I0417 00:27:13.807324 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0417 00:27:13.807488 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0417 00:27:13.807665 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0417 00:27:13.811738 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0417 00:27:13.812200 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0417 00:27:13.812276 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0417 00:27:13.812241 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0417 00:27:13.815437 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0417 00:27:13.832516 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0417 00:27:13.837464 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0417 00:27:13.837499 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0417 00:27:13.838027 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0417 00:27:13.845431 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0417 00:27:13.848600 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0417 00:27:13.850464 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0417 00:27:13.852670 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0417 00:27:13.854944 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0417 00:27:13.854977 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0417 00:27:13.855035 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0417 00:27:13.857465 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0417 00:27:13.858271 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0417 00:27:13.863643 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0417 00:27:13.868378 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0417 00:27:13.870536 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0417 00:27:13.871849 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0417 00:27:13.873882 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0417 00:27:13.878426 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0417 00:27:13.881335 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0417 00:27:13.883559 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0417 00:27:13.887326 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0417 00:27:13.891069 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0417 00:27:13.893881 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0417 00:27:13.894227 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0417 00:27:13.896221 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.897457 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.898192 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.919199 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.930770 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.942563 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.957709 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.977046 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.983043 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:13.990656 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0417 00:27:31.128537 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-17 00:27:31.128515515 +0000 UTC m=+17.350299071 I0417 00:27:31.810979 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-17 00:27:31.810964355 +0000 UTC m=+18.032747921 I0417 00:27:31.812080 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:27:31.812140 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-17 00:27:31.812133041 +0000 UTC m=+18.033916597 E0417 00:27:31.824142 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0417 00:27:31.824187 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-17 00:27:31.824182665 +0000 UTC m=+18.045966201 E0417 00:27:31.824205 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0417 00:27:31.831243 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" E0417 00:27:31.831465 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0417 00:27:31.831536 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:27:31.831553 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-17 00:27:31.831549238 +0000 UTC m=+18.053332774 E0417 00:27:31.831617 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:27:31.831740 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0417 00:27:31.831783 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0417 00:27:31.873230 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:31.880116 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-sjjhh" condition "Approved" to 2026-04-17 00:27:31.880104061 +0000 UTC m=+18.101887627 I0417 00:27:31.892532 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-sjjhh" condition "Ready" to 2026-04-17 00:27:31.892525317 +0000 UTC m=+18.114308853 I0417 00:27:31.912585 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:31.912576449 +0000 UTC m=+18.134359985 I0417 00:27:31.926137 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:31.927215 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:31.927201626 +0000 UTC m=+18.148985192 I0417 00:27:31.943594 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:31.944030 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:31.943985243 +0000 UTC m=+18.165768789 I0417 00:27:36.832258 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:36.832235461 +0000 UTC m=+23.054019027 I0417 00:27:59.042300 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:27:59.042349 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-17 00:27:59.042335104 +0000 UTC m=+45.264118640 I0417 00:27:59.042780 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-17 00:27:59.042759196 +0000 UTC m=+45.264542722 I0417 00:27:59.055287 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-17 00:27:59.055269242 +0000 UTC m=+45.277052778 I0417 00:27:59.070135 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:59.070265 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-17 00:27:59.070252498 +0000 UTC m=+45.292036034 I0417 00:27:59.323234 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:59.358419 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-zswww" condition "Approved" to 2026-04-17 00:27:59.358407816 +0000 UTC m=+45.580191352 I0417 00:27:59.396145 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-zswww" condition "Ready" to 2026-04-17 00:27:59.396135053 +0000 UTC m=+45.617918579 I0417 00:27:59.432566 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:59.432549184 +0000 UTC m=+45.654332720 I0417 00:27:59.451829 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:27:59.452789 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:27:59.452780875 +0000 UTC m=+45.674564401 I0417 00:27:59.477000 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:00.840918 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-157.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0417 00:32:00.840953 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Issuing" to 2026-04-17 00:32:00.840940617 +0000 UTC m=+287.062724143 I0417 00:32:00.841261 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Ready" to 2026-04-17 00:32:00.841243678 +0000 UTC m=+287.063027244 I0417 00:32:00.857213 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-157.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-157.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:00.857283 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Ready" to 2026-04-17 00:32:00.857275808 +0000 UTC m=+287.079059344 I0417 00:32:01.077697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-157.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-157.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:01.137135 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-157.nip.io-tls-dj5m7" condition "Approved" to 2026-04-17 00:32:01.137126542 +0000 UTC m=+287.358910068 I0417 00:32:01.181215 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-157.nip.io-tls-dj5m7" condition "Ready" to 2026-04-17 00:32:01.181207593 +0000 UTC m=+287.402991119 I0417 00:32:01.204836 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:32:01.204823356 +0000 UTC m=+287.426606892 I0417 00:32:01.234751 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-157.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-157.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:01.235351 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:32:01.235341419 +0000 UTC m=+287.457124975 I0417 00:32:01.240196 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-157.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-157.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:01.250820 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-157.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-157.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0417 00:32:01.251109 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-157.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-17 00:32:01.251101476 +0000 UTC m=+287.472885002