I0506 17:55:04.001629 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0506 17:55:04.001727 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0506 17:55:04.001781 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0506 17:55:04.008237 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0506 17:55:04.009147 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0506 17:55:04.009212 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0506 17:55:04.009233 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0506 17:55:04.014043 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0506 17:55:04.042141 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0506 17:55:04.042386 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0506 17:55:04.048310 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0506 17:55:04.051033 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0506 17:55:04.053546 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0506 17:55:04.057014 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0506 17:55:04.063862 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0506 17:55:04.064045 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0506 17:55:04.066737 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0506 17:55:04.068585 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0506 17:55:04.068604 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0506 17:55:04.068614 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0506 17:55:04.068614 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0506 17:55:04.070792 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0506 17:55:04.072476 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0506 17:55:04.074372 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0506 17:55:04.076335 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0506 17:55:04.078920 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0506 17:55:04.086783 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0506 17:55:04.089360 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0506 17:55:04.091036 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0506 17:55:04.092810 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0506 17:55:04.094705 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0506 17:55:04.096990 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0506 17:55:04.097421 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0506 17:55:04.101168 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.101729 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.101988 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.130919 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.156656 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.158740 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.186392 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.201362 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.205261 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:04.222254 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0506 17:55:21.413941 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-06 17:55:21.413917626 +0000 UTC m=+17.442868207 I0506 17:55:22.131759 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 17:55:22.131851 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 17:55:22.131840333 +0000 UTC m=+18.160790914 I0506 17:55:22.131774 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-06 17:55:22.131757937 +0000 UTC m=+18.160708508 E0506 17:55:22.149320 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 17:55:22.149390 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-06 17:55:22.149382826 +0000 UTC m=+18.178333377 E0506 17:55:22.149411 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 17:55:22.156276 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:22.156338 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 17:55:22.156353 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-06 17:55:22.156346795 +0000 UTC m=+18.185297346 E0506 17:55:22.166730 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0506 17:55:22.166816 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 17:55:22.167102 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 17:55:22.167146 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0506 17:55:22.192232 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:22.198785 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-wqgcc" condition "Approved" to 2026-05-06 17:55:22.198775609 +0000 UTC m=+18.227726170 I0506 17:55:22.209751 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-wqgcc" condition "Ready" to 2026-05-06 17:55:22.209739493 +0000 UTC m=+18.238690054 I0506 17:55:22.232926 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 17:55:22.23291718 +0000 UTC m=+18.261867711 I0506 17:55:22.249166 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:22.279482 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:27.167330 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 17:55:27.167312299 +0000 UTC m=+23.196262870 I0506 17:55:52.609848 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 17:55:52.610069 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-06 17:55:52.610065396 +0000 UTC m=+48.639015937 I0506 17:55:52.610031 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 17:55:52.610022212 +0000 UTC m=+48.638972793 I0506 17:55:52.632243 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:52.632325 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-06 17:55:52.632318106 +0000 UTC m=+48.661268647 I0506 17:55:52.634828 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-06 17:55:52.634822003 +0000 UTC m=+48.663772554 I0506 17:55:52.818947 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:52.854911 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-h4kr8" condition "Approved" to 2026-05-06 17:55:52.85489836 +0000 UTC m=+48.883848931 I0506 17:55:52.883270 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-h4kr8" condition "Ready" to 2026-05-06 17:55:52.883256836 +0000 UTC m=+48.912207387 I0506 17:55:52.915966 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 17:55:52.915948361 +0000 UTC m=+48.944898912 I0506 17:55:52.941673 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 17:55:53.012915 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:01:49.464292 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-78.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:01:49.464278 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Ready" to 2026-05-06 18:01:49.464239013 +0000 UTC m=+405.493189584 I0506 18:01:49.464324 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Issuing" to 2026-05-06 18:01:49.464316878 +0000 UTC m=+405.493267419 I0506 18:01:49.479663 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-78.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-78.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:01:49.479713 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-78.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:01:49.479730 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Issuing" to 2026-05-06 18:01:49.479723127 +0000 UTC m=+405.508673678 I0506 18:01:49.627401 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-78.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-78.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:01:49.635700 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-78.nip.io-tls-7kp8r" condition "Approved" to 2026-05-06 18:01:49.635691816 +0000 UTC m=+405.664642367 I0506 18:01:49.665276 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-78.nip.io-tls-7kp8r" condition "Ready" to 2026-05-06 18:01:49.66526266 +0000 UTC m=+405.694213231 I0506 18:01:49.689742 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:01:49.689728569 +0000 UTC m=+405.718679130 I0506 18:01:49.705261 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-78.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-78.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:01:49.705616 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:01:49.705606635 +0000 UTC m=+405.734557176 I0506 18:01:49.730128 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-78.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-78.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:01:49.730507 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-78.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:01:49.730497059 +0000 UTC m=+405.759447620 I0506 18:02:56.373044 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:02:56.372915905 +0000 UTC m=+472.401866506 I0506 18:02:56.373306 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:02:56.373453 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-06 18:02:56.373402417 +0000 UTC m=+472.402352978 I0506 18:02:56.485185 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:56.485316 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-06 18:02:56.485304338 +0000 UTC m=+472.514254919 E0506 18:02:56.546553 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:02:56.546629 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-06 18:02:56.546615335 +0000 UTC m=+472.575565906 E0506 18:02:56.546875 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0506 18:02:56.568498 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" E0506 18:02:56.632839 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0506 18:02:56.633941 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:02:56.633986 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0506 18:02:56.634048 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0506 18:02:56.657613 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-tlsdv" condition "Approved" to 2026-05-06 18:02:56.657596307 +0000 UTC m=+472.686546858 I0506 18:02:56.879506 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-tlsdv" condition "Ready" to 2026-05-06 18:02:56.879492556 +0000 UTC m=+472.908443127 I0506 18:02:57.146761 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:57.1467451 +0000 UTC m=+473.175695681 I0506 18:02:57.174697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:02:57.174916 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:02:57.174909494 +0000 UTC m=+473.203860045 I0506 18:02:57.208004 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:01.635392 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:01.635384209 +0000 UTC m=+477.664334750 I0506 18:03:44.384886 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.385156 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-06 18:03:44.385135003 +0000 UTC m=+520.414085574 I0506 18:03:44.385289 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-06 18:03:44.385273882 +0000 UTC m=+520.414224423 I0506 18:03:44.395040 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.395164 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-06 18:03:44.395156934 +0000 UTC m=+520.424107485 I0506 18:03:44.395654 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-06 18:03:44.395647937 +0000 UTC m=+520.424598488 I0506 18:03:44.395971 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.396025 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-06 18:03:44.396020422 +0000 UTC m=+520.424970973 I0506 18:03:44.396444 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-06 18:03:44.39643745 +0000 UTC m=+520.425388001 I0506 18:03:44.420479 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:44.420697 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.420727 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-06 18:03:44.420720427 +0000 UTC m=+520.449670968 I0506 18:03:44.427393 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:44.427442 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-06 18:03:44.427436088 +0000 UTC m=+520.456386649 I0506 18:03:44.429580 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:44.429814 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.429839 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-06 18:03:44.429833129 +0000 UTC m=+520.458783680 I0506 18:03:44.741236 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:44.803809 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-c8xdt" condition "Approved" to 2026-05-06 18:03:44.803798331 +0000 UTC m=+520.832748872 I0506 18:03:44.818744 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-c8xdt" condition "Ready" to 2026-05-06 18:03:44.818734652 +0000 UTC m=+520.847685213 I0506 18:03:44.905641 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:44.905692 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-06 18:03:44.905683789 +0000 UTC m=+520.934634330 I0506 18:03:44.906054 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-c6kd7" condition "Approved" to 2026-05-06 18:03:44.906039203 +0000 UTC m=+520.934989734 I0506 18:03:44.935509 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-c6kd7" condition "Ready" to 2026-05-06 18:03:44.935497458 +0000 UTC m=+520.964448019 I0506 18:03:44.965593 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:44.968057 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:44.9680495 +0000 UTC m=+520.997000041 I0506 18:03:44.985394 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-d6wmg" condition "Approved" to 2026-05-06 18:03:44.985384881 +0000 UTC m=+521.014335422 I0506 18:03:44.990652 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:44.990642904 +0000 UTC m=+521.019593445 I0506 18:03:44.996005 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:44.995997432 +0000 UTC m=+521.024947963 I0506 18:03:45.009363 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-d6wmg" condition "Ready" to 2026-05-06 18:03:45.009352947 +0000 UTC m=+521.038303498 I0506 18:03:45.310792 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:45.403095 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:45.403881 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:45.403868003 +0000 UTC m=+521.432818574 I0506 18:03:45.954765 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:46.053525 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:46.366230 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-qbhjs" condition "Approved" to 2026-05-06 18:03:46.366220762 +0000 UTC m=+522.395171303 I0506 18:03:46.666037 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-qbhjs" condition "Ready" to 2026-05-06 18:03:46.666025888 +0000 UTC m=+522.694976439 I0506 18:03:46.804318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:46.971250 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" resource_name="prometheus-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="prometheus-tls-qbhjs" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="prometheus-tls-flfxk" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0506 18:03:47.209800 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-fh8wk" condition "Approved" to 2026-05-06 18:03:47.209782022 +0000 UTC m=+523.238732603 I0506 18:03:47.514891 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-fh8wk" condition "Ready" to 2026-05-06 18:03:47.514876365 +0000 UTC m=+523.543826946 I0506 18:03:47.756204 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:47.756020184 +0000 UTC m=+523.784970765 I0506 18:03:47.910840 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:47.911323 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:47.91131171 +0000 UTC m=+523.940262291 I0506 18:03:48.203418 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:48.255886 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:55.994108 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" condition "Ready" to 2026-05-06 18:03:55.994088767 +0000 UTC m=+532.023039338 I0506 18:03:55.994227 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:55.994276 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" condition "Issuing" to 2026-05-06 18:03:55.994259589 +0000 UTC m=+532.023210130 I0506 18:03:56.009506 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:03:56.009590 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:03:56.009608 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" condition "Issuing" to 2026-05-06 18:03:56.009602024 +0000 UTC m=+532.038552575 I0506 18:03:56.226362 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-ssrfs-ppdvn" condition "Approved" to 2026-05-06 18:03:56.226347499 +0000 UTC m=+532.255298050 I0506 18:03:56.255162 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-ssrfs-ppdvn" condition "Ready" to 2026-05-06 18:03:56.255153173 +0000 UTC m=+532.284103714 I0506 18:03:56.286895 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:03:56.286882873 +0000 UTC m=+532.315833414 I0506 18:03:56.312269 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-ssrfs-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:17.695268 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:04:17.695299 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-06 18:04:17.695292272 +0000 UTC m=+553.724242823 I0506 18:04:17.695491 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-06 18:04:17.695445792 +0000 UTC m=+553.724396343 I0506 18:04:17.722252 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:17.722381 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-06 18:04:17.722372067 +0000 UTC m=+553.751322618 I0506 18:04:17.987644 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:04:18.020939 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-g6wk6" condition "Approved" to 2026-05-06 18:04:18.020927961 +0000 UTC m=+554.049878512 I0506 18:04:18.043148 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-g6wk6" condition "Ready" to 2026-05-06 18:04:18.043106664 +0000 UTC m=+554.072057205 I0506 18:04:18.074569 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:04:18.074553619 +0000 UTC m=+554.103504170 I0506 18:04:18.095805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:07:38.252625 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:07:38.252674 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-06 18:07:38.252667487 +0000 UTC m=+754.281618038 I0506 18:07:38.252896 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-06 18:07:38.252878548 +0000 UTC m=+754.281829099 I0506 18:07:38.276878 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:07:38.276956 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-06 18:07:38.276950068 +0000 UTC m=+754.305900609 I0506 18:07:38.416444 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:07:38.444873 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-g2ck7" condition "Approved" to 2026-05-06 18:07:38.444855732 +0000 UTC m=+754.473806303 I0506 18:07:38.464330 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-g2ck7" condition "Ready" to 2026-05-06 18:07:38.464316943 +0000 UTC m=+754.493267514 I0506 18:07:38.502718 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:07:38.502702831 +0000 UTC m=+754.531653382 I0506 18:07:38.526851 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:07:38.527978 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:07:38.527973298 +0000 UTC m=+754.556923839 I0506 18:07:38.552177 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:07:38.552475 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:07:38.552466941 +0000 UTC m=+754.581417492 I0506 18:08:20.540786 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:08:20.540858 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-06 18:08:20.54085054 +0000 UTC m=+796.569801091 I0506 18:08:20.541159 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-06 18:08:20.541145874 +0000 UTC m=+796.570096425 I0506 18:08:20.561456 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:08:20.561575 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0506 18:08:20.561606 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-06 18:08:20.561600029 +0000 UTC m=+796.590550580 I0506 18:08:20.789553 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-8wldl" condition "Approved" to 2026-05-06 18:08:20.789540474 +0000 UTC m=+796.818491025 I0506 18:08:20.809414 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-8wldl" condition "Ready" to 2026-05-06 18:08:20.80940314 +0000 UTC m=+796.838353691 I0506 18:08:20.852928 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:08:20.852911866 +0000 UTC m=+796.881862417 I0506 18:08:20.891997 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0506 18:08:20.892406 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-06 18:08:20.892397355 +0000 UTC m=+796.921347896 I0506 18:08:20.912825 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"