I0508 19:56:26.939540 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0508 19:56:26.939640 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0508 19:56:26.939708 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0508 19:56:26.946426 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0508 19:56:26.947378 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0508 19:56:26.947502 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0508 19:56:26.947619 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0508 19:56:26.951879 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0508 19:56:26.962623 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0508 19:56:26.968048 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0508 19:56:26.970360 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0508 19:56:26.974311 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0508 19:56:26.976571 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0508 19:56:26.976683 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0508 19:56:26.978470 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0508 19:56:26.980320 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0508 19:56:26.982149 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0508 19:56:26.983975 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0508 19:56:26.984009 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0508 19:56:26.985885 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0508 19:56:26.992798 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0508 19:56:26.996426 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0508 19:56:26.998417 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0508 19:56:27.000065 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0508 19:56:27.001920 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0508 19:56:27.001942 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0508 19:56:27.002101 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0508 19:56:27.003614 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0508 19:56:27.005232 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0508 19:56:27.005391 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0508 19:56:27.006884 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0508 19:56:27.007027 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0508 19:56:27.010196 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0508 19:56:27.013642 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.014381 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.014610 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.014614 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.015102 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.015138 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.015113 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.015401 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.015533 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:27.088945 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0508 19:56:44.556101 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-05-08 19:56:44.556082714 +0000 UTC m=+17.645527785 I0508 19:56:45.230777 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 19:56:45.230935 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-05-08 19:56:45.230922641 +0000 UTC m=+18.320367722 I0508 19:56:45.230976 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-08 19:56:45.230962842 +0000 UTC m=+18.320407923 E0508 19:56:45.242992 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 19:56:45.243110 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-05-08 19:56:45.243103285 +0000 UTC m=+18.332548356 E0508 19:56:45.243155 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 19:56:45.250073 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:56:45.250175 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-05-08 19:56:45.250167177 +0000 UTC m=+18.339612248 E0508 19:56:45.259450 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0508 19:56:45.259919 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 19:56:45.259948 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 19:56:45.259982 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0508 19:56:45.267337 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:56:45.285767 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-htfr4" condition "Approved" to 2026-05-08 19:56:45.285757403 +0000 UTC m=+18.375202474 I0508 19:56:45.297695 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-htfr4" condition "Ready" to 2026-05-08 19:56:45.297454618 +0000 UTC m=+18.386899689 I0508 19:56:45.315217 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 19:56:45.315207396 +0000 UTC m=+18.404652457 I0508 19:56:45.331040 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:56:45.364036 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:56:50.260231 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 19:56:50.260216952 +0000 UTC m=+23.349662023 I0508 19:57:11.916892 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-05-08 19:57:11.916874211 +0000 UTC m=+45.006319282 I0508 19:57:11.916905 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 19:57:11.917199 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-08 19:57:11.91717702 +0000 UTC m=+45.006622131 I0508 19:57:11.936900 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-05-08 19:57:11.936890117 +0000 UTC m=+45.026335168 I0508 19:57:11.946812 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:57:11.946954 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 19:57:11.947188 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-05-08 19:57:11.947182812 +0000 UTC m=+45.036627873 I0508 19:57:12.088681 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-z8s9s" condition "Approved" to 2026-05-08 19:57:12.08866957 +0000 UTC m=+45.178114641 I0508 19:57:12.115914 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-z8s9s" condition "Ready" to 2026-05-08 19:57:12.115903903 +0000 UTC m=+45.205348974 I0508 19:57:12.145458 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 19:57:12.145443773 +0000 UTC m=+45.234888854 I0508 19:57:12.176747 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:57:12.176983 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 19:57:12.176978992 +0000 UTC m=+45.266424053 I0508 19:57:12.190050 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0508 19:57:12.190385 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 19:57:12.190374496 +0000 UTC m=+45.279819577 I0508 20:01:07.769081 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-204-45-129.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:01:07.769142 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Issuing" to 2026-05-08 20:01:07.769135178 +0000 UTC m=+280.858580259 I0508 20:01:07.769774 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Ready" to 2026-05-08 20:01:07.769767758 +0000 UTC m=+280.859212829 I0508 20:01:07.790098 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:07.790376 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Ready" to 2026-05-08 20:01:07.790367654 +0000 UTC m=+280.879812715 I0508 20:01:07.985254 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:08.010227 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-129.nip.io-tls-wbfhd" condition "Approved" to 2026-05-08 20:01:08.009887077 +0000 UTC m=+281.099332148 I0508 20:01:08.041625 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-204-45-129.nip.io-tls-wbfhd" condition "Ready" to 2026-05-08 20:01:08.041616329 +0000 UTC m=+281.131061400 I0508 20:01:08.066943 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:01:08.066925327 +0000 UTC m=+281.156370438 I0508 20:01:08.091016 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:08.091357 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:01:08.091350678 +0000 UTC m=+281.180795749 I0508 20:01:08.093426 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:08.109645 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:08.110300 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-204-45-129.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-204-45-129.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:01:08.110790 1 conditions.go:192] Found status change for Certificate "keycloak.199-204-45-129.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:01:08.110782032 +0000 UTC m=+281.200227113 I0508 20:02:11.486247 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-08 20:02:11.486219273 +0000 UTC m=+344.575664344 I0508 20:02:11.486367 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:02:11.486433 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-05-08 20:02:11.486427938 +0000 UTC m=+344.575873009 E0508 20:02:11.502726 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 20:02:11.502788 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-05-08 20:02:11.50277709 +0000 UTC m=+344.592222181 E0508 20:02:11.503064 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0508 20:02:11.504665 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:11.504777 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-05-08 20:02:11.50476898 +0000 UTC m=+344.594214051 E0508 20:02:11.514346 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0508 20:02:11.514410 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 20:02:11.514436 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0508 20:02:11.514516 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0508 20:02:11.519003 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:11.534738 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-cdjcx" condition "Approved" to 2026-05-08 20:02:11.534724246 +0000 UTC m=+344.624169317 I0508 20:02:11.544852 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-cdjcx" condition "Ready" to 2026-05-08 20:02:11.5448458 +0000 UTC m=+344.634290861 I0508 20:02:11.563730 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:11.563715536 +0000 UTC m=+344.653160607 I0508 20:02:11.581727 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:11.582064 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:11.582054359 +0000 UTC m=+344.671499450 I0508 20:02:11.595740 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:16.515328 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:16.515315067 +0000 UTC m=+349.604760168 I0508 20:02:56.251307 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:02:56.251532 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-05-08 20:02:56.251526821 +0000 UTC m=+389.340971892 I0508 20:02:56.251954 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-08 20:02:56.251083671 +0000 UTC m=+389.340528732 I0508 20:02:56.259622 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:02:56.259658 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-05-08 20:02:56.259651356 +0000 UTC m=+389.349096427 I0508 20:02:56.260121 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-08 20:02:56.260115286 +0000 UTC m=+389.349560357 I0508 20:02:56.260593 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-05-08 20:02:56.260588177 +0000 UTC m=+389.350033248 I0508 20:02:56.260880 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:02:56.261036 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-08 20:02:56.260900833 +0000 UTC m=+389.350345904 I0508 20:02:56.301464 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.301517 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-05-08 20:02:56.301512256 +0000 UTC m=+389.390957317 I0508 20:02:56.363729 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.363772 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:02:56.363798 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-05-08 20:02:56.363791096 +0000 UTC m=+389.453236157 I0508 20:02:56.364039 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.364062 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-05-08 20:02:56.364059242 +0000 UTC m=+389.453504303 I0508 20:02:56.498436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.525883 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-tfkgp" condition "Approved" to 2026-05-08 20:02:56.525871324 +0000 UTC m=+389.615316395 I0508 20:02:56.536098 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.550212 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-tfkgp" condition "Ready" to 2026-05-08 20:02:56.550203948 +0000 UTC m=+389.639649009 I0508 20:02:56.568840 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-n64zg" condition "Approved" to 2026-05-08 20:02:56.568829759 +0000 UTC m=+389.658274820 I0508 20:02:56.590481 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-n64zg" condition "Ready" to 2026-05-08 20:02:56.590471824 +0000 UTC m=+389.679916885 I0508 20:02:56.595926 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:56.595907361 +0000 UTC m=+389.685352432 I0508 20:02:56.656436 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.656854 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:56.656845002 +0000 UTC m=+389.746290093 I0508 20:02:56.696098 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:56.696089307 +0000 UTC m=+389.785534368 I0508 20:02:56.746891 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:56.749464 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:57.143249 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:57.211920 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-ndkl9" condition "Approved" to 2026-05-08 20:02:57.211911041 +0000 UTC m=+390.301356112 I0508 20:02:57.450936 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-ndkl9" condition "Ready" to 2026-05-08 20:02:57.450923267 +0000 UTC m=+390.540368338 I0508 20:02:57.793696 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:57.79367644 +0000 UTC m=+390.883121531 I0508 20:02:57.973077 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:02:57.973544 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:02:57.973538187 +0000 UTC m=+391.062983258 I0508 20:02:58.143406 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:02.190702 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:03:02.190746 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" condition "Issuing" to 2026-05-08 20:03:02.190735476 +0000 UTC m=+395.280180557 I0508 20:03:02.190967 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" condition "Ready" to 2026-05-08 20:03:02.190952161 +0000 UTC m=+395.280397262 I0508 20:03:02.206529 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-trrf4-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:02.206722 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" condition "Ready" to 2026-05-08 20:03:02.206694653 +0000 UTC m=+395.296139734 I0508 20:03:02.371539 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-trrf4-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:02.417530 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-trrf4-k4rht" condition "Approved" to 2026-05-08 20:03:02.417515805 +0000 UTC m=+395.506960866 I0508 20:03:02.453235 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-trrf4-k4rht" condition "Ready" to 2026-05-08 20:03:02.453224699 +0000 UTC m=+395.542669760 I0508 20:03:02.499884 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:03:02.499868484 +0000 UTC m=+395.589313545 I0508 20:03:02.541367 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-trrf4-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-trrf4-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:17.825153 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-05-08 20:03:17.825117678 +0000 UTC m=+410.914562749 I0508 20:03:17.825347 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:03:17.825420 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-08 20:03:17.825380394 +0000 UTC m=+410.914825465 I0508 20:03:17.842460 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:17.842529 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:03:17.842686 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-05-08 20:03:17.842678873 +0000 UTC m=+410.932123954 I0508 20:03:18.325595 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vczcz" condition "Approved" to 2026-05-08 20:03:18.325584035 +0000 UTC m=+411.415029096 I0508 20:03:18.348179 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-vczcz" condition "Ready" to 2026-05-08 20:03:18.348165919 +0000 UTC m=+411.437610970 I0508 20:03:18.385333 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:03:18.385319357 +0000 UTC m=+411.474764418 I0508 20:03:18.410827 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:18.411200 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:03:18.411192529 +0000 UTC m=+411.500637610 I0508 20:03:18.430003 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:03:18.442509 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:06:33.917684 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-05-08 20:06:33.917152099 +0000 UTC m=+607.006597160 I0508 20:06:33.919354 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:06:33.919397 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-08 20:06:33.919393752 +0000 UTC m=+607.008838813 I0508 20:06:33.939357 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:06:33.939520 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:06:33.939589 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-05-08 20:06:33.939558972 +0000 UTC m=+607.029004023 I0508 20:06:34.045921 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-wh6v6" condition "Approved" to 2026-05-08 20:06:34.045908 +0000 UTC m=+607.135353061 I0508 20:06:34.061907 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-wh6v6" condition "Ready" to 2026-05-08 20:06:34.06189868 +0000 UTC m=+607.151343741 I0508 20:06:34.086043 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:06:34.086031427 +0000 UTC m=+607.175476498 I0508 20:06:34.108100 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:06:34.108353 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:06:34.108347888 +0000 UTC m=+607.197792959 I0508 20:06:34.132372 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:06:34.132531 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:06:34.132526725 +0000 UTC m=+607.221971776 I0508 20:07:16.312749 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0508 20:07:16.312753 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-08 20:07:16.312730338 +0000 UTC m=+649.402175389 I0508 20:07:16.312804 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-05-08 20:07:16.312790169 +0000 UTC m=+649.402235240 I0508 20:07:16.335302 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:07:16.335367 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-05-08 20:07:16.335361173 +0000 UTC m=+649.424806244 I0508 20:07:16.523070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:07:16.564264 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-nnz77" condition "Approved" to 2026-05-08 20:07:16.56423775 +0000 UTC m=+649.653682821 I0508 20:07:16.591289 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-nnz77" condition "Ready" to 2026-05-08 20:07:16.591277396 +0000 UTC m=+649.680722457 I0508 20:07:16.620033 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-05-08 20:07:16.620014167 +0000 UTC m=+649.709459238 I0508 20:07:16.638203 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0508 20:07:16.691641 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"