--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-23T17:52:21Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-23T17:52:21Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-23T17:52:21Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-23T17:54:08Z" name: csr-krxpk resourceVersion: "4739" uid: 3b820da1-294c-4059-a2c9-1e5c0d76fe14 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=29badecf7a602e41fc2178df576dce7c7a5e503f7cc242fa6ad1222ac0c5cc93 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0yTFRFM01pNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFTalZtUmhvZDRBYnB6VnQwN1lmM2JuMHd1UUU0VkhJeGt3WjZ1R1B2a2gKeU9JY2JtWWU2c2F4REJXWXY3V3Bxbk5zSHRyNVdRR3duZWQ3bzQwZjdzN2FvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJZ1p3bTJMUDMralc2TlR1SnB2amwzdkhiWGJ1ZnhQdW9MM0xDOGRnaitWSFFDSVFESGR5eElvYmVnCkprajkxMWgzWmlNSG03Mm4rTHBFWXE0eTJxSzJQdm1wRWc9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQVBCUEY5YWg4aEJ2eXFOOGh2MGpFdk13RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ESXpNVGMwT1RBNFdoY05Namd3TkRJeU1UYzBPVEE0V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0yTFRFM01pNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFTalZtUmhvZDRBYnB6Vgp0MDdZZjNibjB3dVFFNFZISXhrd1o2dUdQdmtoeU9JY2JtWWU2c2F4REJXWXY3V3Bxbk5zSHRyNVdRR3duZWQ3Cm80MGY3czdhbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUhqMUF0cnNTZmF1WERmNXBTNTlIOVNMOHVkVwpLYndkNVZHaFdWV1hwc09jQ25uQmZjaVFtQStMNUFHNUhsRHpsME9WNTJXSlRUVEpjM0JqUEsvelVxRXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUdkQmYyK3NoV09GOUNIL09aTTRacks4WUJpTnRmb0Rvb3dpSTlTWVNaYjkKQzR0aVF0VEY3RzRlRXJYTm8zdlN5ekh0ZlRXdWJUeDBYTTZPUW9IbGtRdEdMZkFNYmlySXgyUDFlZjdCalM5VQpwNmxidDNGSkFmMjhkeEZZdnpXWVV6cE1sdlNLd1dQZU5yMnlqMG05eFBlTDRZQnVHVjBEYkE3eTkvVEpuRHBEClpTZE9qbmxnb2pJNVA3Ym5lSDBBMWV6dXlkVGtySFZQUHY5cytocGlqeHgyWGRXSkRDaDFNaU5wb3VMdGxSci8KODJCRFhQU1FzcFRPN1ZpM2w4UTlxVGs2M0dDN2RwOVl6L2F4M2NPR0ZoclJZeG50a3JmRFNLTWRuRmdYZGVsagpUWHhCc1J1Q2ZOTDVVTmlKYlNYRGFJRHZ3QnBRVnpaYlB6RWtTMlFqVHhZPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-04-23T17:52:21Z" lastUpdateTime: "2026-04-23T17:52:21Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved