--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-05-21T18:20:23Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-05-21T18:20:23Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-05-21T18:20:23Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-05-21T18:20:23Z" name: csr-gkxkg resourceVersion: "5614" uid: a8824f37-491f-4fc0-a6c0-18257958009d spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=3a622ace25546ff1e61b3d9902214c19bbc58b5abd04a064e6af0775d55af470 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJEQ0Jxd0lCQURCSk1SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TURBdUJnTlZCQU1USjNONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVEk1TFRrekxtVmpNaTVwYm5SbGNtNWhiREJaTUJNR0J5cUdTTTQ5CkFnRUdDQ3FHU000OUF3RUhBMElBQk9Xd0JLZ0gydDZsaDN0L0s4TXZiUzl5VVNyTTJZekU2aTEwa3hjVEZlNUMKcDdZT2Y2WWFlZUJBYktvckcrbWgrbnFrcWRxTS9FaHRIUHhxaXIvdlpHR2dBREFLQmdncWhrak9QUVFEQWdOSQpBREJGQWlFQWhtZHQzUXZKUXJNalpjTzlQWGd1YUQ4SXd4dWs3QXNUTzJFZlBVMnl3VmdDSUF4ay9lU2JYdlhUClVxS3BHNVdUR2dNQmFLUGNvOENnaHVGZ3dhUFRRNW5iCi0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1ekNDQWFPZ0F3SUJBZ0lSQUxTS0lRd084em5sMzIrcEJsWmVra013RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05USXhNVGd4TlRJeldoY05Namd3TlRJd01UZ3hOVEl6V2pCSk1SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1EQXVCZ05WQkFNVEozTjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVEk1TFRrekxtVmoKTWk1cGJuUmxjbTVoYkRCWk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQk9Xd0JLZ0gydDZsaDN0LwpLOE12YlM5eVVTck0yWXpFNmkxMGt4Y1RGZTVDcDdZT2Y2WWFlZUJBYktvckcrbWgrbnFrcWRxTS9FaHRIUHhxCmlyL3ZaR0dqZ1lNd2dZQXdEZ1lEVlIwUEFRSC9CQVFEQWdlQU1CTUdBMVVkSlFRTU1Bb0dDQ3NHQVFVRkJ3TUMKTUF3R0ExVWRFd0VCL3dRQ01BQXdTd1lEVlIwakJFUXdRb0JBWnZJd09iaXVJMmYwTXpFQm1kZ003QUdoZ2dnVwpnN09jNUZCL3Q5UVgwSE9tL3R0Q0V4bW5haVdUY283cHJjdElZL2Mvb1dBOHpXeFpkcWVHRWhRMitUQU5CZ2txCmhraUc5dzBCQVFzRkFBT0NBUUVBQXpXMHFKcGRvK3FkbVgxOGdYRlZ6T09OMk5MOEk5RDBEMGd1ZkJDQnVRL00KUXozWXZtQkkwd0Z4Sk9pWG8rQVYzWU5RV2duR3ZPdS9GL1hSY01Da29ReFUyM3c2UGk1ZmRPbFY0SmV3eGhzVQpxcFU5MGRNeVlSSi8rRXAxRHc0N1VrRFVIVWVnV0Y2RVdNNDh6L3BzaUpKVmNZL0FuSmZQM2Z1bG1HSnZGbVYzCkN0NjlRVnJKUTNVdzBTNkpqUkEzVlZkTEZjUXVrTWVpZ0MyWmJ4c21PWUZBZk1lTmtLbjVrRW5hd1IyOGRRSVMKN1NQZU02bm9mKzA0Sk5aK3VuNFFyN1JzWk9HZXdpbHRRYkh1V3lucXZxcTVTb09ISTlMV0NLQlZocnNrYWZaSgpZckc4MXZJTnk1TUIrR3UrVUdoVmlVbmlEeDU1OURaMlFxUTNqOStIL0E9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-05-21T18:20:23Z" lastUpdateTime: "2026-05-21T18:20:23Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved