--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-05-20T14:08:44Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-05-20T14:08:44Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-05-20T14:08:44Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-05-20T14:08:44Z" name: csr-jg2bl resourceVersion: "5130" uid: 7333ed2c-8285-4cd2-816c-46c73d7bd7e8 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=61a809b81b182674e16884d09766079452ba2a6232ac52d4551b5b08f2572e24 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0xTFRFeU1DNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFRd2lQKzd5Q29nbitaMWdjR0I4RVVKQjYzQnVjY3p0a21VUWN6K0FkSkcKQld5UUd5aHhtUXAwelErU2Q3emdpYjJ4MlhrdDQ5SUdoY2xrdFJ1Zy82emhvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJaEFLbTFvSWVIa2hPNU4yWEVFVklvb3B2anVFeGs0a2hDbnJDQVM2N0hDZS9jQWlBd0xSRE1rUHhvCisxZmV2OVVuQ0cwbUdYaERCZjR4SEVIOGlVdVUvb1o3Q0E9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQU1IL1BONXR2MTFCZDZEazdTV1JseFF3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05USXdNVFF3TXpRMFdoY05Namd3TlRFNU1UUXdNelEwV2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0xTFRFeU1DNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFRd2lQKzd5Q29nbitaMQpnY0dCOEVVSkI2M0J1Y2N6dGttVVFjeitBZEpHQld5UUd5aHhtUXAwelErU2Q3emdpYjJ4MlhrdDQ5SUdoY2xrCnRSdWcvNnpobzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUxWdEF0aW5OUDlPcU1xQzJIOFJJenVSWjBSMAp1d1c5N1UzVnFzOHdlRWxTd1VVZVM5amV0aFhmQ3QyRFhyaWJPcFJOdEtIVXJOZGNtNkIwQWJ1ZGZERXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUtEV0w5N2NiVGh5RGU3enhOcU94a2VXUEc5bm5FSHdzNy9ON0EwTFFRYjcKeHk4eU5FcWs4ZVpiZFNJZDFwS1NUV1V1bVVqYnY4bk1kb2hRVWJTYTVEN2kzVVdpWGEzckcyd0VTWStjbjY3QgoxWnJpdEdqVWRYazFWdDJsd01XbjZ3Q1RLN01KOWxMSWdqSlZ1VU1tcDJsT29DTmZ6VlNvYWN4NEdSV3oxMGpOCmpKV2Q2OGwyM1VPMFBNbTkwL1hJci8yaUZ0anYyVXBsRSsrYnBVT20wZHU2bThOdXZsVGF6NTFybnhoUWhwU0IKWWZIcllTL1FRQmt6VmNFc3pYa1RXREU0aUlDWDZRMWFEdnFZSitIaFRZTWZoOGJ0M1Z5YWo0NDg1dFZnOXhkTQprWEt6ZjltZE54SUVHaFFJaENQUnRBUmtsVEpWa005WXlobFlJZGhkRkRjPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-05-20T14:08:44Z" lastUpdateTime: "2026-05-20T14:08:44Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved