Name:             cert-manager-webhook-f4fb5df64-tgx98
Namespace:        cert-manager
Priority:         0
Service Account:  cert-manager-webhook
Node:             master-0/192.168.32.10
Start Time:       Thu, 04 Dec 2025 22:28:05 +0000
Labels:           app=webhook
                  app.kubernetes.io/component=webhook
                  app.kubernetes.io/instance=cert-manager
                  app.kubernetes.io/name=webhook
                  app.kubernetes.io/version=v1.18.3
                  pod-template-hash=f4fb5df64
Annotations:      k8s.ovn.org/pod-networks:
                    {"default":{"ip_addresses":["10.128.0.120/23"],"mac_address":"0a:58:0a:80:00:78","gateway_ips":["10.128.0.1"],"routes":[{"dest":"10.128.0....
                  k8s.v1.cni.cncf.io/network-status:
                    [{
                        "name": "ovn-kubernetes",
                        "interface": "eth0",
                        "ips": [
                            "10.128.0.120"
                        ],
                        "mac": "0a:58:0a:80:00:78",
                        "default": true,
                        "dns": {}
                    }]
                  openshift.io/scc: restricted-v2
                  prometheus.io/path: /metrics
                  prometheus.io/port: 9402
                  prometheus.io/scrape: true
                  seccomp.security.alpha.kubernetes.io/pod: runtime/default
Status:           Running
SeccompProfile:   RuntimeDefault
IP:               10.128.0.120
IPs:
  IP:           10.128.0.120
Controlled By:  ReplicaSet/cert-manager-webhook-f4fb5df64
Containers:
  cert-manager-webhook:
    Container ID:  cri-o://efb52ae1897e0c4604747a1e7353079f9d0aae173d90969ace263412d5ee5a39
    Image:         registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df
    Image ID:      registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df
    Ports:         10250/TCP, 6080/TCP, 9402/TCP
    Host Ports:    0/TCP, 0/TCP, 0/TCP
    Command:
      /app/cmd/webhook/webhook
    Args:
      --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
      --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
      --dynamic-serving-dns-names=cert-manager-webhook,cert-manager-webhook.$(POD_NAMESPACE),cert-manager-webhook.$(POD_NAMESPACE).svc
      --secure-port=10250
      --v=2
    State:          Running
      Started:      Thu, 04 Dec 2025 22:28:16 +0000
    Ready:          True
    Restart Count:  0
    Liveness:       http-get http://:healthcheck/livez delay=60s timeout=1s period=10s #success=1 #failure=3
    Readiness:      http-get http://:healthcheck/healthz delay=5s timeout=1s period=5s #success=1 #failure=3
    Environment:
      POD_NAMESPACE:  cert-manager (v1:metadata.namespace)
    Mounts:
      /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-ft8jn (ro)
      /var/run/secrets/openshift/serviceaccount from bound-sa-token (ro)
Conditions:
  Type                        Status
  PodReadyToStartContainers   True 
  Initialized                 True 
  Ready                       True 
  ContainersReady             True 
  PodScheduled                True 
Volumes:
  bound-sa-token:
    Type:                    Projected (a volume that contains injected data from multiple sources)
    TokenExpirationSeconds:  3600
  kube-api-access-ft8jn:
    Type:                    Projected (a volume that contains injected data from multiple sources)
    TokenExpirationSeconds:  3607
    ConfigMapName:           kube-root-ca.crt
    ConfigMapOptional:       <nil>
    DownwardAPI:             true
    ConfigMapName:           openshift-service-ca.crt
    ConfigMapOptional:       <nil>
QoS Class:                   BestEffort
Node-Selectors:              kubernetes.io/os=linux
Tolerations:                 node.kubernetes.io/not-ready:NoExecute op=Exists for 300s
                             node.kubernetes.io/unreachable:NoExecute op=Exists for 300s
Events:
  Type    Reason          Age   From               Message
  ----    ------          ----  ----               -------
  Normal  Scheduled       44m   default-scheduler  Successfully assigned cert-manager/cert-manager-webhook-f4fb5df64-tgx98 to master-0
  Normal  AddedInterface  44m   multus             Add eth0 [10.128.0.120/23] from ovn-kubernetes
  Normal  Pulling         44m   kubelet            Pulling image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df"
  Normal  Pulled          44m   kubelet            Successfully pulled image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df" in 10.535s (10.535s including waiting). Image size: 427346153 bytes.
  Normal  Created         44m   kubelet            Created container: cert-manager-webhook
  Normal  Started         44m   kubelet            Started container cert-manager-webhook
