I0330 15:17:06.300145 1 controller.go:284] "configured acme dns01 nameservers" logger="cert-manager.controller.build-context" nameservers=["172.30.0.10:53"] I0330 15:17:06.300633 1 envvar.go:172] "Feature gate default state" feature="WatchListClient" enabled=false I0330 15:17:06.300649 1 envvar.go:172] "Feature gate default state" feature="ClientsAllowCBOR" enabled=false I0330 15:17:06.300653 1 envvar.go:172] "Feature gate default state" feature="ClientsPreferCBOR" enabled=false I0330 15:17:06.300656 1 envvar.go:172] "Feature gate default state" feature="InformerResourceVersion" enabled=false I0330 15:17:06.302883 1 controller.go:88] "enabled controllers: [certificaterequests-approver certificaterequests-issuer-acme certificaterequests-issuer-ca certificaterequests-issuer-selfsigned certificaterequests-issuer-vault certificaterequests-issuer-venafi certificates-issuing certificates-key-manager certificates-metrics certificates-readiness certificates-request-manager certificates-revision-manager certificates-trigger challenges clusterissuers ingress-shim issuers orders]" logger="cert-manager.controller" I0330 15:17:06.302900 1 controller.go:437] "serving insecurely as tls certificate data not provided" logger="cert-manager.controller" I0330 15:17:06.302907 1 controller.go:101] "listening for insecure connections" logger="cert-manager.controller" address="0.0.0.0:9402" I0330 15:17:06.303192 1 controller.go:125] "starting metrics server" logger="cert-manager.controller" address="[::]:9402" I0330 15:17:06.303282 1 controller.go:176] "starting leader election" logger="cert-manager.controller" I0330 15:17:06.303281 1 controller.go:169] "starting healthz server" logger="cert-manager.controller" address="[::]:9403" I0330 15:17:06.305677 1 leaderelection.go:257] attempting to acquire leader lease kube-system/cert-manager-controller... E0330 15:17:06.323540 1 leaderelection.go:436] error retrieving resource lock kube-system/cert-manager-controller: leases.coordination.k8s.io "cert-manager-controller" is forbidden: User "system:serviceaccount:cert-manager:cert-manager" cannot get resource "leases" in API group "coordination.k8s.io" in the namespace "kube-system" I0330 15:17:29.621847 1 leaderelection.go:271] successfully acquired lease kube-system/cert-manager-controller I0330 15:17:29.624498 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-key-manager" I0330 15:17:29.626525 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-metrics" I0330 15:17:29.628312 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-trigger" I0330 15:17:29.630978 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-acme" I0330 15:17:29.630992 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="gateway-shim" I0330 15:17:29.631086 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-vault" I0330 15:17:29.632942 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-readiness" I0330 15:17:29.634612 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-request-manager" I0330 15:17:29.636128 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-ca" I0330 15:17:29.636140 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-vault" I0330 15:17:29.636147 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-venafi" I0330 15:17:29.636179 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-ca" I0330 15:17:29.637937 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="issuers" I0330 15:17:29.640893 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-approver" I0330 15:17:29.642660 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-issuing" I0330 15:17:29.644317 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="clusterissuers" I0330 15:17:29.645989 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="challenges" I0330 15:17:29.647808 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="ingress-shim" I0330 15:17:29.649553 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificates-revision-manager" I0330 15:17:29.651103 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="orders" I0330 15:17:29.652971 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-acme" I0330 15:17:29.655438 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-selfsigned" I0330 15:17:29.656859 1 controller.go:223] "skipping disabled controller" logger="cert-manager.controller" controller="certificatesigningrequests-issuer-selfsigned" I0330 15:17:29.656925 1 controller.go:240] "starting controller" logger="cert-manager.controller" controller="certificaterequests-issuer-venafi" I0330 15:17:29.661335 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.661349 1 reflector.go:376] Caches populated for *v1.Ingress from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.661430 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.661597 1 reflector.go:376] Caches populated for *v1.CertificateRequest from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.661883 1 reflector.go:376] Caches populated for *v1.Secret from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.661911 1 reflector.go:376] Caches populated for *v1.Certificate from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.662004 1 reflector.go:376] Caches populated for *v1.ClusterIssuer from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.662076 1 reflector.go:376] Caches populated for *v1.Order from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.662283 1 reflector.go:376] Caches populated for *v1.Issuer from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.662488 1 reflector.go:376] Caches populated for *v1.Challenge from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:17:29.671150 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:21:50.332401 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="cert-manager/selfsigned-ca" condition="Ready" lastTransitionTime="2026-03-30 15:21:50.332382382 +0000 UTC m=+284.052282494" I0330 15:21:50.332457 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/selfsigned-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:50.332507 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="cert-manager/selfsigned-ca" condition="Issuing" lastTransitionTime="2026-03-30 15:21:50.332500964 +0000 UTC m=+284.052401072" I0330 15:21:50.511219 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:50.511279 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="cert-manager/selfsigned-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:50.511298 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="cert-manager/selfsigned-ca" condition="Issuing" lastTransitionTime="2026-03-30 15:21:50.511292531 +0000 UTC m=+284.231192640" E0330 15:21:50.595230 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"root-secret\" not found" logger="cert-manager.controller.setup" resource_name="ca-issuer" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" I0330 15:21:50.595276 1 conditions.go:102] "Setting lastTransitionTime for Issuer condition" logger="cert-manager" issuer="ca-issuer" condition="Ready" lastTransitionTime="2026-03-30 15:21:50.595267461 +0000 UTC m=+284.315167567" E0330 15:21:50.595311 1 sync.go:62] "error setting up issuer" err="secrets \"root-secret\" not found" logger="cert-manager.controller" resource_name="ca-issuer" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0330 15:21:50.671092 1 controller.go:157] "re-queuing item due to error processing" err="secrets \"root-secret\" not found" logger="cert-manager.controller" E0330 15:21:50.671201 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"root-secret\" not found" logger="cert-manager.controller.setup" resource_name="ca-issuer" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0330 15:21:50.671224 1 sync.go:62] "error setting up issuer" err="secrets \"root-secret\" not found" logger="cert-manager.controller" resource_name="ca-issuer" resource_namespace="" resource_kind="ClusterIssuer" resource_version="v1" E0330 15:21:50.671255 1 controller.go:157] "re-queuing item due to error processing" err="secrets \"root-secret\" not found" logger="cert-manager.controller" I0330 15:21:50.714908 1 conditions.go:102] "Setting lastTransitionTime for Issuer condition" logger="cert-manager" issuer="self-signed-cluster-issuer" condition="Ready" lastTransitionTime="2026-03-30 15:21:50.714897615 +0000 UTC m=+284.434797726" I0330 15:21:50.787285 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="namespace-lister/namespace-lister" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:50.787289 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="namespace-lister/namespace-lister" condition="Ready" lastTransitionTime="2026-03-30 15:21:50.787279767 +0000 UTC m=+284.507179879" I0330 15:21:50.787308 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="namespace-lister/namespace-lister" condition="Issuing" lastTransitionTime="2026-03-30 15:21:50.787302011 +0000 UTC m=+284.507202118" I0330 15:21:50.843896 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:50.964270 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"namespace-lister\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:50.964321 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="namespace-lister/namespace-lister" condition="Ready" lastTransitionTime="2026-03-30 15:21:50.964312403 +0000 UTC m=+284.684212517" I0330 15:21:51.182346 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="cert-manager/selfsigned-ca-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:51.182321852 +0000 UTC m=+284.902221957" I0330 15:21:51.207267 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"namespace-lister\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.432208 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="namespace-lister/namespace-lister-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:51.432189625 +0000 UTC m=+285.152089734" I0330 15:21:51.487701 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="cert-manager/selfsigned-ca-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.487689946 +0000 UTC m=+285.207590052" I0330 15:21:51.495402 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="namespace-lister/namespace-lister-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.495384168 +0000 UTC m=+285.215284266" I0330 15:21:51.545828 1 conditions.go:86] "Found status change for Issuer condition; setting lastTransitionTime" logger="cert-manager" issuer="ca-issuer" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:51.545816342 +0000 UTC m=+285.265716448" I0330 15:21:51.545936 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="cert-manager/selfsigned-ca" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:51.5459224 +0000 UTC m=+285.265822512" I0330 15:21:51.572461 1 conditions.go:269] "Found status change for CertificateRequest condition; setting lastTransitionTime" logger="cert-manager" certificateRequest="namespace-lister/namespace-lister-1" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:51.572452423 +0000 UTC m=+285.292352528" I0330 15:21:51.610910 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.677069 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="namespace-lister/namespace-lister" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:51.677058993 +0000 UTC m=+285.396959117" I0330 15:21:51.684987 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/dex-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.685018 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/dex-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.685009739 +0000 UTC m=+285.404909848" I0330 15:21:51.685033 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/dex-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.685022845 +0000 UTC m=+285.404922952" I0330 15:21:51.703105 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"namespace-lister\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.703664 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="namespace-lister/namespace-lister" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:51.703652622 +0000 UTC m=+285.423552720" I0330 15:21:51.717907 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"dex-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.717959 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/dex-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.717988 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/dex-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.717979505 +0000 UTC m=+285.437879618" I0330 15:21:51.720924 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/oauth2-proxy-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.720951 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/oauth2-proxy-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.720942503 +0000 UTC m=+285.440842615" I0330 15:21:51.720956 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/oauth2-proxy-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.720945327 +0000 UTC m=+285.440845442" I0330 15:21:51.742352 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"selfsigned-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.768266 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"namespace-lister\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.768267 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"namespace-lister\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.774810 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"oauth2-proxy-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.774859 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/oauth2-proxy-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.774849044 +0000 UTC m=+285.494749161" I0330 15:21:51.774876 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.774918 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/serving-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.774909744 +0000 UTC m=+285.494809857" I0330 15:21:51.774885 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/serving-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.774875442 +0000 UTC m=+285.494775556" I0330 15:21:51.831205 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/ui-ca" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.831187103 +0000 UTC m=+285.551087222" I0330 15:21:51.831219 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/ui-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.831324 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/ui-ca" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.831316023 +0000 UTC m=+285.551216134" I0330 15:21:51.842005 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.842059 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/serving-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.842050758 +0000 UTC m=+285.561950875" I0330 15:21:51.867048 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="integration-service/serving-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.867038145 +0000 UTC m=+285.586938250" I0330 15:21:51.867064 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="integration-service/serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.867092 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="integration-service/serving-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.867083854 +0000 UTC m=+285.586983967" E0330 15:21:51.870934 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"ui-ca\" not found" logger="cert-manager.controller.setup" resource_name="ui-ca-issuer" resource_namespace="konflux-ui" resource_kind="Issuer" resource_version="v1" I0330 15:21:51.870990 1 conditions.go:102] "Setting lastTransitionTime for Issuer condition" logger="cert-manager" issuer="konflux-ui/ui-ca-issuer" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.870980308 +0000 UTC m=+285.590880415" I0330 15:21:51.871010 1 sync.go:62] "Error initializing issuer: secrets \"ui-ca\" not found" logger="cert-manager.controller" resource_name="ui-ca-issuer" resource_namespace="konflux-ui" resource_kind="Issuer" resource_version="v1" I0330 15:21:51.928629 1 conditions.go:102] "Setting lastTransitionTime for Issuer condition" logger="cert-manager" issuer="integration-service/selfsigned-issuer" condition="Ready" lastTransitionTime="2026-03-30 15:21:51.928615598 +0000 UTC m=+285.648515703" I0330 15:21:51.961955 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"ui-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:51.962002 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="konflux-ui/ui-ca" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:51.962020 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="konflux-ui/ui-ca" condition="Issuing" lastTransitionTime="2026-03-30 15:21:51.962014321 +0000 UTC m=+285.681914428" I0330 15:21:52.268804 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:52.268848 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="integration-service/serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:52.268867 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="integration-service/serving-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:52.268860568 +0000 UTC m=+285.988760674" E0330 15:21:52.311344 1 controller.go:157] "re-queuing item due to error processing" err="secrets \"ui-ca\" not found" logger="cert-manager.controller" E0330 15:21:52.311405 1 setup.go:48] "error getting signing CA TLS certificate" err="secrets \"ui-ca\" not found" logger="cert-manager.controller.setup" resource_name="ui-ca-issuer" resource_namespace="konflux-ui" resource_kind="Issuer" resource_version="v1" I0330 15:21:52.311426 1 sync.go:62] "Error initializing issuer: secrets \"ui-ca\" not found" logger="cert-manager.controller" resource_name="ui-ca-issuer" resource_namespace="konflux-ui" resource_kind="Issuer" resource_version="v1" E0330 15:21:52.311446 1 controller.go:157] "re-queuing item due to error processing" err="secrets \"ui-ca\" not found" logger="cert-manager.controller" I0330 15:21:52.518065 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:52.609756 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"oauth2-proxy-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:52.682839 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="release-service/serving-cert" condition="Ready" lastTransitionTime="2026-03-30 15:21:52.682817833 +0000 UTC m=+286.402717949" I0330 15:21:52.682879 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="release-service/serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:52.682903 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="release-service/serving-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:52.682897302 +0000 UTC m=+286.402797407" I0330 15:21:52.714361 1 conditions.go:102] "Setting lastTransitionTime for Issuer condition" logger="cert-manager" issuer="release-service/selfsigned-issuer" condition="Ready" lastTransitionTime="2026-03-30 15:21:52.714344387 +0000 UTC m=+286.434244499" I0330 15:21:53.154922 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:53.154968 1 trigger_controller.go:225] "Certificate must be re-issued" logger="cert-manager.controller" key="release-service/serving-cert" reason="DoesNotExist" message="Issuing certificate as Secret does not exist" I0330 15:21:53.154985 1 conditions.go:217] "Setting lastTransitionTime for Certificate condition" logger="cert-manager" certificate="release-service/serving-cert" condition="Issuing" lastTransitionTime="2026-03-30 15:21:53.154979422 +0000 UTC m=+286.874879529" I0330 15:21:53.468680 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/serving-cert-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:53.468665489 +0000 UTC m=+287.188565594" I0330 15:21:53.627220 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/oauth2-proxy-cert-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:53.627198318 +0000 UTC m=+287.347098435" I0330 15:21:53.633636 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"dex-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:53.687056 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/dex-cert-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:53.687043473 +0000 UTC m=+287.406943589" I0330 15:21:53.819715 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"ui-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:53.908544 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/ui-ca-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:53.908526952 +0000 UTC m=+287.628427075" I0330 15:21:54.312067 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/serving-cert-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:54.312052417 +0000 UTC m=+288.031952513" I0330 15:21:54.381416 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/oauth2-proxy-cert-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:54.381397014 +0000 UTC m=+288.101297111" I0330 15:21:54.426776 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/dex-cert-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:54.426761542 +0000 UTC m=+288.146661635" I0330 15:21:54.532851 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="konflux-ui/ui-ca-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:54.532836432 +0000 UTC m=+288.252736538" I0330 15:21:54.555667 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:54.616851 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="integration-service/serving-cert-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:54.616836167 +0000 UTC m=+288.336736276" I0330 15:21:55.319153 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="integration-service/serving-cert-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:55.319137376 +0000 UTC m=+289.039037483" I0330 15:21:55.806403 1 conditions.go:86] "Found status change for Issuer condition; setting lastTransitionTime" logger="cert-manager" issuer="konflux-ui/ui-ca-issuer" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:55.806386899 +0000 UTC m=+289.526287005" I0330 15:21:55.806454 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/ui-ca" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:55.806439087 +0000 UTC m=+289.526339187" I0330 15:21:56.066796 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="release-service/serving-cert-1" condition="Approved" lastTransitionTime="2026-03-30 15:21:56.066777481 +0000 UTC m=+289.786677593" I0330 15:21:56.408130 1 conditions.go:269] "Found status change for CertificateRequest condition; setting lastTransitionTime" logger="cert-manager" certificateRequest="konflux-ui/oauth2-proxy-cert-1" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:56.408113253 +0000 UTC m=+290.128013358" I0330 15:21:56.408193 1 conditions.go:269] "Found status change for CertificateRequest condition; setting lastTransitionTime" logger="cert-manager" certificateRequest="konflux-ui/serving-cert-1" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:56.408172912 +0000 UTC m=+290.128073009" I0330 15:21:56.408237 1 conditions.go:269] "Found status change for CertificateRequest condition; setting lastTransitionTime" logger="cert-manager" certificateRequest="konflux-ui/dex-cert-1" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:56.408228835 +0000 UTC m=+290.128128928" I0330 15:21:56.502496 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"ui-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:56.502758 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/ui-ca" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:56.502750593 +0000 UTC m=+290.222650701" I0330 15:21:56.558365 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="integration-service/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:56.558348147 +0000 UTC m=+290.278248253" I0330 15:21:56.767989 1 conditions.go:285] "Setting lastTransitionTime for CertificateRequest condition" logger="cert-manager" certificateRequest="release-service/serving-cert-1" condition="Ready" lastTransitionTime="2026-03-30 15:21:56.767973993 +0000 UTC m=+290.487874100" I0330 15:21:57.402338 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:57.402869 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="integration-service/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:57.402860557 +0000 UTC m=+291.122760651" I0330 15:21:57.851209 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"ui-ca\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:57.906889 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/oauth2-proxy-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:57.90687449 +0000 UTC m=+291.626774599" I0330 15:21:57.957083 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:57.957071203 +0000 UTC m=+291.676971312" I0330 15:21:58.007503 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/dex-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:58.00749141 +0000 UTC m=+291.727391519" I0330 15:21:58.358730 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="release-service/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:58.358708891 +0000 UTC m=+292.078609008" I0330 15:21:58.603266 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"oauth2-proxy-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:58.604045 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/oauth2-proxy-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:58.604031146 +0000 UTC m=+292.323931262" I0330 15:21:58.702675 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:58.703378 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:58.703352226 +0000 UTC m=+292.423252341" I0330 15:21:58.802470 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"dex-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:58.803240 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="konflux-ui/dex-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:58.803228368 +0000 UTC m=+292.523128473" I0330 15:21:58.852814 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:58.903698 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:59.052846 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:59.053486 1 conditions.go:201] "Found status change for Certificate condition; setting lastTransitionTime" logger="cert-manager" certificate="release-service/serving-cert" condition="Ready" oldStatus="False" status="True" lastTransitionTime="2026-03-30 15:21:59.053471744 +0000 UTC m=+292.773371850" I0330 15:21:59.852486 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"oauth2-proxy-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:59.902432 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:21:59.952275 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"dex-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:22:00.002490 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"dex-cert\": the object has been modified; please apply your changes to the latest version and try again" I0330 15:22:00.102024 1 controller.go:152] "re-queuing item due to optimistic locking on resource" logger="cert-manager.controller" error="Operation cannot be fulfilled on certificates.cert-manager.io \"serving-cert\": the object has been modified; please apply your changes to the latest version and try again" W0330 15:29:49.445362 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Issuer ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445380 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.ClusterIssuer ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445394 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.CertificateRequest ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445395 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Order ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445364 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.PartialObjectMetadata ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445364 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Ingress ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445404 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.PartialObjectMetadata ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding E0330 15:29:49.445418 1 leaderelection.go:429] Failed to update lock optimistically: Put "https://172.30.0.1:443/apis/coordination.k8s.io/v1/namespaces/kube-system/leases/cert-manager-controller": http2: client connection lost, falling back to slow path W0330 15:29:49.445421 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Secret ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445410 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.PartialObjectMetadata ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445415 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Certificate ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding W0330 15:29:49.445458 1 reflector.go:492] pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251: watch of *v1.Challenge ended with: an error on the server ("unable to decode an event from the watch stream: http2: client connection lost") has prevented the request from succeeding I0330 15:29:50.364134 1 reflector.go:376] Caches populated for *v1.Secret from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.379685 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.411213 1 reflector.go:376] Caches populated for *v1.Certificate from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.414434 1 reflector.go:376] Caches populated for *v1.Ingress from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.529122 1 reflector.go:376] Caches populated for *v1.Issuer from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.632333 1 reflector.go:376] Caches populated for *v1.ClusterIssuer from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.683643 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.706765 1 reflector.go:376] Caches populated for *v1.PartialObjectMetadata from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:50.729775 1 reflector.go:376] Caches populated for *v1.Order from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:51.495529 1 reflector.go:376] Caches populated for *v1.CertificateRequest from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251 I0330 15:29:51.886783 1 reflector.go:376] Caches populated for *v1.Challenge from pkg/mod/k8s.io/client-go@v0.32.0/tools/cache/reflector.go:251