W0505 13:05:51.582460 1 cmd.go:257] Using insecure, self-signed certificates I0505 13:05:51.582712 1 crypto.go:601] Generating new CA for service-ca-operator-signer@1777986351 cert, and key in /tmp/serving-cert-3987444784/serving-signer.crt, /tmp/serving-cert-3987444784/serving-signer.key Validity period of the certificate for "service-ca-operator-signer@1777986351" is unset, resetting to 157680000000000000 years! I0505 13:05:52.329027 1 leaderelection.go:121] The leader election gives 4 retries and allows for 30s of clock skew. The kube-apiserver downtime tolerance is 78s. Worst non-graceful lease acquisition is 2m43s. Worst graceful lease acquisition is {26s}. I0505 13:05:52.329344 1 observer_polling.go:159] Starting file observer I0505 13:05:52.329459 1 envvar.go:172] "Feature gate default state" feature="ClientsPreferCBOR" enabled=false I0505 13:05:52.329474 1 envvar.go:172] "Feature gate default state" feature="InformerResourceVersion" enabled=false I0505 13:05:52.329479 1 envvar.go:172] "Feature gate default state" feature="WatchListClient" enabled=false I0505 13:05:52.329483 1 envvar.go:172] "Feature gate default state" feature="ClientsAllowCBOR" enabled=false I0505 13:05:52.360150 1 builder.go:304] service-ca-operator version - I0505 13:05:52.361234 1 dynamic_serving_content.go:116] "Loaded a new cert/key pair" name="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" I0505 13:05:52.973505 1 requestheader_controller.go:255] Loaded a new request header values for RequestHeaderAuthRequestController I0505 13:05:52.980412 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0505 13:05:52.980433 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0505 13:05:52.980456 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0505 13:05:52.980463 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0505 13:05:52.983561 1 secure_serving.go:57] Forcing use of http/1.1 only I0505 13:05:52.983570 1 genericapiserver.go:535] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete W0505 13:05:52.983580 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256' detected. W0505 13:05:52.983586 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256' detected. W0505 13:05:52.983592 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_GCM_SHA256' detected. W0505 13:05:52.983595 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_GCM_SHA384' detected. W0505 13:05:52.983598 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_CBC_SHA' detected. W0505 13:05:52.983600 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_CBC_SHA' detected. I0505 13:05:52.990232 1 requestheader_controller.go:180] Starting RequestHeaderAuthRequestController I0505 13:05:52.990234 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0505 13:05:52.990256 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0505 13:05:52.990278 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0505 13:05:52.990276 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0505 13:05:52.990262 1 shared_informer.go:313] Waiting for caches to sync for RequestHeaderAuthRequestController I0505 13:05:52.990526 1 dynamic_serving_content.go:135] "Starting controller" name="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" I0505 13:05:52.990612 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-operator-signer@1777986351\" (2026-05-05 13:05:51 +0000 UTC to 2026-05-05 13:05:52 +0000 UTC (now=2026-05-05 13:05:52.990588323 +0000 UTC))" I0505 13:05:52.990794 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777986352\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777986352\" (2026-05-05 12:05:52 +0000 UTC to 2027-05-05 12:05:52 +0000 UTC (now=2026-05-05 13:05:52.990777165 +0000 UTC))" I0505 13:05:52.990810 1 secure_serving.go:213] Serving securely on [::]:8443 I0505 13:05:52.990827 1 genericapiserver.go:685] [graceful-termination] waiting for shutdown to be initiated I0505 13:05:52.990859 1 tlsconfig.go:243] "Starting DynamicServingCertificateController" I0505 13:05:52.991811 1 leaderelection.go:257] attempting to acquire leader lease openshift-service-ca-operator/service-ca-operator-lock... I0505 13:05:52.993565 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:52.993626 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:52.994280 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.005354 1 leaderelection.go:271] successfully acquired lease openshift-service-ca-operator/service-ca-operator-lock I0505 13:05:53.005527 1 event.go:377] Event(v1.ObjectReference{Kind:"Lease", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator-lock", UID:"0761e47d-108c-4ed4-84a9-31f86a8db300", APIVersion:"coordination.k8s.io/v1", ResourceVersion:"10194", FieldPath:""}): type: 'Normal' reason: 'LeaderElection' service-ca-operator-7f694b5f95-ssz2j_d3faa4b7-079f-4f35-84cd-d0833fc28004 became leader I0505 13:05:53.006205 1 starter.go:111] Fetching FeatureGates I0505 13:05:53.006278 1 simple_featuregate_reader.go:171] Starting feature-gate-detector I0505 13:05:53.009935 1 reflector.go:376] Caches populated for *v1.FeatureGate from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.010142 1 starter.go:160] Setting signing certificate lifetime to 18960h0m0s, minimum trust duration to 9480h0m0s I0505 13:05:53.010142 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'FeatureGatesInitialized' FeatureGates updated to featuregates.Features{Enabled:[]v1.FeatureGateName{"AdditionalRoutingCapabilities", "AdminNetworkPolicy", "AlibabaPlatform", "AzureWorkloadIdentity", "BuildCSIVolumes", "CPMSMachineNamePrefix", "ConsolePluginContentSecurityPolicy", "ExternalOIDC", "ExternalOIDCWithUIDAndExtraClaimMappings", "GatewayAPI", "GatewayAPIController", "HighlyAvailableArbiter", "ImageVolume", "IngressControllerLBSubnetsAWS", "KMSv1", "MachineConfigNodes", "ManagedBootImages", "ManagedBootImagesAWS", "MetricsCollectionProfiles", "NetworkDiagnosticsConfig", "NetworkLiveMigration", "NetworkSegmentation", "PinnedImages", "ProcMountType", "RouteAdvertisements", "RouteExternalCertificate", "ServiceAccountTokenNodeBinding", "SetEIPForNLBIngressController", "SigstoreImageVerification", "StoragePerformantSecurityPolicy", "UpgradeStatus", "UserNamespacesPodSecurityStandards", "UserNamespacesSupport", "VSphereMultiDisk", "VSphereMultiNetworks"}, Disabled:[]v1.FeatureGateName{"AWSClusterHostedDNS", "AWSClusterHostedDNSInstall", "AWSDedicatedHosts", "AWSServiceLBNetworkSecurityGroup", "AutomatedEtcdBackup", "AzureClusterHostedDNSInstall", "AzureDedicatedHosts", "AzureMultiDisk", "BootImageSkewEnforcement", "BootcNodeManagement", "ClusterAPIInstall", "ClusterAPIInstallIBMCloud", "ClusterMonitoringConfig", "ClusterVersionOperatorConfiguration", "DNSNameResolver", "DualReplica", "DyanmicServiceEndpointIBMCloud", "DynamicResourceAllocation", "EtcdBackendQuota", "EventedPLEG", "Example", "Example2", "ExternalSnapshotMetadata", "GCPClusterHostedDNS", "GCPClusterHostedDNSInstall", "GCPCustomAPIEndpoints", "GCPCustomAPIEndpointsInstall", "ImageModeStatusReporting", "ImageStreamImportMode", "IngressControllerDynamicConfigurationManager", "InsightsConfig", "InsightsConfigAPI", "InsightsOnDemandDataGather", "IrreconcilableMachineConfig", "KMSEncryptionProvider", "MachineAPIMigration", "MachineAPIOperatorDisableMachineHealthCheckController", "ManagedBootImagesAzure", "ManagedBootImagesvSphere", "MaxUnavailableStatefulSet", "MinimumKubeletVersion", "MixedCPUsAllocation", "MultiArchInstallAzure", "MultiDiskSetup", "MutatingAdmissionPolicy", "NewOLM", "NewOLMCatalogdAPIV1Metas", "NewOLMOwnSingleNamespace", "NewOLMPreflightPermissionChecks", "NewOLMWebhookProviderOpenshiftServiceCA", "NoRegistryClusterOperations", "NodeSwap", "NutanixMultiSubnets", "OVNObservability", "OpenShiftPodSecurityAdmission", "PreconfiguredUDNAddresses", "SELinuxMount", "ShortCertRotation", "SignatureStores", "SigstoreImageVerificationPKI", "TranslateStreamCloseWebsocketRequests", "VSphereConfigurableMaxAllowedBlockVolumesPerNode", "VSphereHostVMGroupZonal", "VSphereMixedNodeEnv", "VolumeAttributesClass", "VolumeGroupSnapshot"}} I0505 13:05:53.010427 1 base_controller.go:76] Waiting for caches to sync for resource-sync I0505 13:05:53.010585 1 base_controller.go:76] Waiting for caches to sync for ServiceCAOperator I0505 13:05:53.010587 1 base_controller.go:76] Waiting for caches to sync for LoggingSyncer I0505 13:05:53.010746 1 base_controller.go:76] Waiting for caches to sync for StatusSyncer_service-ca I0505 13:05:53.011116 1 reflector.go:376] Caches populated for *v1.ClusterVersion from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.014592 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.014659 1 reflector.go:376] Caches populated for *v1.ServiceAccount from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.014641 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.016694 1 reflector.go:376] Caches populated for *v1.ClusterOperator from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017229 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017233 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017466 1 reflector.go:376] Caches populated for *v1.Deployment from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017632 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017643 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017671 1 reflector.go:376] Caches populated for *v1.ServiceCA from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.017960 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.018167 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.018579 1 reflector.go:376] Caches populated for *v1.Infrastructure from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.034446 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.090984 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0505 13:05:53.091002 1 shared_informer.go:320] Caches are synced for RequestHeaderAuthRequestController I0505 13:05:53.091018 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0505 13:05:53.091168 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-05-05 12:54:24 +0000 UTC to 2036-05-02 12:54:24 +0000 UTC (now=2026-05-05 13:05:53.091140168 +0000 UTC))" I0505 13:05:53.091359 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-operator-signer@1777986351\" (2026-05-05 13:05:51 +0000 UTC to 2026-05-05 13:05:52 +0000 UTC (now=2026-05-05 13:05:53.091346656 +0000 UTC))" I0505 13:05:53.091543 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777986352\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777986352\" (2026-05-05 12:05:52 +0000 UTC to 2027-05-05 12:05:52 +0000 UTC (now=2026-05-05 13:05:53.091531591 +0000 UTC))" I0505 13:05:53.091682 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-05-05 12:54:25 +0000 UTC to 2036-05-02 12:54:25 +0000 UTC (now=2026-05-05 13:05:53.091666624 +0000 UTC))" I0505 13:05:53.091701 1 tlsconfig.go:181] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-05-05 12:54:29 +0000 UTC to 2036-05-02 12:54:29 +0000 UTC (now=2026-05-05 13:05:53.091693112 +0000 UTC))" I0505 13:05:53.091720 1 tlsconfig.go:181] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-05-05 12:54:31 +0000 UTC to 2036-05-02 12:54:31 +0000 UTC (now=2026-05-05 13:05:53.091709497 +0000 UTC))" I0505 13:05:53.091735 1 tlsconfig.go:181] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"hcco-signer\" [] issuer=\"\" (2026-05-05 12:54:32 +0000 UTC to 2036-05-02 12:54:32 +0000 UTC (now=2026-05-05 13:05:53.091727389 +0000 UTC))" I0505 13:05:53.091750 1 tlsconfig.go:181] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer\" [] issuer=\"\" (2026-05-05 12:54:34 +0000 UTC to 2036-05-02 12:54:34 +0000 UTC (now=2026-05-05 13:05:53.091742218 +0000 UTC))" I0505 13:05:53.091770 1 tlsconfig.go:181] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2q3pgo6vorv79frkblfeomuaacfmc4ot-kx-a826458b8e_customer-system-admin-signer@1777985778\" [] issuer=\"\" (2026-05-05 12:56:19 +0000 UTC to 2026-05-12 12:56:20 +0000 UTC (now=2026-05-05 13:05:53.091761038 +0000 UTC))" I0505 13:05:53.091788 1 tlsconfig.go:181] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2q3pgo6vorv79frkblfeomuaacfmc4ot-kx-a826458b8e_sre-system-admin-signer@1777985778\" [] issuer=\"\" (2026-05-05 12:56:18 +0000 UTC to 2026-05-12 12:56:19 +0000 UTC (now=2026-05-05 13:05:53.091777755 +0000 UTC))" I0505 13:05:53.091805 1 tlsconfig.go:181] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-05-05 12:54:24 +0000 UTC to 2036-05-02 12:54:24 +0000 UTC (now=2026-05-05 13:05:53.091797792 +0000 UTC))" I0505 13:05:53.091984 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-operator-signer@1777986351\" (2026-05-05 13:05:51 +0000 UTC to 2026-05-05 13:05:52 +0000 UTC (now=2026-05-05 13:05:53.091974025 +0000 UTC))" I0505 13:05:53.092141 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1777986352\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1777986352\" (2026-05-05 12:05:52 +0000 UTC to 2027-05-05 12:05:52 +0000 UTC (now=2026-05-05 13:05:53.09213099 +0000 UTC))" I0505 13:05:53.111315 1 base_controller.go:82] Caches are synced for LoggingSyncer I0505 13:05:53.111332 1 base_controller.go:119] Starting #1 worker of LoggingSyncer controller ... I0505 13:05:53.111343 1 base_controller.go:82] Caches are synced for StatusSyncer_service-ca I0505 13:05:53.111355 1 base_controller.go:119] Starting #1 worker of StatusSyncer_service-ca controller ... I0505 13:05:53.111781 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"conditions":[{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Degraded"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Progressing"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Available"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Upgradeable"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"EvaluationConditionsDetected"}],"relatedObjects":[{"group":"operator.openshift.io","name":"cluster","resource":"servicecas"},{"group":"","name":"openshift-config","resource":"namespaces"},{"group":"","name":"openshift-config-managed","resource":"namespaces"},{"group":"","name":"openshift-service-ca-operator","resource":"namespaces"},{"group":"","name":"openshift-service-ca","resource":"namespaces"}]}} I0505 13:05:53.125058 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/service-ca changed: Degraded set to Unknown (""),Progressing set to Unknown (""),Available set to Unknown (""),Upgradeable set to Unknown (""),EvaluationConditionsDetected set to Unknown (""),status.relatedObjects changed from [] to [{"operator.openshift.io" "servicecas" "" "cluster"} {"" "namespaces" "" "openshift-config"} {"" "namespaces" "" "openshift-config-managed"} {"" "namespaces" "" "openshift-service-ca-operator"} {"" "namespaces" "" "openshift-service-ca"}] I0505 13:05:53.125207 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"conditions":[{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Degraded"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Progressing"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Available"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Upgradeable"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"EvaluationConditionsDetected"}],"relatedObjects":[{"group":"operator.openshift.io","name":"cluster","resource":"servicecas"},{"group":"","name":"openshift-config","resource":"namespaces"},{"group":"","name":"openshift-config-managed","resource":"namespaces"},{"group":"","name":"openshift-service-ca-operator","resource":"namespaces"},{"group":"","name":"openshift-service-ca","resource":"namespaces"}]}} E0505 13:05:53.143244 1 base_controller.go:279] "Unhandled Error" err="StatusSyncer_service-ca reconciliation failed: Operation cannot be fulfilled on clusteroperators.config.openshift.io \"service-ca\": the object has been modified; please apply your changes to the latest version and try again" I0505 13:05:53.215080 1 reflector.go:376] Caches populated for *v1.Namespace from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.310718 1 base_controller.go:82] Caches are synced for ServiceCAOperator I0505 13:05:53.310742 1 base_controller.go:119] Starting #1 worker of ServiceCAOperator controller ... I0505 13:05:53.414059 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0505 13:05:53.511218 1 base_controller.go:82] Caches are synced for resource-sync I0505 13:05:53.511237 1 base_controller.go:119] Starting #1 worker of resource-sync controller ... I0505 13:05:53.554010 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"conditions":[{"lastTransitionTime":"2026-05-05T13:05:53Z","message":"All is well","reason":"AsExpected","status":"False","type":"Degraded"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Progressing"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Available"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"Upgradeable"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"EvaluationConditionsDetected"}]}} I0505 13:05:53.577950 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/service-ca changed: Degraded changed from Unknown to False ("All is well") I0505 13:05:53.820612 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'NamespaceCreated' Created Namespace/openshift-service-ca because it was missing I0505 13:05:53.838576 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'ClusterRoleCreated' Created ClusterRole.rbac.authorization.k8s.io/system:openshift:controller:service-ca because it was missing I0505 13:05:53.861293 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'ClusterRoleBindingCreated' Created ClusterRoleBinding.rbac.authorization.k8s.io/system:openshift:controller:service-ca because it was missing I0505 13:05:53.879856 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'RoleCreated' Created Role.rbac.authorization.k8s.io/system:openshift:controller:service-ca -n openshift-service-ca because it was missing I0505 13:05:53.914200 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'RoleBindingCreated' Created RoleBinding.rbac.authorization.k8s.io/system:openshift:controller:service-ca -n openshift-service-ca because it was missing I0505 13:05:54.220441 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'ServiceAccountCreated' Created ServiceAccount/service-ca -n openshift-service-ca because it was missing I0505 13:05:54.821471 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'SecretCreated' Created Secret/signing-key -n openshift-service-ca because it was missing I0505 13:05:55.447266 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'ConfigMapCreated' Created ConfigMap/signing-cabundle -n openshift-service-ca because it was missing I0505 13:05:55.492169 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'DeploymentCreated' Created Deployment.apps/service-ca -n openshift-service-ca because it was missing I0505 13:05:55.521893 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"conditions":[{"lastTransitionTime":"2026-05-05T13:05:53Z","message":"All is well","reason":"AsExpected","status":"False","type":"Degraded"},{"lastTransitionTime":"2026-05-05T13:05:55Z","message":"Progressing: \nProgressing: service-ca does not have available replicas","reason":"_ManagedDeploymentsAvailable","status":"True","type":"Progressing"},{"lastTransitionTime":"2026-05-05T13:05:55Z","message":"All is well","reason":"AsExpected","status":"True","type":"Available"},{"lastTransitionTime":"2026-05-05T13:05:55Z","message":"All is well","reason":"AsExpected","status":"True","type":"Upgradeable"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"EvaluationConditionsDetected"}]}} I0505 13:05:55.542183 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/service-ca changed: Progressing changed from Unknown to True ("Progressing: \nProgressing: service-ca does not have available replicas"),Available changed from Unknown to True ("All is well"),Upgradeable changed from Unknown to True ("All is well") I0505 13:05:55.630960 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'ConfigMapCreated' Created ConfigMap/service-ca -n openshift-config-managed because it was missing I0505 13:05:56.433223 1 apps.go:155] Deployment "openshift-service-ca/service-ca" changes: {"spec":{"progressDeadlineSeconds":null,"replicas":null,"revisionHistoryLimit":null,"template":{"spec":{"containers":[{"args":["-v=2"],"command":["service-ca-operator","controller"],"image":"quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:521712486e2c6e3c020dad6a1cb340db8e55665b69f7c208fab9cd9e965fd588","imagePullPolicy":"IfNotPresent","name":"service-ca-controller","ports":[{"containerPort":8443}],"resources":{"requests":{"cpu":"10m","memory":"120Mi"}},"securityContext":{"runAsNonRoot":true},"terminationMessagePolicy":"FallbackToLogsOnError","volumeMounts":[{"mountPath":"/var/run/secrets/signing-key","name":"signing-key"},{"mountPath":"/var/run/configmaps/signing-cabundle","name":"signing-cabundle"}]}],"dnsPolicy":null,"restartPolicy":null,"schedulerName":null,"securityContext":null,"serviceAccount":null,"terminationGracePeriodSeconds":null,"volumes":[{"name":"signing-key","secret":{"secretName":"signing-key"}},{"configMap":{"name":"signing-cabundle"},"name":"signing-cabundle"}]}}}} I0505 13:05:56.445680 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'DeploymentUpdated' Updated Deployment.apps/service-ca -n openshift-service-ca because it changed I0505 13:05:57.236643 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorVersionChanged' clusteroperator/service-ca version "operator" changed from "" to "4.20.8" I0505 13:05:57.236999 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"versions":[{"name":"operator","version":"4.20.8"}]}} I0505 13:05:57.256454 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/service-ca changed: status.versions changed from [] to [{"operator" "4.20.8"}] I0505 13:05:57.257560 1 status_controller.go:229] clusteroperator/service-ca diff {"status":{"conditions":[{"lastTransitionTime":"2026-05-05T13:05:53Z","message":"All is well","reason":"AsExpected","status":"False","type":"Degraded"},{"lastTransitionTime":"2026-05-05T13:05:57Z","message":"Progressing: All service-ca-operator deployments updated","reason":"AsExpected","status":"False","type":"Progressing"},{"lastTransitionTime":"2026-05-05T13:05:55Z","message":"All is well","reason":"AsExpected","status":"True","type":"Available"},{"lastTransitionTime":"2026-05-05T13:05:55Z","message":"All is well","reason":"AsExpected","status":"True","type":"Upgradeable"},{"lastTransitionTime":"2026-05-05T13:05:53Z","reason":"NoData","status":"Unknown","type":"EvaluationConditionsDetected"}]}} I0505 13:05:57.274053 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"d62cd117-0e8f-4b65-8324-9c1f31cc6327", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/service-ca changed: Progressing changed from True to False ("Progressing: All service-ca-operator deployments updated") I0505 13:07:17.330058 1 observer_polling.go:111] Observed file "/var/run/secrets/serving-cert/tls.crt" has been created (hash="57f62556454fb5a3f08e64f47a7e28642223d93af88a613129df8e29a166b2fd") W0505 13:07:17.330098 1 builder.go:160] Restart triggered because of file /var/run/secrets/serving-cert/tls.crt was created I0505 13:07:17.330151 1 observer_polling.go:111] Observed file "/var/run/secrets/serving-cert/tls.key" has been created (hash="83d9b0d5b5b9d25e83222b6852c046e370a6237f7f6bc061a2bcf1e1fa78ace4") I0505 13:07:17.330157 1 genericapiserver.go:693] "[graceful-termination] pre-shutdown hooks completed" name="PreShutdownHooksStopped" I0505 13:07:17.330182 1 genericapiserver.go:548] "[graceful-termination] shutdown event" name="ShutdownInitiated" I0505 13:07:17.330198 1 genericapiserver.go:551] "[graceful-termination] shutdown event" name="AfterShutdownDelayDuration" I0505 13:07:17.330204 1 base_controller.go:181] Shutting down resource-sync ... I0505 13:07:17.330209 1 base_controller.go:181] Shutting down StatusSyncer_service-ca ... I0505 13:07:17.330223 1 base_controller.go:159] All StatusSyncer_service-ca post start hooks have been terminated I0505 13:07:17.330215 1 genericapiserver.go:617] "[graceful-termination] shutdown event" name="NotAcceptingNewRequest" I0505 13:07:17.330229 1 base_controller.go:181] Shutting down ServiceCAOperator ... I0505 13:07:17.330234 1 base_controller.go:123] Shutting down worker of resource-sync controller ... I0505 13:07:17.330239 1 base_controller.go:123] Shutting down worker of ServiceCAOperator controller ... I0505 13:07:17.330234 1 object_count_tracker.go:151] "StorageObjectCountTracker pruner is exiting" I0505 13:07:17.330246 1 base_controller.go:123] Shutting down worker of StatusSyncer_service-ca controller ... I0505 13:07:17.330247 1 base_controller.go:113] All ServiceCAOperator workers have been terminated I0505 13:07:17.330252 1 genericapiserver.go:642] [graceful-termination] in-flight non long-running request(s) have drained I0505 13:07:17.330260 1 base_controller.go:113] All resource-sync workers have been terminated I0505 13:07:17.330258 1 base_controller.go:181] Shutting down LoggingSyncer ... I0505 13:07:17.330263 1 genericapiserver.go:651] "[graceful-termination] not going to wait for active watch request(s) to drain" I0505 13:07:17.330272 1 base_controller.go:123] Shutting down worker of LoggingSyncer controller ... I0505 13:07:17.330272 1 simple_featuregate_reader.go:177] Shutting down feature-gate-detector I0505 13:07:17.330280 1 base_controller.go:113] All LoggingSyncer workers have been terminated I0505 13:07:17.330278 1 base_controller.go:113] All StatusSyncer_service-ca workers have been terminated I0505 13:07:17.330287 1 genericapiserver.go:683] "[graceful-termination] shutdown event" name="InFlightRequestsDrained" I0505 13:07:17.330327 1 configmap_cafile_content.go:226] "Shutting down controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0505 13:07:17.330339 1 requestheader_controller.go:194] Shutting down RequestHeaderAuthRequestController I0505 13:07:17.330339 1 secure_serving.go:258] Stopped listening on [::]:8443 I0505 13:07:17.330340 1 dynamic_serving_content.go:149] "Shutting down controller" name="serving-cert::/tmp/serving-cert-3987444784/tls.crt::/tmp/serving-cert-3987444784/tls.key" I0505 13:07:17.330332 1 tlsconfig.go:258] "Shutting down DynamicServingCertificateController" I0505 13:07:17.330355 1 configmap_cafile_content.go:226] "Shutting down controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0505 13:07:17.330362 1 genericapiserver.go:600] "[graceful-termination] shutdown event" name="HTTPServerStoppedListening" I0505 13:07:17.330367 1 genericapiserver.go:713] [graceful-termination] apiserver is exiting I0505 13:07:17.330384 1 builder.go:335] server exited W0505 13:07:17.342006 1 leaderelection.go:84] leader election lost