--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-06-02T21:41:48Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-06-02T21:41:48Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-06-02T21:41:48Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-06-02T21:41:48Z" name: csr-z672k resourceVersion: "5791" uid: f09a53a9-b363-4694-a150-3eda226e8d07 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=5a212fe1f0a7ae993aad8f985fd457d9d128619e38852d426312f46493ccbbca groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkF6Q0Jxd0lCQURCSk1SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TURBdUJnTlZCQU1USjNONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE01TFRZM0xtVmpNaTVwYm5SbGNtNWhiREJaTUJNR0J5cUdTTTQ5CkFnRUdDQ3FHU000OUF3RUhBMElBQkZSbEZlUk9VM29GMTZhMzlMcnM4V3pjV2VXMWYxcUtwcWI0dkR6QzJYYjgKbE5WNGVWbnlBeTRHb3RMUThhRUlBOWo1azNCaXlVT0IyZGszMnFpeXRBS2dBREFLQmdncWhrak9QUVFEQWdOSApBREJFQWlCemk1QndyTkQ2WW55M3JnaDgvcVAxN0FoejZFVmhkbXdIVVN0bUFFd21EUUlnQ1lGcDBmdDlqQXF2Cm5Td3RRenQvNGJvbVVsVXY2VFVHQTU0ZU5uczZoWUU9Ci0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1akNDQWFLZ0F3SUJBZ0lRQmhuSkx6QXZDZ2d5eURpN3lvZFI1REFOQmdrcWhraUc5dzBCQVFzRkFEQXUKTVJJd0VBWURWUVFMRXdsdmNHVnVjMmhwWm5ReEdEQVdCZ05WQkFNVEQydDFZbVV0WTNOeUxYTnBaMjVsY2pBZQpGdzB5TmpBMk1ESXlNVE0yTkRoYUZ3MHlPREEyTURFeU1UTTJORGhhTUVreEZUQVRCZ05WQkFvVERITjVjM1JsCmJUcHViMlJsY3pFd01DNEdBMVVFQXhNbmMzbHpkR1Z0T201dlpHVTZhWEF0TVRBdE1DMHhNemt0TmpjdVpXTXkKTG1sdWRHVnlibUZzTUZrd0V3WUhLb1pJemowQ0FRWUlLb1pJemowREFRY0RRZ0FFVkdVVjVFNVRlZ1hYcHJmMAp1dXp4Yk54WjViVi9Xb3FtcHZpOFBNTFpkdnlVMVhoNVdmSURMZ2FpMHREeG9RZ0QyUG1UY0dMSlE0SFoyVGZhCnFMSzBBcU9CZ3pDQmdEQU9CZ05WSFE4QkFmOEVCQU1DQjRBd0V3WURWUjBsQkF3d0NnWUlLd1lCQlFVSEF3SXcKREFZRFZSMFRBUUgvQkFJd0FEQkxCZ05WSFNNRVJEQkNnRUN5QlJ4MXBDM3kvTHVBRUd5VmtBNCtCa2IxdytwRgpwL0Y5a1czYWhhaGV0TDB1bEFHYmo0bVNycHNMa3JCdFZGMG1aN0VRM1lxR3pzSTVRK09LanVIMk1BMEdDU3FHClNJYjNEUUVCQ3dVQUE0SUJBUUNJTHNpMjQ2VHZTY0NjbzNxMkN3ek5wMWJkZlkxV0RjdWQzMTdWM3VxdGRYaU4KWTJQTHkySGVscm5tdklNVWgxTFF5VjRScFlnejd4S0VTakU1alF6Y1ZsY2diMElJeG9mSmdWbk5CQTRKWjdPMgphUi9jcThmbis4NnB5ZTdFNnZqNEtBOXlEMW12OVkwY1hUN1FWNm1yZGFVZVB0Y1NPUDFVZTVrYUJUbUtkc2xECkpLaHA1cXNYWGs3MjVxR0ZEejBQS2x1N0p1cHp0T1lWYWlLZXlKV2k2S1ZvUVZNWWlGczUxUDRWY1doNktkVU0KNzVVdVVaZXA5Y2I2cHIzOVhqZWhNdk5vc1ZPNVVDRHBCc1g3TDJscWJaNXc4UjJuVTBaMFRpZ0RFd0hUZzh3NApHSklsOVpvZ0FpR3RZOWhwbmRUQTZlcENOQXVwd1dLZTdvQktWMzRECi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K conditions: - lastTransitionTime: "2026-06-02T21:41:48Z" lastUpdateTime: "2026-06-02T21:41:48Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved