Copying system trust bundle I0424 12:26:09.352915 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0424 12:26:09.353149 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com" I0424 12:26:09.613337 1 audit.go:340] Using audit backend: ignoreErrors I0424 12:26:09.625771 1 requestheader_controller.go:244] Loaded a new request header values for RequestHeaderAuthRequestController I0424 12:26:09.636398 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0424 12:26:09.636417 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0424 12:26:09.636436 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0424 12:26:09.636440 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0424 12:26:09.640188 1 secure_serving.go:57] Forcing use of http/1.1 only I0424 12:26:09.640482 1 genericapiserver.go:528] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete I0424 12:26:09.644363 1 requestheader_controller.go:169] Starting RequestHeaderAuthRequestController I0424 12:26:09.644445 1 shared_informer.go:311] Waiting for caches to sync for RequestHeaderAuthRequestController I0424 12:26:09.644372 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0424 12:26:09.644479 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0424 12:26:09.644383 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0424 12:26:09.644490 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0424 12:26:09.644701 1 dynamic_serving_content.go:132] "Starting controller" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0424 12:26:09.644780 1 dynamic_serving_content.go:132] "Starting controller" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com" I0424 12:26:09.644856 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777028932\" (2026-04-24 11:09:16 +0000 UTC to 2028-04-23 11:09:17 +0000 UTC (now=2026-04-24 12:26:09.644814791 +0000 UTC))" I0424 12:26:09.645028 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777029007\" (2026-04-24 11:10:08 +0000 UTC to 2028-04-23 11:10:09 +0000 UTC (now=2026-04-24 12:26:09.644998777 +0000 UTC))" I0424 12:26:09.645142 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777033569\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777033569\" (2026-04-24 11:26:09 +0000 UTC to 2027-04-24 11:26:09 +0000 UTC (now=2026-04-24 12:26:09.645132617 +0000 UTC))" I0424 12:26:09.645162 1 secure_serving.go:213] Serving securely on [::]:6443 I0424 12:26:09.645179 1 genericapiserver.go:681] [graceful-termination] waiting for shutdown to be initiated I0424 12:26:09.645192 1 tlsconfig.go:240] "Starting DynamicServingCertificateController" I0424 12:26:09.646941 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0424 12:26:09.647350 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0424 12:26:09.647570 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0424 12:26:09.651435 1 reflector.go:351] Caches populated for *v1.Group from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0424 12:26:09.745432 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0424 12:26:09.745432 1 shared_informer.go:318] Caches are synced for RequestHeaderAuthRequestController I0424 12:26:09.745449 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0424 12:26:09.745730 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-24 10:50:24 +0000 UTC to 2026-04-25 10:50:24 +0000 UTC (now=2026-04-24 12:26:09.745701664 +0000 UTC))" I0424 12:26:09.745863 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777028932\" (2026-04-24 11:09:16 +0000 UTC to 2028-04-23 11:09:17 +0000 UTC (now=2026-04-24 12:26:09.745849894 +0000 UTC))" I0424 12:26:09.745971 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777029007\" (2026-04-24 11:10:08 +0000 UTC to 2028-04-23 11:10:09 +0000 UTC (now=2026-04-24 12:26:09.745960274 +0000 UTC))" I0424 12:26:09.746056 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777033569\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777033569\" (2026-04-24 11:26:09 +0000 UTC to 2027-04-24 11:26:09 +0000 UTC (now=2026-04-24 12:26:09.746048283 +0000 UTC))" I0424 12:26:09.746144 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-24 10:50:22 +0000 UTC to 2036-04-21 10:50:22 +0000 UTC (now=2026-04-24 12:26:09.746135596 +0000 UTC))" I0424 12:26:09.746157 1 tlsconfig.go:178] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-signer\" [] issuer=\"\" (2026-04-24 10:50:25 +0000 UTC to 2026-04-25 10:50:25 +0000 UTC (now=2026-04-24 12:26:09.746150845 +0000 UTC))" I0424 12:26:09.746166 1 tlsconfig.go:178] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-24 10:50:25 +0000 UTC to 2027-04-24 10:50:25 +0000 UTC (now=2026-04-24 12:26:09.746159791 +0000 UTC))" I0424 12:26:09.746175 1 tlsconfig.go:178] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-24 10:50:25 +0000 UTC to 2027-04-24 10:50:25 +0000 UTC (now=2026-04-24 12:26:09.746170132 +0000 UTC))" I0424 12:26:09.746185 1 tlsconfig.go:178] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-bootstrap-kubeconfig-signer\" [] issuer=\"\" (2026-04-24 10:50:23 +0000 UTC to 2036-04-21 10:50:23 +0000 UTC (now=2026-04-24 12:26:09.746179256 +0000 UTC))" I0424 12:26:09.746197 1 tlsconfig.go:178] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer_@1777028935\" [] issuer=\"kubelet-signer\" (2026-04-24 11:08:54 +0000 UTC to 2026-04-25 10:50:25 +0000 UTC (now=2026-04-24 12:26:09.746191498 +0000 UTC))" I0424 12:26:09.746207 1 tlsconfig.go:178] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"openshift-kube-apiserver-operator_node-system-admin-signer@1777028934\" [] issuer=\"\" (2026-04-24 11:08:53 +0000 UTC to 2029-04-23 11:08:54 +0000 UTC (now=2026-04-24 12:26:09.746201145 +0000 UTC))" I0424 12:26:09.746216 1 tlsconfig.go:178] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-24 10:50:24 +0000 UTC to 2026-04-25 10:50:24 +0000 UTC (now=2026-04-24 12:26:09.746210667 +0000 UTC))" I0424 12:26:09.746293 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777028932\" (2026-04-24 11:09:16 +0000 UTC to 2028-04-23 11:09:17 +0000 UTC (now=2026-04-24 12:26:09.746283605 +0000 UTC))" I0424 12:26:09.746382 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool419-52vmb.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777029007\" (2026-04-24 11:10:08 +0000 UTC to 2028-04-23 11:10:09 +0000 UTC (now=2026-04-24 12:26:09.746373212 +0000 UTC))" I0424 12:26:09.746459 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777033569\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777033569\" (2026-04-24 11:26:09 +0000 UTC to 2027-04-24 11:26:09 +0000 UTC (now=2026-04-24 12:26:09.74645224 +0000 UTC))" W0424 12:39:15.843636 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"ab9b7a3f-5867-4100-9280-9f2ad0c31f70", it has already been set to "kubeadmin"