I0416 12:16:53.709774 1 cmd.go:253] Using service-serving-cert provided certificates I0416 12:16:53.709854 1 leaderelection.go:121] The leader election gives 4 retries and allows for 30s of clock skew. The kube-apiserver downtime tolerance is 78s. Worst non-graceful lease acquisition is 2m43s. Worst graceful lease acquisition is {26s}. I0416 12:16:53.710247 1 observer_polling.go:159] Starting file observer I0416 12:16:53.710712 1 envvar.go:172] "Feature gate default state" feature="ClientsAllowCBOR" enabled=false I0416 12:16:53.710742 1 envvar.go:172] "Feature gate default state" feature="ClientsPreferCBOR" enabled=false I0416 12:16:53.710749 1 envvar.go:172] "Feature gate default state" feature="InformerResourceVersion" enabled=false I0416 12:16:53.710755 1 envvar.go:172] "Feature gate default state" feature="WatchListClient" enabled=false I0416 12:16:53.732131 1 builder.go:304] service-ca-operator version - I0416 12:16:53.732712 1 dynamic_serving_content.go:116] "Loaded a new cert/key pair" name="serving-cert::/var/run/secrets/serving-cert/tls.crt::/var/run/secrets/serving-cert/tls.key" I0416 12:16:54.234345 1 requestheader_controller.go:255] Loaded a new request header values for RequestHeaderAuthRequestController I0416 12:16:54.240137 1 maxinflight.go:139] "Initialized nonMutatingChan" len=400 I0416 12:16:54.240151 1 maxinflight.go:145] "Initialized mutatingChan" len=200 I0416 12:16:54.240169 1 maxinflight.go:116] "Set denominator for readonly requests" limit=400 I0416 12:16:54.240173 1 maxinflight.go:120] "Set denominator for mutating requests" limit=200 I0416 12:16:54.243699 1 genericapiserver.go:535] MuxAndDiscoveryComplete has all endpoints registered and discovery information is complete I0416 12:16:54.243731 1 secure_serving.go:57] Forcing use of http/1.1 only W0416 12:16:54.243748 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256' detected. W0416 12:16:54.243753 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256' detected. W0416 12:16:54.243758 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_GCM_SHA256' detected. W0416 12:16:54.243762 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_GCM_SHA384' detected. W0416 12:16:54.243766 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_128_CBC_SHA' detected. W0416 12:16:54.243769 1 secure_serving.go:69] Use of insecure cipher 'TLS_RSA_WITH_AES_256_CBC_SHA' detected. I0416 12:16:54.247981 1 requestheader_controller.go:180] Starting RequestHeaderAuthRequestController I0416 12:16:54.248003 1 shared_informer.go:313] Waiting for caches to sync for RequestHeaderAuthRequestController I0416 12:16:54.248008 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I0416 12:16:54.248027 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0416 12:16:54.248716 1 configmap_cafile_content.go:205] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I0416 12:16:54.248790 1 shared_informer.go:313] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0416 12:16:54.249160 1 dynamic_serving_content.go:135] "Starting controller" name="serving-cert::/var/run/secrets/serving-cert/tls.crt::/var/run/secrets/serving-cert/tls.key" I0416 12:16:54.250192 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/var/run/secrets/serving-cert/tls.crt::/var/run/secrets/serving-cert/tls.key" certDetail="\"metrics.openshift-service-ca-operator.svc\" [serving] validServingFor=[metrics.openshift-service-ca-operator.svc,metrics.openshift-service-ca-operator.svc.cluster.local] issuer=\"openshift-service-serving-signer@1776341734\" (2026-04-16 12:15:44 +0000 UTC to 2028-04-15 12:15:45 +0000 UTC (now=2026-04-16 12:16:54.249576757 +0000 UTC))" I0416 12:16:54.250741 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776341814\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776341814\" (2026-04-16 11:16:53 +0000 UTC to 2027-04-16 11:16:53 +0000 UTC (now=2026-04-16 12:16:54.250708094 +0000 UTC))" I0416 12:16:54.250764 1 secure_serving.go:213] Serving securely on [::]:8443 I0416 12:16:54.250780 1 genericapiserver.go:685] [graceful-termination] waiting for shutdown to be initiated I0416 12:16:54.250791 1 tlsconfig.go:243] "Starting DynamicServingCertificateController" I0416 12:16:54.251101 1 leaderelection.go:257] attempting to acquire leader lease openshift-service-ca-operator/service-ca-operator-lock... I0416 12:16:54.252414 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.252456 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.253025 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.261191 1 leaderelection.go:271] successfully acquired lease openshift-service-ca-operator/service-ca-operator-lock I0416 12:16:54.261250 1 event.go:377] Event(v1.ObjectReference{Kind:"Lease", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator-lock", UID:"e3a2eca3-4003-450d-8d9f-00208eb274c0", APIVersion:"coordination.k8s.io/v1", ResourceVersion:"12593", FieldPath:""}): type: 'Normal' reason: 'LeaderElection' service-ca-operator-bc9564db4-zlhrx_5949c946-7221-44ca-9659-93f534b21c8f became leader I0416 12:16:54.261916 1 starter.go:111] Fetching FeatureGates I0416 12:16:54.262026 1 simple_featuregate_reader.go:171] Starting feature-gate-detector I0416 12:16:54.265343 1 reflector.go:376] Caches populated for *v1.FeatureGate from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.265545 1 starter.go:160] Setting signing certificate lifetime to 18960h0m0s, minimum trust duration to 9480h0m0s I0416 12:16:54.265614 1 event.go:377] Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-service-ca-operator", Name:"service-ca-operator", UID:"2b74d9d1-658f-444d-9e9e-9302073b9199", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'FeatureGatesInitialized' FeatureGates updated to featuregates.Features{Enabled:[]v1.FeatureGateName{"AdditionalRoutingCapabilities", "AdminNetworkPolicy", "AlibabaPlatform", "AzureWorkloadIdentity", "BuildCSIVolumes", "CPMSMachineNamePrefix", "ConsolePluginContentSecurityPolicy", "ExternalOIDC", "ExternalOIDCWithUIDAndExtraClaimMappings", "GCPClusterHostedDNSInstall", "GatewayAPI", "GatewayAPIController", "HighlyAvailableArbiter", "HyperShiftOnlyDynamicResourceAllocation", "ImageStreamImportMode", "ImageVolume", "KMSv1", "MachineConfigNodes", "ManagedBootImages", "ManagedBootImagesAWS", "ManagedBootImagesAzure", "ManagedBootImagesvSphere", "MetricsCollectionProfiles", "NetworkDiagnosticsConfig", "NetworkLiveMigration", "NetworkSegmentation", "PinnedImages", "PreconfiguredUDNAddresses", "ProcMountType", "RouteAdvertisements", "RouteExternalCertificate", "ServiceAccountTokenNodeBinding", "SigstoreImageVerification", "SigstoreImageVerificationPKI", "StoragePerformantSecurityPolicy", "UpgradeStatus", "UserNamespacesPodSecurityStandards", "UserNamespacesSupport", "VSphereMultiDisk", "VSphereMultiNetworks", "VolumeAttributesClass"}, Disabled:[]v1.FeatureGateName{"AWSClusterHostedDNS", "AWSClusterHostedDNSInstall", "AWSDedicatedHosts", "AWSDualStackInstall", "AWSServiceLBNetworkSecurityGroup", "AutomatedEtcdBackup", "AzureClusterHostedDNSInstall", "AzureDedicatedHosts", "AzureDualStackInstall", "AzureMultiDisk", "BootImageSkewEnforcement", "BootcNodeManagement", "CBORServingAndStorage", "CRDCompatibilityRequirementOperator", "ClientsAllowCBOR", "ClientsPreferCBOR", "ClusterAPIInstall", "ClusterAPIInstallIBMCloud", "ClusterAPIMachineManagement", "ClusterAPIMachineManagementVSphere", "ClusterMonitoringConfig", "ClusterVersionOperatorConfiguration", "DNSNameResolver", "DualReplica", "DyanmicServiceEndpointIBMCloud", "EtcdBackendQuota", "EventTTL", "EventedPLEG", "Example", "Example2", "ExternalSnapshotMetadata", "GCPClusterHostedDNS", "GCPCustomAPIEndpoints", "GCPCustomAPIEndpointsInstall", "GCPDualStackInstall", "ImageModeStatusReporting", "IngressControllerDynamicConfigurationManager", "InsightsConfig", "InsightsOnDemandDataGather", "IrreconcilableMachineConfig", "KMSEncryption", "KMSEncryptionProvider", "MachineAPIMigration", "MachineAPIOperatorDisableMachineHealthCheckController", "ManagedBootImagesCPMS", "MaxUnavailableStatefulSet", "MinimumKubeletVersion", "MixedCPUsAllocation", "MultiArchInstallAzure", "MultiDiskSetup", "MutableCSINodeAllocatableCount", "MutatingAdmissionPolicy", "NewOLM", "NewOLMBoxCutterRuntime", "NewOLMCatalogdAPIV1Metas", "NewOLMOwnSingleNamespace", "NewOLMPreflightPermissionChecks", "NewOLMWebhookProviderOpenshiftServiceCA", "NoRegistryClusterInstall", "NutanixMultiSubnets", "OSStreams", "OVNObservability", "OnPremDNSRecords", "OpenShiftPodSecurityAdmission", "ProvisioningRequestAvailable", "SELinuxMount", "ShortCertRotation", "SignatureStores", "TranslateStreamCloseWebsocketRequests", "VSphereConfigurableMaxAllowedBlockVolumesPerNode", "VSphereHostVMGroupZonal", "VSphereMixedNodeEnv", "VolumeGroupSnapshot"}} I0416 12:16:54.265891 1 reflector.go:376] Caches populated for *v1.ClusterVersion from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.266042 1 base_controller.go:76] Waiting for caches to sync for resource-sync I0416 12:16:54.266148 1 base_controller.go:76] Waiting for caches to sync for ServiceCAOperator I0416 12:16:54.266169 1 base_controller.go:76] Waiting for caches to sync for LoggingSyncer I0416 12:16:54.266789 1 base_controller.go:76] Waiting for caches to sync for StatusSyncer_service-ca I0416 12:16:54.270023 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.270022 1 reflector.go:376] Caches populated for *v1.ServiceCA from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.270218 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.270675 1 reflector.go:376] Caches populated for *v1.ClusterOperator from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.271929 1 reflector.go:376] Caches populated for *v1.Deployment from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.272523 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.272546 1 reflector.go:376] Caches populated for *v1.ServiceAccount from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.272911 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.273227 1 reflector.go:376] Caches populated for *v1.Infrastructure from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.273231 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.273482 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.273833 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.273959 1 reflector.go:376] Caches populated for *v1.Secret from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.274341 1 reflector.go:376] Caches populated for *v1.Namespace from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.348060 1 shared_informer.go:320] Caches are synced for RequestHeaderAuthRequestController I0416 12:16:54.348106 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I0416 12:16:54.348436 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-16 12:06:12 +0000 UTC to 2036-04-13 12:06:12 +0000 UTC (now=2026-04-16 12:16:54.348405906 +0000 UTC))" I0416 12:16:54.348461 1 tlsconfig.go:181] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-16 12:06:18 +0000 UTC to 2036-04-13 12:06:18 +0000 UTC (now=2026-04-16 12:16:54.348451251 +0000 UTC))" I0416 12:16:54.348477 1 tlsconfig.go:181] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-16 12:06:20 +0000 UTC to 2036-04-13 12:06:20 +0000 UTC (now=2026-04-16 12:16:54.348468446 +0000 UTC))" I0416 12:16:54.348491 1 tlsconfig.go:181] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"hcco-signer\" [] issuer=\"\" (2026-04-16 12:06:22 +0000 UTC to 2036-04-13 12:06:22 +0000 UTC (now=2026-04-16 12:16:54.348483047 +0000 UTC))" I0416 12:16:54.348505 1 tlsconfig.go:181] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer\" [] issuer=\"\" (2026-04-16 12:06:26 +0000 UTC to 2036-04-13 12:06:26 +0000 UTC (now=2026-04-16 12:16:54.348497799 +0000 UTC))" I0416 12:16:54.348527 1 tlsconfig.go:181] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2pn82so64dbfd7cg358bevtr5m7peubm-kx-a30c6ad771_customer-system-admin-signer@1776341346\" [] issuer=\"\" (2026-04-16 12:09:05 +0000 UTC to 2026-04-23 12:09:06 +0000 UTC (now=2026-04-16 12:16:54.348511487 +0000 UTC))" I0416 12:16:54.348545 1 tlsconfig.go:181] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2pn82so64dbfd7cg358bevtr5m7peubm-kx-a30c6ad771_sre-system-admin-signer@1776341346\" [] issuer=\"\" (2026-04-16 12:09:07 +0000 UTC to 2026-04-23 12:09:08 +0000 UTC (now=2026-04-16 12:16:54.348536621 +0000 UTC))" I0416 12:16:54.348757 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/var/run/secrets/serving-cert/tls.crt::/var/run/secrets/serving-cert/tls.key" certDetail="\"metrics.openshift-service-ca-operator.svc\" [serving] validServingFor=[metrics.openshift-service-ca-operator.svc,metrics.openshift-service-ca-operator.svc.cluster.local] issuer=\"openshift-service-serving-signer@1776341734\" (2026-04-16 12:15:44 +0000 UTC to 2028-04-15 12:15:45 +0000 UTC (now=2026-04-16 12:16:54.348744335 +0000 UTC))" I0416 12:16:54.348926 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776341814\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776341814\" (2026-04-16 11:16:53 +0000 UTC to 2027-04-16 11:16:53 +0000 UTC (now=2026-04-16 12:16:54.34891203 +0000 UTC))" I0416 12:16:54.348950 1 shared_informer.go:320] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I0416 12:16:54.349141 1 tlsconfig.go:181] "Loaded client CA" index=0 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-control-plane-signer\" [] issuer=\"\" (2026-04-16 12:06:12 +0000 UTC to 2036-04-13 12:06:12 +0000 UTC (now=2026-04-16 12:16:54.349128308 +0000 UTC))" I0416 12:16:54.349168 1 tlsconfig.go:181] "Loaded client CA" index=1 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-apiserver-to-kubelet-signer\" [] issuer=\"\" (2026-04-16 12:06:18 +0000 UTC to 2036-04-13 12:06:18 +0000 UTC (now=2026-04-16 12:16:54.349152331 +0000 UTC))" I0416 12:16:54.349189 1 tlsconfig.go:181] "Loaded client CA" index=2 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"admin-kubeconfig-signer\" [] issuer=\"\" (2026-04-16 12:06:20 +0000 UTC to 2036-04-13 12:06:20 +0000 UTC (now=2026-04-16 12:16:54.349175005 +0000 UTC))" I0416 12:16:54.349206 1 tlsconfig.go:181] "Loaded client CA" index=3 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"hcco-signer\" [] issuer=\"\" (2026-04-16 12:06:22 +0000 UTC to 2036-04-13 12:06:22 +0000 UTC (now=2026-04-16 12:16:54.349197908 +0000 UTC))" I0416 12:16:54.349219 1 tlsconfig.go:181] "Loaded client CA" index=4 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"kube-csr-signer\" [] issuer=\"\" (2026-04-16 12:06:26 +0000 UTC to 2036-04-13 12:06:26 +0000 UTC (now=2026-04-16 12:16:54.349211984 +0000 UTC))" I0416 12:16:54.349236 1 tlsconfig.go:181] "Loaded client CA" index=5 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2pn82so64dbfd7cg358bevtr5m7peubm-kx-a30c6ad771_customer-system-admin-signer@1776341346\" [] issuer=\"\" (2026-04-16 12:09:05 +0000 UTC to 2026-04-23 12:09:06 +0000 UTC (now=2026-04-16 12:16:54.349227521 +0000 UTC))" I0416 12:16:54.349262 1 tlsconfig.go:181] "Loaded client CA" index=6 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"ocm-production-2pn82so64dbfd7cg358bevtr5m7peubm-kx-a30c6ad771_sre-system-admin-signer@1776341346\" [] issuer=\"\" (2026-04-16 12:09:07 +0000 UTC to 2026-04-23 12:09:08 +0000 UTC (now=2026-04-16 12:16:54.349253794 +0000 UTC))" I0416 12:16:54.349278 1 tlsconfig.go:181] "Loaded client CA" index=7 certName="client-ca::kube-system::extension-apiserver-authentication::client-ca-file,client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" certDetail="\"aggregator-signer\" [] issuer=\"\" (2026-04-16 12:06:10 +0000 UTC to 2036-04-13 12:06:10 +0000 UTC (now=2026-04-16 12:16:54.349271114 +0000 UTC))" I0416 12:16:54.349445 1 tlsconfig.go:203] "Loaded serving cert" certName="serving-cert::/var/run/secrets/serving-cert/tls.crt::/var/run/secrets/serving-cert/tls.key" certDetail="\"metrics.openshift-service-ca-operator.svc\" [serving] validServingFor=[metrics.openshift-service-ca-operator.svc,metrics.openshift-service-ca-operator.svc.cluster.local] issuer=\"openshift-service-serving-signer@1776341734\" (2026-04-16 12:15:44 +0000 UTC to 2028-04-15 12:15:45 +0000 UTC (now=2026-04-16 12:16:54.349434312 +0000 UTC))" I0416 12:16:54.349611 1 named_certificates.go:53] "Loaded SNI cert" index=0 certName="self-signed loopback" certDetail="\"apiserver-loopback-client@1776341814\" [serving] validServingFor=[apiserver-loopback-client] issuer=\"apiserver-loopback-client-ca@1776341814\" (2026-04-16 11:16:53 +0000 UTC to 2027-04-16 11:16:53 +0000 UTC (now=2026-04-16 12:16:54.34960137 +0000 UTC))" I0416 12:16:54.366348 1 base_controller.go:82] Caches are synced for LoggingSyncer I0416 12:16:54.366368 1 base_controller.go:119] Starting #1 worker of LoggingSyncer controller ... I0416 12:16:54.366424 1 base_controller.go:82] Caches are synced for ServiceCAOperator I0416 12:16:54.366445 1 base_controller.go:119] Starting #1 worker of ServiceCAOperator controller ... I0416 12:16:54.367589 1 base_controller.go:82] Caches are synced for StatusSyncer_service-ca I0416 12:16:54.367597 1 base_controller.go:119] Starting #1 worker of StatusSyncer_service-ca controller ... I0416 12:16:54.469844 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.682764 1 reflector.go:376] Caches populated for *v1.ConfigMap from k8s.io/client-go@v0.32.2/tools/cache/reflector.go:251 I0416 12:16:54.766521 1 base_controller.go:82] Caches are synced for resource-sync I0416 12:16:54.766538 1 base_controller.go:119] Starting #1 worker of resource-sync controller ...