You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add ACME identity label protection for solver extra labels
Prevent global solver extra labels from overwriting ACME identity labels
(acme.cert-manager.io/http-domain, acme.cert-manager.io/http-token,
acme.cert-manager.io/http01-solver) on dynamically-created HTTP01 solver
resources. A filterACMEIdentityLabels helper strips these protected keys
before merging. Without this guard, extra labels could silently break
resource discovery.
Signed-off-by: Yuedong Wu <dwcn22@outlook.com>
Copy file name to clipboardExpand all lines: deploy/charts/cert-manager/README.template.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -112,7 +112,7 @@ If a component-specific nodeSelector is also set, it will be merged and take pre
112
112
Labels to apply to all resources.
113
113
These labels are also applied to dynamically-created ACME HTTP01 solver resources
114
114
(pods, services, ingresses, or Gateway API HTTPRoutes).
115
-
For per-Issuer-specific labels, use the HTTP01 ingress solver podTemplate and ingressTemplate fields for pod/ingress resources, or the gatewayHTTPRoute solver labels field for Gateway API HTTPRoute resources.
115
+
The following ACME identity label keys are reserved and will be silently ignored on dynamically-created resources: acme.cert-manager.io/http-domain, acme.cert-manager.io/http-token, acme.cert-manager.io/http01-solver. For per-Issuer-specific labels, use the HTTP01 ingress solver podTemplate and ingressTemplate fields for pod/ingress resources, or the gatewayHTTPRoute solver labels field for Gateway API HTTPRoute resources.
116
116
#### **global.revisionHistoryLimit** ~ `number`
117
117
118
118
The number of old ReplicaSets to retain to allow rollback (if not set, the default Kubernetes value is set to 10).
Copy file name to clipboardExpand all lines: deploy/charts/cert-manager/values.schema.json
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -831,7 +831,7 @@
831
831
},
832
832
"helm-values.global.commonLabels": {
833
833
"default": {},
834
-
"description": "Labels to apply to all resources.\nThese labels are also applied to dynamically-created ACME HTTP01 solver resources\n(pods, services, ingresses, or Gateway API HTTPRoutes).\nFor per-Issuer-specific labels, use the HTTP01 ingress solver podTemplate and ingressTemplate fields for pod/ingress resources, or the gatewayHTTPRoute solver labels field for Gateway API HTTPRoute resources.",
834
+
"description": "Labels to apply to all resources.\nThese labels are also applied to dynamically-created ACME HTTP01 solver resources\n(pods, services, ingresses, or Gateway API HTTPRoutes).\nThe following ACME identity label keys are reserved and will be silently ignored on dynamically-created resources: acme.cert-manager.io/http-domain, acme.cert-manager.io/http-token, acme.cert-manager.io/http01-solver. For per-Issuer-specific labels, use the HTTP01 ingress solver podTemplate and ingressTemplate fields for pod/ingress resources, or the gatewayHTTPRoute solver labels field for Gateway API HTTPRoute resources.",
0 commit comments