Name: cert-manager-webhook-f4fb5df64-kfv5q Namespace: cert-manager Priority: 0 Service Account: cert-manager-webhook Node: master-0/192.168.32.10 Start Time: Wed, 03 Dec 2025 14:37:45 +0000 Labels: app=webhook app.kubernetes.io/component=webhook app.kubernetes.io/instance=cert-manager app.kubernetes.io/name=webhook app.kubernetes.io/version=v1.18.3 pod-template-hash=f4fb5df64 Annotations: k8s.ovn.org/pod-networks: {"default":{"ip_addresses":["10.128.0.84/23"],"mac_address":"0a:58:0a:80:00:54","gateway_ips":["10.128.0.1"],"routes":[{"dest":"10.128.0.0... k8s.v1.cni.cncf.io/network-status: [{ "name": "ovn-kubernetes", "interface": "eth0", "ips": [ "10.128.0.84" ], "mac": "0a:58:0a:80:00:54", "default": true, "dns": {} }] openshift.io/scc: restricted-v2 prometheus.io/path: /metrics prometheus.io/port: 9402 prometheus.io/scrape: true seccomp.security.alpha.kubernetes.io/pod: runtime/default Status: Running SeccompProfile: RuntimeDefault IP: 10.128.0.84 IPs: IP: 10.128.0.84 Controlled By: ReplicaSet/cert-manager-webhook-f4fb5df64 Containers: cert-manager-webhook: Container ID: cri-o://76a060906d16d0c0d905dd62fb2f3e7d990b2c001f4c4e36d7034fe3e10f0904 Image: registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df Image ID: registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df Ports: 10250/TCP, 6080/TCP, 9402/TCP Host Ports: 0/TCP, 0/TCP, 0/TCP Command: /app/cmd/webhook/webhook Args: --dynamic-serving-ca-secret-name=cert-manager-webhook-ca --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE) --dynamic-serving-dns-names=cert-manager-webhook,cert-manager-webhook.$(POD_NAMESPACE),cert-manager-webhook.$(POD_NAMESPACE).svc --secure-port=10250 --v=2 State: Running Started: Wed, 03 Dec 2025 14:38:08 +0000 Ready: True Restart Count: 0 Liveness: http-get http://:healthcheck/livez delay=60s timeout=1s period=10s #success=1 #failure=3 Readiness: http-get http://:healthcheck/healthz delay=5s timeout=1s period=5s #success=1 #failure=3 Environment: POD_NAMESPACE: cert-manager (v1:metadata.namespace) Mounts: /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-lr55x (ro) /var/run/secrets/openshift/serviceaccount from bound-sa-token (ro) Conditions: Type Status PodReadyToStartContainers True Initialized True Ready True ContainersReady True PodScheduled True Volumes: bound-sa-token: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3600 kube-api-access-lr55x: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: DownwardAPI: true ConfigMapName: openshift-service-ca.crt ConfigMapOptional: QoS Class: BestEffort Node-Selectors: kubernetes.io/os=linux Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 10m default-scheduler Successfully assigned cert-manager/cert-manager-webhook-f4fb5df64-kfv5q to master-0 Normal AddedInterface 10m multus Add eth0 [10.128.0.84/23] from ovn-kubernetes Normal Pulling 10m kubelet Pulling image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df" Normal Pulled 10m kubelet Successfully pulled image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df" in 13.407s (13.407s including waiting). Image size: 427346153 bytes. Normal Created 10m kubelet Created container: cert-manager-webhook Normal Started 10m kubelet Started container cert-manager-webhook