I0403 02:26:07.586713 1 start.go:75] "starting controller" logger="cert-manager" version="v1.12.17" git-commit="37b853ff34a6c093e946c657c189f40413c0f628" I0403 02:26:07.586858 1 controller.go:262] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["10.96.0.10:53"] W0403 02:26:07.587024 1 client_config.go:618] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. I0403 02:26:07.592315 1 controller.go:82] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0403 02:26:07.592819 1 controller.go:156] "starting leader election" logger="cert-manager.controller" I0403 02:26:07.592875 1 controller.go:149] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0403 02:26:07.592885 1 controller.go:103] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0403 02:26:07.595352 1 leaderelection.go:250] attempting to acquire leader lease cert-manager/cert-manager-controller... I0403 02:26:07.613588 1 leaderelection.go:260] successfully acquired lease cert-manager/cert-manager-controller I0403 02:26:07.621126 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0403 02:26:07.624136 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0403 02:26:07.626684 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0403 02:26:07.626712 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0403 02:26:07.626722 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0403 02:26:07.626820 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0403 02:26:07.629557 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0403 02:26:07.631676 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0403 02:26:07.633417 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0403 02:26:07.633451 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0403 02:26:07.638044 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0403 02:26:07.642161 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="orders" I0403 02:26:07.645907 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0403 02:26:07.647789 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0403 02:26:07.649531 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0403 02:26:07.651046 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="gateway-shim" I0403 02:26:07.651204 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0403 02:26:07.653232 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0403 02:26:07.654722 1 controller.go:203] "not starting controller as it's disabled" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0403 02:26:07.654873 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0403 02:26:07.659329 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="issuers" I0403 02:26:07.663854 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="challenges" I0403 02:26:07.667830 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0403 02:26:07.669987 1 controller.go:226] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0403 02:26:07.672997 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.673610 1 reflector.go:351] Caches populated for *v1.PartialObjectMetadata from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.674326 1 reflector.go:351] Caches populated for *v1.Certificate from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.674939 1 reflector.go:351] Caches populated for *v1.Ingress from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.691655 1 reflector.go:351] Caches populated for *v1.CertificateRequest from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.709952 1 reflector.go:351] Caches populated for *v1.Issuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.729412 1 reflector.go:351] Caches populated for *v1.Challenge from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.742152 1 reflector.go:351] Caches populated for *v1.Order from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.760069 1 reflector.go:351] Caches populated for *v1.ClusterIssuer from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:07.766472 1 reflector.go:351] Caches populated for *v1.Secret from k8s.io/client-go@v0.29.7/tools/cache/reflector.go:229 I0403 02:26:19.254534 1 conditions.go:96] Setting lastTransitionTime for Issuer "self-signed" condition "Ready" to 2026-04-03 02:26:19.254498361 +0000 UTC m=+11.712763565 I0403 02:26:19.932715 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/self-signed-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:26:19.932812 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Issuing" to 2026-04-03 02:26:19.932802708 +0000 UTC m=+12.391067912 I0403 02:26:19.933082 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-03 02:26:19.933059468 +0000 UTC m=+12.391324702 E0403 02:26:19.949089 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0403 02:26:19.949171 1 conditions.go:96] Setting lastTransitionTime for Issuer "atmosphere" condition "Ready" to 2026-04-03 02:26:19.949161638 +0000 UTC m=+12.407426842 E0403 02:26:19.949195 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0403 02:26:19.949976 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:19.951064 1 conditions.go:203] Setting lastTransitionTime for Certificate "self-signed-ca" condition "Ready" to 2026-04-03 02:26:19.95081243 +0000 UTC m=+12.409077664 E0403 02:26:19.959737 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" E0403 02:26:19.960008 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0403 02:26:19.960091 1 sync.go:62] "error setting up issuer" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" resource_name="atmosphere" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0403 02:26:19.960134 1 controller.go:167] "re-queuing item due to error processing" err="secret \"cert-manager-selfsigned-ca\" not found" logger="cert-manager.clusterissuers" key="atmosphere" I0403 02:26:19.968779 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:19.991262 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6rbhf" condition "Approved" to 2026-04-03 02:26:19.991243498 +0000 UTC m=+12.449508732 I0403 02:26:20.004467 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "self-signed-ca-6rbhf" condition "Ready" to 2026-04-03 02:26:20.004453341 +0000 UTC m=+12.462718565 I0403 02:26:20.025193 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:26:20.025186618 +0000 UTC m=+12.483451822 I0403 02:26:20.042460 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:20.042767 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:26:20.042757368 +0000 UTC m=+12.501022572 I0403 02:26:20.084618 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/self-signed-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"self-signed-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:20.084955 1 conditions.go:192] Found status change for Certificate "self-signed-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:26:20.084946489 +0000 UTC m=+12.543211673 I0403 02:26:24.960483 1 conditions.go:85] Found status change for Issuer "atmosphere" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:26:24.960465367 +0000 UTC m=+17.418730591 I0403 02:26:47.865063 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/rabbitmq-messaging-topology-operator-webhook" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:26:47.865092 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-03 02:26:47.865046035 +0000 UTC m=+40.323311239 I0403 02:26:47.865115 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Issuing" to 2026-04-03 02:26:47.865103117 +0000 UTC m=+40.323368331 I0403 02:26:47.887450 1 conditions.go:96] Setting lastTransitionTime for Issuer "rabbitmq-cluster-operator" condition "Ready" to 2026-04-03 02:26:47.887426203 +0000 UTC m=+40.345691407 I0403 02:26:47.910732 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:47.910821 1 conditions.go:203] Setting lastTransitionTime for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready" to 2026-04-03 02:26:47.910813112 +0000 UTC m=+40.369078296 I0403 02:26:47.990036 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:48.020527 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-5vcjh" condition "Approved" to 2026-04-03 02:26:48.02051178 +0000 UTC m=+40.478776984 I0403 02:26:48.051424 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "rabbitmq-messaging-topology-operator-webhook-5vcjh" condition "Ready" to 2026-04-03 02:26:48.051409193 +0000 UTC m=+40.509674397 I0403 02:26:48.085650 1 conditions.go:192] Found status change for Certificate "rabbitmq-messaging-topology-operator-webhook" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:26:48.085618009 +0000 UTC m=+40.543883213 I0403 02:26:48.108546 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:26:48.161843 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/rabbitmq-messaging-topology-operator-webhook" error="Operation cannot be fulfilled on certificates.cert-manager.io \"rabbitmq-messaging-topology-operator-webhook\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:31:44.279829 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-186.nip.io-tls" condition "Ready" to 2026-04-03 02:31:44.279804392 +0000 UTC m=+336.738069586 I0403 02:31:44.280402 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-186.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:31:44.280467 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-186.nip.io-tls" condition "Issuing" to 2026-04-03 02:31:44.2804503 +0000 UTC m=+336.738715524 I0403 02:31:44.298894 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-186.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-186.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:31:44.298980 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="auth-system/keycloak.199-19-213-186.nip.io-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:31:44.299007 1 conditions.go:203] Setting lastTransitionTime for Certificate "keycloak.199-19-213-186.nip.io-tls" condition "Issuing" to 2026-04-03 02:31:44.298999218 +0000 UTC m=+336.757264412 I0403 02:31:44.498751 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-186.nip.io-tls-j84wx" condition "Approved" to 2026-04-03 02:31:44.498694369 +0000 UTC m=+336.956959603 I0403 02:31:44.523675 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keycloak.199-19-213-186.nip.io-tls-j84wx" condition "Ready" to 2026-04-03 02:31:44.523662615 +0000 UTC m=+336.981927809 I0403 02:31:44.552029 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-186.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:31:44.552010315 +0000 UTC m=+337.010275519 I0403 02:31:44.568845 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="auth-system/keycloak.199-19-213-186.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-186.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:31:44.569222 1 conditions.go:192] Found status change for Certificate "keycloak.199-19-213-186.nip.io-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:31:44.569213244 +0000 UTC m=+337.027478448 I0403 02:31:44.583309 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="auth-system/keycloak.199-19-213-186.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-186.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:31:44.593134 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="auth-system/keycloak.199-19-213-186.nip.io-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keycloak.199-19-213-186.nip.io-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.090766 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="cert-manager/kube-prometheus-stack-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:32:49.090798 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Issuing" to 2026-04-03 02:32:49.09079304 +0000 UTC m=+401.549058244 I0403 02:32:49.090922 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-03 02:32:49.090650777 +0000 UTC m=+401.548915981 I0403 02:32:49.102466 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.102622 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-03 02:32:49.102612696 +0000 UTC m=+401.560877900 E0403 02:32:49.104650 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0403 02:32:49.104689 1 conditions.go:96] Setting lastTransitionTime for Issuer "kube-prometheus-stack" condition "Ready" to 2026-04-03 02:32:49.104682277 +0000 UTC m=+401.562947471 E0403 02:32:49.104746 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0403 02:32:49.118242 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.118321 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-03 02:32:49.118309298 +0000 UTC m=+401.576574502 E0403 02:32:49.118364 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" E0403 02:32:49.118569 1 setup.go:48] "error getting signing CA TLS certificate" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers.setup" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0403 02:32:49.118624 1 sync.go:62] "error setting up issuer" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" resource_name="kube-prometheus-stack" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0403 02:32:49.118711 1 controller.go:167] "re-queuing item due to error processing" err="secret \"kube-prometheus-stack-ca\" not found" logger="cert-manager.clusterissuers" key="kube-prometheus-stack" I0403 02:32:49.131041 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-f5r22" condition "Approved" to 2026-04-03 02:32:49.130993535 +0000 UTC m=+401.589258769 I0403 02:32:49.136313 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-ca" condition "Ready" to 2026-04-03 02:32:49.136291768 +0000 UTC m=+401.594556982 I0403 02:32:49.143901 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.146566 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-ca-f5r22" condition "Ready" to 2026-04-03 02:32:49.146556564 +0000 UTC m=+401.604821768 I0403 02:32:49.167126 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:32:49.167107948 +0000 UTC m=+401.625373142 I0403 02:32:49.182250 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.182910 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:32:49.182898172 +0000 UTC m=+401.641163376 I0403 02:32:49.202930 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:49.203192 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-ca" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:32:49.20318334 +0000 UTC m=+401.661448534 I0403 02:32:49.204132 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="cert-manager/kube-prometheus-stack-ca" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-ca\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:32:54.119036 1 conditions.go:85] Found status change for Issuer "kube-prometheus-stack" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:32:54.11901821 +0000 UTC m=+406.577283404 I0403 02:33:38.449759 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/alertmanager-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:38.449812 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Issuing" to 2026-04-03 02:33:38.449806768 +0000 UTC m=+450.908071962 I0403 02:33:38.450208 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-03 02:33:38.450204137 +0000 UTC m=+450.908469331 I0403 02:33:38.450436 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Ready" to 2026-04-03 02:33:38.450429902 +0000 UTC m=+450.908695096 I0403 02:33:38.450638 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:38.450651 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-03 02:33:38.450648198 +0000 UTC m=+450.908913392 I0403 02:33:38.451246 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-03 02:33:38.451242552 +0000 UTC m=+450.909507736 I0403 02:33:38.454874 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:38.454893 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Issuing" to 2026-04-03 02:33:38.454890338 +0000 UTC m=+450.913155532 I0403 02:33:38.477640 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.481329 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-tls" condition "Ready" to 2026-04-03 02:33:38.481314952 +0000 UTC m=+450.939580146 I0403 02:33:38.483582 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.483649 1 conditions.go:203] Setting lastTransitionTime for Certificate "alertmanager-tls" condition "Ready" to 2026-04-03 02:33:38.483642517 +0000 UTC m=+450.941907711 I0403 02:33:38.483992 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.484044 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/grafana-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:38.484079 1 conditions.go:203] Setting lastTransitionTime for Certificate "grafana-tls" condition "Issuing" to 2026-04-03 02:33:38.484062777 +0000 UTC m=+450.942327981 I0403 02:33:38.601737 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-bqcfw" condition "Approved" to 2026-04-03 02:33:38.601727907 +0000 UTC m=+451.059993101 I0403 02:33:38.616612 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.629795 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "grafana-tls-bqcfw" condition "Ready" to 2026-04-03 02:33:38.62978644 +0000 UTC m=+451.088051634 I0403 02:33:38.654129 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:38.654116895 +0000 UTC m=+451.112382119 I0403 02:33:38.657889 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-qd294" condition "Approved" to 2026-04-03 02:33:38.657874834 +0000 UTC m=+451.116140068 I0403 02:33:38.674790 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "alertmanager-tls-qd294" condition "Ready" to 2026-04-03 02:33:38.674778283 +0000 UTC m=+451.133043477 I0403 02:33:38.721119 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.721413 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:38.721408085 +0000 UTC m=+451.179673269 I0403 02:33:38.765000 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.765177 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/grafana-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"grafana-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:38.765342 1 conditions.go:192] Found status change for Certificate "grafana-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:38.765336352 +0000 UTC m=+451.223601546 I0403 02:33:38.825601 1 conditions.go:192] Found status change for Certificate "alertmanager-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:38.825593796 +0000 UTC m=+451.283858990 I0403 02:33:39.020221 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:39.072326 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-n2cl4" condition "Approved" to 2026-04-03 02:33:39.072311392 +0000 UTC m=+451.530576606 I0403 02:33:39.178667 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-tls-n2cl4" condition "Ready" to 2026-04-03 02:33:39.178657492 +0000 UTC m=+451.636922686 I0403 02:33:39.832999 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:39.832981094 +0000 UTC m=+452.291246328 I0403 02:33:39.968070 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:39.969132 1 conditions.go:192] Found status change for Certificate "prometheus-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:39.969116687 +0000 UTC m=+452.427381911 I0403 02:33:40.015737 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/alertmanager-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"alertmanager-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:40.220272 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="monitoring/prometheus-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:46.145195 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" condition "Ready" to 2026-04-03 02:33:46.145179341 +0000 UTC m=+458.603444545 I0403 02:33:46.145357 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:46.145439 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" condition "Issuing" to 2026-04-03 02:33:46.145426838 +0000 UTC m=+458.603692062 I0403 02:33:46.161937 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-lq67t-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:33:46.162032 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:33:46.162055 1 conditions.go:203] Setting lastTransitionTime for Certificate "kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" condition "Issuing" to 2026-04-03 02:33:46.162046267 +0000 UTC m=+458.620311491 I0403 02:33:46.420811 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-lq67t-dm46g" condition "Approved" to 2026-04-03 02:33:46.420799604 +0000 UTC m=+458.879064808 I0403 02:33:46.767601 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "kube-prometheus-stack-prometheus-node-exporter-lq67t-dm46g" condition "Ready" to 2026-04-03 02:33:46.767590644 +0000 UTC m=+459.225855848 I0403 02:33:47.093689 1 conditions.go:192] Found status change for Certificate "kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:33:47.093670588 +0000 UTC m=+459.551935812 I0403 02:33:47.118843 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/kube-prometheus-stack-prometheus-node-exporter-lq67t-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"kube-prometheus-stack-prometheus-node-exporter-lq67t-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:34:02.574508 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready" to 2026-04-03 02:34:02.574464597 +0000 UTC m=+475.032729801 I0403 02:34:02.574787 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:34:02.574876 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-03 02:34:02.574864157 +0000 UTC m=+475.033129361 I0403 02:34:02.593729 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:34:02.593870 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:34:02.593911 1 conditions.go:203] Setting lastTransitionTime for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Issuing" to 2026-04-03 02:34:02.593902417 +0000 UTC m=+475.052167611 I0403 02:34:02.815244 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-2t2rb" condition "Approved" to 2026-04-03 02:34:02.815234195 +0000 UTC m=+475.273499399 I0403 02:34:02.834189 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "prometheus-kube-prometheus-stack-prometheus-0-tls-2t2rb" condition "Ready" to 2026-04-03 02:34:02.834176963 +0000 UTC m=+475.292442167 I0403 02:34:02.865127 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:34:02.865108488 +0000 UTC m=+475.323373682 I0403 02:34:02.879805 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:34:02.880123 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:34:02.880117444 +0000 UTC m=+475.338382638 I0403 02:34:02.901578 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:34:02.903067 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="monitoring/prometheus-kube-prometheus-stack-prometheus-0-tls" error="Operation cannot be fulfilled on certificates.cert-manager.io \"prometheus-kube-prometheus-stack-prometheus-0-tls\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:34:02.903468 1 conditions.go:192] Found status change for Certificate "prometheus-kube-prometheus-stack-prometheus-0-tls" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:34:02.903457164 +0000 UTC m=+475.361722398 I0403 02:37:33.843145 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/keystone-api-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:37:33.843191 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-03 02:37:33.843145726 +0000 UTC m=+686.301410930 I0403 02:37:33.843195 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Issuing" to 2026-04-03 02:37:33.843168016 +0000 UTC m=+686.301433220 I0403 02:37:33.896151 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:37:33.896241 1 conditions.go:203] Setting lastTransitionTime for Certificate "keystone-api-certs" condition "Ready" to 2026-04-03 02:37:33.896233499 +0000 UTC m=+686.354498703 I0403 02:37:34.272148 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:37:34.642092 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6wl9n" condition "Approved" to 2026-04-03 02:37:34.642075447 +0000 UTC m=+687.100340671 I0403 02:37:34.791770 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "keystone-api-certs-6wl9n" condition "Ready" to 2026-04-03 02:37:34.791755313 +0000 UTC m=+687.250020547 I0403 02:37:35.796404 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:37:35.796385052 +0000 UTC m=+688.254650276 I0403 02:37:36.115419 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-readiness" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:37:36.115798 1 conditions.go:192] Found status change for Certificate "keystone-api-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:37:36.115790979 +0000 UTC m=+688.574056183 I0403 02:37:36.359007 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-key-manager" key="openstack/keystone-api-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"keystone-api-certs\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:38:44.297210 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Ready" to 2026-04-03 02:38:44.297170472 +0000 UTC m=+756.755435676 I0403 02:38:44.297715 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:38:44.297748 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-03 02:38:44.297742824 +0000 UTC m=+756.756008028 I0403 02:38:44.484808 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again" I0403 02:38:44.485139 1 trigger_controller.go:194] "Certificate must be re-issued" logger="cert-manager.certificates-trigger" key="openstack/horizon-int-certs" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0403 02:38:44.485183 1 conditions.go:203] Setting lastTransitionTime for Certificate "horizon-int-certs" condition "Issuing" to 2026-04-03 02:38:44.485172336 +0000 UTC m=+756.943437570 I0403 02:38:45.082179 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ffn7m" condition "Approved" to 2026-04-03 02:38:45.082163677 +0000 UTC m=+757.540428901 I0403 02:38:45.177212 1 conditions.go:263] Setting lastTransitionTime for CertificateRequest "horizon-int-certs-ffn7m" condition "Ready" to 2026-04-03 02:38:45.177199631 +0000 UTC m=+757.635464835 I0403 02:38:45.277743 1 conditions.go:192] Found status change for Certificate "horizon-int-certs" condition "Ready": "False" -> "True"; setting lastTransitionTime to 2026-04-03 02:38:45.277719775 +0000 UTC m=+757.735984979 I0403 02:38:45.688338 1 controller.go:162] "re-queuing item due to optimistic locking on resource" logger="cert-manager.certificates-issuing" key="openstack/horizon-int-certs" error="Operation cannot be fulfilled on certificates.cert-manager.io \"horizon-int-certs\": the object has been modified; please apply your changes to the latest version and try again"