Name: cert-manager-webhook-f4fb5df64-42npf Namespace: cert-manager Priority: 0 Service Account: cert-manager-webhook Node: master-0/192.168.32.10 Start Time: Thu, 04 Dec 2025 12:12:25 +0000 Labels: app=webhook app.kubernetes.io/component=webhook app.kubernetes.io/instance=cert-manager app.kubernetes.io/name=webhook app.kubernetes.io/version=v1.18.3 pod-template-hash=f4fb5df64 Annotations: k8s.ovn.org/pod-networks: {"default":{"ip_addresses":["10.128.0.148/23"],"mac_address":"0a:58:0a:80:00:94","gateway_ips":["10.128.0.1"],"routes":[{"dest":"10.128.0.... k8s.v1.cni.cncf.io/network-status: [{ "name": "ovn-kubernetes", "interface": "eth0", "ips": [ "10.128.0.148" ], "mac": "0a:58:0a:80:00:94", "default": true, "dns": {} }] openshift.io/scc: restricted-v2 prometheus.io/path: /metrics prometheus.io/port: 9402 prometheus.io/scrape: true seccomp.security.alpha.kubernetes.io/pod: runtime/default Status: Running SeccompProfile: RuntimeDefault IP: 10.128.0.148 IPs: IP: 10.128.0.148 Controlled By: ReplicaSet/cert-manager-webhook-f4fb5df64 Containers: cert-manager-webhook: Container ID: cri-o://852178fa237f2ad0bce2cd40d22715c90c835e664cd9b0bba86468773e4e3948 Image: registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df Image ID: registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df Ports: 10250/TCP, 6080/TCP, 9402/TCP Host Ports: 0/TCP, 0/TCP, 0/TCP Command: /app/cmd/webhook/webhook Args: --dynamic-serving-ca-secret-name=cert-manager-webhook-ca --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE) --dynamic-serving-dns-names=cert-manager-webhook,cert-manager-webhook.$(POD_NAMESPACE),cert-manager-webhook.$(POD_NAMESPACE).svc --secure-port=10250 --v=2 State: Running Started: Thu, 04 Dec 2025 12:12:37 +0000 Ready: True Restart Count: 0 Liveness: http-get http://:healthcheck/livez delay=60s timeout=1s period=10s #success=1 #failure=3 Readiness: http-get http://:healthcheck/healthz delay=5s timeout=1s period=5s #success=1 #failure=3 Environment: POD_NAMESPACE: cert-manager (v1:metadata.namespace) Mounts: /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-tmcvf (ro) /var/run/secrets/openshift/serviceaccount from bound-sa-token (ro) Conditions: Type Status PodReadyToStartContainers True Initialized True Ready True ContainersReady True PodScheduled True Volumes: bound-sa-token: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3600 kube-api-access-tmcvf: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: DownwardAPI: true ConfigMapName: openshift-service-ca.crt ConfigMapOptional: QoS Class: BestEffort Node-Selectors: kubernetes.io/os=linux Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 37m default-scheduler Successfully assigned cert-manager/cert-manager-webhook-f4fb5df64-42npf to master-0 Normal AddedInterface 37m multus Add eth0 [10.128.0.148/23] from ovn-kubernetes Normal Pulling 37m kubelet Pulling image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df" Normal Pulled 37m kubelet Successfully pulled image "registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:29a0fa1c2f2a6cee62a0468a3883d16d491b4af29130dad6e3e2bb2948f274df" in 10.426s (10.426s including waiting). Image size: 427346153 bytes. Normal Created 37m kubelet Created container: cert-manager-webhook Normal Started 37m kubelet Started container cert-manager-webhook