I0505 23:12:34.493143 1 start.go:75] "cert-manager: starting controller" version="v1.12.10" git-commit="4131d77fe377e78a6fa562af6bdbd31532ddb1ad" I0505 23:12:34.493455 1 controller.go:262] "cert-manager/controller/build-context: configured acme dns01 nameservers" nameservers=["10.96.0.10:53"] W0505 23:12:34.493697 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0505 23:12:34.496952 1 controller.go:82] "cert-manager/controller: enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0505 23:12:34.497274 1 controller.go:156] "cert-manager/controller: starting leader election" I0505 23:12:34.497361 1 controller.go:103] "cert-manager/controller: starting metrics server" address="[::]:9402" I0505 23:12:34.497482 1 controller.go:149] "cert-manager/controller: starting healthz server" address="[::]:9403" I0505 23:12:34.504114 1 leaderelection.go:245] attempting to acquire leader lease cert-manager/cert-manager-controller... E0505 23:13:04.505155 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout E0505 23:13:58.858268 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout E0505 23:14:53.926109 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout E0505 23:15:43.577731 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout E0505 23:16:41.978039 1 leaderelection.go:327] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": dial tcp 10.96.0.1:443: i/o timeout I0505 23:17:02.415483 1 leaderelection.go:255] successfully acquired lease cert-manager/cert-manager-controller I0505 23:17:02.420105 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-readiness" I0505 23:17:02.423947 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-acme" I0505 23:17:02.426615 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-selfsigned" I0505 23:17:02.426652 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-vault" I0505 23:17:02.429374 1 controller.go:226] "cert-manager/controller: starting controller" controller="clusterissuers" I0505 23:17:02.432218 1 controller.go:226] "cert-manager/controller: starting controller" controller="issuers" I0505 23:17:02.434763 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-key-manager" I0505 23:17:02.439821 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-trigger" I0505 23:17:02.442724 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-acme" I0505 23:17:02.442749 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-vault" I0505 23:17:02.442858 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-venafi" I0505 23:17:02.445410 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-issuing" I0505 23:17:02.447831 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-metrics" I0505 23:17:02.449567 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-request-manager" I0505 23:17:02.451547 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificates-revision-manager" I0505 23:17:02.453199 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-ca" I0505 23:17:02.453216 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="certificatesigningrequests-issuer-venafi" I0505 23:17:02.453342 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-ca" I0505 23:17:02.455237 1 controller.go:203] "cert-manager/controller: not starting controller as it's disabled" controller="gateway-shim" I0505 23:17:02.455329 1 controller.go:226] "cert-manager/controller: starting controller" controller="challenges" I0505 23:17:02.457259 1 controller.go:226] "cert-manager/controller: starting controller" controller="ingress-shim" I0505 23:17:02.459104 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-approver" I0505 23:17:02.462290 1 controller.go:226] "cert-manager/controller: starting controller" controller="orders" I0505 23:17:02.466362 1 controller.go:226] "cert-manager/controller: starting controller" controller="certificaterequests-issuer-selfsigned" I0505 23:21:04.199873 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 23:21:04.199850 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Ready" to 2026-05-05 23:21:04.199795026 +0000 UTC m=+509.777880523 I0505 23:21:04.199998 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-05-05 23:21:04.19998517 +0000 UTC m=+509.778070717 I0505 23:21:04.214754 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:04.214867 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/manila-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 23:21:04.214893 1 conditions.go:203] Setting lastTransitionTime for Certificate "manila-api-certs" condition "Issuing" to 2026-05-05 23:21:04.214885813 +0000 UTC m=+509.792971310 I0505 23:21:04.405882 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-62zz2" condition "Approved" to 2026-05-05 23:21:04.405869313 +0000 UTC m=+509.983954820 I0505 23:21:04.424046 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "manila-api-certs-62zz2" condition "Ready" to 2026-05-05 23:21:04.423986169 +0000 UTC m=+510.002071666 I0505 23:21:04.457448 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 23:21:04.457439959 +0000 UTC m=+510.035525446 I0505 23:21:04.489429 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:04.490328 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 23:21:04.490316735 +0000 UTC m=+510.068402252 I0505 23:21:04.507231 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:04.507827 1 controller.go:162] "cert-manager/certificates-readiness: re-queuing item due to optimistic locking on resource" key="openstack/manila-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"manila-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:04.508709 1 conditions.go:192] Found status change for Certificate "manila-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 23:21:04.508695106 +0000 UTC m=+510.086780633 I0505 23:21:39.886961 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-05 23:21:39.8869401 +0000 UTC m=+545.465025597 I0505 23:21:39.887054 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 23:21:39.887095 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 23:21:39.887088183 +0000 UTC m=+545.465173680 I0505 23:21:39.903330 1 controller.go:162] "cert-manager/certificates-trigger: re-queuing item due to optimistic locking on resource" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:39.903395 1 trigger_controller.go:194] "cert-manager/certificates-trigger: Certificate must be re-issued" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0505 23:21:39.903409 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-05 23:21:39.903402139 +0000 UTC m=+545.481487636 I0505 23:21:40.037451 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:40.046187 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-l2fxc" condition "Approved" to 2026-05-05 23:21:40.046174398 +0000 UTC m=+545.624259895 I0505 23:21:40.066911 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-l2fxc" condition "Ready" to 2026-05-05 23:21:40.066896992 +0000 UTC m=+545.644982499 I0505 23:21:40.101691 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-05 23:21:40.101674652 +0000 UTC m=+545.679760149 I0505 23:21:40.123429 1 controller.go:162] "cert-manager/certificates-issuing: re-queuing item due to optimistic locking on resource" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0505 23:21:40.185032 1 controller.go:162] "cert-manager/certificates-key-manager: re-queuing item due to optimistic locking on resource" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"