--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-17T16:22:04Z" generateName: system:openshift:openshift-monitoring- labels: metrics.openshift.io/csr.subject: metrics-server managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: cluster-policy-controller operation: Update subresource: approval time: "2026-04-17T16:22:04Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} f:labels: .: {} f:metrics.openshift.io/csr.subject: {} manager: operator operation: Update time: "2026-04-17T16:22:04Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-17T16:22:05Z" name: system:openshift:openshift-monitoring-cbjdp resourceVersion: "7912" uid: 2e62fb15-37c6-494e-826c-a3561004eaec spec: extra: authentication.kubernetes.io/credential-id: - JTI=efbc9c25-2827-43fb-b81b-0a2b35695250 authentication.kubernetes.io/node-name: - ip-10-0-136-214.ec2.internal authentication.kubernetes.io/node-uid: - c9cbaa56-ccb8-42a3-863d-720c5ebeddef authentication.kubernetes.io/pod-name: - cluster-monitoring-operator-75587bd455-rtp7q authentication.kubernetes.io/pod-uid: - 487fdfa2-04ee-41df-9603-b59486486e7e groups: - system:serviceaccounts - system:serviceaccounts:openshift-monitoring - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkFEQ0JwZ0lCQURCRU1VSXdRQVlEVlFRREV6bHplWE4wWlcwNmMyVnlkbWxqWldGalkyOTFiblE2YjNCbApibk5vYVdaMExXMXZibWwwYjNKcGJtYzZiV1YwY21samN5MXpaWEoyWlhJd1dUQVRCZ2NxaGtqT1BRSUJCZ2dxCmhrak9QUU1CQndOQ0FBUU02c2Vja0ZqYnFnMHNUOEtSVG5KSHUrblprZXRkalhteXVxdWVBc3owdERmT0FMSDYKYm4vWFIvY3JDZjBqaDl6bmdzWWI5L285MUVLU2pWQm1RdEtZb0FBd0NnWUlLb1pJemowRUF3SURTUUF3UmdJaApBSlI3Q1JBcmVORjF2cFYvMFRZVnFNcXlPZVlyWThjSi9FamNWV2tDaFQzQUFpRUFqcEtsemZJaDRqem8xVWNFCmlHd09BMGxnWnlldFE1YkdveXErc2k3bjlnOD0KLS0tLS1FTkQgQ0VSVElGSUNBVEUgUkVRVUVTVC0tLS0tCg== signerName: kubernetes.io/kube-apiserver-client uid: 4c4801d5-3f80-42f2-a811-5b43a457a2e7 usages: - digital signature - key encipherment - client auth username: system:serviceaccount:openshift-monitoring:cluster-monitoring-operator status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN0akNDQVo2Z0F3SUJBZ0lSQUpyL05veE82RVRDRVFVNDREN2hqemt3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ERTNNVFl4TnpBMVdoY05Namd3TkRFMk1UWXhOekExV2pCRU1VSXdRQVlEVlFRREV6bHplWE4wClpXMDZjMlZ5ZG1salpXRmpZMjkxYm5RNmIzQmxibk5vYVdaMExXMXZibWwwYjNKcGJtYzZiV1YwY21samN5MXoKWlhKMlpYSXdXVEFUQmdjcWhrak9QUUlCQmdncWhrak9QUU1CQndOQ0FBUU02c2Vja0ZqYnFnMHNUOEtSVG5KSAp1K25aa2V0ZGpYbXl1cXVlQXN6MHREZk9BTEg2Ym4vWFIvY3JDZjBqaDl6bmdzWWI5L285MUVLU2pWQm1RdEtZCm80R0RNSUdBTUE0R0ExVWREd0VCL3dRRUF3SUZvREFUQmdOVkhTVUVEREFLQmdnckJnRUZCUWNEQWpBTUJnTlYKSFJNQkFmOEVBakFBTUVzR0ExVWRJd1JFTUVLQVFCNENRTlBNNU9uOE5Dd2N1TmtLd0JsWm5nTW53M21qOVFYUQpPSGpWNTBRT1VlSi9DdUdCSFlDSG15Uzl6eVg4Ky92VlkvczMrUy9ka1N3Qjk5MXJLTVV3RFFZSktvWklodmNOCkFRRUxCUUFEZ2dFQkFDenJicGZiQ2tOdHp2NGN2RFExam9jVWh3NjJiRXJZNWV6RzQ5Sm55YjVMMlJDa3hhME8KVlAxM0ZmYWdCajRXdGx4eHdVL2ZhT2JwQnV5YUtlMEhpOGYvUVJqazBhTE9BWEVEV2w1ZmZ6MFphVHFtT3NTRwpRbkpqQjZDQ3hQLzg2NHpXQ3R4QUdwQ0tYQVNxaGdXeEJFNDFGQ1JBaUtiaFRqQUhUSU4xYU8xN2kwdVdLb1BnCmNFUTJPamtSTFl0M201US9Ia0FnaTNLeDd1UzVxU2FzdDNQN0lYeHAxQjQ1MjBHMm9nKzl6ZTFacnNYMHZwMXgKcDBjWDAyK04wQnE0YXRLYjRWOTZHV1NkS1RCYnZJYzFOK21QQmpkNmkyc1RNdnU4c0ZsMU1nL1ZVUVlGeWhrbgpwZ0oySjlwOUtrZ09sQWk3c0I2OC9BMHgweXdHckdDS0EvOD0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= conditions: - lastTransitionTime: "2026-04-17T16:22:04Z" lastUpdateTime: "2026-04-17T16:22:04Z" message: Auto-approved CSR "system:openshift:openshift-monitoring-cbjdp" reason: AutoApproved status: "True" type: Approved