--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-05-21T15:31:30Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-05-21T15:31:30Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-05-21T15:31:30Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-05-21T15:31:30Z" name: csr-c7k7g resourceVersion: "5345" uid: 02a1e226-35f4-4800-a9f5-f8711e4fad49 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=f5cdf2edf5c8b70d03084c673298aeb393d04116303a6550dbbcb1486a1bcbd8 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0xTFRJeU9DNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFSUnJEVzZZNjhsaGRGTStqRi9wUnA1R245eUo3c21ncjZzVjhxVHk4Q2UKWC9DT0NNYkRHaFpvVE9IV1NLaEhNcllKTWNBNk45cndCMkZQazdqVFVISElvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJZ0hld2orMkRqQ3gxVHFDWU8zMUFrUUg1OWY2dHo1aW42ZVFwbUpWT3kyU1FDSVFDc21VamRGRWlaCjh6OFVvY2xpdkJ0Y0JLN1lLbE96ZXU0REFLSkR1TXZMT3c9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQUpodk9sQnJ5YlA4WkwxK3I3VnJZSkl3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05USXhNVFV5TmpNd1doY05Namd3TlRJd01UVXlOak13V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0xTFRJeU9DNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFSUnJEVzZZNjhsaGRGTQorakYvcFJwNUduOXlKN3NtZ3I2c1Y4cVR5OENlWC9DT0NNYkRHaFpvVE9IV1NLaEhNcllKTWNBNk45cndCMkZQCms3alRVSEhJbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUU42aWNnQVIxaXVLQXJrdjRVekZiTXFJTVdwKwpxRlBaamIwRWQrMGZsV0xCZ1ZGQlNjWDQ1OTA1dC9LcFptK25EYmdvcll2TDR4d1U3bjdBNXU3QTB5QXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUc3REpqTVpwKzF1cWkwWnJlMi9GQkNzQVZURUZFeUNHaG4rKytQZUFpbEIKajhoK2E4Q2xOU0NZeUx3dHBZU2hkRmU5YmNWdExVQ2pzaysrK1ZXUkVDeC9oUFROaGdrSVE4Mlg2YUhRbkk1VQpSNHdSZ29WZ2pURk5pNXBtTmhrTytZSDlBbEhmcC9RT0tGUDdSbU12WXRBTDZvakFaU212ZmpNRkRCQkt4a24rCmloaGlKaHlQOU1kYUE2TnR2ZXdjemU5bUZGdHlnWTdVODlhTHMyYnEvWGV1eElybWxnaFVDdDUxL3EwSGo4dksKQ3hKQ3JMSjYzOGJYaWpuc2YwL3V5TlA3ZFEyL3c5ZzBRN3BxaUhNaVFEb1ByNnUzMHJuT3JBQzhBN3p6RzFFTgo5UWY1QWEwWUp1dTQ5aVk5YWY0TUpnUkVnRWpYcnVEL2hEdDlWR2FENlVjPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-05-21T15:31:30Z" lastUpdateTime: "2026-05-21T15:31:30Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved