--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-05-25T07:35:49Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-05-25T07:35:49Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-05-25T07:35:49Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-05-25T07:35:49Z" name: csr-qv2t7 resourceVersion: "5301" uid: d85653d7-2ef3-455e-8648-de35f0c79cf4 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=3d360b6620823db35742f2bc0d6d78b5e7b5f42819031698f06f0509ceb0fd39 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE16TFRJME9TNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFUaklCUGVOUHJSMGxaK0ZxTUJsUnB0b1hrcW5mRGh0bWVPWU8rSDFjcEMKVXNNd3lPOEptMjRWQStwV0NnVnZmS1JWVW16dG1CUjVmanpmalk1ZThJVkVvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJaEFNTzNEUlNBNi9mRi9lcC8xZ3psRlBjN3FpVktxeHk5Q0gwQ1p3UTNJbnJpQWlBUVFKaTRsc2cvCkpqM2xDeHdPQUxTZ0pva2FJS1lUenNnMUlSTk5NOG9IK3c9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQU9RTXFjR0U0UVprZ21lSEhBelV2bmd3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05USTFNRGN6TURRNVdoY05Namd3TlRJME1EY3pNRFE1V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE16TFRJME9TNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFUaklCUGVOUHJSMGxaKwpGcU1CbFJwdG9Ya3FuZkRodG1lT1lPK0gxY3BDVXNNd3lPOEptMjRWQStwV0NnVnZmS1JWVW16dG1CUjVmanpmCmpZNWU4SVZFbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUU51VENpamFBZTFXNGNWQnR6bDNFR3VUenJhdAppN1pXck96QzJsQk5MWFcrYmlobytIV1YyaVJ1MU5mSUt2TEJERjlpa1R6UnhUU2NGekgvMHA0QmpIVXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUxNbGo3dGZQMVpqS0ZwWjVnc3U4S213TDR6cFZxMk9CeXNKUjl2eUlJNFcKUmQyc25Ram1tMjJSYXRpUTdJWG1HdnNjNlV2bnN1RkJyL0ExdG1xN0ZRMjJsbXRQUUdURENLemF4emw3djRldApPVWllb0ZRNHI0N3dUUTVuOVVNbHpnaWJCSERXQXdHRmEzbDRxaGoxTkpqcEFNSzNPL1hXRGI5MVY5cUFKaysrCm9KMCt0M0lrSUtHdlgvRjd2c2xiTCtaRGU1aUZKTTRSRmxuL2NYSm51MlJqOHRWRnF0VWZhYnBOQXBXRGFVdkoKUnVSSWgyUE5ybGErK3VMMFhocWdRbGRJa01WWGFtUXZBWnlYRlVEcVdJeTRtck03SlBldnNWdU1va294OTRReApOSkpCMTFEVnUyRUZZTzM5aEFvWlRTOHRibVJkZlNFUkRSTVdxclhjOE40PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-05-25T07:35:49Z" lastUpdateTime: "2026-05-25T07:35:49Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved