I0527 15:32:24.287504 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0527 15:32:24.287625 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0527 15:32:24.287686 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0527 15:32:24.291621 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0527 15:32:24.292588 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0527 15:32:24.293085 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0527 15:32:24.293167 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0527 15:32:24.296326 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0527 15:32:24.310896 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0527 15:32:24.311215 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0527 15:32:24.314438 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0527 15:32:24.317749 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0527 15:32:24.320006 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0527 15:32:24.320034 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0527 15:32:24.325216 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0527 15:32:24.328064 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0527 15:32:24.331003 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0527 15:32:24.336786 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0527 15:32:24.341203 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0527 15:32:24.343407 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0527 15:32:24.345498 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0527 15:32:24.345744 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0527 15:32:24.347859 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0527 15:32:24.347879 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0527 15:32:24.347888 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0527 15:32:24.348122 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0527 15:32:24.350332 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0527 15:32:24.352381 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0527 15:32:24.354762 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0527 15:32:24.356913 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0527 15:32:24.365080 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0527 15:32:24.369869 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0527 15:32:24.372599 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0527 15:32:24.375827 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.376312 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.376311 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.376368 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.376623 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.376753 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.377122 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.377251 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.377488 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:32:24.491201 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0527 15:33:21.837473 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-27 15:33:21.837456822 +0000 UTC m=+57.588257865 I0527 15:33:22.625730 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-27 15:33:22.625712495 +0000 UTC m=+58.376513558 I0527 15:33:22.625818 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:22.625853 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-27 15:33:22.625842982 +0000 UTC m=+58.376644035 E0527 15:33:22.655140 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0527 15:33:22.655254 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-27 15:33:22.655244207 +0000 UTC m=+58.406045270 E0527 15:33:22.655287 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0527 15:33:22.658694 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:22.658802 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:22.658844 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-27 15:33:22.658832656 +0000 UTC m=+58.409633719 E0527 15:33:22.665027 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0527 15:33:22.665322 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0527 15:33:22.665356 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0527 15:33:22.665387 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0527 15:33:22.717851 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:22.724245 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-d84vf" condition "Approved" to 2026-05-27 15:33:22.724232655 +0000 UTC m=+58.475033688 I0527 15:33:22.744148 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-d84vf" condition "Ready" to 2026-05-27 15:33:22.744136197 +0000 UTC m=+58.494937230 I0527 15:33:22.781196 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:22.781182442 +0000 UTC m=+58.531983475 I0527 15:33:22.803181 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:22.803513 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:22.803504594 +0000 UTC m=+58.554305647 I0527 15:33:22.824483 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:27.666253 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:27.66623938 +0000 UTC m=+63.417040433 I0527 15:33:30.042698 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-27 15:33:30.04268721 +0000 UTC m=+65.793488243 I0527 15:33:30.043035 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:30.043051 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-27 15:33:30.043046648 +0000 UTC m=+65.793847691 I0527 15:33:30.056060 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-27 15:33:30.056046316 +0000 UTC m=+65.806847339 I0527 15:33:30.070428 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:30.070588 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:30.070624 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-27 15:33:30.070613672 +0000 UTC m=+65.821414705 I0527 15:33:30.224977 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:30.235572 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-7kf7r" condition "Approved" to 2026-05-27 15:33:30.235557392 +0000 UTC m=+65.986358455 I0527 15:33:30.287779 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-7kf7r" condition "Ready" to 2026-05-27 15:33:30.287766884 +0000 UTC m=+66.038567917 I0527 15:33:30.343774 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:30.343754944 +0000 UTC m=+66.094555997 I0527 15:33:30.377683 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:30.430666 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:34.709689 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-vnc-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:34.709738 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Issuing" to 2026-05-27 15:33:34.709729973 +0000 UTC m=+70.460531006 I0527 15:33:34.709803 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-27 15:33:34.709781126 +0000 UTC m=+70.460582189 I0527 15:33:34.730509 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:34.730587 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-27 15:33:34.730577582 +0000 UTC m=+70.481378615 I0527 15:33:34.749095 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:34.749172 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-vnc-ca" condition "Ready" to 2026-05-27 15:33:34.749161638 +0000 UTC m=+70.499962701 I0527 15:33:34.760153 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-z8g5f" condition "Approved" to 2026-05-27 15:33:34.760139805 +0000 UTC m=+70.510940838 I0527 15:33:34.787376 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-vnc-ca-z8g5f" condition "Ready" to 2026-05-27 15:33:34.787360052 +0000 UTC m=+70.538161105 I0527 15:33:34.879870 1 conditions.go:192] Found status change for Certificate "libvirt-vnc-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:34.87983496 +0000 UTC m=+70.630635993 I0527 15:33:34.921865 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:34.987436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-vnc-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-vnc-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:35.615393 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:35.615437 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-05-27 15:33:35.615426399 +0000 UTC m=+71.366227452 I0527 15:33:35.615547 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Ready" to 2026-05-27 15:33:35.615530974 +0000 UTC m=+71.366331997 I0527 15:33:35.644930 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:35.645040 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/libvirt-api-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:33:35.645074 1 conditions.go:203] Setting lastTransitionTime for Certificate "libvirt-api-ca" condition "Issuing" to 2026-05-27 15:33:35.645064806 +0000 UTC m=+71.395865859 I0527 15:33:35.695970 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-sswnf" condition "Approved" to 2026-05-27 15:33:35.695956602 +0000 UTC m=+71.446757635 I0527 15:33:35.712661 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "libvirt-api-ca-sswnf" condition "Ready" to 2026-05-27 15:33:35.712652744 +0000 UTC m=+71.463453757 I0527 15:33:35.735963 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:35.735951005 +0000 UTC m=+71.486752038 I0527 15:33:35.778302 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:35.778497 1 conditions.go:192] Found status change for Certificate "libvirt-api-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:33:35.778491045 +0000 UTC m=+71.529292058 I0527 15:33:35.808675 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/libvirt-api-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"libvirt-api-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:33:36.532186 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-vnc" condition "Ready" to 2026-05-27 15:33:36.532174235 +0000 UTC m=+72.282975268 I0527 15:33:37.245061 1 conditions.go:96] Setting lastTransitionTime for Issuer "libvirt-api" condition "Ready" to 2026-05-27 15:33:37.245046571 +0000 UTC m=+72.995847634 I0527 15:40:05.443405 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:40:05.443462 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Issuing" to 2026-05-27 15:40:05.443455454 +0000 UTC m=+461.194256477 I0527 15:40:05.443499 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-05-27 15:40:05.443478145 +0000 UTC m=+461.194279208 E0527 15:40:05.461804 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0527 15:40:05.461838 1 conditions.go:96] Setting lastTransitionTime for Issuer "valkey" condition "Ready" to 2026-05-27 15:40:05.461831353 +0000 UTC m=+461.212632386 I0527 15:40:05.461875 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0527 15:40:05.466422 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.466475 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-ca" condition "Ready" to 2026-05-27 15:40:05.466469794 +0000 UTC m=+461.217270827 E0527 15:40:05.476493 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" E0527 15:40:05.476634 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers.setup" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" I0527 15:40:05.476693 1 sync.go:62] "Error initializing issuer: secret \"valkey-ca\" not found" logger="cert-manager.issuers" resource_name="valkey" resource_namespace="openstack" resource_kind="Issuer" resource_version="v1" E0527 15:40:05.476729 1 controller.go:167] "re-queuing item due to error processing" err="secret \"valkey-ca\" not found" logger="cert-manager.issuers" key="openstack/valkey" I0527 15:40:05.481898 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/valkey-server" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0527 15:40:05.481922 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Issuing" to 2026-05-27 15:40:05.481916862 +0000 UTC m=+461.232717915 I0527 15:40:05.481946 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-05-27 15:40:05.481941943 +0000 UTC m=+461.232742956 I0527 15:40:05.498301 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.498355 1 conditions.go:203] Setting lastTransitionTime for Certificate "valkey-server" condition "Ready" to 2026-05-27 15:40:05.498349414 +0000 UTC m=+461.249150447 I0527 15:40:05.598564 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.718628 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-jmddb" condition "Approved" to 2026-05-27 15:40:05.71861926 +0000 UTC m=+461.469420283 I0527 15:40:05.735948 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-server-jmddb" condition "Ready" to 2026-05-27 15:40:05.735936713 +0000 UTC m=+461.486737746 I0527 15:40:05.828732 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.858886 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-s5h6l" condition "Approved" to 2026-05-27 15:40:05.858872257 +0000 UTC m=+461.609673290 I0527 15:40:05.881400 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "valkey-ca-s5h6l" condition "Ready" to 2026-05-27 15:40:05.881386604 +0000 UTC m=+461.632187637 I0527 15:40:05.922985 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:05.922969516 +0000 UTC m=+461.673770549 I0527 15:40:05.944989 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.945352 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:05.94534458 +0000 UTC m=+461.696145613 I0527 15:40:05.946939 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.962959 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:05.963169 1 conditions.go:192] Found status change for Certificate "valkey-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:05.963162895 +0000 UTC m=+461.713963928 I0527 15:40:05.964372 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-ca\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:10.477375 1 conditions.go:85] Found status change for Issuer "valkey" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:10.47736167 +0000 UTC m=+466.228162723 I0527 15:40:10.496261 1 conditions.go:252] Found status change for CertificateRequest "valkey-server-jmddb" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:10.496249051 +0000 UTC m=+466.247050084 I0527 15:40:10.527706 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:10.527692871 +0000 UTC m=+466.278493924 I0527 15:40:10.545762 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:10.546082 1 conditions.go:192] Found status change for Certificate "valkey-server" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-27 15:40:10.54607374 +0000 UTC m=+466.296874783 I0527 15:40:10.555802 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" I0527 15:40:10.567188 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/valkey-server" error="Operation cannot be fulfilled on certificates.cert-manager.io \"valkey-server\": the object has been modified; please apply your changes to the latest version and try again" E0527 15:40:58.953697 1 leaderelection.go:369] Failed to update lock: etcdserver: request timed out E0527 15:41:27.404877 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: etcdserver: request timed out E0527 15:41:31.945880 1 leaderelection.go:332] error retrieving resource lock cert-manager/cert-manager-controller: Get "https://10.96.0.1:443/apis/coordination.k8s.io/v1/namespaces/cert-manager/leases/cert-manager-controller": context deadline exceeded I0527 15:41:31.945959 1 leaderelection.go:285] failed to renew lease cert-manager/cert-manager-controller: timed out waiting for the condition E0527 15:41:32.230003 1 leaderelection.go:308] Failed to release lock: Operation cannot be fulfilled on leases.coordination.k8s.io "cert-manager-controller": the object has been modified; please apply your changes to the latest version and try again I0527 15:41:32.230243 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-metrics" I0527 15:41:32.230301 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-trigger" I0527 15:41:32.230369 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.ingress-shim" I0527 15:41:32.230401 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-approver" I0527 15:41:32.230430 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-request-manager" I0527 15:41:32.230449 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-readiness" I0527 15:41:32.230405 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.orders" I0527 15:41:32.230469 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-key-manager" I0527 15:41:32.230417 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-venafi" I0527 15:41:32.230496 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.challenges" I0527 15:41:32.230518 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-acme" I0527 15:41:32.230413 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.clusterissuers" I0527 15:41:32.230537 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-selfsigned" I0527 15:41:32.230560 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-ca" I0527 15:41:32.230557 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-issuing" I0527 15:41:32.230583 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.issuers" I0527 15:41:32.230618 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificaterequests-issuer-vault" I0527 15:41:32.230344 1 controller.go:127] "shutting down queue as workqueue signaled shutdown" logger="cert-manager.certificates-revision-manager" E0527 15:41:32.230843 1 main.go:35] "error executing command" err="error starting controller: leader election lost" logger="cert-manager"