--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-20T15:02:30Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-20T15:02:30Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-20T15:02:30Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-20T15:02:30Z" name: csr-hn6mx resourceVersion: "5641" uid: ff0dbd32-eb8b-4df1-a4be-61c7423d44e5 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=fa52a2085ef38a90839d3a839795fcb35064ce8f83b1f07c2860166283d4f4df groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJqQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVEk1TFRFeE5TNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFSYUZUU2lnbk1Ya3NwRFowaGdSOWJTSUJvd2NzeUJXQ1N3R1VIMi9RZkgKc1EzcjNjbGFrL1B2SnN5K3NyOWJpcnVxbUV4UURQaFgwQUp6N20wMG5NUnFvQUF3Q2dZSUtvWkl6ajBFQXdJRApTUUF3UmdJaEFOQ283UTdKNy85dFRPeE9ralRadmNuekl2QjR6a3hNK2dQZ3g1SDlBdkRpQWlFQXFyVVYzcnBhCm1YQ2FsaUFLTTRDZXVFSnpZQUd4ZDFURXJWNXd0NUt6eVhJPQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQU92SERtSUkxak9JcFJXMGN1KzU1RkF3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ESXdNVFExTnpNd1doY05Namd3TkRFNU1UUTFOek13V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVEk1TFRFeE5TNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFSYUZUU2lnbk1Ya3NwRApaMGhnUjliU0lCb3djc3lCV0NTd0dVSDIvUWZIc1EzcjNjbGFrL1B2SnN5K3NyOWJpcnVxbUV4UURQaFgwQUp6CjdtMDBuTVJxbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUlTL1lNajFJNDM4eEZQZzV1ZS96L20xOHFmMgplQ0ZSNlRtWml2VnpxWkM1QXNsQkVwZjNJYXd2ZlNsV1FUZ1FrdEUxSmhUVjJxZGZiSDlPRWZhNmp1Z3dEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUZCT0REV0VENUluWmc2VVZFRnh1TkJrZERpVDlFRHJ1Sy9uZTd1Z3Voc00KMm9YLzk1akRsMXNzNFExR29HMWRjT3l2aWtBYzVldGUyTDJCVksyQkQ0V1dZaFN1a3RRaG5sMHJYcVJ1TndUVQpNN1BGNXJPWU9Ydjk3Y0d1QkpoalR0TFZFeGdwbDVZc3k3eDdyMDZ1RkIyZkd4U0ZLaDRna0pnMkYrVTQ4ajB4Ci92WnEwSllab2M2MU5leUZaTFd5bDNyZllwUUNVUnp0NUE5UG92Snk4bkNncmFTN05yTnVlZGZ5TDRSMlR0N0sKcUlJU09VY3dJbDd2OVptRHJlYVRBc0ZCRVhBUSt0bGQ0eTJHeVVBNWZ1dEplZ1lsdVR2d0FtK3QxZE1sb3RRYwpuVVpwNFpwRmxMZ3MyaWkxSmdGTm1HT25SY3F2RFV2VUFWMEFRejFyclBFPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-04-20T15:02:30Z" lastUpdateTime: "2026-04-20T15:02:30Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved