--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-05-20T13:50:15Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-05-20T13:50:15Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-05-20T13:50:15Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-05-20T13:50:15Z" name: csr-xgp7f resourceVersion: "5471" uid: 942d68ac-c140-423e-bb17-261527d54ef9 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=0e8012070618b38fb925fff73a2951e742f827e1b41badcd5ee3569ba20229a4 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJEQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0zTFRFME9DNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFRVE9zdVdBd0VOY0VrRUdhakxNTS9Sc211K3FuZ2hXMW1vaGNkZU5WYisKOFd2bDdqUkJZajAzcHRIb0VmYWN1bVA1REFNRVlqQko4b3JJYWMva3Y4MGZvQUF3Q2dZSUtvWkl6ajBFQXdJRApSd0F3UkFJZ1h2aEh0cC96MExWcGtoTUU3SnB6eGh0RUVEMUJ0Sjdjd1dIWC9GWWFtYllDSUVTM01vK3NuVGVICjU0OEIvNlNrYXNJaHlSZE5jb3RZK05PdzZPNVE1TmZOCi0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQUo5em5xU3IzMklUNTI4cVRTcTJhdWt3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05USXdNVE0wTlRFMVdoY05Namd3TlRFNU1UTTBOVEUxV2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0zTFRFME9DNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFRVE9zdVdBd0VOY0VrRQpHYWpMTU0vUnNtdStxbmdoVzFtb2hjZGVOVmIrOFd2bDdqUkJZajAzcHRIb0VmYWN1bVA1REFNRVlqQko4b3JJCmFjL2t2ODBmbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUdqbzl1ZjByTVB2b0F2djVXbXBMaVNNTWo4aQp2dG5TRitmYVZpakZvZ2Rtb2Exc3R4ZzhMeHBTNWtnOUVFeWJVWU5aM0tHa3VuQUFaR2V2Rm13aWx5RXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQURwUGRuWkpYeXk3dVczQnFmTzRCQ3hVMStpeWhmVU1LVklWdS9uakR6UmUKVTE1Um1SZ3FGV1BTZnE2YVlMYWlTWUh2RGFwR3pia3pkNlVTL20yM2txbkVWNHJGV000SFlMZi96cE5kbndFdgoxaGpsWkVqMFFTenoyall0alZ6djFZVHV1K0p3S24yMVZzUUM0dVJWSjJQbkRsQ3dzR3NXM2diekZmVzVkYUE3ClNCNEtjZll1MXBJVXkrVi84UGdMOTltYWk1dE1qNGlEandUaE5hV1pRUDAwdnF3TDBJa3F4VmlnVXg1cjVKVWQKVHF3OUVxeWJHb3FJTHhpMnpMTlB4S1N2ZUhnczB4eklUUmxEWjU4U3RPQmh3bC9PTWxDTVozdzhSV0pyYkE4VApzYlhiQlNiVlc3NzVkTDVESzlkTWNwT1UxWHVoR3MzM2N1Ty9NVnUwNFpRPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-05-20T13:50:15Z" lastUpdateTime: "2026-05-20T13:50:15Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved