Upgrade chef-client to v18.8.9 or later, which contains the corrected key-install logic. If you are pinned and cannot upgrade, fetch the key out of band (e.g. download the key file directly) and point apt_repository at the file instead of the keyserver. After upgrading, re-run the recipe and confirm the signed-by keyring is created without errors.

Context: GitHub issue chef/chef#14943 (closed): on Chef 18.7.3 with Ubuntu 20.04/22.04, apt_repository cannot create the GPG key file when the key is specified via keyserver; the reporter notes the install-key conditions look wrong. The reporter confirms the fix: resolved by PRs #15008 and #15043, released in v18.8.9.