I0420 02:05:59.022728 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0420 02:05:59.022867 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0420 02:05:59.022960 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0420 02:05:59.027555 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0420 02:05:59.027918 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0420 02:05:59.028084 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0420 02:05:59.028117 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0420 02:05:59.030267 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0420 02:05:59.045246 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0420 02:05:59.052554 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0420 02:05:59.052648 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0420 02:05:59.056337 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0420 02:05:59.059821 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0420 02:05:59.063059 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0420 02:05:59.064775 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0420 02:05:59.066595 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0420 02:05:59.069019 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0420 02:05:59.074455 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0420 02:05:59.074526 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0420 02:05:59.074528 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0420 02:05:59.074586 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0420 02:05:59.077138 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0420 02:05:59.079408 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0420 02:05:59.081817 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0420 02:05:59.083766 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0420 02:05:59.085539 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0420 02:05:59.087167 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0420 02:05:59.087337 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0420 02:05:59.089095 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0420 02:05:59.094408 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0420 02:05:59.097918 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0420 02:05:59.101852 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0420 02:05:59.102273 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0420 02:05:59.104808 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.105549 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.105953 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.106107 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.123640 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.141121 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.158475 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.179864 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.191081 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:05:59.196091 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0420 02:06:10.836581 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-20 02:06:10.836558917 +0000 UTC m=+11.846738972 I0420 02:06:11.543384 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:11.543449 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 02:06:11.543441375 +0000 UTC m=+12.553621410 I0420 02:06:11.544743 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-20 02:06:11.544730827 +0000 UTC m=+12.554910862 I0420 02:06:11.560374 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:11.560496 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" E0420 02:06:11.560447 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 02:06:11.560698 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-20 02:06:11.560684192 +0000 UTC m=+12.570864257 I0420 02:06:11.560591 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-20 02:06:11.560580679 +0000 UTC m=+12.570760744 E0420 02:06:11.560769 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:06:11.572392 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0420 02:06:11.572492 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:06:11.572522 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:06:11.572565 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0420 02:06:11.601697 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:11.602249 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rfs8m" condition "Approved" to 2026-04-20 02:06:11.602234185 +0000 UTC m=+12.612414210 I0420 02:06:11.612283 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-rfs8m" condition "Ready" to 2026-04-20 02:06:11.612276169 +0000 UTC m=+12.622456204 I0420 02:06:11.635745 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:11.635722767 +0000 UTC m=+12.645902832 I0420 02:06:11.658407 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:11.658881 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:11.658869775 +0000 UTC m=+12.669049840 I0420 02:06:11.675271 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:11.675689 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:11.675675668 +0000 UTC m=+12.685855723 I0420 02:06:16.573069 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:16.573055734 +0000 UTC m=+17.583235799 I0420 02:06:38.608155 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-20 02:06:38.608134292 +0000 UTC m=+39.618314357 I0420 02:06:38.608393 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.608477 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 02:06:38.608465502 +0000 UTC m=+39.618645537 I0420 02:06:38.616747 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-20 02:06:38.616735398 +0000 UTC m=+39.626915423 I0420 02:06:38.633499 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.633589 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:06:38.633622 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-20 02:06:38.633613861 +0000 UTC m=+39.643793906 I0420 02:06:38.815970 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.819812 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-864dv" condition "Approved" to 2026-04-20 02:06:38.819804473 +0000 UTC m=+39.829984498 I0420 02:06:38.844662 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-864dv" condition "Ready" to 2026-04-20 02:06:38.844650721 +0000 UTC m=+39.854830756 I0420 02:06:38.875743 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:38.87573054 +0000 UTC m=+39.885910575 I0420 02:06:38.893133 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.893670 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:06:38.893658426 +0000 UTC m=+39.903838491 I0420 02:06:38.903295 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:06:38.909971 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:25.842116 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:08:25.842124 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-04-20 02:08:25.842076702 +0000 UTC m=+146.852256767 I0420 02:08:25.842175 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-20 02:08:25.842164065 +0000 UTC m=+146.852344100 E0420 02:08:25.856705 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 02:08:25.856776 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-04-20 02:08:25.856766932 +0000 UTC m=+146.866946967 I0420 02:08:25.856821 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 02:08:25.859436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:25.859523 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:08:25.859554 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-04-20 02:08:25.859545041 +0000 UTC m=+146.869725096 E0420 02:08:25.867195 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0420 02:08:25.867532 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0420 02:08:25.867647 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0420 02:08:25.867768 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0420 02:08:25.874691 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-20 02:08:25.874674824 +0000 UTC m=+146.884854879 I0420 02:08:25.874733 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:08:25.874766 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-04-20 02:08:25.874756177 +0000 UTC m=+146.884936212 I0420 02:08:25.889414 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:25.889563 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-04-20 02:08:25.889483408 +0000 UTC m=+146.899663433 I0420 02:08:26.036400 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-qktmh" condition "Approved" to 2026-04-20 02:08:26.036379045 +0000 UTC m=+147.046559100 I0420 02:08:26.070423 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-qktmh" condition "Ready" to 2026-04-20 02:08:26.070407203 +0000 UTC m=+147.080587298 I0420 02:08:26.098646 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:08:26.098629726 +0000 UTC m=+147.108809791 I0420 02:08:26.112131 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:26.112847 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:08:26.11283528 +0000 UTC m=+147.123015335 I0420 02:08:26.130282 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:26.134031 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:26.208026 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:08:26.240113 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-rq24g" condition "Approved" to 2026-04-20 02:08:26.24009503 +0000 UTC m=+147.250275085 I0420 02:08:26.258539 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-rq24g" condition "Ready" to 2026-04-20 02:08:26.258528499 +0000 UTC m=+147.268708554 I0420 02:08:30.868142 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:08:30.868126693 +0000 UTC m=+151.878306758 I0420 02:08:30.885876 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-rq24g" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:08:30.88586422 +0000 UTC m=+151.896044245 I0420 02:08:30.920352 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:08:30.920327472 +0000 UTC m=+151.930507547 I0420 02:08:30.942582 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:11:03.489711 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-35.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:11:03.489833 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-35.nip.io-tls" condition "Ready" to 2026-04-20 02:11:03.489814044 +0000 UTC m=+304.499994069 I0420 02:11:03.489785 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-35.nip.io-tls" condition "Issuing" to 2026-04-20 02:11:03.489743661 +0000 UTC m=+304.499923686 I0420 02:11:03.510899 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-35.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-35.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:11:03.510962 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-35.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:11:03.511007 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-35.nip.io-tls" condition "Issuing" to 2026-04-20 02:11:03.511000858 +0000 UTC m=+304.521180883 I0420 02:11:03.675328 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-35.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-35.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:11:03.685351 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-35.nip.io-tls-9hb52" condition "Approved" to 2026-04-20 02:11:03.685337043 +0000 UTC m=+304.695517098 I0420 02:11:03.707895 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-35.nip.io-tls-9hb52" condition "Ready" to 2026-04-20 02:11:03.70788113 +0000 UTC m=+304.718061165 I0420 02:11:03.746601 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-35.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:11:03.746585211 +0000 UTC m=+304.756765266 I0420 02:11:03.788478 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-35.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-35.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:11:03.788930 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-35.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:11:03.788918958 +0000 UTC m=+304.799099023 I0420 02:11:03.846702 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-35.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-35.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:14.022960 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:14.023009 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 02:12:14.022996381 +0000 UTC m=+375.033176436 I0420 02:12:14.023108 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-20 02:12:14.023081454 +0000 UTC m=+375.033261489 E0420 02:12:14.038657 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 02:12:14.038752 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-20 02:12:14.038741481 +0000 UTC m=+375.048921516 E0420 02:12:14.038972 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0420 02:12:14.039915 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:14.040051 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:14.040077 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-20 02:12:14.040071723 +0000 UTC m=+375.050251758 E0420 02:12:14.048508 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0420 02:12:14.048794 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:12:14.048869 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0420 02:12:14.049024 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0420 02:12:14.075201 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-ksrjf" condition "Approved" to 2026-04-20 02:12:14.075180638 +0000 UTC m=+375.085360673 I0420 02:12:14.088472 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-ksrjf" condition "Ready" to 2026-04-20 02:12:14.088446099 +0000 UTC m=+375.098626164 I0420 02:12:14.110822 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:14.110811849 +0000 UTC m=+375.120991884 I0420 02:12:14.129406 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:19.050844 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:19.049939358 +0000 UTC m=+380.060119413 I0420 02:12:58.203046 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 02:12:58.203020568 +0000 UTC m=+419.213200633 I0420 02:12:58.203194 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:58.203221 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-20 02:12:58.203215454 +0000 UTC m=+419.213395479 I0420 02:12:58.209921 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:58.209956 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-20 02:12:58.209946528 +0000 UTC m=+419.220126563 I0420 02:12:58.210313 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 02:12:58.21030461 +0000 UTC m=+419.220484665 I0420 02:12:58.219190 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-20 02:12:58.219179242 +0000 UTC m=+419.229359277 I0420 02:12:58.220214 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:58.220250 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 02:12:58.220242705 +0000 UTC m=+419.230422730 I0420 02:12:58.246168 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.246370 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.246390 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.246456 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-20 02:12:58.246445217 +0000 UTC m=+419.256625262 I0420 02:12:58.246527 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-20 02:12:58.24651573 +0000 UTC m=+419.256695765 I0420 02:12:58.246770 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:12:58.247018 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-20 02:12:58.247009325 +0000 UTC m=+419.257189360 I0420 02:12:58.386464 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.416124 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-b7lhn" condition "Approved" to 2026-04-20 02:12:58.416097344 +0000 UTC m=+419.426277409 I0420 02:12:58.433280 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-b7lhn" condition "Ready" to 2026-04-20 02:12:58.433263879 +0000 UTC m=+419.443443914 I0420 02:12:58.459774 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:58.459761591 +0000 UTC m=+419.469941626 I0420 02:12:58.467882 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.490312 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.511299 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-z6rtk" condition "Approved" to 2026-04-20 02:12:58.511284027 +0000 UTC m=+419.521464052 I0420 02:12:58.523779 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:58.531447 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-z6rtk" condition "Ready" to 2026-04-20 02:12:58.531435127 +0000 UTC m=+419.541615152 I0420 02:12:58.532999 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-8bjd7" condition "Approved" to 2026-04-20 02:12:58.532989566 +0000 UTC m=+419.543169601 I0420 02:12:58.752239 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-8bjd7" condition "Ready" to 2026-04-20 02:12:58.752219787 +0000 UTC m=+419.762399842 I0420 02:12:59.098088 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:59.098075209 +0000 UTC m=+420.108255234 I0420 02:12:59.299718 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:59.352817 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:59.352801347 +0000 UTC m=+420.362981412 I0420 02:12:59.398504 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:59.494345 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:59.494332832 +0000 UTC m=+420.504512857 I0420 02:12:59.545013 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:59.694568 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:12:59.695211 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:12:59.69519981 +0000 UTC m=+420.705379865 I0420 02:13:00.091378 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:00.143516 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:00.295318 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:06.676174 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" condition "Ready" to 2026-04-20 02:13:06.676150844 +0000 UTC m=+427.686330899 I0420 02:13:06.676408 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:13:06.676464 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" condition "Issuing" to 2026-04-20 02:13:06.676451294 +0000 UTC m=+427.686631329 I0420 02:13:06.692771 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:06.692867 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:13:06.692895 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" condition "Issuing" to 2026-04-20 02:13:06.692886986 +0000 UTC m=+427.703067021 I0420 02:13:06.844556 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:06.851969 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-n9fdw-p6ngp" condition "Approved" to 2026-04-20 02:13:06.851943706 +0000 UTC m=+427.862123761 I0420 02:13:06.868272 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-n9fdw-p6ngp" condition "Ready" to 2026-04-20 02:13:06.868259045 +0000 UTC m=+427.878439080 I0420 02:13:06.895629 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:13:06.895597912 +0000 UTC m=+427.905777937 I0420 02:13:06.915899 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:06.916142 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:13:06.916132524 +0000 UTC m=+427.926312559 I0420 02:13:06.928189 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:06.940700 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-n9fdw-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:33.926041 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 02:13:33.926013532 +0000 UTC m=+454.936193587 I0420 02:13:33.926189 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:13:33.926231 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-20 02:13:33.926221619 +0000 UTC m=+454.936401684 I0420 02:13:33.950122 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:33.950255 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-20 02:13:33.950240461 +0000 UTC m=+454.960420526 I0420 02:13:34.136729 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:34.166248 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-ghc79" condition "Approved" to 2026-04-20 02:13:34.16623451 +0000 UTC m=+455.176414545 I0420 02:13:34.184854 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-ghc79" condition "Ready" to 2026-04-20 02:13:34.184841171 +0000 UTC m=+455.195021196 I0420 02:13:34.213932 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:13:34.213915984 +0000 UTC m=+455.224096019 I0420 02:13:34.232674 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:34.233198 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:13:34.233184406 +0000 UTC m=+455.243364441 I0420 02:13:34.242026 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:34.252271 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:13:34.253025 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:13:34.252997645 +0000 UTC m=+455.263177680 I0420 02:13:34.255487 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:16:59.709925 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:16:59.710024 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 02:16:59.709987204 +0000 UTC m=+660.720167259 I0420 02:16:59.710040 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-20 02:16:59.710005244 +0000 UTC m=+660.720185309 I0420 02:16:59.728182 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:16:59.728278 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:16:59.728317 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-20 02:16:59.728310815 +0000 UTC m=+660.738490840 I0420 02:16:59.880077 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-dlqtd" condition "Approved" to 2026-04-20 02:16:59.880050181 +0000 UTC m=+660.890230246 I0420 02:16:59.900708 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-dlqtd" condition "Ready" to 2026-04-20 02:16:59.900692196 +0000 UTC m=+660.910872251 I0420 02:16:59.937338 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:16:59.937306608 +0000 UTC m=+660.947486643 I0420 02:16:59.965123 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:16:59.965342 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:16:59.965337148 +0000 UTC m=+660.975517173 I0420 02:16:59.985930 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:19:24.821826 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-04-20 02:19:24.82177329 +0000 UTC m=+805.831953355 I0420 02:19:24.821932 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/barbican-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:19:24.821998 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Issuing" to 2026-04-20 02:19:24.821991097 +0000 UTC m=+805.832171132 I0420 02:19:24.843445 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:19:24.843572 1 conditions.go:203] Setting lastTransitionTime for Certificate "barbican-api-certs" condition "Ready" to 2026-04-20 02:19:24.843560221 +0000 UTC m=+805.853740276 I0420 02:19:25.072194 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:19:25.101551 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-dc7xk" condition "Approved" to 2026-04-20 02:19:25.101536903 +0000 UTC m=+806.111716938 I0420 02:19:25.121349 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "barbican-api-certs-dc7xk" condition "Ready" to 2026-04-20 02:19:25.121332691 +0000 UTC m=+806.131512716 I0420 02:19:25.145737 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:19:25.145725535 +0000 UTC m=+806.155905560 I0420 02:19:25.174101 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:19:25.174466 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:19:25.174458196 +0000 UTC m=+806.184638221 I0420 02:19:25.194395 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/barbican-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"barbican-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:19:25.194778 1 conditions.go:192] Found status change for Certificate "barbican-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:19:25.19476671 +0000 UTC m=+806.204946745 I0420 02:20:31.967575 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:20:31.967643 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-04-20 02:20:31.967634864 +0000 UTC m=+872.977814919 I0420 02:20:31.967574 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready" to 2026-04-20 02:20:31.967538321 +0000 UTC m=+872.977718376 I0420 02:20:31.991307 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:20:31.991504 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rook-ceph-rgw-ceph-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:20:31.991699 1 conditions.go:203] Setting lastTransitionTime for Certificate "rook-ceph-rgw-ceph-certs" condition "Issuing" to 2026-04-20 02:20:31.991530102 +0000 UTC m=+873.001710167 I0420 02:20:32.704461 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-5ghlh" condition "Approved" to 2026-04-20 02:20:32.704437203 +0000 UTC m=+873.714617228 I0420 02:20:32.729199 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rook-ceph-rgw-ceph-certs-5ghlh" condition "Ready" to 2026-04-20 02:20:32.729187528 +0000 UTC m=+873.739367563 I0420 02:20:32.776282 1 conditions.go:192] Found status change for Certificate "rook-ceph-rgw-ceph-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:20:32.776266991 +0000 UTC m=+873.786447016 I0420 02:20:32.805093 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rook-ceph-rgw-ceph-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rook-ceph-rgw-ceph-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:23:31.406516 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Ready" to 2026-04-20 02:23:31.406468883 +0000 UTC m=+1052.416648938 I0420 02:23:31.406721 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:23:31.406856 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-04-20 02:23:31.406807633 +0000 UTC m=+1052.416987698 I0420 02:23:31.423853 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:23:31.423976 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/glance-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0420 02:23:31.424010 1 conditions.go:203] Setting lastTransitionTime for Certificate "glance-api-certs" condition "Issuing" to 2026-04-20 02:23:31.424001509 +0000 UTC m=+1052.434181574 I0420 02:23:31.586306 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-hzws6" condition "Approved" to 2026-04-20 02:23:31.586293037 +0000 UTC m=+1052.596473072 I0420 02:23:31.609207 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "glance-api-certs-hzws6" condition "Ready" to 2026-04-20 02:23:31.609175342 +0000 UTC m=+1052.619355397 I0420 02:23:31.639194 1 conditions.go:192] Found status change for Certificate "glance-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-20 02:23:31.639180264 +0000 UTC m=+1052.649360289 I0420 02:23:31.657459 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0420 02:23:31.708982 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/glance-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"glance-api-certs\": the object has been modified; please apply your changes to the latest version and try again"