--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-06-12T19:21:08Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-06-12T19:21:08Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-06-12T19:21:08Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-06-12T19:21:08Z" name: csr-xkq9n resourceVersion: "6040" uid: 159aa718-eb8c-4a13-a295-1ea1bfb48ca3 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=ef3b46e860c8f749b2afbe9cc7414410b8962d22a281538b8bb88d89aa9af5e9 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE14TFRJd055NWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFURytsMDMvOThIaXgwZm1JQ2VjbFVxN0c0clVZWVk1dit1Tk9pQlEvUHoKUEpteURQN2F6bFlOMU5ZcENMbVhrR2N6RVlFT3NHQkZubkN2N3ZWL0E1TzlvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJZ0tVeVlLblFXakNUMkxaMnZZR0FKb2daNVpqZ1ZyV2NuSi9pd0FVaE9SelVDSVFDbXEycDhNNlllCmFHR1hBQ2lCNmJTWVppQmx5bnkybW1IK2ROb1BwazFjaEE9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQVAzRWYxZVZrTFRYemFPYlBBcUY2NVl3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05qRXlNVGt4TmpBNFdoY05Namd3TmpFeE1Ua3hOakE0V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE14TFRJd055NWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFURytsMDMvOThIaXgwZgptSUNlY2xVcTdHNHJVWVlZNXYrdU5PaUJRL1B6UEpteURQN2F6bFlOMU5ZcENMbVhrR2N6RVlFT3NHQkZubkN2Cjd2Vi9BNU85bzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUU4yRG1iRjRNZGJyeHI0ZCtLYkhDdnprM091OQpLUHRNNjVDOGJpQTNJSFRzaDI2bnpDQ2Z2Sno4SGtFVC8zcXNJRDV3V2ZNTzg1N3QxSXpicFFjb1hTOHdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUFqbFh6Z29Nb0R2NFlWdDBEQzRTNHdiNHV6cWpDbURxeDc3dzFPdnNmcEIKYkVTWDd5dUpyRENsVFhHVkxoWFVRVGdCVEhyR3F6VDViRlNMdU5FMDlSRkNXblpXaUNqOWtyMEJDMXVLR2g5UQppTnFiM0Z2SlNUczI5OXJ6bW9SS3d3Ym5oMkRFT0pyQVo3bDNsYXFIeUNDRUpPQ1lkaXZtOElyaUMzaHhwZWlDCnBvajJSbWd3R1FwWWRMUHFaR1c1WWNzRWhnSFo4SExmNWNjNXlxby80RWtDalFQdjlTc3JnT1JINEZ0aWx2L2cKaDdzeEFlSENNaVJWdDZGZ1ozdUsxYnhxOHNUSllnM2syN2RZcldKWDhzSU52VmczWDVqREVCRkxOVllDamVOdAp5bk53YVg2K1JSRWYveXJ1Ti9XYU5RNmE5TGZ1SVNqL1FIMGhIL1pIMG5BPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-06-12T19:21:08Z" lastUpdateTime: "2026-06-12T19:21:08Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved