Name:             cert-manager-webhook-687f57d79b-jfhbt
Namespace:        cert-manager
Priority:         0
Service Account:  cert-manager-webhook
Node:             crc/192.168.126.11
Start Time:       Tue, 27 Jan 2026 18:17:47 +0000
Labels:           app=webhook
                  app.kubernetes.io/component=webhook
                  app.kubernetes.io/instance=cert-manager
                  app.kubernetes.io/name=webhook
                  app.kubernetes.io/version=v1.19.2
                  pod-template-hash=687f57d79b
Annotations:      k8s.ovn.org/pod-networks:
                    {"default":{"ip_addresses":["10.217.0.13/23"],"mac_address":"0a:58:0a:d9:00:0d","gateway_ips":["10.217.0.1"],"routes":[{"dest":"10.217.0.0...
                  k8s.v1.cni.cncf.io/network-status:
                    [{
                        "name": "ovn-kubernetes",
                        "interface": "eth0",
                        "ips": [
                            "10.217.0.13"
                        ],
                        "mac": "0a:58:0a:d9:00:0d",
                        "default": true,
                        "dns": {}
                    }]
                  openshift.io/scc: restricted-v2
                  prometheus.io/path: /metrics
                  prometheus.io/port: 9402
                  prometheus.io/scrape: true
                  seccomp.security.alpha.kubernetes.io/pod: runtime/default
Status:           Running
SeccompProfile:   RuntimeDefault
IP:               10.217.0.13
IPs:
  IP:           10.217.0.13
Controlled By:  ReplicaSet/cert-manager-webhook-687f57d79b
Containers:
  cert-manager-webhook:
    Container ID:  cri-o://16eb4e3e04684bc396f8b415958a6dfeff3981eeff07496a006170e7acbc673f
    Image:         quay.io/jetstack/cert-manager-webhook:v1.19.2
    Image ID:      quay.io/jetstack/cert-manager-webhook@sha256:041f7bb9259557188d7ff416ce90d670a0d0aa8710203927703743682064270b
    Ports:         10250/TCP, 6080/TCP, 9402/TCP
    Host Ports:    0/TCP, 0/TCP, 0/TCP
    Args:
      --v=2
      --secure-port=10250
      --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
      --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
      --dynamic-serving-dns-names=cert-manager-webhook
      --dynamic-serving-dns-names=cert-manager-webhook.$(POD_NAMESPACE)
      --dynamic-serving-dns-names=cert-manager-webhook.$(POD_NAMESPACE).svc
    State:          Running
      Started:      Tue, 27 Jan 2026 18:18:06 +0000
    Ready:          True
    Restart Count:  0
    Liveness:       http-get http://:healthcheck/livez delay=60s timeout=1s period=10s #success=1 #failure=3
    Readiness:      http-get http://:healthcheck/healthz delay=5s timeout=1s period=5s #success=1 #failure=3
    Environment:
      POD_NAMESPACE:  cert-manager (v1:metadata.namespace)
    Mounts:
      /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-hrzvw (ro)
Conditions:
  Type                        Status
  PodReadyToStartContainers   True 
  Initialized                 True 
  Ready                       True 
  ContainersReady             True 
  PodScheduled                True 
Volumes:
  kube-api-access-hrzvw:
    Type:                    Projected (a volume that contains injected data from multiple sources)
    TokenExpirationSeconds:  3607
    ConfigMapName:           kube-root-ca.crt
    ConfigMapOptional:       <nil>
    DownwardAPI:             true
    ConfigMapName:           openshift-service-ca.crt
    ConfigMapOptional:       <nil>
QoS Class:                   BestEffort
Node-Selectors:              kubernetes.io/os=linux
Tolerations:                 node.kubernetes.io/not-ready:NoExecute op=Exists for 300s
                             node.kubernetes.io/unreachable:NoExecute op=Exists for 300s
Events:
  Type     Reason                  Age                   From               Message
  ----     ------                  ----                  ----               -------
  Normal   Scheduled               80m                   default-scheduler  Successfully assigned cert-manager/cert-manager-webhook-687f57d79b-jfhbt to crc
  Warning  FailedCreatePodSandBox  80m                   kubelet            Failed to create pod sandbox: rpc error: code = Unknown desc = failed to create pod network sandbox k8s_cert-manager-webhook-687f57d79b-jfhbt_cert-manager_53565dd2-5a29-4ba0-9654-36b9600f765b_0(8f951fdbf6ec980d4798a3115b6cb29985a372d421e325ec4ae9c0d2bade4977): no CNI configuration file in /etc/kubernetes/cni/net.d/. Has your network provider started?
  Warning  FailedCreatePodSandBox  80m                   kubelet            Failed to create pod sandbox: rpc error: code = Unknown desc = failed to create pod network sandbox k8s_cert-manager-webhook-687f57d79b-jfhbt_cert-manager_53565dd2-5a29-4ba0-9654-36b9600f765b_0(6ac74bee930f68148680ac07734c051bda9ae7fe889f196ba52d77463f5ee28d): no CNI configuration file in /etc/kubernetes/cni/net.d/. Has your network provider started?
  Normal   AddedInterface          80m                   multus             Add eth0 [10.217.0.13/23] from ovn-kubernetes
  Normal   Pulling                 80m                   kubelet            Pulling image "quay.io/jetstack/cert-manager-webhook:v1.19.2"
  Normal   Pulled                  80m                   kubelet            Successfully pulled image "quay.io/jetstack/cert-manager-webhook:v1.19.2" in 3.395s (3.395s including waiting). Image size: 69110520 bytes.
  Normal   Created                 80m                   kubelet            Created container cert-manager-webhook
  Normal   Started                 80m                   kubelet            Started container cert-manager-webhook
  Warning  Unhealthy               8m5s (x3 over 8m25s)  kubelet            Readiness probe failed: Get "http://10.217.0.13:6080/healthz": context deadline exceeded (Client.Timeout exceeded while awaiting headers)
