Copying system trust bundle I0428 13:00:19.134007 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0428 13:00:19.134257 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com" I0428 13:00:19.462516 1 audit.go:340] Using audit backend: ignoreErrors I0428 13:00:19.473296 1 requestheader_controller.go:244] Loaded a new request header values for RequestHeaderAuthRequestController I0428 13:00:19.503418 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0428 13:00:19.503517 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0428 13:00:19.503569 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0428 13:00:19.503601 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0428 13:00:19.507756 1 secure_serving.go:57] Forcing use of http/1.1 only I0428 13:00:19.507776 1 genericapiserver.go:528] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete I0428 13:00:19.511628 1 requestheader_controller.go:169] Starting RequestHeaderAuthRequestController I0428 13:00:19.511700 1 shared_informer.go:311] Waiting for caches to sync for RequestHeaderAuthRequestController I0428 13:00:19.511651 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0428 13:00:19.511763 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0428 13:00:19.511653 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0428 13:00:19.511780 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0428 13:00:19.511989 1 dynamic_serving_content.go:132] "Starting controller" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0428 13:00:19.512057 1 dynamic_serving_content.go:132] "Starting controller" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com" I0428 13:00:19.512104 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777376945\" (2026-04-28 11:49:27 +0000 UTC to 2028-04-27 11:49:28 +0000 UTC (now=2026-04-28 13:00:19.512061768 +0000 UTC))" I0428 13:00:19.512340 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777376974\" (2026-04-28 11:49:34 +0000 UTC to 2028-04-27 11:49:35 +0000 UTC (now=2026-04-28 13:00:19.512315898 +0000 UTC))" I0428 13:00:19.512442 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381219\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381219\" (2026-04-28 12:00:19 +0000 UTC to 2027-04-28 12:00:19 +0000 UTC (now=2026-04-28 13:00:19.512429049 +0000 UTC))" I0428 13:00:19.512464 1 secure_serving.go:213] Serving securely on [::]:6443 I0428 13:00:19.512479 1 genericapiserver.go:681] [graceful-termination] waiting for shutdown to be initiated I0428 13:00:19.512491 1 tlsconfig.go:240] "Starting DynamicServingCertificateController" I0428 13:00:19.513816 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 13:00:19.513874 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 13:00:19.514318 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 13:00:19.517851 1 reflector.go:351] Caches populated for *v1.Group from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 13:00:19.612074 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0428 13:00:19.612096 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0428 13:00:19.612138 1 shared_informer.go:318] Caches are synced for RequestHeaderAuthRequestController I0428 13:00:19.612399 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-28 11:33:39 +0000 UTC to 2026-04-29 11:33:39 +0000 UTC (now=2026-04-28 13:00:19.612369453 +0000 UTC))" I0428 13:00:19.612528 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777376945\" (2026-04-28 11:49:27 +0000 UTC to 2028-04-27 11:49:28 +0000 UTC (now=2026-04-28 13:00:19.612515666 +0000 UTC))" I0428 13:00:19.612644 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777376974\" (2026-04-28 11:49:34 +0000 UTC to 2028-04-27 11:49:35 +0000 UTC (now=2026-04-28 13:00:19.612625352 +0000 UTC))" I0428 13:00:19.612744 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381219\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381219\" (2026-04-28 12:00:19 +0000 UTC to 2027-04-28 12:00:19 +0000 UTC (now=2026-04-28 13:00:19.612735661 +0000 UTC))" I0428 13:00:19.612843 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-28 11:33:37 +0000 UTC to 2036-04-25 11:33:37 +0000 UTC (now=2026-04-28 13:00:19.612833372 +0000 UTC))" I0428 13:00:19.612857 1 tlsconfig.go:178] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-signer\" [] issuer=\"\" (2026-04-28 11:33:41 +0000 UTC to 2026-04-29 11:33:41 +0000 UTC (now=2026-04-28 13:00:19.612850063 +0000 UTC))" I0428 13:00:19.612874 1 tlsconfig.go:178] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-28 11:33:41 +0000 UTC to 2027-04-28 11:33:41 +0000 UTC (now=2026-04-28 13:00:19.612864858 +0000 UTC))" I0428 13:00:19.612886 1 tlsconfig.go:178] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-28 11:33:42 +0000 UTC to 2027-04-28 11:33:42 +0000 UTC (now=2026-04-28 13:00:19.612880312 +0000 UTC))" I0428 13:00:19.612894 1 tlsconfig.go:178] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-bootstrap-kubeconfig-signer\" [] issuer=\"\" (2026-04-28 11:33:38 +0000 UTC to 2036-04-25 11:33:38 +0000 UTC (now=2026-04-28 13:00:19.612889396 +0000 UTC))" I0428 13:00:19.612906 1 tlsconfig.go:178] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer_@1777376945\" [] issuer=\"kubelet-signer\" (2026-04-28 11:49:04 +0000 UTC to 2026-04-29 11:33:41 +0000 UTC (now=2026-04-28 13:00:19.612900416 +0000 UTC))" I0428 13:00:19.612915 1 tlsconfig.go:178] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"openshift-kube-apiserver-operator_node-system-admin-signer@1777376944\" [] issuer=\"\" (2026-04-28 11:49:03 +0000 UTC to 2027-04-28 11:49:04 +0000 UTC (now=2026-04-28 13:00:19.612909359 +0000 UTC))" I0428 13:00:19.612926 1 tlsconfig.go:178] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-28 11:33:39 +0000 UTC to 2026-04-29 11:33:39 +0000 UTC (now=2026-04-28 13:00:19.612921523 +0000 UTC))" I0428 13:00:19.613035 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777376945\" (2026-04-28 11:49:27 +0000 UTC to 2028-04-27 11:49:28 +0000 UTC (now=2026-04-28 13:00:19.613021931 +0000 UTC))" I0428 13:00:19.613153 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool418-bb45f.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777376974\" (2026-04-28 11:49:34 +0000 UTC to 2028-04-27 11:49:35 +0000 UTC (now=2026-04-28 13:00:19.613127992 +0000 UTC))" I0428 13:00:19.613249 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381219\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381219\" (2026-04-28 12:00:19 +0000 UTC to 2027-04-28 12:00:19 +0000 UTC (now=2026-04-28 13:00:19.613241462 +0000 UTC))" W0428 13:11:25.121409 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"02bb6e46-d274-4f47-a0cb-a985cdd39e4f", it has already been set to "kubeadmin" W0428 13:12:08.597703 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"5315775a-19d1-4404-9fb8-7ddc482e5c56", it has already been set to "kubeadmin"