I0507 03:45:38.374471 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0507 03:45:38.374615 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0507 03:45:38.374706 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0507 03:45:38.379405 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0507 03:45:38.379856 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0507 03:45:38.379873 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0507 03:45:38.379928 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0507 03:45:38.381952 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0507 03:45:38.398778 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0507 03:45:38.402846 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0507 03:45:38.409551 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0507 03:45:38.412365 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0507 03:45:38.415772 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0507 03:45:38.418241 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0507 03:45:38.418269 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0507 03:45:38.418348 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0507 03:45:38.420934 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0507 03:45:38.423251 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0507 03:45:38.428184 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0507 03:45:38.433048 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0507 03:45:38.434816 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0507 03:45:38.436442 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0507 03:45:38.436460 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0507 03:45:38.436506 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0507 03:45:38.438352 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0507 03:45:38.440064 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0507 03:45:38.441772 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0507 03:45:38.443398 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0507 03:45:38.443533 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0507 03:45:38.445463 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0507 03:45:38.451957 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0507 03:45:38.452125 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0507 03:45:38.456947 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0507 03:45:38.462429 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.462728 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.463118 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.479748 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.499821 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.509292 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.529646 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.547867 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.551372 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:38.561265 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0507 03:45:55.026121 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-07 03:45:55.026080389 +0000 UTC m=+16.682614994 I0507 03:45:55.681288 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 03:45:55.681337 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-07 03:45:55.681326144 +0000 UTC m=+17.337860759 I0507 03:45:55.682473 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-07 03:45:55.68246386 +0000 UTC m=+17.338998465 I0507 03:45:55.702396 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:45:55.702517 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-07 03:45:55.702506331 +0000 UTC m=+17.359040946 E0507 03:45:55.702673 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0507 03:45:55.702738 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-07 03:45:55.702731936 +0000 UTC m=+17.359266521 E0507 03:45:55.702763 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 03:45:55.720281 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0507 03:45:55.720318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" E0507 03:45:55.720382 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 03:45:55.720418 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0507 03:45:55.720443 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0507 03:45:55.722252 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:45:55.722298 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-07 03:45:55.722292577 +0000 UTC m=+17.378827142 I0507 03:45:55.730190 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-92nq7" condition "Approved" to 2026-05-07 03:45:55.730182854 +0000 UTC m=+17.386717429 I0507 03:45:55.741139 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-92nq7" condition "Ready" to 2026-05-07 03:45:55.74112774 +0000 UTC m=+17.397662325 I0507 03:45:55.764102 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 03:45:55.764091697 +0000 UTC m=+17.420626282 I0507 03:45:55.779804 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:45:55.825302 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:46:00.720871 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 03:46:00.720853388 +0000 UTC m=+22.377387993 I0507 03:46:22.413030 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-07 03:46:22.412997123 +0000 UTC m=+44.069531698 I0507 03:46:22.413336 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 03:46:22.413360 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-07 03:46:22.41335224 +0000 UTC m=+44.069886815 I0507 03:46:22.429746 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-07 03:46:22.42973608 +0000 UTC m=+44.086270665 I0507 03:46:22.437755 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:46:22.437805 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 03:46:22.437819 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-07 03:46:22.437813991 +0000 UTC m=+44.094348576 I0507 03:46:22.738618 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:46:22.749300 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-cstt6" condition "Approved" to 2026-05-07 03:46:22.749290591 +0000 UTC m=+44.405825166 I0507 03:46:22.787813 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-cstt6" condition "Ready" to 2026-05-07 03:46:22.787801344 +0000 UTC m=+44.444335929 I0507 03:46:22.824417 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 03:46:22.82440523 +0000 UTC m=+44.480939805 I0507 03:46:22.860400 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:46:22.860713 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 03:46:22.860705179 +0000 UTC m=+44.517239754 I0507 03:46:22.873293 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:46:22.883150 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:50:24.216539 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 03:50:24.216549 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Ready" to 2026-05-07 03:50:24.216520439 +0000 UTC m=+285.873055044 I0507 03:50:24.216575 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Issuing" to 2026-05-07 03:50:24.216567231 +0000 UTC m=+285.873101816 I0507 03:50:24.233055 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:50:24.233170 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-140.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0507 03:50:24.233207 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Issuing" to 2026-05-07 03:50:24.233199429 +0000 UTC m=+285.889734014 I0507 03:50:24.525933 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0507 03:50:24.535798 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-140.nip.io-tls-x69k7" condition "Approved" to 2026-05-07 03:50:24.535787614 +0000 UTC m=+286.192322199 I0507 03:50:24.556487 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-140.nip.io-tls-x69k7" condition "Ready" to 2026-05-07 03:50:24.5564781 +0000 UTC m=+286.213012685 I0507 03:50:24.582980 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-140.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-07 03:50:24.582968212 +0000 UTC m=+286.239502807 I0507 03:50:24.605138 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-140.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-140.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again"