I0422 07:04:48.262705 1 feature_gate.go:249] feature gates: &{map[AdditionalCertificateOutputFormats:true]} I0422 07:04:48.262922 1 start.go:75] cert-manager "msg"="starting controller" "git-commit"="b1d501c85d97afd2adde2e86c2b119ac060caece" "version"="v1.11.5" I0422 07:04:48.262981 1 controller.go:242] cert-manager/controller/build-context "msg"="configured acme dns01 nameservers" "nameservers"=["10.96.0.10:53"] W0422 07:04:48.263156 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0422 07:04:48.265456 1 controller.go:70] cert-manager/controller "msg"="enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" I0422 07:04:48.266154 1 controller.go:134] cert-manager/controller "msg"="starting leader election" I0422 07:04:48.267183 1 controller.go:91] cert-manager/controller "msg"="starting metrics server" "address"={"IP":"::","Port":9402,"Zone":""} I0422 07:04:48.269204 1 leaderelection.go:248] attempting to acquire leader lease cert-manager/cert-manager-controller... I0422 07:04:48.282619 1 leaderelection.go:258] successfully acquired lease cert-manager/cert-manager-controller I0422 07:04:48.283626 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-metrics" I0422 07:04:48.285323 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-request-manager" I0422 07:04:48.286323 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="orders" I0422 07:04:48.286850 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-approver" I0422 07:04:48.287453 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-ca" I0422 07:04:48.288099 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-vault" I0422 07:04:48.289117 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-venafi" I0422 07:04:48.290098 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-issuing" I0422 07:04:48.291322 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-ca" I0422 07:04:48.291363 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-revision-manager" I0422 07:04:48.291389 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="gateway-shim" I0422 07:04:48.293072 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-acme" I0422 07:04:48.293599 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-key-manager" I0422 07:04:48.294044 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-trigger" I0422 07:04:48.294487 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="issuers" I0422 07:04:48.294881 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="challenges" I0422 07:04:48.295704 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-acme" I0422 07:04:48.295724 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-selfsigned" I0422 07:04:48.295735 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-vault" I0422 07:04:48.295747 1 controller.go:182] cert-manager/controller "msg"="not starting controller as it's disabled" "controller"="certificatesigningrequests-issuer-venafi" I0422 07:04:48.295806 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificaterequests-issuer-selfsigned" I0422 07:04:48.296259 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="ingress-shim" I0422 07:04:48.296550 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="certificates-readiness" I0422 07:04:48.298676 1 controller.go:205] cert-manager/controller "msg"="starting controller" "controller"="clusterissuers" I0422 07:05:08.910098 1 conditions.go:96] Setting lastTransitionTime for Issuer "test-selfsigned" condition "Ready" to 2026-04-22 07:05:08.908914354 +0000 UTC m=+20.687764969 I0422 07:05:08.927300 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Ready" to 2026-04-22 07:05:08.927282104 +0000 UTC m=+20.706132749 I0422 07:05:08.928684 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:08.928714 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 07:05:08.928706706 +0000 UTC m=+20.707557331 I0422 07:05:08.948744 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="cert-manager-test/selfsigned-cert" I0422 07:05:08.948836 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="cert-manager-test/selfsigned-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:08.948858 1 conditions.go:203] Setting lastTransitionTime for Certificate "selfsigned-cert" condition "Issuing" to 2026-04-22 07:05:08.948850794 +0000 UTC m=+20.727701419 E0422 07:05:08.954144 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"test-selfsigned\" not found" E0422 07:05:08.964207 1 event.go:267] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"selfsigned-cert.18a89bf033cd1198", GenerateName:"", Namespace:"cert-manager-test", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), DeletionTimestamp:, DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Certificate", Namespace:"cert-manager-test", Name:"selfsigned-cert", UID:"59550146-55c2-4317-a2dd-b9f3050a4a43", APIVersion:"cert-manager.io/v1", ResourceVersion:"1219", FieldPath:""}, Reason:"Issuing", Message:"Issuing certificate as Secret does not exist", Source:v1.EventSource{Component:"cert-manager-certificates-trigger", Host:""}, FirstTimestamp:time.Date(2026, time.April, 22, 7, 5, 8, 961194392, time.Local), LastTimestamp:time.Date(2026, time.April, 22, 7, 5, 8, 961194392, time.Local), Count:1, Type:"Normal", EventTime:time.Date(1, time.January, 1, 0, 0, 0, 0, time.UTC), Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events "selfsigned-cert.18a89bf033cd1198" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated' (will not retry!) I0422 07:05:08.990807 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 07:05:08.990798272 +0000 UTC m=+20.769648887 I0422 07:05:09.029057 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-system/capi-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:09.029091 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Issuing" to 2026-04-22 07:05:09.02908444 +0000 UTC m=+20.807935055 I0422 07:05:09.029436 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:05:09.029432066 +0000 UTC m=+20.808282691 I0422 07:05:09.050767 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 07:05:09.059115 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:05:09.059102759 +0000 UTC m=+20.837953374 E0422 07:05:09.092897 1 controller.go:167] cert-manager/certificates-key-manager "msg"="re-queuing item due to error processing" "error"="secrets \"selfsigned-cert-\" is forbidden: unable to create new content in namespace cert-manager-test because it is being terminated" "key"="cert-manager-test/selfsigned-cert" I0422 07:05:09.437813 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 07:05:09.480380 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-bm44h" condition "Approved" to 2026-04-22 07:05:09.480370909 +0000 UTC m=+21.259221534 I0422 07:05:09.519690 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-serving-cert-bm44h" condition "Ready" to 2026-04-22 07:05:09.519679033 +0000 UTC m=+21.298529658 I0422 07:05:09.526855 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 07:05:09.526846325 +0000 UTC m=+21.305696930 I0422 07:05:09.537786 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 07:05:09.537774532 +0000 UTC m=+21.316625157 I0422 07:05:09.538265 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:09.538289 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 07:05:09.538284564 +0000 UTC m=+21.317135189 I0422 07:05:09.555830 1 conditions.go:192] Found status change for Certificate "capi-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:09.555816148 +0000 UTC m=+21.334666773 I0422 07:05:09.562749 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:05:09.562810 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:09.562822 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Issuing" to 2026-04-22 07:05:09.562818943 +0000 UTC m=+21.341669558 I0422 07:05:09.585697 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-system/capi-serving-cert" I0422 07:05:09.871824 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 07:05:09.87180957 +0000 UTC m=+21.650660195 I0422 07:05:09.888683 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 07:05:09.888669805 +0000 UTC m=+21.667520430 I0422 07:05:09.889117 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:09.889134 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 07:05:09.889131205 +0000 UTC m=+21.667981820 I0422 07:05:09.924808 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:05:09.924951 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:09.924982 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Issuing" to 2026-04-22 07:05:09.924974077 +0000 UTC m=+21.703824732 I0422 07:05:10.057214 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:05:10.063687 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-nbhlk" condition "Approved" to 2026-04-22 07:05:10.063678383 +0000 UTC m=+21.842528998 I0422 07:05:10.090640 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-bootstrap-serving-cert-nbhlk" condition "Ready" to 2026-04-22 07:05:10.090631708 +0000 UTC m=+21.869482323 I0422 07:05:10.201896 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:10.201884307 +0000 UTC m=+21.980734912 I0422 07:05:10.244507 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:05:10.244783 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 07:05:10.244774016 +0000 UTC m=+22.023624631 I0422 07:05:10.244845 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:10.244824069 +0000 UTC m=+22.023674674 I0422 07:05:10.248917 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:05:10.256461 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-bootstrap-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-bootstrap-system/capi-kubeadm-bootstrap-serving-cert" I0422 07:05:10.256647 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:10.256642275 +0000 UTC m=+22.035492890 I0422 07:05:10.258995 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:10.259050 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 07:05:10.259033548 +0000 UTC m=+22.037884163 I0422 07:05:10.259064 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 07:05:10.259052809 +0000 UTC m=+22.037903424 I0422 07:05:10.276525 1 controller.go:162] cert-manager/certificates-trigger "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 07:05:10.276589 1 trigger_controller.go:200] cert-manager/certificates-trigger "msg"="Certificate must be re-issued" "key"="capo-system/capo-serving-cert" "message"="Issuing certificate as Secret does not exist" "reason"="DoesNotExist" I0422 07:05:10.276602 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Issuing" to 2026-04-22 07:05:10.276598514 +0000 UTC m=+22.055449129 I0422 07:05:10.367971 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-g8fmc" condition "Approved" to 2026-04-22 07:05:10.367959626 +0000 UTC m=+22.146810241 I0422 07:05:10.673251 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capi-kubeadm-control-plane-serving-cert-g8fmc" condition "Ready" to 2026-04-22 07:05:10.673239962 +0000 UTC m=+22.452090597 I0422 07:05:11.025296 1 conditions.go:192] Found status change for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:11.025283947 +0000 UTC m=+22.804134572 I0422 07:05:11.130808 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-l6spw" condition "Approved" to 2026-04-22 07:05:11.130793517 +0000 UTC m=+22.909644142 I0422 07:05:11.186029 1 controller.go:162] cert-manager/certificates-issuing "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capi-kubeadm-control-plane-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capi-kubeadm-control-plane-system/capi-kubeadm-control-plane-serving-cert" I0422 07:05:11.564954 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "capo-serving-cert-l6spw" condition "Ready" to 2026-04-22 07:05:11.564935461 +0000 UTC m=+23.343786116 I0422 07:05:11.879666 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:11.879648869 +0000 UTC m=+23.658499514 I0422 07:05:12.079228 1 controller.go:162] cert-manager/certificates-readiness "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" I0422 07:05:12.079459 1 conditions.go:192] Found status change for Certificate "capo-serving-cert" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-22 07:05:12.079454249 +0000 UTC m=+23.858304864 I0422 07:05:12.337796 1 controller.go:162] cert-manager/certificates-key-manager "msg"="re-queuing item due to optimistic locking on resource" "error"="Operation cannot be fulfilled on certificates.cert-manager.io \"capo-serving-cert\": the object has been modified; please apply your changes to the latest version and try again" "key"="capo-system/capo-serving-cert" E0422 07:06:21.983311 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-selfsigned-issuer\" not found" I0422 07:06:22.023209 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-selfsigned-issuer" condition "Ready" to 2026-04-22 07:06:22.023194335 +0000 UTC m=+93.802044950 I0422 07:06:22.044463 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-serving-cert" condition "Ready" to 2026-04-22 07:06:22.044448914 +0000 UTC m=+93.823299529 E0422 07:06:24.178117 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-bootstrap-selfsigned-issuer\" not found" I0422 07:06:24.210239 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-bootstrap-selfsigned-issuer" condition "Ready" to 2026-04-22 07:06:24.210223599 +0000 UTC m=+95.989074234 I0422 07:06:24.231626 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-bootstrap-serving-cert" condition "Ready" to 2026-04-22 07:06:24.231611753 +0000 UTC m=+96.010462378 E0422 07:06:25.784469 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capi-kubeadm-control-plane-selfsigned-issuer\" not found" I0422 07:06:25.820725 1 conditions.go:96] Setting lastTransitionTime for Issuer "capi-kubeadm-control-plane-selfsigned-issuer" condition "Ready" to 2026-04-22 07:06:25.82070625 +0000 UTC m=+97.599556875 I0422 07:06:25.846029 1 conditions.go:203] Setting lastTransitionTime for Certificate "capi-kubeadm-control-plane-serving-cert" condition "Ready" to 2026-04-22 07:06:25.845995704 +0000 UTC m=+97.624846319 E0422 07:06:27.658583 1 controller.go:137] cert-manager/issuers "msg"="issuer in work queue no longer exists" "error"="issuer.cert-manager.io \"capo-selfsigned-issuer\" not found" I0422 07:06:27.708542 1 conditions.go:96] Setting lastTransitionTime for Issuer "capo-selfsigned-issuer" condition "Ready" to 2026-04-22 07:06:27.70852714 +0000 UTC m=+99.487377755 I0422 07:06:27.732778 1 conditions.go:203] Setting lastTransitionTime for Certificate "capo-serving-cert" condition "Ready" to 2026-04-22 07:06:27.732766408 +0000 UTC m=+99.511617033