--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-24T21:16:41Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-24T21:16:41Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-24T21:16:41Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-24T21:16:41Z" name: csr-tkgsx resourceVersion: "5456" uid: 3331e754-2fa2-403b-9413-c9fe46757d93 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=8fb21b446121fed7decdf59a26000e937b6352d33c42dfaf794b60492fc7fbda groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkF6Q0Jxd0lCQURCSk1SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TURBdUJnTlZCQU1USjNONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVFF4TFRRMkxtVmpNaTVwYm5SbGNtNWhiREJaTUJNR0J5cUdTTTQ5CkFnRUdDQ3FHU000OUF3RUhBMElBQk1vTXZzNjYxTEt6NnNHMkpOeHFJWFZKaTc4aVc1QzlkUDQ5cHNpL0tCM2wKc2hGKzlOUWhEbkl1cGtKanNhck9WRlRvK2VxcDJVOFA0M2VQbGw2YlJwcWdBREFLQmdncWhrak9QUVFEQWdOSApBREJFQWlBUnUwVDI2enZRaFdvSE93UEpwc0psV2E0Q3QrdkxteHo4ZHFMSjlQaFkvUUlnRzd3bXNSdXdvK0FkCmI3NW44WFQwNC82aWtwbnNCRU1aM0VzWnY5czJPNTg9Ci0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1akNDQWFLZ0F3SUJBZ0lRYzZGU0g2Zk1HRmNLM3ZPVXlhcW83VEFOQmdrcWhraUc5dzBCQVFzRkFEQXUKTVJJd0VBWURWUVFMRXdsdmNHVnVjMmhwWm5ReEdEQVdCZ05WQkFNVEQydDFZbVV0WTNOeUxYTnBaMjVsY2pBZQpGdzB5TmpBME1qUXlNVEV4TkRGYUZ3MHlPREEwTWpNeU1URXhOREZhTUVreEZUQVRCZ05WQkFvVERITjVjM1JsCmJUcHViMlJsY3pFd01DNEdBMVVFQXhNbmMzbHpkR1Z0T201dlpHVTZhWEF0TVRBdE1DMHhOREV0TkRZdVpXTXkKTG1sdWRHVnlibUZzTUZrd0V3WUhLb1pJemowQ0FRWUlLb1pJemowREFRY0RRZ0FFeWd5K3pyclVzclBxd2JZawozR29oZFVtTHZ5SmJrTDEwL2oybXlMOG9IZVd5RVg3MDFDRU9jaTZtUW1PeHFzNVVWT2o1NnFuWlR3L2pkNCtXClhwdEdtcU9CZ3pDQmdEQU9CZ05WSFE4QkFmOEVCQU1DQjRBd0V3WURWUjBsQkF3d0NnWUlLd1lCQlFVSEF3SXcKREFZRFZSMFRBUUgvQkFJd0FEQkxCZ05WSFNNRVJEQkNnRUJ0WjhvWkJueWVQOU13MlhzbHJvMVpIRCtTbzdwbwpDTXB0ZUIra1lteHdzVllrZ3ZTV2xyT0N4TVppZXhYMEpmVlJRYlBadEc1MEpoY1pmTXh4VzRsRk1BMEdDU3FHClNJYjNEUUVCQ3dVQUE0SUJBUUJzZVJyVHlZbHl3YWl2V2IxdXZURFVodUU2YkhaMWhzbjBrYjF6ZFMzb0ZYdngKQjViMmZ1V2hhZFhXVE1OdEJ5SjM5Nzg0MlNUenlzZnhpVUNnSGVkdWh3ZHRHaEgzbVQ0c3RUTWNJL3N3L0FXagpUaTRoRUZmQVA1dE1wVTA5cVowMFBpM09zbW1rQ20yVGNnWTlKZXg0R3c5UTdhR09GZ2hqREErN1RsOXplK1lpCkp5Z3dwRzkwRkhYMUFyT2VJOGlpUXlxV2FFQjJyNHZkZ3JjbWFlM2JBVU4vL2d1UWQxMlVOWjRIVWRycFJNazIKanhmYUZOSnZWV0lPWTdhV0swRm9tRCtHN1I1K1NpQWoxTmxjMmw5S1pKWXFpbzlmb2hTQ0M1Z0lHTzI1bVpFRgo5WnlsdSsvSHp3VVJISi9qYlEreDlPRW9YbHdqM2xSK2EzVHdKcVo4Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K conditions: - lastTransitionTime: "2026-04-24T21:16:41Z" lastUpdateTime: "2026-04-24T21:16:41Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved