Today, I tried to upgrade cert-manager, but it failed.
So I reinstalled cert-manager several times.
I keep getting error of certification is invalide.
Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: kibana.kfr.storm.treasury-factory.com
I ran this command:
I tried to upgrade cert-manager from 0.2.3 to 0.6.2
It produced this output:
Error creating new order :: too many new orders recently: see https://letsencrypt.org/docs/rate-limits/
Type Reason Age From Message │ certmanager.k8s.io/
---- ------ ---- ---- ------- │ v1alpha1
Normal OrderCreated 36m cert-manager Created Order resource “kfr-kibana-tls-876723094” │ kind: Issuer
Normal OrderCreated 36m cert-manager Created Order resource “kfr-kibana-tls-3948581898” │ metadata:
Normal Cleanup 36m cert-manager Deleting old Order resource “kfr-kibana-tls-876723094” │ name: monitoring-
Normal Cleanup 36m cert-manager Deleting old Order resource “kfr-kibana-tls-876723094” │ letsencrypt-prod
Warning ErrorCheckCertificate 36m (x2 over 36m) cert-manager-controller Error checking existing TLS certificate: error decoding cert PEM block │ namespace:
Normal PrepareCertificate 36m (x3 over 36m) cert-manager-controller Preparing certificate with issuer │ monitoring
Normal Generated 36m cert-manager Generated new private key │ spec:
Normal Generated 36m cert-manager Generated new private key │ acme:
Warning ErrorCheckCertificate 36m cert-manager-controller Error checking existing TLS certificate: secret “kfr-kibana-tls” not found │ server: https://
Warning ErrorPrepareCertificate 36m (x3 over 36m) cert-manager-controller Error preparing issuer for certificate: Error checking ACME domain validation: error getting authorization │ acme-v02.api.
for domains: [’’: getting acme authorization failed: Head : unsupported protocol scheme “”] │ letsencrypt.org/
Normal OrderCreated 36m (x2 over 36m) cert-manager Created Order resource “kfr-kibana-tls-3948581898” │ directory
Warning IssuerNotReady 26m (x646 over 36m) cert-manager Issuer kfr-letsencrypt-prod not ready │ email: devops@
Warning IssuerNotReady 26m (x652 over 36m) cert-manager Issuer kfr-letsencrypt-prod not ready │ kyriba.com
Warning ErrorIssuerNotReady 26m (x76 over 36m) cert-manager-controller Issuer kfr-letsencrypt-prod not ready │
Normal Cleanup 21m (x15 over 36m) cert-manager Deleting old Order resource “kfr-kibana-tls-3948581898” │ privateKeySecretRef:
Normal Generated 17m cert-manager Generated new private key │ name:
Normal OrderCreated 15m (x3 over 17m) cert-manager Created Order resource “kfr-kibana-tls-3948581898” │ monitoring-
Normal Cleanup 15m (x9 over 17m) cert-manager Deleting old Order resource “kfr-kibana-tls-876723094” │ letsencrypt-prod
Normal OrderCreated 15m (x4 over 17m) cert-manager Created Order resource “kfr-kibana-tls-876723094” │ dns01:
Normal Cleanup 2m (x53 over 17m) cert-manager Deleting old Order resource “kfr-kibana-tls-3948581898” │ providers:
Normal Cleanup 1m (x79 over 36m) cert-manager Deleting old Order resource “kfr-kibana-tls-3948581898”
My web server is (include version): Nginx
The operating system my web server runs on is (include version): Kubernetes nginx Ingress
My hosting provider, if applicable, is:
I can login to a root shell on my machine (yes or no, or I don’t know):
I don’t know
I’m using a control panel to manage my site (no, or provide the name and version of the control panel):
No
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you’re using Certbot):