--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-06-02T17:01:26Z" generateName: csr- managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-06-02T17:01:26Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} manager: kubelet operation: Update time: "2026-06-02T17:01:26Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: machine-approver operation: Update subresource: approval time: "2026-06-02T17:01:26Z" name: csr-r7wdb resourceVersion: "5560" uid: f4d06e9e-a022-44cc-bafe-9cdfbfcb6a2d spec: extra: authentication.kubernetes.io/credential-id: - X509SHA256=de4d14f466d56298f51cca5ce0b3a2a37f48893d2f518adf76d0a85d55895b66 groups: - system:serviceaccounts - system:serviceaccounts:openshift-machine-config-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkJUQ0JyQUlCQURCS01SVXdFd1lEVlFRS0V3eHplWE4wWlcwNmJtOWtaWE14TVRBdkJnTlZCQU1US0hONQpjM1JsYlRwdWIyUmxPbWx3TFRFd0xUQXRNVFF4TFRFME1pNWxZekl1YVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFTZE82N3NWSHlCeHVxYmtGKzRISEt4RGZCNktmdEJFeUpNSE90YXQ3cGYKWmN3cGZDOXBMdWUxZCsxTkhyUVhiNUZNMFN1U0ZvRXk0LzJhbEJTOGJCWVpvQUF3Q2dZSUtvWkl6ajBFQXdJRApTQUF3UlFJaEFOaGM1dXUwMmVKTEhXdkZhcUgrNTdDNUllOUwwRDE2bG5OeEk5TWhHVmxVQWlCV3dhWFV4a3hTCjE4Ynd1TDE4cVRFbHFpT0JZTkZSdFo4Z3NvSVBHa3RQYmc9PQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K signerName: kubernetes.io/kube-apiserver-client-kubelet usages: - digital signature - client auth username: system:serviceaccount:openshift-machine-config-operator:node-bootstrapper status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUN1ekNDQWFPZ0F3SUJBZ0lRRVYzRnFHSW9YY0cyQVBTL2pKNy9rREFOQmdrcWhraUc5dzBCQVFzRkFEQXUKTVJJd0VBWURWUVFMRXdsdmNHVnVjMmhwWm5ReEdEQVdCZ05WQkFNVEQydDFZbVV0WTNOeUxYTnBaMjVsY2pBZQpGdzB5TmpBMk1ESXhOalUyTWpaYUZ3MHlPREEyTURFeE5qVTJNalphTUVveEZUQVRCZ05WQkFvVERITjVjM1JsCmJUcHViMlJsY3pFeE1DOEdBMVVFQXhNb2MzbHpkR1Z0T201dlpHVTZhWEF0TVRBdE1DMHhOREV0TVRReUxtVmoKTWk1cGJuUmxjbTVoYkRCWk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQkowN3J1eFVmSUhHNnB1UQpYN2djY3JFTjhIb3ArMEVUSWt3YzYxcTN1bDlsekNsOEwya3U1N1YzN1UwZXRCZHZrVXpSSzVJV2dUTGovWnFVCkZMeHNGaG1qZ1lNd2dZQXdEZ1lEVlIwUEFRSC9CQVFEQWdlQU1CTUdBMVVkSlFRTU1Bb0dDQ3NHQVFVRkJ3TUMKTUF3R0ExVWRFd0VCL3dRQ01BQXdTd1lEVlIwakJFUXdRb0JBa2dQV0FvYjZhRHFsTXlSNVFzTzV2K3lHN2JkUwpsa3daZkJmME9HQnI5dkRBYis1MTRQSWxNbkFnOTVVbXFKL28zWXphSE10dnFYRWpkeUc1RUtha2Z6QU5CZ2txCmhraUc5dzBCQVFzRkFBT0NBUUVBZjNmZm9qaVZad0IzVm9rQ3g0em9RYUViaFdOVk4vRXJzOXIvMmExYVhrNm8KUU9jQ2tCdTFPcmJCaWFZSEsvWGozc2VkYWg2MTF1NFV6QS9rK3N5Z1YyTER0L2tPRmM1K0lXb0xsV2tQbzdNdgpiK3JxaExSakNKRm9rM3BibFd3K1Y0VFl4elkzQkFDTjlCM1Z1K1E1Z1JPYUc0anpSRmZIdFQ2SFB0cXpzL29UClhwKzZPYTNYNDJlY0E4QUllSFYydUZqUktpVWlkMlFtbm13RHVnVldQK2lwWTAyQWljL1IrMzg2RXJjK21LK0sKbVlJZ3JTU0lRS0Y0TGhjc3lIbjROdnNNSzZKcU5jRVBXeGhCeFFOMzFJZERUWm1LbG9VQUpBNXJwNU9qZFI3VgpuUEhGamVtaDV6d0htcDFmMkZDQUJWbkpCU0hlZHhtTXJNVTQ1UkcrTFE9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== conditions: - lastTransitionTime: "2026-06-02T17:01:26Z" lastUpdateTime: "2026-06-02T17:01:26Z" message: This CSR was approved by the Node CSR Approver (cluster-machine-approver) reason: NodeCSRApprove status: "True" type: Approved