--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-20T16:23:17Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-20T16:23:17Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-20T16:23:17Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-20T16:23:17Z" name: csr-r8h9p resourceVersion: "5741" uid: 32e9909a-371c-4c26-933c-7261e207c05f spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=1ea594603f9977a45b0d51c10589a7dff60f1d69289c21909f78c60f21256e7a groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0Jxd0lCQURCSk1SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TURBdUJnTlZCQU1USjNONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE13TFRjeUxtVmpNaTVwYm5SbGNtNWhiREJaTUJNR0J5cUdTTTQ5CkFnRUdDQ3FHU000OUF3RUhBMElBQkZFQ1lXdUFKR3dlaXVZNXdhMFd6R240b013N3QxM3JZQzdkL0dFeEVZVU4KeTEzTHl3dVpFZDh6NnNyVXlvNmo2VzNvMTUxeWxMc3VjZ2xPOHNzU0VUK2dBREFLQmdncWhrak9QUVFEQWdOSgpBREJHQWlFQTNvN0Z1VEoxOWJDRDdYMUhVMHZMKzFieDVoaTkvS3NoU0g0eTFzR2dXemdDSVFEa210d3J1YVFLCk8zMGc1UGFMengxZlRNSm5ra0s3am9BZWNkOHNnRlU5TFE9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1ekNDQWFPZ0F3SUJBZ0lSQU5FUnI5a1hzeUlVNUFtTWlLNlg0NU13RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ESXdNVFl4T0RFM1doY05Namd3TkRFNU1UWXhPREUzV2pCSk1SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1EQXVCZ05WQkFNVEozTjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE13TFRjeUxtVmoKTWk1cGJuUmxjbTVoYkRCWk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQkZFQ1lXdUFKR3dlaXVZNQp3YTBXekduNG9Ndzd0MTNyWUM3ZC9HRXhFWVVOeTEzTHl3dVpFZDh6NnNyVXlvNmo2VzNvMTUxeWxMc3VjZ2xPCjhzc1NFVCtqZ1lNd2dZQXdEZ1lEVlIwUEFRSC9CQVFEQWdlQU1CTUdBMVVkSlFRTU1Bb0dDQ3NHQVFVRkJ3TUMKTUF3R0ExVWRFd0VCL3dRQ01BQXdTd1lEVlIwakJFUXdRb0JBemJMWVV4MWY2czhUS21SRnZ0WUUrc3JZTzByVgpyM0NqYkZZMmNhRzJ4QmFxZGkyQzhzeVFJRXlJTmlDbk1NQ2FFMmh4L3Y4ekVUdUpVekpjazl3UjlEQU5CZ2txCmhraUc5dzBCQVFzRkFBT0NBUUVBRHlsTXVIOVNrZ1ROTmYxZkdEdG93U2IwNzhqK1Y5OUpYY3EzOGRzVWNwT0MKNnhWM2RqRGRVRG1BRGVKOUtIaEkyQW9SR0lxcysxVks2NzEwdThsNXRYYldJTG1mbi92bmg5VksvQ2d1ODN4NApKTUppS1FBc0o0YTQ5Z2V0N0dCdXJrbkNxMG9HMEpDY2Z2bjFaQm1LR0tZTkJEL0hUeXJyM3RNaTFqQlBhZWNwCmdJV2ZkV1JYRlZwY2ZqRGs1NjIxL0FSTDA5MUxqVCtUOWp5QmtNMmk0cEFoaUgwRlFOMGxJSHZkb2FKTG00b00KdkFLZk5IODE5MG8yeVQ1eHBOSW03QWE4TTJIak5TODlFa1Jzb1JsdW1XZTBLM3RIcFJHYzVaRVZOaFJ2YkNXMgpuMFh5SHlJclpVUjRJbVd3Ymg3UitWckpHUlR1dGR3eHhGUWtHSmF5MUE9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-04-20T16:23:17Z" lastUpdateTime: "2026-04-20T16:23:17Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved