--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-06-12T18:36:17Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-06-12T18:36:17Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-06-12T18:36:17Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-06-12T18:36:17Z" name: csr-wxcqj resourceVersion: "6640" uid: 9f3f9c2d-b6d3-4ba9-a7b3-6327b61fd6a2 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=86644f13acbd421abfc82d6e33066fe2e4e1fd4f7078cb2e06c25cbbceb08be5 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJqQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE15TFRFM05TNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFScnA4S2U4VnVKN3djNHEvSVZEZmxsSnlxQkdDdjVYVk4vdmFXbEFJYW0KWE9DYVhWNm02bStPT0tMSGs3Q3E0TXFxajlpRWFtUXRiLzBLR3BnZGQrTDFvQUF3Q2dZSUtvWkl6ajBFQXdJRApTUUF3UmdJaEFOOGVDNEU4K3lLVVo2NDUyaUlZNDdSa2h3M1pZMTZZTm81MTVtd3BQTnFrQWlFQXBhWEtyeUxECmZac2VOTnhSWFQvY3lXUEVvTWtJTEtKbGl2T0d1b292UlVNPQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQU9tTFo2dm8xYVRFTlhBVzB0SWptK293RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05qRXlNVGd6TVRFM1doY05Namd3TmpFeE1UZ3pNVEUzV2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE15TFRFM05TNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFScnA4S2U4VnVKN3djNApxL0lWRGZsbEp5cUJHQ3Y1WFZOL3ZhV2xBSWFtWE9DYVhWNm02bStPT0tMSGs3Q3E0TXFxajlpRWFtUXRiLzBLCkdwZ2RkK0wxbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUFvdFJLUit6RFZDdTcyQ1oxQ2hlQW9uOGJ2OApJQzRyMzVrQzFlYjBQckhCRXRNRk84OXBlZE56aDdKb0UyMC9ZTURKemtQQWw2Nk9PT0N6ZnZWOUdVVXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUh4ZmI2MkZEbGdZNlp5bFpvQnVZMXEwNy9mRnRqbUdnUGY2TllSNlBGZ1AKWDdwMmtvbkFqUEtUQ1VNd2Q0SW1pVU1YZkQ2VlFjY1Vlb05HMVZjQ2FhenZ3bWZ0cFhlSUVCb1pEMG5PbXFsNgp3bExXeVVsbmoxT3h3YmJzL2FPTUxtYWxQZEEwSzloeVNVUXZiK2ZDMHZiTHlISjdvOXRLNzlCZ3V1K3RPM2J5CjhRKzZpVGJWQkluKzdOaHY1SmhaY1cxYm4ram5DSDhBdDFSTytmRXY0aHZMdVM2M2FVVmx4NnppUnI4TkRVVWIKR0R2UUk5TC9LWTBtRlF2Q1IzSTlvdFd6SzFVS0ZuUHo2UXRRVDBEcFUxeFJydXJEVEhVUzBaeThTUFhma1RFTApPeHhsTlVuUCtkaFU3cmhaY2YzMGNBamRITlZPSGkzdUVHVmVVZEtyYndvPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-06-12T18:36:17Z" lastUpdateTime: "2026-06-12T18:36:17Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved