I0529 21:54:14.984389 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0529 21:54:14.984655 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0529 21:54:14.984802 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0529 21:54:14.990271 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0529 21:54:14.991570 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0529 21:54:14.991769 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0529 21:54:14.992189 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0529 21:54:14.997839 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0529 21:54:15.015447 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0529 21:54:15.020411 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0529 21:54:15.024449 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0529 21:54:15.026541 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0529 21:54:15.031070 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0529 21:54:15.033475 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0529 21:54:15.033562 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0529 21:54:15.033634 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0529 21:54:15.035622 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0529 21:54:15.037311 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0529 21:54:15.037415 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0529 21:54:15.039345 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0529 21:54:15.041189 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0529 21:54:15.043920 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0529 21:54:15.046634 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0529 21:54:15.055478 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0529 21:54:15.055526 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0529 21:54:15.055626 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0529 21:54:15.058074 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0529 21:54:15.062259 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0529 21:54:15.066316 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0529 21:54:15.070239 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0529 21:54:15.070386 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0529 21:54:15.074625 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0529 21:54:15.077370 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0529 21:54:15.080339 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.081392 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.081418 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.082033 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.101604 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.120197 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.138630 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.155720 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.172480 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:15.176728 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0529 21:54:25.353631 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-29 21:54:25.353619271 +0000 UTC m=+10.412761105 I0529 21:54:26.011451 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-29 21:54:26.011440433 +0000 UTC m=+11.070582277 I0529 21:54:26.012109 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 21:54:26.012136 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-29 21:54:26.012130128 +0000 UTC m=+11.071272002 E0529 21:54:26.027727 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0529 21:54:26.027773 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-29 21:54:26.027768217 +0000 UTC m=+11.086910061 E0529 21:54:26.027800 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0529 21:54:26.030967 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:26.031128 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-29 21:54:26.031024009 +0000 UTC m=+11.090165853 E0529 21:54:26.039973 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0529 21:54:26.040050 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0529 21:54:26.040075 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0529 21:54:26.040100 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0529 21:54:26.045518 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:26.045547 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-29 21:54:26.045543024 +0000 UTC m=+11.104684858 I0529 21:54:26.052832 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:26.058831 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-v9f2w" condition "Approved" to 2026-05-29 21:54:26.058821233 +0000 UTC m=+11.117963107 I0529 21:54:26.059893 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-29 21:54:26.059886525 +0000 UTC m=+11.119028389 I0529 21:54:26.069509 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:26.073005 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-v9f2w" condition "Ready" to 2026-05-29 21:54:26.072995541 +0000 UTC m=+11.132137365 I0529 21:54:26.092404 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:54:26.092394811 +0000 UTC m=+11.151536645 I0529 21:54:26.106490 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:31.040527 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:54:31.040486099 +0000 UTC m=+16.099627973 I0529 21:54:56.459770 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 21:54:56.459801 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-29 21:54:56.459782044 +0000 UTC m=+41.518923928 I0529 21:54:56.459862 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-29 21:54:56.459852365 +0000 UTC m=+41.518994239 I0529 21:54:56.546014 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-29 21:54:56.545999041 +0000 UTC m=+41.605140905 I0529 21:54:56.549329 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:56.550170 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-29 21:54:56.550163711 +0000 UTC m=+41.609305535 I0529 21:54:57.279637 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:54:57.363467 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-48hdh" condition "Approved" to 2026-05-29 21:54:57.363453414 +0000 UTC m=+42.422595278 I0529 21:54:57.499919 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-48hdh" condition "Ready" to 2026-05-29 21:54:57.499907484 +0000 UTC m=+42.559049328 I0529 21:54:57.679647 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:54:57.679632788 +0000 UTC m=+42.738774632 I0529 21:54:57.729947 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.180338 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-65.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 21:59:06.180421 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Issuing" to 2026-05-29 21:59:06.180398889 +0000 UTC m=+291.239540763 I0529 21:59:06.181271 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready" to 2026-05-29 21:59:06.181263021 +0000 UTC m=+291.240404885 I0529 21:59:06.196810 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.196915 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready" to 2026-05-29 21:59:06.196908375 +0000 UTC m=+291.256050209 I0529 21:59:06.328427 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.354946 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-65.nip.io-tls-wh56l" condition "Approved" to 2026-05-29 21:59:06.354931955 +0000 UTC m=+291.414073829 I0529 21:59:06.383177 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-65.nip.io-tls-wh56l" condition "Ready" to 2026-05-29 21:59:06.383162992 +0000 UTC m=+291.442304836 I0529 21:59:06.409990 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:59:06.409981132 +0000 UTC m=+291.469122966 I0529 21:59:06.432982 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.433398 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:59:06.43339123 +0000 UTC m=+291.492533074 I0529 21:59:06.454764 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.455549 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-65.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-65.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 21:59:06.455807 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-65.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 21:59:06.455801283 +0000 UTC m=+291.514943127 I0529 22:00:10.624371 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-29 22:00:10.624320514 +0000 UTC m=+355.683462388 I0529 22:00:10.624461 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:00:10.624502 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-29 22:00:10.624491587 +0000 UTC m=+355.683633451 I0529 22:00:10.648691 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:00:10.648832 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-29 22:00:10.648823504 +0000 UTC m=+355.707965348 E0529 22:00:10.661215 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0529 22:00:10.661259 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-29 22:00:10.661251278 +0000 UTC m=+355.720393152 E0529 22:00:10.661310 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0529 22:00:10.688771 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0529 22:00:10.688779 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" E0529 22:00:10.689053 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0529 22:00:10.689183 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0529 22:00:10.689237 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0529 22:00:10.715132 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-pgk7s" condition "Approved" to 2026-05-29 22:00:10.715120561 +0000 UTC m=+355.774262405 I0529 22:00:10.754236 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-pgk7s" condition "Ready" to 2026-05-29 22:00:10.754218216 +0000 UTC m=+355.813360090 I0529 22:00:10.784637 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:00:10.784624891 +0000 UTC m=+355.843766735 I0529 22:00:10.801402 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:00:10.801736 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:00:10.801726043 +0000 UTC m=+355.860867887 I0529 22:00:10.818192 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:00:15.689889 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:00:15.68987886 +0000 UTC m=+360.749020704 I0529 22:01:00.204410 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-29 22:01:00.204376687 +0000 UTC m=+405.263518551 I0529 22:01:00.204490 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:00.205619 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-29 22:01:00.205608592 +0000 UTC m=+405.264750446 I0529 22:01:00.208036 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-29 22:01:00.208028943 +0000 UTC m=+405.267170787 I0529 22:01:00.208295 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:00.208317 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-29 22:01:00.208313309 +0000 UTC m=+405.267455143 I0529 22:01:00.219189 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-29 22:01:00.219174009 +0000 UTC m=+405.278315843 I0529 22:01:00.219964 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:00.220003 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-29 22:01:00.219995656 +0000 UTC m=+405.279137490 I0529 22:01:00.262006 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.262243 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.262304 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:00.262326 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-29 22:01:00.262321099 +0000 UTC m=+405.321462933 I0529 22:01:00.263103 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-29 22:01:00.263098146 +0000 UTC m=+405.322239980 I0529 22:01:00.274204 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.276325 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:00.276364 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-29 22:01:00.276357285 +0000 UTC m=+405.335499129 I0529 22:01:00.421963 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.428609 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.429059 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rnb95" condition "Approved" to 2026-05-29 22:01:00.429044957 +0000 UTC m=+405.488186801 I0529 22:01:00.438022 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-hdlf9" condition "Approved" to 2026-05-29 22:01:00.438008856 +0000 UTC m=+405.497150700 I0529 22:01:00.446667 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-rnb95" condition "Ready" to 2026-05-29 22:01:00.446657429 +0000 UTC m=+405.505799273 I0529 22:01:00.464490 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-hdlf9" condition "Ready" to 2026-05-29 22:01:00.464477066 +0000 UTC m=+405.523618910 I0529 22:01:00.513389 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.528124 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:00.528114888 +0000 UTC m=+405.587256722 I0529 22:01:00.528816 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:00.528811313 +0000 UTC m=+405.587953147 I0529 22:01:00.558518 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.558784 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:00.558778025 +0000 UTC m=+405.617919859 I0529 22:01:00.562827 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.563116 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:00.563109436 +0000 UTC m=+405.622251260 I0529 22:01:00.839715 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:00.944753 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:01.355432 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-c9xpq" condition "Approved" to 2026-05-29 22:01:01.355420845 +0000 UTC m=+406.414562689 I0529 22:01:01.569411 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-c9xpq" condition "Ready" to 2026-05-29 22:01:01.569400704 +0000 UTC m=+406.628542548 I0529 22:01:01.990191 1 issuing_controller.go:324] "next private key does not match CSR public key, waiting for requestmanager controller" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" resource_name="alertmanager-tls" resource_namespace="monitoring" resource_kind="Certificate" resource_version="v1" resource_name="alertmanager-tls-c9xpq" resource_namespace="monitoring" resource_kind="CertificateRequest" resource_version="v1" resource_name="alertmanager-tls-qqpf8" resource_namespace="monitoring" resource_kind="Secret" resource_version="v1" I0529 22:01:02.161665 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-jzrpz" condition "Approved" to 2026-05-29 22:01:02.161647209 +0000 UTC m=+407.220789073 I0529 22:01:02.452061 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-jzrpz" condition "Ready" to 2026-05-29 22:01:02.452053061 +0000 UTC m=+407.511194895 I0529 22:01:02.695421 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:02.695406632 +0000 UTC m=+407.754548476 I0529 22:01:02.956963 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:03.091625 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:09.520273 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" condition "Ready" to 2026-05-29 22:01:09.520254423 +0000 UTC m=+414.579396297 I0529 22:01:09.520552 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:09.520610 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" condition "Issuing" to 2026-05-29 22:01:09.52059598 +0000 UTC m=+414.579737854 I0529 22:01:09.534674 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:09.534752 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:09.534772 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" condition "Issuing" to 2026-05-29 22:01:09.534767256 +0000 UTC m=+414.593909090 I0529 22:01:09.681573 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-x4nkn-msjxn" condition "Approved" to 2026-05-29 22:01:09.681553647 +0000 UTC m=+414.740695511 I0529 22:01:09.705326 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-x4nkn-msjxn" condition "Ready" to 2026-05-29 22:01:09.705315472 +0000 UTC m=+414.764457296 I0529 22:01:09.775040 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:09.775023055 +0000 UTC m=+414.834164919 I0529 22:01:09.853231 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:09.853616 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:09.853606064 +0000 UTC m=+414.912747908 I0529 22:01:09.885132 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-x4nkn-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:25.416633 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:25.416711 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-29 22:01:25.416674679 +0000 UTC m=+430.475816563 I0529 22:01:25.416897 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-29 22:01:25.416554736 +0000 UTC m=+430.475696590 I0529 22:01:25.433052 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:01:25.433145 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:01:25.433193 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-29 22:01:25.433165206 +0000 UTC m=+430.492307050 I0529 22:01:25.789749 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hdbwp" condition "Approved" to 2026-05-29 22:01:25.789735005 +0000 UTC m=+430.848876839 I0529 22:01:25.808129 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-hdbwp" condition "Ready" to 2026-05-29 22:01:25.808116421 +0000 UTC m=+430.867258265 I0529 22:01:25.843052 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:01:25.843037445 +0000 UTC m=+430.902179279 I0529 22:01:25.879619 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:04:40.189200 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-29 22:04:40.189166004 +0000 UTC m=+625.248307868 I0529 22:04:40.189806 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:04:40.189838 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-29 22:04:40.189831706 +0000 UTC m=+625.248973570 I0529 22:04:40.209254 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:04:40.209469 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:04:40.209590 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-29 22:04:40.209582782 +0000 UTC m=+625.268724626 I0529 22:04:40.475507 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:04:40.481353 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cbxmm" condition "Approved" to 2026-05-29 22:04:40.48134556 +0000 UTC m=+625.540487404 I0529 22:04:40.501578 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-cbxmm" condition "Ready" to 2026-05-29 22:04:40.501557494 +0000 UTC m=+625.560699338 I0529 22:04:40.528472 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:04:40.528463071 +0000 UTC m=+625.587604905 I0529 22:04:40.544776 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:05:20.135575 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-29 22:05:20.135559741 +0000 UTC m=+665.194701575 I0529 22:05:20.136379 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:05:20.136398 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-29 22:05:20.136395006 +0000 UTC m=+665.195536840 I0529 22:05:20.151900 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:05:20.152124 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0529 22:05:20.152146 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-29 22:05:20.152140638 +0000 UTC m=+665.211282482 I0529 22:05:20.490877 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-qhvmt" condition "Approved" to 2026-05-29 22:05:20.490861775 +0000 UTC m=+665.550003629 I0529 22:05:20.516572 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-qhvmt" condition "Ready" to 2026-05-29 22:05:20.516561014 +0000 UTC m=+665.575702858 I0529 22:05:20.543031 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:05:20.543003428 +0000 UTC m=+665.602145262 I0529 22:05:20.567527 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0529 22:05:20.568785 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-29 22:05:20.568774028 +0000 UTC m=+665.627915872 I0529 22:05:20.590722 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"