--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-04-20T10:01:12Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-04-20T10:01:12Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-04-20T10:01:12Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-04-20T10:01:12Z" name: csr-thwg8 resourceVersion: "5340" uid: 7d3d670d-7d58-49b5-aac3-cf17b6ad4b7a spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=ec589a6dc98b3bbaaf529dce872e50eb8c376b9cb985c128843fc97807674ea5 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0zTFRFd05pNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFUM3p0bVFnMUF4dU1mQU9zcTFMMXZ2dUdkNS8vcDh6OGVyS3NyS2VEamMKTlM0Yk4xU3NWWmR5RS82T1RvMjZzSVE5VHZIb2RHRWwyUlE5V1F0bzdZdVRvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJZ01lZEY5L0l0M3VPVk1hek5qcTBqUGxMUmV1aEFEZUpPTGtnWjJaekRlTUlDSVFDK2J4VXpjNXBHCjQrRDdQTElkUlQ4RHdxVG0xanBpb3VwUG9GWlVkSTNDSGc9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN2RENDQWFTZ0F3SUJBZ0lSQVBqWVJzWUNER1FOa3dVWXJ1MFVLa013RFFZSktvWklodmNOQVFFTEJRQXcKTGpFU01CQUdBMVVFQ3hNSmIzQmxibk5vYVdaME1SZ3dGZ1lEVlFRREV3OXJkV0psTFdOemNpMXphV2R1WlhJdwpIaGNOTWpZd05ESXdNRGsxTmpFeVdoY05Namd3TkRFNU1EazFOakV5V2pCS01SVXdFd1lEVlFRS0V3eHplWE4wClpXMDZibTlrWlhNeE1UQXZCZ05WQkFNVEtITjVjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVE0zTFRFd05pNWwKWXpJdWFXNTBaWEp1WVd3d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFUM3p0bVFnMUF4dU1mQQpPc3ExTDF2dnVHZDUvL3A4ejhlcktzcktlRGpjTlM0Yk4xU3NWWmR5RS82T1RvMjZzSVE5VHZIb2RHRWwyUlE5CldRdG83WXVUbzRHRE1JR0FNQTRHQTFVZER3RUIvd1FFQXdJSGdEQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNRXNHQTFVZEl3UkVNRUtBUUtMMXhKeGRSY1NHcTZ1bHJ0OWVITHhkS0cxZgpPUEhPM3hGVzNnNHYwZFM4MkVONDhTSUxrVzJqekxUcyt5NWFZa3pYK0FYMkJLTUhrM0dtZCt2b1UxWXdEUVlKCktvWklodmNOQVFFTEJRQURnZ0VCQUxoQkhucGw5aEJwYWk1NmoxK0ZFUXpzUE5LRHRVb21JcFV5NWdXUXFObnMKVnlVUGcyWkh1b2p0TGl0MXBQcVowck93NU9rOXVneldjMDE4aU5heW45NVMrTGpFRWIxSnJobzduVGNGK2VHNgpLcURjQ0l5MklnOVEwbmpXY0pZamM2OGdRNlBIRW1EZmxrcXFqTExXWkFrZ1UzNmZTTkZPT2ZWZjdhSTFuK1A5CnlsOHNHUi9VeW5abUJiL2Zmd2JMYWkyc2t4eGlYaDY2SkFXWkZISW1jTHBKdm9Db3krNG03aElPM2NkQ3U0cjgKTmw1TkJvOFQzUkNRb20zOXI2OHdmY3pKaDE4N1pURG5HUGF2dld5TU56Z1drSDJGR3F1SEM2Q3kwU2FyNjZKZgpTa1FBOCtJRHlRSk1PVUJqNmc3MW9rNDZIT09HSEo0MXRYVUxtcUxFdCtvPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-04-20T10:01:12Z" lastUpdateTime: "2026-04-20T10:01:12Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved