--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-20T17:48:01Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-20T17:48:01Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-20T17:48:01Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-20T17:48:01Z" name: csr-xltk9 resourceVersion: "5368" uid: 62373f22-117b-494c-b915-45218fa8b551 spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=34382c17fbf07fe665855d039020dd079ec1a203e67ce800851cc74ee866bfdf groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkF6Q0JxZ0lCQURCSU1SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14THpBdEJnTlZCQU1USm5ONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE00TFRrdVpXTXlMbWx1ZEdWeWJtRnNNRmt3RXdZSEtvWkl6ajBDCkFRWUlLb1pJemowREFRY0RRZ0FFL2V3M3lUWlkwWnVlbmJkbmRTVjNIN2xlbUhPNVc3WEpVSVo0bHFFeHZ3dVkKeUZqNXZVTGYvOW4wOXpXTExLWXNwNzVGZklkakpVbEJ1dFRjdUJwb0thQUFNQW9HQ0NxR1NNNDlCQU1DQTBnQQpNRVVDSVFESDdxZXlJN2VpdC81NSttdSt4NkVTTzJ0cG1qMlZoNGNBMVB5Q0xHR3gvQUlnY0lOaS9HbDc3VzA0Cm1ZMmpPUWVLMytudmtrS1E1dHdFUHhubWYvTjRwaHc9Ci0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1akNDQWFLZ0F3SUJBZ0lSQUs0d1l2L0U3VkJrQmI1dk1xa3JvMUF3RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ESXdNVGMwTXpBeFdoY05Namd3TkRFNU1UYzBNekF4V2pCSU1SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeEx6QXRCZ05WQkFNVEpuTjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE00TFRrdVpXTXkKTG1sdWRHVnlibUZzTUZrd0V3WUhLb1pJemowQ0FRWUlLb1pJemowREFRY0RRZ0FFL2V3M3lUWlkwWnVlbmJkbgpkU1YzSDdsZW1ITzVXN1hKVUlaNGxxRXh2d3VZeUZqNXZVTGYvOW4wOXpXTExLWXNwNzVGZklkakpVbEJ1dFRjCnVCcG9LYU9CZ3pDQmdEQU9CZ05WSFE4QkFmOEVCQU1DQjRBd0V3WURWUjBsQkF3d0NnWUlLd1lCQlFVSEF3SXcKREFZRFZSMFRBUUgvQkFJd0FEQkxCZ05WSFNNRVJEQkNnRUJpLzFqY08zTXIrWXZ1djlseUtrS2RUT1g5d1pCMAptVFk3YWFkMnJVMDhjYVdneWladGVYY0FrTE8yUHlJZnNCVnN2OTFwaEZjSkJxSFFaanNvOWNpZU1BMEdDU3FHClNJYjNEUUVCQ3dVQUE0SUJBUUFpdXdlQ3hrOVFETXlUZi84NUNHOVBMb1V5dnpqOUNGbFc3Z0ZTU21sZFQ3RHUKbmxNemVXYlhpb2ltTElaS2ZlQ3BLdWdxZlhqWEtCM0cvS2QvalMzUUtJcXMwOSs4OFA4Uk5TcVROZERDTlhWMgpZMFR0VnZkdDBMUGdISUJQWlhPb0ZNcUtPdEN5Yi9XZ3BNbWpxdXppQWRPd2pxb28wbmk2NS80UVE4QkpuMUxsCjFpTk9Ycnh2NERrTG9PUGg0UzVhRUlNRU9GYVRJRTRia0dadkoxeThaSmZUdDJwV3ZpNHNCUmx6TFl4Z2NxNW0KSCtENFk5Q3U4SXUxZHpXV1VOSzh2MXpGSkRqOHFjZkJEM3lNSVUwSERtWFB6NHVTbUlQUzJpbFJBSklWUWJteQpvcWRhL2puZzNzS2ZqQTVLQkRhbzJsVllhV20wRGtUVHhCZkUrT3R4Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K conditions: - lastTransitionTime: "2026-04-20T17:48:01Z" lastUpdateTime: "2026-04-20T17:48:01Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved