W0420 09:00:48.402601 1 cmd.go:257] Using insecure, self-signed certificates I0420 09:00:48.402829 1 crypto.go:601] Generating new CA for service-ca-controller-signer@1776675648 cert, and key in /tmp/serving-cert-669237326/serving-signer.crt, /tmp/serving-cert-669237326/serving-signer.key Validity period of the certificate for "service-ca-controller-signer@1776675648" is unset, resetting to 157680000000000000 years! I0420 09:00:48.585560 1 leaderelection.go:121] The leader election gives 4 retries and allows for 30s of clock skew. The kube-apiserver downtime tolerance is 78s. Worst non-graceful lease acquisition is 2m43s. Worst graceful lease acquisition is {26s}. I0420 09:00:48.585837 1 observer_polling.go:159] Starting file observer I0420 09:00:48.585880 1 envvar.go:172] "Feature gate default state" feature="WatchListClient" enabled=false I0420 09:00:48.585893 1 envvar.go:172] "Feature gate default state" feature="ClientsAllowCBOR" enabled=false I0420 09:00:48.585898 1 envvar.go:172] "Feature gate default state" feature="ClientsPreferCBOR" enabled=false I0420 09:00:48.585902 1 envvar.go:172] "Feature gate default state" feature="InformerResourceVersion" enabled=false I0420 09:00:48.618043 1 builder.go:304] service-ca-controller version - I0420 09:00:48.618612 1 dynamic_serving_content.go:116] "Loaded a new cert/key pair" name="serving-cert::/tmp/serving-cert-669237326/tls.crt::/tmp/serving-cert-669237326/tls.key" I0420 09:00:48.869260 1 requestheader_controller.go:255] Loaded a new request header values for RequestHeaderAuthRequestController I0420 09:00:48.875324 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0420 09:00:48.875339 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0420 09:00:48.875366 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0420 09:00:48.875373 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0420 09:00:48.878660 1 secure_serving.go:57] Forcing use of http/1.1 only W0420 09:00:48.878683 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256' detected. W0420 09:00:48.878687 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256' detected. W0420 09:00:48.878692 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_GCM_SHA256' detected. W0420 09:00:48.878695 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_GCM_SHA384' detected. W0420 09:00:48.878697 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_CBC_SHA' detected. W0420 09:00:48.878700 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_CBC_SHA' detected. I0420 09:00:48.878665 1 genericapiserver.go:535] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete I0420 09:00:48.884164 1 requestheader_controller.go:180] Starting RequestHeaderAuthRequestController I0420 09:00:48.884187 1 shared_informer.go:313] Waiting for caches to sync for RequestHeaderAuthRequestController I0420 09:00:48.884184 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0420 09:00:48.884203 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0420 09:00:48.884907 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0420 09:00:48.884938 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0420 09:00:48.885176 1 dynamic_serving_content.go:135] "Starting controller" name="serving-cert::/tmp/serving-cert-669237326/tls.crt::/tmp/serving-cert-669237326/tls.key" I0420 09:00:48.885479 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-669237326/tls.crt::/tmp/serving-cert-669237326/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-controller-signer@1776675648\" (2026-04-20 09:00:47 +0000 UTC to 2026-04-20 09:00:48 +0000 UTC (now=2026-04-20 09:00:48.885362643 +0000 UTC))" I0420 09:00:48.886244 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776675648\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776675648\" (2026-04-20 08:00:48 +0000 UTC to 2027-04-20 08:00:48 +0000 UTC (now=2026-04-20 09:00:48.886217697 +0000 UTC))" I0420 09:00:48.886264 1 secure_serving.go:213] Serving securely on [::]:8443 I0420 09:00:48.886305 1 genericapiserver.go:685] [graceful-termination] waiting for shutdown to be initiated I0420 09:00:48.886345 1 tlsconfig.go:243] "Starting DynamicServingCertificateController" I0420 09:00:48.886995 1 leaderelection.go:257] attempting to acquire leader lease openshift-service-ca/service-ca-controller-lock... I0420 09:00:48.888349 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.888523 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.889704 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.901477 1 leaderelection.go:271] successfully acquired lease openshift-service-ca/service-ca-controller-lock I0420 09:00:48.901519 1 event.go:377] Event(v1.ObjectReference{Kind:"Lease", Namespace:"openshift-service-ca", Name:"service-ca-controller-lock", UID:"136203c7-6bbe-42ed-adfa-066d2b63b089", APIVersion:"coordination.k8s.io/v1", ResourceVersion:"10243", FieldPath:""}): type: 'Normal' reason: 'LeaderElection' service-ca-5fffcf96d8-rgmpb_5d33a1a5-1dbe-425a-96a7-75c6f8a7650e became leader I0420 09:00:48.902559 1 base_controller.go:76] Waiting for caches to sync for ConfigMapCABundleInjector I0420 09:00:48.902564 1 base_controller.go:76] Waiting for caches to sync for CRDCABundleInjector I0420 09:00:48.902559 1 base_controller.go:76] Waiting for caches to sync for APIServiceCABundleInjector I0420 09:00:48.902578 1 base_controller.go:76] Waiting for caches to sync for ValidatingWebhookCABundleInjector I0420 09:00:48.902560 1 base_controller.go:76] Waiting for caches to sync for MutatingWebhookCABundleInjector I0420 09:00:48.902677 1 base_controller.go:76] Waiting for caches to sync for LegacyVulnerableConfigMapCABundleInjector I0420 09:00:48.902970 1 starter.go:62] Setting certificate lifetime to 17520h0m0s, refresh certificate at 1h0m0s I0420 09:00:48.903487 1 base_controller.go:76] Waiting for caches to sync for ServiceServingCertUpdateController I0420 09:00:48.903527 1 base_controller.go:76] Waiting for caches to sync for ServiceServingCertController I0420 09:00:48.907349 1 reflector.go:376] Caches populated for *v1.MutatingWebhookConfiguration from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.907528 1 reflector.go:376] Caches populated for *v1.ValidatingWebhookConfiguration from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.907807 1 reflector.go:376] Caches populated for *v1.APIService from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.909210 1 reflector.go:376] Caches populated for *v1.Service from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.946868 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:48.984698 1 shared_informer.go:320] Caches are synced for RequestHeaderAuthRequestController I0420 09:00:48.984707 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0420 09:00:48.984972 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0420 09:00:48.985089 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-20 08:49:01 +0000 UTC to 2036-04-17 08:49:01 +0000 UTC (now=2026-04-20 09:00:48.985063783 +0000 UTC))" I0420 09:00:48.985117 1 tlsconfig.go:181] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-20 08:49:06 +0000 UTC to 2036-04-17 08:49:06 +0000 UTC (now=2026-04-20 09:00:48.985106635 +0000 UTC))" I0420 09:00:48.985135 1 tlsconfig.go:181] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-20 08:49:09 +0000 UTC to 2036-04-17 08:49:09 +0000 UTC (now=2026-04-20 09:00:48.98512739 +0000 UTC))" I0420 09:00:48.985158 1 tlsconfig.go:181] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"hcco-signer\" [] issuer=\"\" (2026-04-20 08:49:14 +0000 UTC to 2036-04-17 08:49:14 +0000 UTC (now=2026-04-20 09:00:48.985144175 +0000 UTC))" I0420 09:00:48.985176 1 tlsconfig.go:181] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer\" [] issuer=\"\" (2026-04-20 08:49:15 +0000 UTC to 2036-04-17 08:49:15 +0000 UTC (now=2026-04-20 09:00:48.98516714 +0000 UTC))" I0420 09:00:48.985201 1 tlsconfig.go:181] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2ppphakho7bv59m4jq6j95q87iepucal-kx-a782d3b4f2_customer-system-admin-signer@1776675111\" [] issuer=\"\" (2026-04-20 08:51:53 +0000 UTC to 2026-04-27 08:51:54 +0000 UTC (now=2026-04-20 09:00:48.985186004 +0000 UTC))" I0420 09:00:48.985232 1 tlsconfig.go:181] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2ppphakho7bv59m4jq6j95q87iepucal-kx-a782d3b4f2_sre-system-admin-signer@1776675111\" [] issuer=\"\" (2026-04-20 08:51:51 +0000 UTC to 2026-04-27 08:51:52 +0000 UTC (now=2026-04-20 09:00:48.985216091 +0000 UTC))" I0420 09:00:48.985442 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-669237326/tls.crt::/tmp/serving-cert-669237326/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-controller-signer@1776675648\" (2026-04-20 09:00:47 +0000 UTC to 2026-04-20 09:00:48 +0000 UTC (now=2026-04-20 09:00:48.985429761 +0000 UTC))" I0420 09:00:48.985631 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776675648\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776675648\" (2026-04-20 08:00:48 +0000 UTC to 2027-04-20 08:00:48 +0000 UTC (now=2026-04-20 09:00:48.985613691 +0000 UTC))" I0420 09:00:48.985801 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-20 08:49:01 +0000 UTC to 2036-04-17 08:49:01 +0000 UTC (now=2026-04-20 09:00:48.985788683 +0000 UTC))" I0420 09:00:48.985831 1 tlsconfig.go:181] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-20 08:49:06 +0000 UTC to 2036-04-17 08:49:06 +0000 UTC (now=2026-04-20 09:00:48.985816959 +0000 UTC))" I0420 09:00:48.985860 1 tlsconfig.go:181] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-20 08:49:09 +0000 UTC to 2036-04-17 08:49:09 +0000 UTC (now=2026-04-20 09:00:48.985841665 +0000 UTC))" I0420 09:00:48.985876 1 tlsconfig.go:181] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"hcco-signer\" [] issuer=\"\" (2026-04-20 08:49:14 +0000 UTC to 2036-04-17 08:49:14 +0000 UTC (now=2026-04-20 09:00:48.985868763 +0000 UTC))" I0420 09:00:48.985891 1 tlsconfig.go:181] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer\" [] issuer=\"\" (2026-04-20 08:49:15 +0000 UTC to 2036-04-17 08:49:15 +0000 UTC (now=2026-04-20 09:00:48.985883223 +0000 UTC))" I0420 09:00:48.985918 1 tlsconfig.go:181] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2ppphakho7bv59m4jq6j95q87iepucal-kx-a782d3b4f2_customer-system-admin-signer@1776675111\" [] issuer=\"\" (2026-04-20 08:51:53 +0000 UTC to 2026-04-27 08:51:54 +0000 UTC (now=2026-04-20 09:00:48.985899549 +0000 UTC))" I0420 09:00:48.985944 1 tlsconfig.go:181] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2ppphakho7bv59m4jq6j95q87iepucal-kx-a782d3b4f2_sre-system-admin-signer@1776675111\" [] issuer=\"\" (2026-04-20 08:51:51 +0000 UTC to 2026-04-27 08:51:52 +0000 UTC (now=2026-04-20 09:00:48.98592749 +0000 UTC))" I0420 09:00:48.985964 1 tlsconfig.go:181] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-20 08:48:59 +0000 UTC to 2036-04-17 08:48:59 +0000 UTC (now=2026-04-20 09:00:48.985953054 +0000 UTC))" I0420 09:00:48.986156 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/tmp/serving-cert-669237326/tls.crt::/tmp/serving-cert-669237326/tls.key" certDetail="\"localhost\" [serving] validServingFor=[localhost] issuer=\"service-ca-controller-signer@1776675648\" (2026-04-20 09:00:47 +0000 UTC to 2026-04-20 09:00:48 +0000 UTC (now=2026-04-20 09:00:48.986141109 +0000 UTC))" I0420 09:00:48.986321 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776675648\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776675648\" (2026-04-20 08:00:48 +0000 UTC to 2027-04-20 08:00:48 +0000 UTC (now=2026-04-20 09:00:48.986306955 +0000 UTC))" I0420 09:00:48.991881 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:49.002698 1 base_controller.go:82] Caches are synced for MutatingWebhookCABundleInjector I0420 09:00:49.002713 1 base_controller.go:119] Starting #1 worker of MutatingWebhookCABundleInjector controller ... I0420 09:00:49.002719 1 base_controller.go:119] Starting #2 worker of MutatingWebhookCABundleInjector controller ... I0420 09:00:49.002718 1 base_controller.go:82] Caches are synced for ConfigMapCABundleInjector I0420 09:00:49.002724 1 base_controller.go:119] Starting #3 worker of MutatingWebhookCABundleInjector controller ... I0420 09:00:49.002727 1 base_controller.go:119] Starting #4 worker of MutatingWebhookCABundleInjector controller ... I0420 09:00:49.002702 1 base_controller.go:82] Caches are synced for APIServiceCABundleInjector I0420 09:00:49.002771 1 base_controller.go:119] Starting #1 worker of APIServiceCABundleInjector controller ... I0420 09:00:49.002783 1 base_controller.go:119] Starting #2 worker of APIServiceCABundleInjector controller ... I0420 09:00:49.002790 1 base_controller.go:119] Starting #3 worker of APIServiceCABundleInjector controller ... I0420 09:00:49.002795 1 base_controller.go:119] Starting #4 worker of APIServiceCABundleInjector controller ... I0420 09:00:49.002799 1 base_controller.go:119] Starting #5 worker of APIServiceCABundleInjector controller ... I0420 09:00:49.002725 1 base_controller.go:82] Caches are synced for ValidatingWebhookCABundleInjector I0420 09:00:49.002826 1 base_controller.go:119] Starting #1 worker of ValidatingWebhookCABundleInjector controller ... I0420 09:00:49.002830 1 base_controller.go:119] Starting #2 worker of ValidatingWebhookCABundleInjector controller ... I0420 09:00:49.002730 1 base_controller.go:119] Starting #5 worker of MutatingWebhookCABundleInjector controller ... I0420 09:00:49.002776 1 base_controller.go:82] Caches are synced for LegacyVulnerableConfigMapCABundleInjector I0420 09:00:49.002851 1 admissionwebhook.go:116] updating validatingwebhookconfiguration performance-addon-operator with the service signing CA bundle I0420 09:00:49.002859 1 base_controller.go:119] Starting #1 worker of LegacyVulnerableConfigMapCABundleInjector controller ... I0420 09:00:49.002729 1 base_controller.go:119] Starting #1 worker of ConfigMapCABundleInjector controller ... I0420 09:00:49.002875 1 base_controller.go:119] Starting #2 worker of ConfigMapCABundleInjector controller ... I0420 09:00:49.002834 1 base_controller.go:119] Starting #3 worker of ValidatingWebhookCABundleInjector controller ... I0420 09:00:49.002880 1 base_controller.go:119] Starting #3 worker of ConfigMapCABundleInjector controller ... I0420 09:00:49.002884 1 base_controller.go:119] Starting #4 worker of ValidatingWebhookCABundleInjector controller ... I0420 09:00:49.002886 1 base_controller.go:119] Starting #4 worker of ConfigMapCABundleInjector controller ... I0420 09:00:49.002889 1 base_controller.go:119] Starting #5 worker of ValidatingWebhookCABundleInjector controller ... I0420 09:00:49.002890 1 base_controller.go:119] Starting #5 worker of ConfigMapCABundleInjector controller ... I0420 09:00:49.002909 1 configmap.go:109] updating configmap dedicated-admin/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.002867 1 base_controller.go:119] Starting #2 worker of LegacyVulnerableConfigMapCABundleInjector controller ... I0420 09:00:49.002942 1 configmap.go:109] updating configmap kube-node-lease/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.002961 1 configmap.go:109] updating configmap kube-system/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.003000 1 base_controller.go:119] Starting #3 worker of LegacyVulnerableConfigMapCABundleInjector controller ... I0420 09:00:49.002942 1 configmap.go:109] updating configmap default/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.003023 1 base_controller.go:119] Starting #4 worker of LegacyVulnerableConfigMapCABundleInjector controller ... I0420 09:00:49.003029 1 base_controller.go:119] Starting #5 worker of LegacyVulnerableConfigMapCABundleInjector controller ... I0420 09:00:49.002954 1 configmap.go:109] updating configmap kube-public/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.003803 1 base_controller.go:82] Caches are synced for ServiceServingCertController I0420 09:00:49.003816 1 base_controller.go:119] Starting #1 worker of ServiceServingCertController controller ... I0420 09:00:49.003821 1 base_controller.go:119] Starting #2 worker of ServiceServingCertController controller ... I0420 09:00:49.003827 1 base_controller.go:119] Starting #3 worker of ServiceServingCertController controller ... I0420 09:00:49.003832 1 base_controller.go:119] Starting #4 worker of ServiceServingCertController controller ... I0420 09:00:49.003836 1 base_controller.go:119] Starting #5 worker of ServiceServingCertController controller ... I0420 09:00:49.003883 1 base_controller.go:82] Caches are synced for ServiceServingCertUpdateController I0420 09:00:49.003895 1 base_controller.go:119] Starting #1 worker of ServiceServingCertUpdateController controller ... I0420 09:00:49.003902 1 base_controller.go:119] Starting #2 worker of ServiceServingCertUpdateController controller ... I0420 09:00:49.003907 1 base_controller.go:119] Starting #3 worker of ServiceServingCertUpdateController controller ... I0420 09:00:49.003914 1 base_controller.go:119] Starting #4 worker of ServiceServingCertUpdateController controller ... I0420 09:00:49.003919 1 base_controller.go:119] Starting #5 worker of ServiceServingCertUpdateController controller ... I0420 09:00:49.019931 1 configmap.go:109] updating configmap open-cluster-management-2ppphakho7bv59m4jq6j95q87iepucal/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.020235 1 configmap.go:109] updating configmap open-cluster-management-agent-addon/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.020271 1 configmap.go:109] updating configmap openshift-apiserver-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.023990 1 configmap.go:109] updating configmap openshift-apiserver/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.024105 1 configmap.go:109] updating configmap openshift-authentication-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.039378 1 configmap.go:109] updating configmap openshift-authentication-operator/service-ca-bundle with the service signing CA bundle I0420 09:00:49.039384 1 configmap.go:109] updating configmap openshift-authentication/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.042968 1 configmap.go:109] updating configmap openshift-backplane-cee/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.047018 1 configmap.go:109] updating configmap openshift-backplane-cse/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.071634 1 reflector.go:376] Caches populated for *v1.CustomResourceDefinition from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0420 09:00:49.103228 1 base_controller.go:82] Caches are synced for CRDCABundleInjector I0420 09:00:49.103241 1 base_controller.go:119] Starting #1 worker of CRDCABundleInjector controller ... I0420 09:00:49.103248 1 base_controller.go:119] Starting #2 worker of CRDCABundleInjector controller ... I0420 09:00:49.103253 1 base_controller.go:119] Starting #3 worker of CRDCABundleInjector controller ... I0420 09:00:49.103259 1 base_controller.go:119] Starting #4 worker of CRDCABundleInjector controller ... I0420 09:00:49.103262 1 base_controller.go:119] Starting #5 worker of CRDCABundleInjector controller ... I0420 09:00:49.103272 1 crd.go:69] updating customresourcedefinition alertmanagerconfigs.monitoring.coreos.com conversion webhook config with the service signing CA bundle W0420 09:00:49.103283 1 crd.go:61] customresourcedefinition consoleplugins.console.openshift.io is annotated for ca bundle injection but does not use strategy "Webhook" I0420 09:00:49.114690 1 configmap.go:109] updating configmap openshift-backplane-csm/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.321340 1 configmap.go:109] updating configmap openshift-backplane-lpsre/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.515930 1 configmap.go:109] updating configmap openshift-backplane-managed-scripts/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.716621 1 configmap.go:109] updating configmap openshift-backplane-mcs-tier-two/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:49.919649 1 configmap.go:109] updating configmap openshift-backplane-mobb/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:50.125026 1 configmap.go:109] updating configmap openshift-backplane-srep-ro/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:50.317516 1 configmap.go:109] updating configmap openshift-backplane-srep/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:50.514572 1 configmap.go:109] updating configmap openshift-backplane-tam/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:50.714548 1 configmap.go:109] updating configmap openshift-backplane/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:50.916531 1 configmap.go:109] updating configmap openshift-cloud-controller-manager/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:51.115289 1 configmap.go:109] updating configmap openshift-cloud-credential-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:51.316377 1 configmap.go:109] updating configmap openshift-cloud-network-config-controller/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:51.516468 1 configmap.go:109] updating configmap openshift-cluster-csi-drivers/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:51.714847 1 configmap.go:109] updating configmap openshift-cluster-machine-approver/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:51.915573 1 configmap.go:109] updating configmap openshift-cluster-node-tuning-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:52.116637 1 configmap.go:109] updating configmap openshift-cluster-samples-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:52.316342 1 configmap.go:109] updating configmap openshift-cluster-storage-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:52.515779 1 configmap.go:109] updating configmap openshift-cluster-version/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:52.720594 1 configmap.go:109] updating configmap openshift-config-managed/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:52.914981 1 configmap.go:109] updating configmap openshift-config-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:53.114907 1 configmap.go:109] updating configmap openshift-config/openshift-service-ca.crt with the service signing CA bundle W0420 09:00:53.116222 1 warnings.go:70] annotation service.kubernetes.io/topology-aware-hints is deprecated, please use service.kubernetes.io/topology-mode instead I0420 09:00:53.316085 1 configmap.go:109] updating configmap openshift-console-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:53.513313 1 configmap.go:109] updating configmap openshift-console-user-settings/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:53.716894 1 configmap.go:109] updating configmap openshift-console/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:53.915799 1 configmap.go:109] updating configmap openshift-controller-manager-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:54.114519 1 configmap.go:109] updating configmap openshift-controller-manager/openshift-service-ca with the service signing CA bundle I0420 09:00:54.317545 1 configmap.go:109] updating configmap openshift-controller-manager/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:54.516027 1 configmap.go:109] updating configmap openshift-customer-monitoring/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:54.721237 1 configmap.go:109] updating configmap openshift-deployment-validation-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:54.913694 1 configmap.go:109] updating configmap openshift-dns-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:55.115676 1 configmap.go:109] updating configmap openshift-dns/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:55.316771 1 configmap.go:109] updating configmap openshift-etcd/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:55.514856 1 configmap.go:109] updating configmap openshift-host-network/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:55.714908 1 configmap.go:109] updating configmap openshift-image-registry/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:55.913789 1 configmap.go:109] updating configmap openshift-image-registry/serviceca with the service signing CA bundle I0420 09:00:56.116125 1 configmap.go:109] updating configmap openshift-infra/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:56.315418 1 configmap.go:109] updating configmap openshift-ingress-canary/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:56.514502 1 configmap.go:109] updating configmap openshift-ingress-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:56.715898 1 configmap.go:109] updating configmap openshift-ingress/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:56.916840 1 configmap.go:109] updating configmap openshift-ingress/service-ca-bundle with the service signing CA bundle I0420 09:00:57.113833 1 configmap.go:109] updating configmap openshift-insights/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:57.315927 1 configmap.go:109] updating configmap openshift-insights/service-ca-bundle with the service signing CA bundle I0420 09:00:57.517403 1 configmap.go:109] updating configmap openshift-kube-apiserver-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:57.714441 1 configmap.go:109] updating configmap openshift-kube-apiserver/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:57.915315 1 configmap.go:109] updating configmap openshift-kube-controller-manager-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:58.115772 1 configmap.go:109] updating configmap openshift-kube-controller-manager/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:58.315045 1 configmap.go:109] updating configmap openshift-kube-scheduler-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:58.519543 1 configmap.go:109] updating configmap openshift-kube-scheduler/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:58.717160 1 configmap.go:109] updating configmap openshift-kube-storage-version-migrator-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:58.915287 1 configmap.go:109] updating configmap openshift-kube-storage-version-migrator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:59.116474 1 configmap.go:109] updating configmap openshift-logging/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:59.315897 1 configmap.go:109] updating configmap openshift-machine-api/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:59.513711 1 configmap.go:109] updating configmap openshift-machine-config-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:59.713948 1 configmap.go:109] updating configmap openshift-marketplace/openshift-service-ca.crt with the service signing CA bundle I0420 09:00:59.912824 1 configmap.go:109] updating configmap openshift-monitoring/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:00.113796 1 configmap.go:109] updating configmap openshift-multus/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:00.319051 1 configmap.go:109] updating configmap openshift-must-gather-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:00.519633 1 configmap.go:109] updating configmap openshift-network-console/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:00.714012 1 configmap.go:109] updating configmap openshift-network-diagnostics/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:00.913471 1 configmap.go:109] updating configmap openshift-network-node-identity/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:01.113098 1 configmap.go:109] updating configmap openshift-network-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:01.315807 1 configmap.go:109] updating configmap openshift-node/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:01.514917 1 configmap.go:109] updating configmap openshift-operator-lifecycle-manager/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:01.714092 1 configmap.go:109] updating configmap openshift-operators-redhat/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:01.916366 1 configmap.go:109] updating configmap openshift-operators/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:02.115406 1 configmap.go:109] updating configmap openshift-ovn-kubernetes/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:02.317064 1 configmap.go:109] updating configmap openshift-package-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:02.514387 1 configmap.go:109] updating configmap openshift-route-controller-manager/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:02.714334 1 configmap.go:109] updating configmap openshift-service-ca-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:02.913295 1 configmap.go:109] updating configmap openshift-service-ca/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:03.114887 1 configmap.go:109] updating configmap openshift-user-workload-monitoring/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:03.314697 1 configmap.go:109] updating configmap openshift/openshift-service-ca.crt with the service signing CA bundle I0420 09:01:19.518086 1 admissionwebhook.go:116] updating validatingwebhookconfiguration prometheusrules.openshift.io with the service signing CA bundle I0420 09:01:19.528392 1 admissionwebhook.go:116] updating validatingwebhookconfiguration alertmanagerconfigs.openshift.io with the service signing CA bundle I0420 09:01:23.666698 1 configmap.go:109] updating configmap openshift-monitoring/serving-certs-ca-bundle with the service signing CA bundle I0420 09:01:23.669556 1 configmap.go:109] updating configmap openshift-monitoring/telemeter-client-serving-certs-ca-bundle with the service signing CA bundle I0420 09:01:32.762047 1 configmap.go:109] updating configmap openshift-console/service-ca with the service signing CA bundle I0420 09:01:53.627044 1 apiservice.go:62] updating apiservice v1beta1.metrics.k8s.io with the service signing CA bundle I0420 09:02:52.178514 1 admissionwebhook.go:116] updating validatingwebhookconfiguration monitoringconfigmaps.openshift.io with the service signing CA bundle I0420 09:06:59.705191 1 configmap.go:109] updating configmap tsf/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.812773 1 configmap.go:109] updating configmap tsf-tas/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.812833 1 configmap.go:109] updating configmap rhtpa-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.831394 1 configmap.go:109] updating configmap tsf-keycloak/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.847484 1 configmap.go:109] updating configmap rhbk-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.864440 1 configmap.go:109] updating configmap cert-manager-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.875365 1 configmap.go:109] updating configmap konflux-operator/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.889267 1 configmap.go:109] updating configmap tsf-tpa/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:03.907069 1 configmap.go:109] updating configmap konflux-ui/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:43.822170 1 configmap.go:109] updating configmap trusted-artifact-signer/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:52.696725 1 configmap.go:109] updating configmap openshift-pipelines/openshift-service-ca.crt with the service signing CA bundle I0420 09:07:56.107905 1 configmap.go:109] updating configmap cert-manager-operator/config-service-cabundle with the service signing CA bundle I0420 09:07:56.204551 1 configmap.go:109] updating configmap default/config-service-cabundle with the service signing CA bundle I0420 09:07:56.307222 1 configmap.go:109] updating configmap konflux-operator/config-service-cabundle with the service signing CA bundle I0420 09:07:56.407896 1 configmap.go:109] updating configmap konflux-ui/config-service-cabundle with the service signing CA bundle I0420 09:07:56.511356 1 configmap.go:109] updating configmap open-cluster-management-2ppphakho7bv59m4jq6j95q87iepucal/config-service-cabundle with the service signing CA bundle I0420 09:07:56.610697 1 configmap.go:109] updating configmap openshift/config-service-cabundle with the service signing CA bundle I0420 09:07:56.709685 1 configmap.go:109] updating configmap rhbk-operator/config-service-cabundle with the service signing CA bundle I0420 09:07:56.800624 1 configmap.go:109] updating configmap rhtpa-operator/config-service-cabundle with the service signing CA bundle I0420 09:07:56.899996 1 configmap.go:109] updating configmap trusted-artifact-signer/config-service-cabundle with the service signing CA bundle I0420 09:07:57.000440 1 configmap.go:109] updating configmap tsf/config-service-cabundle with the service signing CA bundle I0420 09:07:57.100052 1 configmap.go:109] updating configmap tsf-keycloak/config-service-cabundle with the service signing CA bundle I0420 09:07:57.200269 1 configmap.go:109] updating configmap tsf-tas/config-service-cabundle with the service signing CA bundle I0420 09:07:57.304344 1 configmap.go:109] updating configmap tsf-tpa/config-service-cabundle with the service signing CA bundle I0420 09:07:57.615422 1 configmap.go:109] updating configmap openshift-pipelines/config-service-cabundle with the service signing CA bundle W0420 09:20:49.073164 1 crd.go:61] customresourcedefinition consoleplugins.console.openshift.io is annotated for ca bundle injection but does not use strategy "Webhook"