apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  creationTimestamp: "2026-04-06T12:18:20Z"
  generation: 1
  labels:
    service-cert: ""
  name: keystone-internal-svc
  namespace: openstack
  ownerReferences:
  - apiVersion: core.openstack.org/v1beta1
    blockOwnerDeletion: true
    controller: true
    kind: OpenStackControlPlane
    name: controlplane
    uid: e9483bca-f0de-49be-8485-de75f78b1729
  resourceVersion: "45905"
  uid: 99d828f7-6364-4af5-aa0a-04fedbae6114
spec:
  dnsNames:
  - keystone-internal.openstack.svc
  - keystone-internal.openstack.svc.cluster.local
  duration: 43800h0m0s
  issuerRef:
    group: cert-manager.io
    kind: Issuer
    name: rootca-internal
  secretName: cert-keystone-internal-svc
  secretTemplate:
    labels:
      service-cert: ""
  usages:
  - key encipherment
  - digital signature
  - server auth
status:
  conditions:
  - lastTransitionTime: "2026-04-06T12:18:21Z"
    message: Certificate is up to date and has not expired
    observedGeneration: 1
    reason: Ready
    status: "True"
    type: Ready
  notAfter: "2031-04-05T12:18:21Z"
  notBefore: "2026-04-06T12:18:21Z"
  renewalTime: "2029-08-05T04:18:21Z"
  revision: 1
