Copying system trust bundle I0428 12:58:24.315247 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0428 12:58:24.315537 1 dynamic_serving_content.go:113] "Loaded a new cert/key pair" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com" I0428 12:58:24.725824 1 audit.go:340] Using audit backend: ignoreErrors I0428 12:58:24.736416 1 requestheader_controller.go:244] Loaded a new request header values for RequestHeaderAuthRequestController I0428 12:58:24.746758 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0428 12:58:24.746818 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0428 12:58:24.746851 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0428 12:58:24.746868 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0428 12:58:24.750169 1 secure_serving.go:57] Forcing use of http/1.1 only I0428 12:58:24.750191 1 genericapiserver.go:528] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete I0428 12:58:24.753430 1 requestheader_controller.go:169] Starting RequestHeaderAuthRequestController I0428 12:58:24.753490 1 shared_informer.go:311] Waiting for caches to sync for RequestHeaderAuthRequestController I0428 12:58:24.753441 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0428 12:58:24.753528 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0428 12:58:24.753467 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0428 12:58:24.753539 1 shared_informer.go:311] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0428 12:58:24.753823 1 dynamic_serving_content.go:132] "Starting controller" name="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" I0428 12:58:24.753917 1 dynamic_serving_content.go:132] "Starting controller" name="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com" I0428 12:58:24.754084 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777378979\" (2026-04-28 12:23:22 +0000 UTC to 2028-04-27 12:23:23 +0000 UTC (now=2026-04-28 12:58:24.754051607 +0000 UTC))" I0428 12:58:24.754321 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777379050\" (2026-04-28 12:24:13 +0000 UTC to 2028-04-27 12:24:14 +0000 UTC (now=2026-04-28 12:58:24.754306232 +0000 UTC))" I0428 12:58:24.754466 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381104\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381104\" (2026-04-28 11:58:24 +0000 UTC to 2027-04-28 11:58:24 +0000 UTC (now=2026-04-28 12:58:24.754458314 +0000 UTC))" I0428 12:58:24.754488 1 secure_serving.go:213] Serving securely on [::]:6443 I0428 12:58:24.754504 1 genericapiserver.go:681] [graceful-termination] waiting for shutdown to be initiated I0428 12:58:24.754520 1 tlsconfig.go:240] "Starting DynamicServingCertificateController" I0428 12:58:24.755395 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 12:58:24.755397 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 12:58:24.755410 1 reflector.go:351] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 12:58:24.759256 1 reflector.go:351] Caches populated for *v1.Group from k8s.io/client-go@v0.29.2/tools/cache/reflector.go:229 I0428 12:58:24.854241 1 shared_informer.go:318] Caches are synced for RequestHeaderAuthRequestController I0428 12:58:24.854262 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0428 12:58:24.854241 1 shared_informer.go:318] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0428 12:58:24.854458 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-28 12:06:06 +0000 UTC to 2026-04-29 12:06:06 +0000 UTC (now=2026-04-28 12:58:24.854432102 +0000 UTC))" I0428 12:58:24.854679 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777378979\" (2026-04-28 12:23:22 +0000 UTC to 2028-04-27 12:23:23 +0000 UTC (now=2026-04-28 12:58:24.85466634 +0000 UTC))" I0428 12:58:24.854819 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777379050\" (2026-04-28 12:24:13 +0000 UTC to 2028-04-27 12:24:14 +0000 UTC (now=2026-04-28 12:58:24.854806704 +0000 UTC))" I0428 12:58:24.854939 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381104\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381104\" (2026-04-28 11:58:24 +0000 UTC to 2027-04-28 11:58:24 +0000 UTC (now=2026-04-28 12:58:24.854930726 +0000 UTC))" I0428 12:58:24.855063 1 tlsconfig.go:178] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-28 12:06:03 +0000 UTC to 2036-04-25 12:06:03 +0000 UTC (now=2026-04-28 12:58:24.855015064 +0000 UTC))" I0428 12:58:24.855081 1 tlsconfig.go:178] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-signer\" [] issuer=\"\" (2026-04-28 12:06:08 +0000 UTC to 2026-04-29 12:06:08 +0000 UTC (now=2026-04-28 12:58:24.85507281 +0000 UTC))" I0428 12:58:24.855091 1 tlsconfig.go:178] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-28 12:06:09 +0000 UTC to 2027-04-28 12:06:09 +0000 UTC (now=2026-04-28 12:58:24.855084389 +0000 UTC))" I0428 12:58:24.855101 1 tlsconfig.go:178] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-28 12:06:09 +0000 UTC to 2027-04-28 12:06:09 +0000 UTC (now=2026-04-28 12:58:24.855095056 +0000 UTC))" I0428 12:58:24.855115 1 tlsconfig.go:178] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kubelet-bootstrap-kubeconfig-signer\" [] issuer=\"\" (2026-04-28 12:06:04 +0000 UTC to 2036-04-25 12:06:04 +0000 UTC (now=2026-04-28 12:58:24.855107267 +0000 UTC))" I0428 12:58:24.855136 1 tlsconfig.go:178] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer_@1777378976\" [] issuer=\"kubelet-signer\" (2026-04-28 12:22:56 +0000 UTC to 2026-04-29 12:06:09 +0000 UTC (now=2026-04-28 12:58:24.855126571 +0000 UTC))" I0428 12:58:24.855149 1 tlsconfig.go:178] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"openshift-kube-apiserver-operator_node-system-admin-signer@1777378980\" [] issuer=\"\" (2026-04-28 12:22:59 +0000 UTC to 2029-04-27 12:23:00 +0000 UTC (now=2026-04-28 12:58:24.855142878 +0000 UTC))" I0428 12:58:24.855160 1 tlsconfig.go:178] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-28 12:06:06 +0000 UTC to 2026-04-29 12:06:06 +0000 UTC (now=2026-04-28 12:58:24.855154002 +0000 UTC))" I0428 12:58:24.855302 1 tlsconfig.go:200] "Loaded serving cert" certName="serving-cert::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.crt::/var/config/system/secrets/v4-0-config-system-serving-cert/tls.key" certDetail="\"oauth-openshift.openshift-authentication.svc\" [serving] validServingFor=[oauth-openshift.openshift-authentication.svc,oauth-openshift.openshift-authentication.svc.cluster.local] issuer=\"openshift-service-serving-signer@1777378979\" (2026-04-28 12:23:22 +0000 UTC to 2028-04-27 12:23:23 +0000 UTC (now=2026-04-28 12:58:24.855290336 +0000 UTC))" I0428 12:58:24.855434 1 named_certificates.go:53] "Loaded SNI cert" index=1 certName="sni-serving-cert::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com::/var/config/system/secrets/v4-0-config-system-router-certs/apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com" certDetail="\"*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com\" [serving] validServingFor=[*.apps.clusterpool420-54bqn.rhtap.devcluster.openshift.com] issuer=\"ingress-operator@1777379050\" (2026-04-28 12:24:13 +0000 UTC to 2028-04-27 12:24:14 +0000 UTC (now=2026-04-28 12:58:24.855425205 +0000 UTC))" I0428 12:58:24.855558 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777381104\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777381104\" (2026-04-28 11:58:24 +0000 UTC to 2027-04-28 11:58:24 +0000 UTC (now=2026-04-28 12:58:24.855551818 +0000 UTC))" W0428 13:15:18.870020 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"a2e66759-f067-475f-be28-a777f13437f4", it has already been set to "kubeadmin" W0428 13:16:34.175641 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"c4d1d731-704c-43b0-a389-c30a0b5810dd", it has already been set to "kubeadmin" W0428 13:17:16.053009 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"ec42392a-d1df-4256-bcd8-e35cc5bc93cd", it has already been set to "kubeadmin" W0428 13:17:18.070021 1 context.go:119] Failed to set annotations["authentication.openshift.io/username"] to "kube:admin" for audit:"07219922-0607-42b1-868a-f32df424fad5", it has already been set to "kubeadmin"