:deployment-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:disruption-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:disruption-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpoint-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpoint-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslice-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslice-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslicemirroring-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:endpointslicemirroring-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ephemeral-volume-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ephemeral-volume-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:expand-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:expand-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:generic-garbage-collector.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:generic-garbage-collector.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:horizontal-pod-autoscaler.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:horizontal-pod-autoscaler.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:job-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:job-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:namespace-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:namespace-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:node-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:node-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:persistent-volume-binder.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:persistent-volume-binder.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pod-garbage-collector.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pod-garbage-collector.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pv-protection-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pv-protection-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pvc-protection-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:pvc-protection-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:replicaset-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:replicaset-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:replication-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:replication-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:resourcequota-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:resourcequota-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:root-ca-cert-publisher.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:root-ca-cert-publisher.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:route-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:route-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-account-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-account-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:service-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:statefulset-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:statefulset-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-after-finished-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-after-finished-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-controller.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:controller:ttl-controller.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:coredns.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:coredns.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:discovery.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:discovery.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-controller-manager.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-controller-manager.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-dns.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-dns.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-scheduler.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:kube-scheduler.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:monitoring.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:monitoring.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:node-proxier.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:node-proxier.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:node.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:node.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:public-info-viewer.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:public-info-viewer.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:service-account-issuer-discovery.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:service-account-issuer-discovery.yaml",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:volume-scheduler.txt",
                                ">f+++++++++ objects/cluster/clusterrolebinding/system:volume-scheduler.yaml",
                                "cd+++++++++ objects/cluster/namespace/",
                                ">f+++++++++ objects/cluster/namespace/default.txt",
                                ">f+++++++++ objects/cluster/namespace/default.yaml",
                                ">f+++++++++ objects/cluster/namespace/envoy-gateway-system.txt",
                                ">f+++++++++ objects/cluster/namespace/envoy-gateway-system.yaml",
                                ">f+++++++++ objects/cluster/namespace/kube-node-lease.txt",
                                ">f+++++++++ objects/cluster/namespace/kube-node-lease.yaml",
                                ">f+++++++++ objects/cluster/namespace/kube-public.txt",
                                ">f+++++++++ objects/cluster/namespace/kube-public.yaml",
                                ">f+++++++++ objects/cluster/namespace/kube-system.txt",
                                ">f+++++++++ objects/cluster/namespace/kube-system.yaml",
                                ">f+++++++++ objects/cluster/namespace/secretgen-controller.txt",
                                ">f+++++++++ objects/cluster/namespace/secretgen-controller.yaml",
                                "cd+++++++++ objects/cluster/node/",
                                ">f+++++++++ objects/cluster/node/controller.txt",
                                ">f+++++++++ objects/cluster/node/controller.yaml",
                                "cd+++++++++ objects/namespaced/",
                                "cd+++++++++ objects/namespaced/default/",
                                "cd+++++++++ objects/namespaced/default/configmaps/",
                                ">f+++++++++ objects/namespaced/default/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/default/configmaps/kube-root-ca.crt.yaml",
                                "cd+++++++++ objects/namespaced/default/endpoints/",
                                ">f+++++++++ objects/namespaced/default/endpoints/kubernetes.txt",
                                ">f+++++++++ objects/namespaced/default/endpoints/kubernetes.yaml",
                                "cd+++++++++ objects/namespaced/default/secrets/",
                                ">f+++++++++ objects/namespaced/default/secrets/test-password.txt",
                                ">f+++++++++ objects/namespaced/default/secrets/test-password.yaml",
                                "cd+++++++++ objects/namespaced/default/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/default/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/default/serviceaccounts/default.yaml",
                                "cd+++++++++ objects/namespaced/default/services/",
                                ">f+++++++++ objects/namespaced/default/services/kubernetes.txt",
                                ">f+++++++++ objects/namespaced/default/services/kubernetes.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/configmaps/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/envoy-gateway-config.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/envoy-gateway-config.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/configmaps/kube-root-ca.crt.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/deployment/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/deployment/envoy-gateway.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/deployment/envoy-gateway.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/endpoints/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/endpoints/envoy-gateway.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/endpoints/envoy-gateway.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/pods/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/pods/envoy-gateway-78446f96c9-m97nh.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-certgen.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-infra-manager.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/rolebindings/envoy-gateway-gateway-helm-leader-election-rolebinding.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/roles/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-certgen.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-infra-manager.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/roles/envoy-gateway-gateway-helm-leader-election-role.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/secrets/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-gateway.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-gateway.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-oidc-hmac.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-oidc-hmac.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-rate-limit.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy-rate-limit.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/envoy.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/secrets/sh.helm.release.v1.envoy-gateway.v1.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/default.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway-gateway-helm-certgen.yaml",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/serviceaccounts/envoy-gateway.yaml",
                                "cd+++++++++ objects/namespaced/envoy-gateway-system/services/",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/services/envoy-gateway.txt",
                                ">f+++++++++ objects/namespaced/envoy-gateway-system/services/envoy-gateway.yaml",
                                "cd+++++++++ objects/namespaced/kube-node-lease/",
                                "cd+++++++++ objects/namespaced/kube-node-lease/configmaps/",
                                ">f+++++++++ objects/namespaced/kube-node-lease/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/kube-node-lease/configmaps/kube-root-ca.crt.yaml",
                                "cd+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/kube-node-lease/serviceaccounts/default.yaml",
                                "cd+++++++++ objects/namespaced/kube-public/",
                                "cd+++++++++ objects/namespaced/kube-public/configmaps/",
                                ">f+++++++++ objects/namespaced/kube-public/configmaps/cluster-info.txt",
                                ">f+++++++++ objects/namespaced/kube-public/configmaps/cluster-info.yaml",
                                ">f+++++++++ objects/namespaced/kube-public/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/kube-public/configmaps/kube-root-ca.crt.yaml",
                                "cd+++++++++ objects/namespaced/kube-public/rolebindings/",
                                ">f+++++++++ objects/namespaced/kube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo.txt",
                                ">f+++++++++ objects/namespaced/kube-public/rolebindings/kubeadm:bootstrap-signer-clusterinfo.yaml",
                                ">f+++++++++ objects/namespaced/kube-public/rolebindings/system:controller:bootstrap-signer.txt",
                                ">f+++++++++ objects/namespaced/kube-public/rolebindings/system:controller:bootstrap-signer.yaml",
                                "cd+++++++++ objects/namespaced/kube-public/roles/",
                                ">f+++++++++ objects/namespaced/kube-public/roles/kubeadm:bootstrap-signer-clusterinfo.txt",
                                ">f+++++++++ objects/namespaced/kube-public/roles/kubeadm:bootstrap-signer-clusterinfo.yaml",
                                ">f+++++++++ objects/namespaced/kube-public/roles/system:controller:bootstrap-signer.txt",
                                ">f+++++++++ objects/namespaced/kube-public/roles/system:controller:bootstrap-signer.yaml",
                                "cd+++++++++ objects/namespaced/kube-public/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/kube-public/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/kube-public/serviceaccounts/default.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/",
                                "cd+++++++++ objects/namespaced/kube-system/configmaps/",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/cilium-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/cilium-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/coredns.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/coredns.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/extension-apiserver-authentication.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/extension-apiserver-authentication.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-apiserver-legacy-service-account-token-tracking.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-proxy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-proxy.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kube-root-ca.crt.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kubeadm-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kubeadm-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kubelet-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/configmaps/kubelet-config.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/daemonsets/",
                                ">f+++++++++ objects/namespaced/kube-system/daemonsets/cilium.txt",
                                ">f+++++++++ objects/namespaced/kube-system/daemonsets/cilium.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/daemonsets/kube-proxy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/daemonsets/kube-proxy.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/deployment/",
                                ">f+++++++++ objects/namespaced/kube-system/deployment/cilium-operator.txt",
                                ">f+++++++++ objects/namespaced/kube-system/deployment/cilium-operator.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/deployment/coredns.txt",
                                ">f+++++++++ objects/namespaced/kube-system/deployment/coredns.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/endpoints/",
                                ">f+++++++++ objects/namespaced/kube-system/endpoints/kube-dns.txt",
                                ">f+++++++++ objects/namespaced/kube-system/endpoints/kube-dns.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/pods/",
                                ">f+++++++++ objects/namespaced/kube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/cilium-operator-7fcd8d6ffd-7xwpb.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/cilium-p2q6r.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/cilium-p2q6r.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-5dd5756b68-bwt9r.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-5dd5756b68-bwt9r.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-6r6vb.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-6r6vb.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-ksw4v.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/coredns-77cccfdc44-ksw4v.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/etcd-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/etcd-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-apiserver-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-apiserver-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-controller-manager-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-controller-manager-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-proxy-nbcfs.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-proxy-nbcfs.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-scheduler-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-scheduler-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-vip-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/pods/kube-vip-controller.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/rolebindings/",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/cilium-config-agent.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/cilium-config-agent.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kube-proxy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kube-proxy.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubeadm-certs.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubeadm-certs.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubelet-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:kubelet-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:nodes-kubeadm-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/kubeadm:nodes-kubeadm-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::extension-apiserver-authentication-reader.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::extension-apiserver-authentication-reader.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-controller-manager.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-controller-manager.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-scheduler.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system::leader-locking-kube-scheduler.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:bootstrap-signer.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:bootstrap-signer.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:cloud-provider.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:cloud-provider.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:token-cleaner.txt",
                                ">f+++++++++ objects/namespaced/kube-system/rolebindings/system:controller:token-cleaner.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/roles/",
                                ">f+++++++++ objects/namespaced/kube-system/roles/cilium-config-agent.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/cilium-config-agent.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/extension-apiserver-authentication-reader.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/extension-apiserver-authentication-reader.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kube-proxy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kube-proxy.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubeadm-certs.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubeadm-certs.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubelet-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:kubelet-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:nodes-kubeadm-config.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/kubeadm:nodes-kubeadm-config.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-controller-manager.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-controller-manager.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-scheduler.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system::leader-locking-kube-scheduler.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:bootstrap-signer.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:bootstrap-signer.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:cloud-provider.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:cloud-provider.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:token-cleaner.txt",
                                ">f+++++++++ objects/namespaced/kube-system/roles/system:controller:token-cleaner.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/secrets/",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-83g3cy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-83g3cy.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-goja43.txt",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/bootstrap-token-goja43.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/kubeadm-certs.txt",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/kubeadm-certs.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/sh.helm.release.v1.cilium.v1.txt",
                                ">f+++++++++ objects/namespaced/kube-system/secrets/sh.helm.release.v1.cilium.v1.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/attachdetach-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/attachdetach-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/bootstrap-signer.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/bootstrap-signer.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/certificate-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/certificate-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium-operator.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium-operator.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cilium.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/clusterrole-aggregation-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/clusterrole-aggregation-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/coredns.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/coredns.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cronjob-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/cronjob-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/daemon-set-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/daemon-set-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/default.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/deployment-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/deployment-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/disruption-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/disruption-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpoint-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpoint-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslice-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslice-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslicemirroring-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/endpointslicemirroring-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ephemeral-volume-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ephemeral-volume-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/expand-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/expand-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/generic-garbage-collector.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/generic-garbage-collector.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/horizontal-pod-autoscaler.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/horizontal-pod-autoscaler.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/job-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/job-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/kube-proxy.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/kube-proxy.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/namespace-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/namespace-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/node-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/node-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/persistent-volume-binder.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/persistent-volume-binder.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pod-garbage-collector.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pod-garbage-collector.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pv-protection-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pv-protection-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pvc-protection-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/pvc-protection-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/replicaset-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/replicaset-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/replication-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/replication-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/resourcequota-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/resourcequota-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/root-ca-cert-publisher.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/root-ca-cert-publisher.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-account-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-account-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/service-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/statefulset-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/statefulset-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/token-cleaner.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/token-cleaner.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-after-finished-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-after-finished-controller.yaml",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-controller.txt",
                                ">f+++++++++ objects/namespaced/kube-system/serviceaccounts/ttl-controller.yaml",
                                "cd+++++++++ objects/namespaced/kube-system/services/",
                                ">f+++++++++ objects/namespaced/kube-system/services/kube-dns.txt",
                                ">f+++++++++ objects/namespaced/kube-system/services/kube-dns.yaml",
                                "cd+++++++++ objects/namespaced/secretgen-controller/",
                                "cd+++++++++ objects/namespaced/secretgen-controller/configmaps/",
                                ">f+++++++++ objects/namespaced/secretgen-controller/configmaps/kube-root-ca.crt.txt",
                                ">f+++++++++ objects/namespaced/secretgen-controller/configmaps/kube-root-ca.crt.yaml",
                                "cd+++++++++ objects/namespaced/secretgen-controller/deployment/",
                                ">f+++++++++ objects/namespaced/secretgen-controller/deployment/secretgen-controller.txt",
                                ">f+++++++++ objects/namespaced/secretgen-controller/deployment/secretgen-controller.yaml",
                                "cd+++++++++ objects/namespaced/secretgen-controller/pods/",
                                ">f+++++++++ objects/namespaced/secretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh.txt",
                                ">f+++++++++ objects/namespaced/secretgen-controller/pods/secretgen-controller-ffb97c6dc-4qtrh.yaml",
                                "cd+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/",
                                ">f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/default.txt",
                                ">f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/default.yaml",
                                ">f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/secretgen-controller-sa.txt",
                                ">f+++++++++ objects/namespaced/secretgen-controller/serviceaccounts/secretgen-controller-sa.yaml"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000017",
                        "name": "describe-kubernetes-objects",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/describe-kubernetes-objects"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:40.159653Z",
                            "start": "2026-07-29T18:36:39.538510Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001d",
                        "name": "Downloads logs to executor"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/pod-logs",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/pod-logs",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/pod-logs",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/pod-logs",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001f",
                        "name": "gather-pod-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-pod-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:40.439694Z",
                            "start": "2026-07-29T18:36:40.172383Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000021",
                        "name": "creating directory for pod logs"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/pod-logs/failed-pods",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/pod-logs/failed-pods",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/pod-logs/failed-pods",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/pod-logs/failed-pods",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001f",
                        "name": "gather-pod-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-pod-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:40.694105Z",
                            "start": "2026-07-29T18:36:40.445708Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000022",
                        "name": "creating directory for failed pod logs"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nfunction get_namespaces () {\n  kubectl get namespaces -o name | awk -F '/' '{ print $NF }'\n}\nfunction get_pods () {\n  NAMESPACE=$1\n  kubectl get pods -n ${NAMESPACE} -o name | awk -F '/' '{ print $NF }' | xargs -I {} echo ${NAMESPACE} {}\n}\nexport -f get_pods\nfunction get_pod_logs () {\n  NAMESPACE=${1% *}\n  POD=${1#* }\n  INIT_CONTAINERS=$(kubectl get pod $POD -n ${NAMESPACE} -o json | jq -r '.spec.initContainers[]?.name')\n  CONTAINERS=$(kubectl get pod $POD -n ${NAMESPACE} -o json | jq -r '.spec.containers[].name')\n  for CONTAINER in ${INIT_CONTAINERS} ${CONTAINERS}; do\n    echo \"${NAMESPACE}/${POD}/${CONTAINER}\"\n    mkdir -p \"/tmp/logs/pod-logs/${NAMESPACE}/${POD}\"\n    mkdir -p \"/tmp/logs/pod-logs/failed-pods/${NAMESPACE}/${POD}\"\n    kubectl logs ${POD} -n ${NAMESPACE} -c ${CONTAINER} > \"/tmp/logs/pod-logs/${NAMESPACE}/${POD}/${CONTAINER}.txt\"\n    kubectl logs --previous ${POD} -n ${NAMESPACE} -c ${CONTAINER} > \"/tmp/logs/pod-logs/failed-pods/${NAMESPACE}/${POD}/${CONTAINER}.txt\"\n  done\n}\nexport -f get_pod_logs\nget_namespaces |  xargs -r -I {} bash -c 'get_pods \"$@\"' _ {} |  xargs -r -I {} bash -c 'get_pod_logs \"$@\"' _ {}",
                            "delta": "0:00:06.734643",
                            "end": "2026-07-29 18:36:47.683208",
                            "failed": true,
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nfunction get_namespaces () {\n  kubectl get namespaces -o name | awk -F '/' '{ print $NF }'\n}\nfunction get_pods () {\n  NAMESPACE=$1\n  kubectl get pods -n ${NAMESPACE} -o name | awk -F '/' '{ print $NF }' | xargs -I {} echo ${NAMESPACE} {}\n}\nexport -f get_pods\nfunction get_pod_logs () {\n  NAMESPACE=${1% *}\n  POD=${1#* }\n  INIT_CONTAINERS=$(kubectl get pod $POD -n ${NAMESPACE} -o json | jq -r '.spec.initContainers[]?.name')\n  CONTAINERS=$(kubectl get pod $POD -n ${NAMESPACE} -o json | jq -r '.spec.containers[].name')\n  for CONTAINER in ${INIT_CONTAINERS} ${CONTAINERS}; do\n    echo \"${NAMESPACE}/${POD}/${CONTAINER}\"\n    mkdir -p \"/tmp/logs/pod-logs/${NAMESPACE}/${POD}\"\n    mkdir -p \"/tmp/logs/pod-logs/failed-pods/${NAMESPACE}/${POD}\"\n    kubectl logs ${POD} -n ${NAMESPACE} -c ${CONTAINER} > \"/tmp/logs/pod-logs/${NAMESPACE}/${POD}/${CONTAINER}.txt\"\n    kubectl logs --previous ${POD} -n ${NAMESPACE} -c ${CONTAINER} > \"/tmp/logs/pod-logs/failed-pods/${NAMESPACE}/${POD}/${CONTAINER}.txt\"\n  done\n}\nexport -f get_pod_logs\nget_namespaces |  xargs -r -I {} bash -c 'get_pods \"$@\"' _ {} |  xargs -r -I {} bash -c 'get_pod_logs \"$@\"' _ {}",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000023-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "non-zero return code",
                            "rc": 123,
                            "start": "2026-07-29 18:36:40.948565",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway\nError from server (BadRequest): previous terminated container \"envoy-gateway\" in pod \"envoy-gateway-78446f96c9-m97nh\" not found\nkube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator\nError from server (BadRequest): previous terminated container \"cilium-operator\" in pod \"cilium-operator-7fcd8d6ffd-7xwpb\" not found\nkube-system/cilium-p2q6r/config\nError from server (BadRequest): previous terminated container \"config\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/mount-cgroup\nError from server (BadRequest): previous terminated container \"mount-cgroup\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/apply-sysctl-overwrites\nError from server (BadRequest): previous terminated container \"apply-sysctl-overwrites\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/mount-bpf-fs\nError from server (BadRequest): previous terminated container \"mount-bpf-fs\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/clean-cilium-state\nError from server (BadRequest): previous terminated container \"clean-cilium-state\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/install-cni-binaries\nError from server (BadRequest): previous terminated container \"install-cni-binaries\" in pod \"cilium-p2q6r\" not found\nkube-system/cilium-p2q6r/cilium-agent\nError from server (BadRequest): previous terminated container \"cilium-agent\" in pod \"cilium-p2q6r\" not found\nkube-system/coredns-5dd5756b68-bwt9r/coredns\nError from server (BadRequest): previous terminated container \"coredns\" in pod \"coredns-5dd5756b68-bwt9r\" not found\nkube-system/coredns-77cccfdc44-6r6vb/coredns\nkube-system/coredns-77cccfdc44-ksw4v/coredns\nkube-system/etcd-controller/etcd\nError from server (BadRequest): previous terminated container \"etcd\" in pod \"etcd-controller\" not found\nkube-system/kube-apiserver-controller/kube-apiserver\nError from server (BadRequest): previous terminated container \"kube-apiserver\" in pod \"kube-apiserver-controller\" not found\nkube-system/kube-controller-manager-controller/kube-controller-manager\nError from server (BadRequest): previous terminated container \"kube-controller-manager\" in pod \"kube-controller-manager-controller\" not found\nkube-system/kube-proxy-nbcfs/kube-proxy\nError from server (BadRequest): previous terminated container \"kube-proxy\" in pod \"kube-proxy-nbcfs\" not found\nkube-system/kube-scheduler-controller/kube-scheduler\nError from server (BadRequest): previous terminated container \"kube-scheduler\" in pod \"kube-scheduler-controller\" not found\nkube-system/kube-vip-controller/kube-vip\nError from server (BadRequest): previous terminated container \"kube-vip\" in pod \"kube-vip-controller\" not found\nsecretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller\nError from server (BadRequest): previous terminated container \"secretgen-controller\" in pod \"secretgen-controller-ffb97c6dc-4qtrh\" not found",
                            "stdout_lines": [
                                "envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway",
                                "Error from server (BadRequest): previous terminated container \"envoy-gateway\" in pod \"envoy-gateway-78446f96c9-m97nh\" not found",
                                "kube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator",
                                "Error from server (BadRequest): previous terminated container \"cilium-operator\" in pod \"cilium-operator-7fcd8d6ffd-7xwpb\" not found",
                                "kube-system/cilium-p2q6r/config",
                                "Error from server (BadRequest): previous terminated container \"config\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/mount-cgroup",
                                "Error from server (BadRequest): previous terminated container \"mount-cgroup\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/apply-sysctl-overwrites",
                                "Error from server (BadRequest): previous terminated container \"apply-sysctl-overwrites\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/mount-bpf-fs",
                                "Error from server (BadRequest): previous terminated container \"mount-bpf-fs\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/clean-cilium-state",
                                "Error from server (BadRequest): previous terminated container \"clean-cilium-state\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/install-cni-binaries",
                                "Error from server (BadRequest): previous terminated container \"install-cni-binaries\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/cilium-p2q6r/cilium-agent",
                                "Error from server (BadRequest): previous terminated container \"cilium-agent\" in pod \"cilium-p2q6r\" not found",
                                "kube-system/coredns-5dd5756b68-bwt9r/coredns",
                                "Error from server (BadRequest): previous terminated container \"coredns\" in pod \"coredns-5dd5756b68-bwt9r\" not found",
                                "kube-system/coredns-77cccfdc44-6r6vb/coredns",
                                "kube-system/coredns-77cccfdc44-ksw4v/coredns",
                                "kube-system/etcd-controller/etcd",
                                "Error from server (BadRequest): previous terminated container \"etcd\" in pod \"etcd-controller\" not found",
                                "kube-system/kube-apiserver-controller/kube-apiserver",
                                "Error from server (BadRequest): previous terminated container \"kube-apiserver\" in pod \"kube-apiserver-controller\" not found",
                                "kube-system/kube-controller-manager-controller/kube-controller-manager",
                                "Error from server (BadRequest): previous terminated container \"kube-controller-manager\" in pod \"kube-controller-manager-controller\" not found",
                                "kube-system/kube-proxy-nbcfs/kube-proxy",
                                "Error from server (BadRequest): previous terminated container \"kube-proxy\" in pod \"kube-proxy-nbcfs\" not found",
                                "kube-system/kube-scheduler-controller/kube-scheduler",
                                "Error from server (BadRequest): previous terminated container \"kube-scheduler\" in pod \"kube-scheduler-controller\" not found",
                                "kube-system/kube-vip-controller/kube-vip",
                                "Error from server (BadRequest): previous terminated container \"kube-vip\" in pod \"kube-vip-controller\" not found",
                                "secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller",
                                "Error from server (BadRequest): previous terminated container \"secretgen-controller\" in pod \"secretgen-controller-ffb97c6dc-4qtrh\" not found"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000023-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001f",
                        "name": "gather-pod-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-pod-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:47.765992Z",
                            "start": "2026-07-29T18:36:40.722863Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000023",
                        "name": "retrieve all kubernetes logs, current and previous (if they exist)"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/pod-logs /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/pod-logs",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "cd+++++++++ pod-logs/\ncd+++++++++ pod-logs/envoy-gateway-system/\ncd+++++++++ pod-logs/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/\n>f+++++++++ pod-logs/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway.txt\ncd+++++++++ pod-logs/failed-pods/\ncd+++++++++ pod-logs/failed-pods/envoy-gateway-system/\ncd+++++++++ pod-logs/failed-pods/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/\n>f+++++++++ pod-logs/failed-pods/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/\ncd+++++++++ pod-logs/failed-pods/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/apply-sysctl-overwrites.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/cilium-agent.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/clean-cilium-state.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/config.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/install-cni-binaries.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/mount-bpf-fs.txt\n>f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/mount-cgroup.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/coredns-5dd5756b68-bwt9r/\n>f+++++++++ pod-logs/failed-pods/kube-system/coredns-5dd5756b68-bwt9r/coredns.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-6r6vb/\n>f+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-6r6vb/coredns.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-ksw4v/\n>f+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-ksw4v/coredns.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/etcd-controller/\n>f+++++++++ pod-logs/failed-pods/kube-system/etcd-controller/etcd.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/kube-apiserver-controller/\n>f+++++++++ pod-logs/failed-pods/kube-system/kube-apiserver-controller/kube-apiserver.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/kube-controller-manager-controller/\n>f+++++++++ pod-logs/failed-pods/kube-system/kube-controller-manager-controller/kube-controller-manager.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/kube-proxy-nbcfs/\n>f+++++++++ pod-logs/failed-pods/kube-system/kube-proxy-nbcfs/kube-proxy.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/kube-scheduler-controller/\n>f+++++++++ pod-logs/failed-pods/kube-system/kube-scheduler-controller/kube-scheduler.txt\ncd+++++++++ pod-logs/failed-pods/kube-system/kube-vip-controller/\n>f+++++++++ pod-logs/failed-pods/kube-system/kube-vip-controller/kube-vip.txt\ncd+++++++++ pod-logs/failed-pods/secretgen-controller/\ncd+++++++++ pod-logs/failed-pods/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/\n>f+++++++++ pod-logs/failed-pods/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller.txt\ncd+++++++++ pod-logs/kube-system/\ncd+++++++++ pod-logs/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/\n>f+++++++++ pod-logs/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator.txt\ncd+++++++++ pod-logs/kube-system/cilium-p2q6r/\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/apply-sysctl-overwrites.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/cilium-agent.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/clean-cilium-state.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/config.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/install-cni-binaries.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/mount-bpf-fs.txt\n>f+++++++++ pod-logs/kube-system/cilium-p2q6r/mount-cgroup.txt\ncd+++++++++ pod-logs/kube-system/coredns-5dd5756b68-bwt9r/\n>f+++++++++ pod-logs/kube-system/coredns-5dd5756b68-bwt9r/coredns.txt\ncd+++++++++ pod-logs/kube-system/coredns-77cccfdc44-6r6vb/\n>f+++++++++ pod-logs/kube-system/coredns-77cccfdc44-6r6vb/coredns.txt\ncd+++++++++ pod-logs/kube-system/coredns-77cccfdc44-ksw4v/\n>f+++++++++ pod-logs/kube-system/coredns-77cccfdc44-ksw4v/coredns.txt\ncd+++++++++ pod-logs/kube-system/etcd-controller/\n>f+++++++++ pod-logs/kube-system/etcd-controller/etcd.txt\ncd+++++++++ pod-logs/kube-system/kube-apiserver-controller/\n>f+++++++++ pod-logs/kube-system/kube-apiserver-controller/kube-apiserver.txt\ncd+++++++++ pod-logs/kube-system/kube-controller-manager-controller/\n>f+++++++++ pod-logs/kube-system/kube-controller-manager-controller/kube-controller-manager.txt\ncd+++++++++ pod-logs/kube-system/kube-proxy-nbcfs/\n>f+++++++++ pod-logs/kube-system/kube-proxy-nbcfs/kube-proxy.txt\ncd+++++++++ pod-logs/kube-system/kube-scheduler-controller/\n>f+++++++++ pod-logs/kube-system/kube-scheduler-controller/kube-scheduler.txt\ncd+++++++++ pod-logs/kube-system/kube-vip-controller/\n>f+++++++++ pod-logs/kube-system/kube-vip-controller/kube-vip.txt\ncd+++++++++ pod-logs/secretgen-controller/\ncd+++++++++ pod-logs/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/\n>f+++++++++ pod-logs/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller.txt\n",
                            "rc": 0,
                            "stdout_lines": [
                                "cd+++++++++ pod-logs/",
                                "cd+++++++++ pod-logs/envoy-gateway-system/",
                                "cd+++++++++ pod-logs/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/",
                                ">f+++++++++ pod-logs/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway.txt",
                                "cd+++++++++ pod-logs/failed-pods/",
                                "cd+++++++++ pod-logs/failed-pods/envoy-gateway-system/",
                                "cd+++++++++ pod-logs/failed-pods/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/",
                                ">f+++++++++ pod-logs/failed-pods/envoy-gateway-system/envoy-gateway-78446f96c9-m97nh/envoy-gateway.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/apply-sysctl-overwrites.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/cilium-agent.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/clean-cilium-state.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/config.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/install-cni-binaries.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/mount-bpf-fs.txt",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/cilium-p2q6r/mount-cgroup.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/coredns-5dd5756b68-bwt9r/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/coredns-5dd5756b68-bwt9r/coredns.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-6r6vb/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-6r6vb/coredns.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-ksw4v/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/coredns-77cccfdc44-ksw4v/coredns.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/etcd-controller/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/etcd-controller/etcd.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/kube-apiserver-controller/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/kube-apiserver-controller/kube-apiserver.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/kube-controller-manager-controller/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/kube-controller-manager-controller/kube-controller-manager.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/kube-proxy-nbcfs/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/kube-proxy-nbcfs/kube-proxy.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/kube-scheduler-controller/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/kube-scheduler-controller/kube-scheduler.txt",
                                "cd+++++++++ pod-logs/failed-pods/kube-system/kube-vip-controller/",
                                ">f+++++++++ pod-logs/failed-pods/kube-system/kube-vip-controller/kube-vip.txt",
                                "cd+++++++++ pod-logs/failed-pods/secretgen-controller/",
                                "cd+++++++++ pod-logs/failed-pods/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/",
                                ">f+++++++++ pod-logs/failed-pods/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller.txt",
                                "cd+++++++++ pod-logs/kube-system/",
                                "cd+++++++++ pod-logs/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/",
                                ">f+++++++++ pod-logs/kube-system/cilium-operator-7fcd8d6ffd-7xwpb/cilium-operator.txt",
                                "cd+++++++++ pod-logs/kube-system/cilium-p2q6r/",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/apply-sysctl-overwrites.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/cilium-agent.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/clean-cilium-state.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/config.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/install-cni-binaries.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/mount-bpf-fs.txt",
                                ">f+++++++++ pod-logs/kube-system/cilium-p2q6r/mount-cgroup.txt",
                                "cd+++++++++ pod-logs/kube-system/coredns-5dd5756b68-bwt9r/",
                                ">f+++++++++ pod-logs/kube-system/coredns-5dd5756b68-bwt9r/coredns.txt",
                                "cd+++++++++ pod-logs/kube-system/coredns-77cccfdc44-6r6vb/",
                                ">f+++++++++ pod-logs/kube-system/coredns-77cccfdc44-6r6vb/coredns.txt",
                                "cd+++++++++ pod-logs/kube-system/coredns-77cccfdc44-ksw4v/",
                                ">f+++++++++ pod-logs/kube-system/coredns-77cccfdc44-ksw4v/coredns.txt",
                                "cd+++++++++ pod-logs/kube-system/etcd-controller/",
                                ">f+++++++++ pod-logs/kube-system/etcd-controller/etcd.txt",
                                "cd+++++++++ pod-logs/kube-system/kube-apiserver-controller/",
                                ">f+++++++++ pod-logs/kube-system/kube-apiserver-controller/kube-apiserver.txt",
                                "cd+++++++++ pod-logs/kube-system/kube-controller-manager-controller/",
                                ">f+++++++++ pod-logs/kube-system/kube-controller-manager-controller/kube-controller-manager.txt",
                                "cd+++++++++ pod-logs/kube-system/kube-proxy-nbcfs/",
                                ">f+++++++++ pod-logs/kube-system/kube-proxy-nbcfs/kube-proxy.txt",
                                "cd+++++++++ pod-logs/kube-system/kube-scheduler-controller/",
                                ">f+++++++++ pod-logs/kube-system/kube-scheduler-controller/kube-scheduler.txt",
                                "cd+++++++++ pod-logs/kube-system/kube-vip-controller/",
                                ">f+++++++++ pod-logs/kube-system/kube-vip-controller/kube-vip.txt",
                                "cd+++++++++ pod-logs/secretgen-controller/",
                                "cd+++++++++ pod-logs/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/",
                                ">f+++++++++ pod-logs/secretgen-controller/secretgen-controller-ffb97c6dc-4qtrh/secretgen-controller.txt"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000001f",
                        "name": "gather-pod-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-pod-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:48.310118Z",
                            "start": "2026-07-29T18:36:47.771224Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000024",
                        "name": "Downloads pod logs to executor"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/prometheus",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/prometheus",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/prometheus",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/prometheus",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000026",
                        "name": "gather-prom-metrics",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-prom-metrics"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:48.586299Z",
                            "start": "2026-07-29T18:36:48.327505Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000028",
                        "name": "creating directory for helm release descriptions"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nNAMESPACES=$(kubectl get namespaces -o json | jq -r '.items[].metadata.name')\nfor NS in $NAMESPACES; do\n  SERVICES=$(kubectl get svc -n $NS -o json | jq -r '.items[] | select(.spec.ports[].name==\"metrics\") | .metadata.name')\n  for SVC in $SERVICES; do\n    PORT=$(kubectl get svc $SVC -n $NS -o json | jq -r '.spec.ports[] | select(.name==\"metrics\") | .port')\n    echo \"Scraping $SVC.$NS:$PORT/metrics:\"\n    curl \"$SVC.$NS:$PORT/metrics\" >> \"/tmp/logs\"/prometheus/$NS-$SVC.txt || true\n  done\ndone",
                            "delta": "0:00:00.864103",
                            "end": "2026-07-29 18:36:49.711347",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nNAMESPACES=$(kubectl get namespaces -o json | jq -r '.items[].metadata.name')\nfor NS in $NAMESPACES; do\n  SERVICES=$(kubectl get svc -n $NS -o json | jq -r '.items[] | select(.spec.ports[].name==\"metrics\") | .metadata.name')\n  for SVC in $SERVICES; do\n    PORT=$(kubectl get svc $SVC -n $NS -o json | jq -r '.spec.ports[] | select(.name==\"metrics\") | .port')\n    echo \"Scraping $SVC.$NS:$PORT/metrics:\"\n    curl \"$SVC.$NS:$PORT/metrics\" >> \"/tmp/logs\"/prometheus/$NS-$SVC.txt || true\n  done\ndone",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000029-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:48.847244",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "Scraping envoy-gateway.envoy-gateway-system:19001/metrics:\n  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current\n                                 Dload  Upload   Total   Spent    Left  Speed\n\r  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0curl: (6) Could not resolve host: envoy-gateway.envoy-gateway-system\nScraping kube-dns.kube-system:9153/metrics:\n  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current\n                                 Dload  Upload   Total   Spent    Left  Speed\n\r  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0curl: (6) Could not resolve host: kube-dns.kube-system",
                            "stdout_lines": [
                                "Scraping envoy-gateway.envoy-gateway-system:19001/metrics:",
                                "  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current",
                                "                                 Dload  Upload   Total   Spent    Left  Speed",
                                "",
                                "  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0curl: (6) Could not resolve host: envoy-gateway.envoy-gateway-system",
                                "Scraping kube-dns.kube-system:9153/metrics:",
                                "  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current",
                                "                                 Dload  Upload   Total   Spent    Left  Speed",
                                "",
                                "  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0curl: (6) Could not resolve host: kube-dns.kube-system"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000029-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000026",
                        "name": "gather-prom-metrics",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-prom-metrics"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:50.137723Z",
                            "start": "2026-07-29T18:36:48.615669Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000029",
                        "name": "Get metrics from exporter services in all namespaces"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nmgr_endpoints=$(kubectl get endpoints -n ceph -l component=manager -o json | jq -r '.items[].subsets[].addresses[].ip')\necho \"ceph-mgr endpoints: $mgr_endpoints\"\nfor endpoint in $mgr_endpoints; do\n  echo \"checking ceph-mgr at $endpoint\"\n  metrics_curl=\"curl $endpoint:9283/metrics\"\n  op=$(eval \"$metrics_curl\")\n  if [[ -n $op ]]; then\n    curl $endpoint:9283/metrics >> \"/tmp/logs\"/prometheus/ceph-ceph-mgr.txt\n    break\n  else\n    echo \"$endpoint is a standby ceph-mgr. Trying next endpoint\"\n  fi\ndone",
                            "delta": "0:00:00.103408",
                            "end": "2026-07-29 18:36:50.513225",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nmgr_endpoints=$(kubectl get endpoints -n ceph -l component=manager -o json | jq -r '.items[].subsets[].addresses[].ip')\necho \"ceph-mgr endpoints: $mgr_endpoints\"\nfor endpoint in $mgr_endpoints; do\n  echo \"checking ceph-mgr at $endpoint\"\n  metrics_curl=\"curl $endpoint:9283/metrics\"\n  op=$(eval \"$metrics_curl\")\n  if [[ -n $op ]]; then\n    curl $endpoint:9283/metrics >> \"/tmp/logs\"/prometheus/ceph-ceph-mgr.txt\n    break\n  else\n    echo \"$endpoint is a standby ceph-mgr. Trying next endpoint\"\n  fi\ndone",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000002a-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:50.409817",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "ceph-mgr endpoints: ",
                            "stdout_lines": [
                                "ceph-mgr endpoints: "
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000002a-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000026",
                        "name": "gather-prom-metrics",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-prom-metrics"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:50.681781Z",
                            "start": "2026-07-29T18:36:50.164414Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002a",
                        "name": "Get ceph metrics from ceph-mgr"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -e\nNAMESPACE=\"osh-infra\"\nAPP_LABEL=\"fluentd\"\nPODS=$(kubectl get pods -n $NAMESPACE -l application=$APP_LABEL -o json | jq -r '.items[].metadata.name')\nfor POD in $PODS; do\n  IP=$(kubectl get pod -n $NAMESPACE $POD -o json | jq -r '.status.podIP')\n  PORT=$(kubectl get pod -n $NAMESPACE $POD -o json |  jq -r '.spec.containers[0].ports[] | select(.name==\"metrics\") | .containerPort')\n  echo \"Scraping $POD at $IP:$PORT/metrics\"\n  curl \"$IP:$PORT/metrics\" >> \"/tmp/logs\"/prometheus/$POD.txt || true\ndone",
                            "delta": "0:00:00.099850",
                            "end": "2026-07-29 18:36:51.047525",
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -e\nNAMESPACE=\"osh-infra\"\nAPP_LABEL=\"fluentd\"\nPODS=$(kubectl get pods -n $NAMESPACE -l application=$APP_LABEL -o json | jq -r '.items[].metadata.name')\nfor POD in $PODS; do\n  IP=$(kubectl get pod -n $NAMESPACE $POD -o json | jq -r '.status.podIP')\n  PORT=$(kubectl get pod -n $NAMESPACE $POD -o json |  jq -r '.spec.containers[0].ports[] | select(.name==\"metrics\") | .containerPort')\n  echo \"Scraping $POD at $IP:$PORT/metrics\"\n  curl \"$IP:$PORT/metrics\" >> \"/tmp/logs\"/prometheus/$POD.txt || true\ndone",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000002b-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "",
                            "rc": 0,
                            "start": "2026-07-29 18:36:50.947675",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "",
                            "stdout_lines": [],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-00000000002b-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000026",
                        "name": "gather-prom-metrics",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-prom-metrics"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:51.232181Z",
                            "start": "2026-07-29T18:36:50.714736Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002b",
                        "name": "Get metrics from fluentd pods"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/prometheus /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/prometheus",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "cd+++++++++ prometheus/\n>f+++++++++ prometheus/envoy-gateway-system-envoy-gateway.txt\n>f+++++++++ prometheus/kube-system-kube-dns.txt\n",
                            "rc": 0,
                            "stdout_lines": [
                                "cd+++++++++ prometheus/",
                                ">f+++++++++ prometheus/envoy-gateway-system-envoy-gateway.txt",
                                ">f+++++++++ prometheus/kube-system-kube-dns.txt"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-000000000026",
                        "name": "gather-prom-metrics",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-prom-metrics"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:51.876321Z",
                            "start": "2026-07-29T18:36:51.239395Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002c",
                        "name": "Downloads logs to executor"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "diff": {
                                "after": {
                                    "path": "/tmp/logs/selenium",
                                    "state": "directory"
                                },
                                "before": {
                                    "path": "/tmp/logs/selenium",
                                    "state": "absent"
                                }
                            },
                            "gid": 0,
                            "group": "root",
                            "invocation": {
                                "module_args": {
                                    "_diff_peek": null,
                                    "_original_basename": null,
                                    "access_time": null,
                                    "access_time_format": "%Y%m%d%H%M.%S",
                                    "attributes": null,
                                    "follow": true,
                                    "force": false,
                                    "group": null,
                                    "mode": null,
                                    "modification_time": null,
                                    "modification_time_format": "%Y%m%d%H%M.%S",
                                    "owner": null,
                                    "path": "/tmp/logs/selenium",
                                    "recurse": false,
                                    "selevel": null,
                                    "serole": null,
                                    "setype": null,
                                    "seuser": null,
                                    "src": null,
                                    "state": "directory",
                                    "unsafe_writes": false
                                }
                            },
                            "mode": "0755",
                            "owner": "root",
                            "path": "/tmp/logs/selenium",
                            "size": 4096,
                            "state": "directory",
                            "uid": 0
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002e",
                        "name": "gather-selenium-data",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-selenium-data"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:52.143684Z",
                            "start": "2026-07-29T18:36:51.885884Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000030",
                        "name": "creating directory for helm release descriptions"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "cmd": "set -x\ncp /tmp/artifacts/* /tmp/logs/selenium/.",
                            "delta": "0:00:00.011267",
                            "end": "2026-07-29 18:36:52.416832",
                            "failed": true,
                            "invocation": {
                                "module_args": {
                                    "_raw_params": "set -x\ncp /tmp/artifacts/* /tmp/logs/selenium/.",
                                    "_uses_shell": true,
                                    "argv": null,
                                    "chdir": null,
                                    "creates": null,
                                    "executable": "/bin/bash",
                                    "expand_argument_vars": true,
                                    "removes": null,
                                    "stdin": null,
                                    "stdin_add_newline": true,
                                    "strip_empty_ends": true,
                                    "zuul_ansible_split_streams": false,
                                    "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000031-1-controller",
                                    "zuul_no_log": false,
                                    "zuul_output_max_bytes": 1073741824
                                }
                            },
                            "msg": "non-zero return code",
                            "rc": 1,
                            "start": "2026-07-29 18:36:52.405565",
                            "stderr": "",
                            "stderr_lines": [],
                            "stdout": "+ cp '/tmp/artifacts/*' /tmp/logs/selenium/.\ncp: cannot stat '/tmp/artifacts/*': No such file or directory",
                            "stdout_lines": [
                                "+ cp '/tmp/artifacts/*' /tmp/logs/selenium/.",
                                "cp: cannot stat '/tmp/artifacts/*': No such file or directory"
                            ],
                            "zuul_log_id": "0242ac17-0010-5d7d-c0aa-000000000031-1-controller"
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002e",
                        "name": "gather-selenium-data",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-selenium-data"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:52.690301Z",
                            "start": "2026-07-29T18:36:52.173868Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000031",
                        "name": "Get selenium data"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --rsh='/usr/bin/ssh -S none -o Port=22 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' --rsync-path='sudo -u root rsync' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/tmp/logs/selenium /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                            "invocation": {
                                "module_args": {
                                    "_local_rsync_password": null,
                                    "_local_rsync_path": "rsync",
                                    "_ssh_args": null,
                                    "_substitute_controller": false,
                                    "archive": true,
                                    "checksum": false,
                                    "compress": true,
                                    "copy_links": false,
                                    "delay_updates": true,
                                    "delete": false,
                                    "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/controller",
                                    "dest_port": 22,
                                    "dirs": false,
                                    "existing_only": false,
                                    "group": null,
                                    "link_dest": null,
                                    "links": null,
                                    "mode": "pull",
                                    "owner": null,
                                    "partial": false,
                                    "perms": null,
                                    "private_key": null,
                                    "recursive": null,
                                    "rsync_opts": [],
                                    "rsync_path": "sudo -u root rsync",
                                    "rsync_timeout": 0,
                                    "set_remote_user": true,
                                    "src": "zuul@199.19.213.139:/tmp/logs/selenium",
                                    "ssh_connection_multiplexing": false,
                                    "times": null,
                                    "use_ssh_args": false,
                                    "verify_host": false
                                }
                            },
                            "msg": "cd+++++++++ selenium/\n",
                            "rc": 0,
                            "stdout_lines": [
                                "cd+++++++++ selenium/"
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-5d7d-c0aa-00000000002e",
                        "name": "gather-selenium-data",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/untrusted/project_4/opendev.org/openstack/openstack-helm/roles/gather-selenium-data"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:53.229682Z",
                            "start": "2026-07-29T18:36:52.697672Z"
                        },
                        "id": "0242ac17-0010-5d7d-c0aa-000000000032",
                        "name": "Downloads logs to executor"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 23,
            "failures": 0,
            "ignored": 2,
            "ok": 23,
            "rescued": 0,
            "skipped": 0,
            "unreachable": 0
        }
    },
    "trusted": false
},
{
    "branch": "main",
    "index": "1",
    "phase": "post",
    "playbook": "github.com/vexxhost/zuul-config/playbooks/base/post.yaml",
    "plays": [
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:37:00.934193Z",
                    "start": "2026-07-29T18:36:57.181742Z"
                },
                "id": "0242ac17-0010-1352-f3fa-000000000002",
                "name": "all"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "set_fact",
                            "changed": false,
                            "false_condition": "groups['all'] | length > 1",
                            "skip_reason": "Conditional result was False",
                            "skipped": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-000000000006",
                        "name": "fetch-output",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/fetch-output"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:57.237537Z",
                            "start": "2026-07-29T18:36:57.192814Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-000000000008",
                        "name": "Set log path for multiple nodes"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "set_fact",
                            "ansible_facts": {
                                "log_path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs"
                            },
                            "changed": false
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-000000000006",
                        "name": "fetch-output",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/fetch-output"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:57.290008Z",
                            "start": "2026-07-29T18:36:57.248130Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-000000000009",
                        "name": "Set log path for single node"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "file",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": false,
                                    "diff": {
                                        "after": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs"
                                        },
                                        "before": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 0,
                                    "group": "root",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "root",
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 0,
                                    "zj_output_dir": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts",
                                            "state": "absent"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 0,
                                    "group": "root",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "root",
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 0,
                                    "zj_output_dir": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts"
                                },
                                {
                                    "ansible_loop_var": "zj_output_dir",
                                    "changed": true,
                                    "diff": {
                                        "after": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs",
                                            "state": "directory"
                                        },
                                        "before": {
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs",
                                            "state": "absent"
                                        }
                                    },
                                    "failed": false,
                                    "gid": 0,
                                    "group": "root",
                                    "invocation": {
                                        "module_args": {
                                            "_diff_peek": null,
                                            "_original_basename": null,
                                            "access_time": null,
                                            "access_time_format": "%Y%m%d%H%M.%S",
                                            "attributes": null,
                                            "follow": true,
                                            "force": false,
                                            "group": null,
                                            "mode": 493,
                                            "modification_time": null,
                                            "modification_time_format": "%Y%m%d%H%M.%S",
                                            "owner": null,
                                            "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs",
                                            "recurse": false,
                                            "selevel": null,
                                            "serole": null,
                                            "setype": null,
                                            "seuser": null,
                                            "src": null,
                                            "state": "directory",
                                            "unsafe_writes": false
                                        }
                                    },
                                    "mode": "0755",
                                    "owner": "root",
                                    "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs",
                                    "size": 4096,
                                    "state": "directory",
                                    "uid": 0,
                                    "zj_output_dir": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs"
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-000000000006",
                        "name": "fetch-output",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/fetch-output"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:36:58.431667Z",
                            "start": "2026-07-29T18:36:57.294905Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-00000000000a",
                        "name": "Ensure local output dirs"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "synchronize",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_output",
                                    "changed": true,
                                    "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --no-owner --no-group --rsh='/usr/bin/ssh -S none -o Port=22' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/home/zuul/zuul-output/logs/ /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/",
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_local_rsync_password": null,
                                            "_local_rsync_path": "rsync",
                                            "_ssh_args": null,
                                            "_substitute_controller": false,
                                            "archive": true,
                                            "checksum": false,
                                            "compress": true,
                                            "copy_links": false,
                                            "delay_updates": true,
                                            "delete": false,
                                            "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/",
                                            "dest_port": 22,
                                            "dirs": false,
                                            "existing_only": false,
                                            "group": false,
                                            "link_dest": null,
                                            "links": null,
                                            "mode": "pull",
                                            "owner": false,
                                            "partial": false,
                                            "perms": null,
                                            "private_key": null,
                                            "recursive": null,
                                            "rsync_opts": [],
                                            "rsync_path": null,
                                            "rsync_timeout": 0,
                                            "set_remote_user": true,
                                            "src": "zuul@199.19.213.139:/home/zuul/zuul-output/logs/",
                                            "ssh_connection_multiplexing": false,
                                            "times": null,
                                            "use_ssh_args": false,
                                            "verify_host": true
                                        }
                                    },
                                    "msg": ".d..t...... ./\n",
                                    "rc": 0,
                                    "stdout_lines": [
                                        ".d..t...... ./"
                                    ],
                                    "zj_output": {
                                        "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs",
                                        "src": "logs"
                                    }
                                },
                                {
                                    "ansible_loop_var": "zj_output",
                                    "changed": true,
                                    "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --no-owner --no-group --rsh='/usr/bin/ssh -S none -o Port=22' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/home/zuul/zuul-output/artifacts/ /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts/",
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_local_rsync_password": null,
                                            "_local_rsync_path": "rsync",
                                            "_ssh_args": null,
                                            "_substitute_controller": false,
                                            "archive": true,
                                            "checksum": false,
                                            "compress": true,
                                            "copy_links": false,
                                            "delay_updates": true,
                                            "delete": false,
                                            "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts/",
                                            "dest_port": 22,
                                            "dirs": false,
                                            "existing_only": false,
                                            "group": false,
                                            "link_dest": null,
                                            "links": null,
                                            "mode": "pull",
                                            "owner": false,
                                            "partial": false,
                                            "perms": null,
                                            "private_key": null,
                                            "recursive": null,
                                            "rsync_opts": [],
                                            "rsync_path": null,
                                            "rsync_timeout": 0,
                                            "set_remote_user": true,
                                            "src": "zuul@199.19.213.139:/home/zuul/zuul-output/artifacts/",
                                            "ssh_connection_multiplexing": false,
                                            "times": null,
                                            "use_ssh_args": false,
                                            "verify_host": true
                                        }
                                    },
                                    "msg": ".d..t...... ./\n",
                                    "rc": 0,
                                    "stdout_lines": [
                                        ".d..t...... ./"
                                    ],
                                    "zj_output": {
                                        "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts",
                                        "src": "artifacts"
                                    }
                                },
                                {
                                    "ansible_loop_var": "zj_output",
                                    "changed": true,
                                    "cmd": "/usr/bin/rsync --delay-updates -F --compress --archive --no-owner --no-group --rsh='/usr/bin/ssh -S none -o Port=22' --out-format='<<CHANGED>>%i %n%L' zuul@199.19.213.139:/home/zuul/zuul-output/docs/ /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs/",
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_local_rsync_password": null,
                                            "_local_rsync_path": "rsync",
                                            "_ssh_args": null,
                                            "_substitute_controller": false,
                                            "archive": true,
                                            "checksum": false,
                                            "compress": true,
                                            "copy_links": false,
                                            "delay_updates": true,
                                            "delete": false,
                                            "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs/",
                                            "dest_port": 22,
                                            "dirs": false,
                                            "existing_only": false,
                                            "group": false,
                                            "link_dest": null,
                                            "links": null,
                                            "mode": "pull",
                                            "owner": false,
                                            "partial": false,
                                            "perms": null,
                                            "private_key": null,
                                            "recursive": null,
                                            "rsync_opts": [],
                                            "rsync_path": null,
                                            "rsync_timeout": 0,
                                            "set_remote_user": true,
                                            "src": "zuul@199.19.213.139:/home/zuul/zuul-output/docs/",
                                            "ssh_connection_multiplexing": false,
                                            "times": null,
                                            "use_ssh_args": false,
                                            "verify_host": true
                                        }
                                    },
                                    "msg": ".d..t...... ./\n",
                                    "rc": 0,
                                    "stdout_lines": [
                                        ".d..t...... ./"
                                    ],
                                    "zj_output": {
                                        "dest": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs",
                                        "src": "docs"
                                    }
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-000000000006",
                        "name": "fetch-output",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/fetch-output"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:37:00.148747Z",
                            "start": "2026-07-29T18:36:58.441761Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-00000000000c",
                        "name": "Collect logs, artifacts and docs"
                    }
                },
                {
                    "hosts": {
                        "controller": {
                            "action": "shell",
                            "changed": true,
                            "msg": "All items completed",
                            "results": [
                                {
                                    "ansible_loop_var": "zj_item",
                                    "changed": true,
                                    "cmd": "if [ -n \"$(find /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts -mindepth 1)\" ] ; then\n  # Only create target directory if it is needed.\n  # Do not fail if it is already there.\n  mkdir -p /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/artifacts\n  # Leave the original directory behind so that other roles\n  # operating on the interface directories can simply no-op.\n  mv -f /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts/* /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/artifacts\nfi\n",
                                    "delta": "0:00:00.102513",
                                    "end": "2026-07-29 18:37:00.648835",
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_raw_params": "if [ -n \"$(find /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts -mindepth 1)\" ] ; then\n  # Only create target directory if it is needed.\n  # Do not fail if it is already there.\n  mkdir -p /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/artifacts\n  # Leave the original directory behind so that other roles\n  # operating on the interface directories can simply no-op.\n  mv -f /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/artifacts/* /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/artifacts\nfi\n",
                                            "_uses_shell": true,
                                            "argv": null,
                                            "chdir": null,
                                            "creates": null,
                                            "executable": null,
                                            "expand_argument_vars": true,
                                            "removes": null,
                                            "stdin": null,
                                            "stdin_add_newline": true,
                                            "strip_empty_ends": true,
                                            "zuul_ansible_split_streams": false,
                                            "zuul_log_id": "in-loop-ignore",
                                            "zuul_no_log": false,
                                            "zuul_output_max_bytes": 1073741824
                                        }
                                    },
                                    "msg": "",
                                    "rc": 0,
                                    "start": "2026-07-29 18:37:00.546322",
                                    "stderr": "",
                                    "stderr_lines": [],
                                    "stdout": "",
                                    "stdout_lines": [],
                                    "zj_item": "artifacts",
                                    "zuul_log_id": "in-loop-ignore"
                                },
                                {
                                    "ansible_loop_var": "zj_item",
                                    "changed": true,
                                    "cmd": "if [ -n \"$(find /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs -mindepth 1)\" ] ; then\n  # Only create target directory if it is needed.\n  # Do not fail if it is already there.\n  mkdir -p /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/docs\n  # Leave the original directory behind so that other roles\n  # operating on the interface directories can simply no-op.\n  mv -f /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs/* /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/docs\nfi\n",
                                    "delta": "0:00:00.009778",
                                    "end": "2026-07-29 18:37:00.884509",
                                    "failed": false,
                                    "invocation": {
                                        "module_args": {
                                            "_raw_params": "if [ -n \"$(find /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs -mindepth 1)\" ] ; then\n  # Only create target directory if it is needed.\n  # Do not fail if it is already there.\n  mkdir -p /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/docs\n  # Leave the original directory behind so that other roles\n  # operating on the interface directories can simply no-op.\n  mv -f /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/docs/* /var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/work/logs/docs\nfi\n",
                                            "_uses_shell": true,
                                            "argv": null,
                                            "chdir": null,
                                            "creates": null,
                                            "executable": null,
                                            "expand_argument_vars": true,
                                            "removes": null,
                                            "stdin": null,
                                            "stdin_add_newline": true,
                                            "strip_empty_ends": true,
                                            "zuul_ansible_split_streams": false,
                                            "zuul_log_id": "in-loop-ignore",
                                            "zuul_no_log": false,
                                            "zuul_output_max_bytes": 1073741824
                                        }
                                    },
                                    "msg": "",
                                    "rc": 0,
                                    "start": "2026-07-29 18:37:00.874731",
                                    "stderr": "",
                                    "stderr_lines": [],
                                    "stdout": "",
                                    "stdout_lines": [],
                                    "zj_item": "docs",
                                    "zuul_log_id": "in-loop-ignore"
                                }
                            ]
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-00000000000f",
                        "name": "merge-output-to-logs",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/merge-output-to-logs"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:37:00.934193Z",
                            "start": "2026-07-29T18:37:00.162717Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-000000000011",
                        "name": "Move artifacts and docs to logs dir"
                    }
                }
            ]
        },
        {
            "play": {
                "duration": {
                    "end": "2026-07-29T18:37:01.462894Z",
                    "start": "2026-07-29T18:37:00.949303Z"
                },
                "id": "0242ac17-0010-1352-f3fa-000000000013",
                "name": "all"
            },
            "tasks": [
                {
                    "hosts": {
                        "controller": {
                            "action": "authorized_key",
                            "changed": true,
                            "comment": null,
                            "exclusive": false,
                            "follow": false,
                            "invocation": {
                                "module_args": {
                                    "changed": true,
                                    "comment": null,
                                    "exclusive": false,
                                    "follow": false,
                                    "key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCmDHOdGrQeoRqhLHqTWhV3QHEYCvX9JXswHgsgu21Iv6EhFwZDzTwhIpA1Icc0Qb8U4/j3fg7R/Knr/oAq8CJxVK2gCJ0e/ucYK7kbnyNNdKhdL5nS8LEhsUaDqFC1vZC3v2BRcNo7ePVPygFCsxy0Zf/H6JI3BR47Z6C1n5nliH4cVvxvgJyzLJUCr6NtaAOCD+buWMRnuro5MU4a+Rxo2EQ3DK+3h7yhv+gKZRlwY2Mkbrhq30aVw8q9Lb1YhNxrgEIOqKTF0oInC/bpXavTQ7awjO47N2tTzJe3/nfMf3t+uA8lu+aAqZ6OzCbUtCosAedWur1vcLzyKpS+67IiMgIf49wAB2gM5CcdrmKjLJEY5vXBzMiRKgIIi0TiQzY0cCbBwuOOrhJOnlaAx8jS23wO8rZI3EdK2eBWxdrTs5gw3ZYncQwMMhHsX3UCe0QTIs1itz2I4B9WwdqsqYNh8tAB3FwzQcIklVzr/hcBDP+KWjfTPm8xB4jDYcQYiJc= zuul-build-sshkey",
                                    "key_options": null,
                                    "keyfile": "/home/zuul/.ssh/authorized_keys",
                                    "manage_dir": true,
                                    "path": null,
                                    "state": "absent",
                                    "user": "zuul",
                                    "validate_certs": true
                                }
                            },
                            "key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCmDHOdGrQeoRqhLHqTWhV3QHEYCvX9JXswHgsgu21Iv6EhFwZDzTwhIpA1Icc0Qb8U4/j3fg7R/Knr/oAq8CJxVK2gCJ0e/ucYK7kbnyNNdKhdL5nS8LEhsUaDqFC1vZC3v2BRcNo7ePVPygFCsxy0Zf/H6JI3BR47Z6C1n5nliH4cVvxvgJyzLJUCr6NtaAOCD+buWMRnuro5MU4a+Rxo2EQ3DK+3h7yhv+gKZRlwY2Mkbrhq30aVw8q9Lb1YhNxrgEIOqKTF0oInC/bpXavTQ7awjO47N2tTzJe3/nfMf3t+uA8lu+aAqZ6OzCbUtCosAedWur1vcLzyKpS+67IiMgIf49wAB2gM5CcdrmKjLJEY5vXBzMiRKgIIi0TiQzY0cCbBwuOOrhJOnlaAx8jS23wO8rZI3EdK2eBWxdrTs5gw3ZYncQwMMhHsX3UCe0QTIs1itz2I4B9WwdqsqYNh8tAB3FwzQcIklVzr/hcBDP+KWjfTPm8xB4jDYcQYiJc= zuul-build-sshkey",
                            "key_options": null,
                            "keyfile": "/home/zuul/.ssh/authorized_keys",
                            "manage_dir": true,
                            "path": null,
                            "state": "absent",
                            "user": "zuul",
                            "validate_certs": true
                        }
                    },
                    "role": {
                        "id": "0242ac17-0010-1352-f3fa-000000000016",
                        "name": "remove-build-sshkey",
                        "path": "/var/lib/zuul/builds/df925605a75e40088f795833ad47c03e/trusted/project_1/opendev.org/zuul/zuul-jobs/roles/remove-build-sshkey"
                    },
                    "task": {
                        "duration": {
                            "end": "2026-07-29T18:37:01.462894Z",
                            "start": "2026-07-29T18:37:00.958975Z"
                        },
                        "id": "0242ac17-0010-1352-f3fa-000000000018",
                        "name": "Remove the build SSH key from all nodes"
                    }
                }
            ]
        }
    ],
    "stats": {
        "controller": {
            "changed": 4,
            "failures": 0,
            "ignored": 0,
            "ok": 5,
            "rescued": 0,
            "skipped": 1,
            "unreachable": 0
        }
    },
    "trusted": true
}
]
