Releases: cert-manager/cert-manager
Release list
v1.20.4
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects.
All users should upgrade.
Note
Security scanners still report three golang.org/x/crypto findings. None of them affects cert-manager and we do not plan to fix them in the 1.20 line.
- CVE-2026-56855 and CVE-2026-78662 are deadlocks in the
golang.org/x/crypto/sshconnection multiplexer, triggered by a malicious SSH peer after a connection is established. cert-manager never opens an SSH connection. Only the controller links thesshpackage, throughvcert, which uses it to format a public key. The fix,golang.org/x/cryptov0.56.0, requires Go language version 1.26, which we will not adopt in a patch release.govulncheckconfirms the vulnerable functions are not called. - GO-2026-5932 marks
golang.org/x/crypto/openpgpas unmaintained. cert-manager does not import that package and there is no fixed version.
cert-manager 1.21 already uses golang.org/x/crypto v0.56.0, so upgrade to 1.21 if you need a clean scan.
Changes by Kind
Bug or Regression
- Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects (#9315, @KR-Ravindra)
Other (Cleanup or Flake)
- Update Go to 1.26.5 and then 1.26.6, which include security fixes to the go command, and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages (#8995, @wallrj-cyberark; #9152, @wallrj)
- Bump
golang.org/x/netto v0.58.0,golang.org/x/textto v0.41.0 andgolang.org/x/cryptoto v0.55.0 to fix CVE-2026-46600, CVE-2026-56852 and CVE-2026-56854 (#9040, @wallrj-cyberark) - Bump
google.golang.org/grpcto v1.83.2 to fix CVE-2026-84304, CVE-2026-84445, CVE-2026-84303 and one further advisory (#9062, #9257, #9316) - Bump
github.com/google/cel-goto v0.30.0 to fix a reported vulnerability (#9070, #9186) - Bump
software.sslmate.com/src/go-pkcs12to v0.7.2 to fix a reported vulnerability (#8988) - Bump
golang.org/x/mod,go.opentelemetry.io/otelandgo.etcd.io/etcd/client/pkg/v3to versions flagged by security scanners (#9143, #9071, #9185) - Update the distroless base images (#8991, #9024, #9055, #9325)
- The release staging process now signs
metadata.jsonwith cosign so the publish step can verify its authenticity (#9090, @FelixPhipps)
v1.21.2
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.
All users should upgrade.
Changes by Kind
Bug or Regression
- ACME Issuer response bodies are no longer reflected into Issuer status conditions or Kubernetes Events. Only ACME problem documents are surfaced (bounded in length); other responses are reported by HTTP status code alone, with the full error available in the controller logs. (#9239, @FelixPhipps)
- Cap ACME server response bodies at 16 MiB to guard against unbounded-body denial-of-service. (#9222, @FelixPhipps)
- De-duplicate dnsNames when multiple Gateway/ListenerSet listeners share a Secret (#9234, @speer)
- Fix certificate renewal windows using February 29 cron schedules across non-leap century years. (#9240, @wieghx)
- Fix validating webhook panics when AdmissionReview requests omit optional fields, by routing identity, approval, and resource validation on the always-present Resource/SubResource fields and denying (rather than silently allowing) requests with an unset or mismatched resource. As a side effect, validation is now also enforced for equivalent-converted requests on non-v1 API versions, which previously could skip validation. (#9235, @lunarwhite)
- Fixed HTTP-01 solver cleanup so that a solver ingress, pod or service that has already been deleted no longer fails the cleanup with a NotFound error. (#9278, @arpitjain099)
- Fixed a bug where
replacesfield was being populated for the wrong issuer on issuer changes (#9236, @hjoshi123) - Fixed a data race in the ACME HTTP-01 self-check that could occur when custom DNS servers were configured. (#9313, @shashankvarma499)
- Fixed a panic in the certificates-issuing controller when a CertificateRequest has a failure time set but no Ready condition. (#9238, @thc1006)
- Fixed a race in pkg/scheduler where the cleanup of a fired timer could cancel a newer timer scheduled for the same object, silently dropping a rescheduled poll. (#9312, @shashankvarma499)
- Fixed an issue where the body of a non-Vault HTTP response from
spec.vault.servercould be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. (#9262, @FelixPhipps) - Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects (#9314, @KR-Ravindra)
- The ACME HTTP-01 self-check no longer reflects the fetched response body in
Challenge.status.reason, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. (#9232, @FelixPhipps) - The
vaultissuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespacedIssuer, unless ambient credentials are explicitly enabled via--issuer-ambient-credentials.ClusterIssuerand explicitserviceAccountRef(IRSA) configurations are unaffected. (#9231, @FelixPhipps)
Other (Cleanup or Flake)
- Upgrade Go to 1.26.6, which includes security fixes to the go command, and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages. (#9151, @wallrj)
- Upgrade Go to 1.26.8. (#9323, @wallrj)
- Bump
google.golang.org/grpcto v1.83.2 to fix reported security vulnerabilities (#9255, #9317) - Bump
golang.org/x/cryptoto v0.56.0 to fix reported security vulnerabilities (#9265)
v1.21.1
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck at Ready=False (InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.
All users should upgrade.
Changes by Kind
Bug or Regression
- Avoid controller panic if a Certificate sets spec.renewal.policy=Disabled (#9038, @sklirg)
- Fix Issuer/ClusterIssuer stuck at Ready=False/InvalidSolver after a missing ACME DNS-01 solver Secret is created (#9083, @SebTardif)
- Fix log spam and dropped Secret informer events for non-cert-manager Secrets, caused by a generics regression introduced in 1.21.0. (#9037, @wallrj-cyberark)
- Fixed the commented Gateway API config example in the Helm chart values to use
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)
Other (Cleanup or Flake)
- Bump
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark) - Bump
google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063) - Bump
github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072) - Bump
go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073) - Update distroless base images (#9000, #9025)
v1.21.0
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading.
Known Issues
- Controller crash-loops when a Certificate sets
renewal.policy: Disabled: the new Certificate renewal policies feature (#8258) causes a nil pointer dereference panic in the trigger controller whenever a Certificate'sspec.renewal.policyis set toDisabled—pki.RenewalTime()returns(nil, nil)for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. Workaround: do not setrenewal.policy: Disabledon any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See #9031 for details. - Log spam for non-cert-manager-labelled Secret events: the typed predicates refactoring (#8407) causes
filteredEventHandlertype assertion failures ("OnAdd missing Object","OnUpdate missing ObjectOld","OnDelete missing Object") for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. This is cosmetic only — the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See #8994 for details. - Issuer/ClusterIssuer can get stuck at
Ready: False, Reason: InvalidSolverand never self-correct: new eager validation of ACME solver Secrets (#8255) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly reportReady: False, but creating the missing Secret afterwards does not trigger re-reconciliation — the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. Workaround: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See #9036 for details and a fix proposal.
Major Themes
Default tokenrequest RBAC removed from Helm chart
⚠️ Breaking change
The Helm chart no longer creates a default Role and RoleBinding granting the cert-manager controller permission to create tokens for its own ServiceAccount (serviceaccounts/token: create). No documented workflow requires this RBAC — the Route53 docs section that motivated it was removed in 2024.
If you use serviceAccountRef.name pointing at the controller ServiceAccount, you must now either create your own Role/RoleBinding granting serviceaccounts/token: create, or migrate to a dedicated ServiceAccount (recommended — see the Vault or Route53 documentation).
Restrict Challenge and Order RBAC in cert-manager-edit ClusterRole
⚠️ Potentially breaking change
The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io (GHSA-8rvj-mm4h-c258). These resources are internal to cert-manager's ACME workflow. Challenge patch and update are retained because users may need them to remove stuck finalizers.
This change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly.
Metrics port name and path Helm values removed
⚠️ Breaking change
The Helm values prometheus.servicemonitor.targetPort, prometheus.servicemonitor.path, and prometheus.podmonitor.path have been removed. The controller Service metrics port has been renamed from tcp-prometheus-servicemonitor to http-metrics. Because the Helm values schema uses additionalProperties: false, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade — remove them before upgrading. (#8952)
ACME and Certificate Management
- ACME Renewal Information (ARI): experimental support for RFC 9773 behind the
ACMEUseARIfeature gate. When enabled, cert-manager queries the ACME server'srenewalInfoendpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. (#8798) waitInsteadOfSelfChecksolver option: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See configuration details. (#8858)- AWS IAM authentication for Vault: the Vault issuer now supports IRSA, EKS Pod Identity, and ambient EC2/ECS credentials, removing the need for long-lived AWS Secrets. (#8422)
- Certificate renewal policies: a new
renewalPoliciesfield on the Certificate API provides more expressive control over renewal scheduling, complementingrenewBeforeandrenewBeforePercentage. (#8258) - Configurable CertificateRequest retry backoff: the new
--certificate-request-maximum-backoff-durationflag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. (#8893) - Modern2026 PKCS#12 profile: a new FIPS 140-3 compatible encoding profile using AES-256 + SHA-256 KDFs instead of legacy 3DES/RC2. (#8841)
- Webhook certificate renewal after system suspend: the webhook now detects missed certificate renewals after system suspend (S3/S4) or VM live migration by polling wall-clock time, recovering within one minute of resume. (#8464)
Gateway API and cainjector
- HTTP01 ListenerSet parentRef fallback: the
acme.cert-manager.io/http01-parentreffallback: "true"annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. (#8749) cert-manager.io/ignore-tls-listenersannotation: exclude specific Gateway TLS listeners from certificate management. (#8727)- Additional listener protocols: configurable listener protocols beyond the default set. (#8683)
enableGatewayAPIconfiguration restructure:enableGatewayAPIandenableGatewayAPIListenerSetare deprecated in favor ofgatewayAPI.enabled/gatewayAPI.enableListenerSet. The old fields continue to work. (#8732)CAInjectorMergingpromoted to GA: unconditionally enabled; will be removed in a future release. (#8583)- cainjector server-side apply unconditional: the
ServerSideApplyfeature gate is deprecated. (#8692) - cainjector
--ignore-namespacesflag: skip specified namespaces when watching Secrets for injection. (#8614)
Deployment and Observability
- Venafi OAuth token observability: a new
AuthFailedIssuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. (#8808, #8779) runtimeClassNamesupport: configurable for cert-manager components and ACME HTTP01 solver pods. (#8791, #8976)startupapicheck.ttlSecondsAfterFinished: opt-in automatic cleanup of the startupapicheck Job. (#8523)--acme-http01-solver-extra-labels: propagateglobal.commonLabelsto dynamically-created ACME HTTP01 solver resources. (#8761)
Notable Bug Fixes
- Integer overflow in
renewBeforePercentage: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. (#8947) - Infinite re-issuance loop: cert-manager no longer loops when an issuer returns an already-expired certificate. (#8610)
- ACME transient network errors: challenges no longer permanently fail on TLS handshake timeouts, DNS resolution failures, or context cancellation during nonce fetches and authorization waits. (#8760)
- DNS-over-HTTPS response body cap: response body reads are now bounded at 128 KB to prevent potential OOM. (#8803)
- Vault path traversal: the Vault issuer webhook now rejects
..path segments, preventingpath.Joinfrom silently resolving relative segments. (#8930) - DNS issuer secrets validated before ready: prevents silent misconfiguration. (#8255)
Community
As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.
A special thanks to:
- @Copilot
- @FelixPhipps
- @Peac36
- @SebTardif
- @apkatsikas
- @bitloi
- @dap0am
- @figaw
- @immanuwell
- @jabbrwcky
- @jnohlgard
- @jsoref
- @ltwongaa
- @lunarwhite
- @mateenali66
- @onurmicoogullari
- @putongyong
- @seanorama
- @texasich
for their contributions, comments and support!
Also, thanks to the cert-manager maintainer team for their help in this release:
- @sgtc...
v1.21.0-beta.0
Note
For full release notes including breaking changes, upgrade notes, major themes and community credits, see the v1.21 release notes.
Changes since v1.21.0-alpha.1
Feature
- Add
certificateRequestMaximumBackoffDurationcontroller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file,--certificate-request-maximum-backoff-durationCLI flag, or Helm valueconfig.certificateRequestMaximumBackoffDuration. Defaults to 32 hours for backward compatibility. (#8893, @lunarwhite) - Add an optional
waitInsteadOfSelfCheckfield to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. (#8858, @wallrj) - Add configurable
runtimeClassNamesupport for cert-manager components and ACME HTTP01 solver pods. (#8791, @jsoref) - Added ARI support through the ACMEUseARI feature gate. (#8798, @hjoshi123)
- Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). (#8422, @bitloi)
- Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3. (#8841, @seanorama)
- A new flag
--ignore-namespaceswas added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. (#8614, @figaw) - Disabled client side rate-limiting if AP&F is enabled. (#8757, @hjoshi123)
- Processed annotations
cert-manager.io/alt-names,cert-manager.io/ip-sansto Certificates generated from ingress like objects in cert-shim controllers. (#8927, @jabbrwcky) - When using ACME HTTP-01 with a ListenerSet, setting the annotation
acme.cert-manager.io/http01-parentreffallback: "true"causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. (#8749, @apkatsikas)
Bug or Regression
- BREAKING: The Helm chart no longer ships a default
RoleandRoleBindinggranting the cert-manager controller ServiceAccount permission to create tokens for itself (serviceaccounts/token: create). This RBAC was added in v1.16 (#7213) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely onserviceAccountRef.namepointing at the controller ServiceAccount (an undocumented pattern), you must now create your ownRoleandRoleBindinggrantingserviceaccounts/token: createon that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). (#8931, @wallrj-cyberark) - ACME challenges no longer terminally fail on transient network errors (TLS handshake timeouts, DNS failures, context cancellation) during nonce fetches and authorization waits. The challenge controller returns the error and lets the workqueue retry with backoff. (#8760, @texasich)
- Fix webhook serving certificate not being renewed after system suspend. (#8464, @Peac36)
- Fixed a rare panic in the trigger controller when a Certificate is deleted from the informer cache while a reconcile is in progress (e.g. during namespace teardown). (#8962, @hjoshi123)
- Fixed an integer overflow in
renewBeforePercentagecalculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. (#8947, @ThatsMrTalbot) - Fixed potential OOM in DNS-over-HTTPS client by bounding response body read with io.LimitReader (128 KB cap). (#8803, @SebTardif)
- Fixed validation of timezone-prefixed renewal window cron specs without a schedule. (#8813, @immanuwell)
- Harden ACME Challenge and Order resources: reject user-created Challenges without Order ownership, enforce Order spec immutability, and detect pre-placed same-name Challenges with mismatched specs. (#8948, @wallrj-cyberark)
- Remove ACME Challenge
createand Ordercreate/patch/updatefrom the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). (#8958, @wallrj-cyberark) - Update logic to identify and preserve the secret matching nextPrivateKeySecretName. (#8577, @putongyong)
- Vault Issuer webhook validation now rejects
...path segments inspec.vault.pathand auth mount path fields, preventingpath.Joinfrom silently resolving relative segments before constructing the Vault API request. (#8930, @wallrj-cyberark)
Other (Cleanup or Flake)
- Remove Helm values
prometheus.servicemonitor.targetPort,prometheus.servicemonitor.path, andprometheus.podmonitor.path. The metrics path is always/metricsand the target port is alwayshttp-metrics. Rename the controller service metrics port fromtcp-prometheus-servicemonitortohttp-metricsfor consistency with other workloads. Users must remove these keys from their value overrides before upgrading. (#8952, @erikgb) - Update base images to Debian 13. (#8849, @ltwongaa)
v1.20.3
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.
This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.
All users should upgrade.
Warning
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.
Changes by Kind
Bug or Regression
- Security (HIGH): Remove Challenge
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8940, @wallrj-cyberark) - Remove issuer owner reference from challenges blocking challenge garbage collection (#8759, @cert-manager-bot)
Other (Cleanup or Flake)
- Bump go to 1.26.3, other deps to fix several govulncheck issues (#8789, @SgtCoDFish)
- Update Go to
v1.26.4to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8926, @wallrj-cyberark)
v1.19.6
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.
This release also includes Go version bumps to address reported CVEs. All users should upgrade.
Warning
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.
Changes by Kind
Bug or Regression
- Security (HIGH): Remove Challenge
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8941, @wallrj-cyberark)
Other (Cleanup or Flake)
- Update Go to
v1.25.11to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8925, @wallrj-cyberark) - Upgrade Go to 1.25.10 to fix reported vulnerabilities, along with other dependency bumps (#8788, @SgtCoDFish)
v1.21.0-alpha.1
Changes since v1.21.0-alpha.0
Note
Feature
- Add Venafi OAuth token request observability and a new
AuthFailedIssuer condition reason to distinguish bad credentials from transient infrastructure errors. (#8808, @FelixPhipps) - Add new controller flag
--acme-http01-solver-extra-labels, allowing Helm'sglobal.commonLabelsto propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). (#8761, @lunarwhite) - Add opt-in
startupapicheck.ttlSecondsAfterFinishedHelm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. (#8523, @dap0am) - Added
cert-manager.io/ignore-tls-listenersannotation for ignoring gwapi listeners. (#8727, @hjoshi123) - Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. (#8683, @ThatsMrTalbot)
- Extend the Venafi/CyberArk integration to also support PANW NGTS. (#8779, @FelixPhipps)
- Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate (#8692, @erikgb)
Bug or Regression
- Add dns issuer secrets validation before marking it as ready (#8255, @Peac36)
- Add missing issuer finalizer RBAC to the order controller to support owner references (#8654, @erikgb)
- ClusterIssuer metrics collector now correctly respects the enabled-controllers configuration, avoiding a redundant startup when only operating within a namespace. (#8822, @lunarwhite)
- Fix Venafi TPP issuer setup and signing regression on master: restore authentication of the vcert connector in the client constructor, which was removed in #8808. (#8843, @wallrj-cyberark)
- Fix a performance issue in the certificateRequestApproval webhook where CertificateRequests referencing a GroupKind whose CRD is not yet installed would trigger repeated API server discovery queries on every admission request. Negative results are now cached for 30 seconds. (#8651, @mateenali66)
- Fixed infinite re-issuance loop when issuer returns an already expired certificate (#8610, @onurmicoogullari)
- Fixed local
e2e-setup-samplewebhookinstallation to use the samplewebhook image repository and tag from the saved image tarball manifest. (#8821, @wallrj) - Helm chart bugfix: rename image helper to avoid umbrella chart conflicts (#8753, @FelixPhipps)
- Helm: Fix invalid YAML generated when both
webhook.configandwebhook.volumesare defined. (#8664, @jnohlgard) - Remove issuer owner reference from challenges blocking challenge garbage collection (#8743, @erikgb)
Other (Cleanup or Flake)
- The
enableGatewayAPIandenableGatewayAPIListenerSetfields onControllerConfigurationare deprecated and moved into thegatewayAPIsub-struct asgatewayAPI.enabledandgatewayAPI.enableListenerSet. The old fields continue to work. (#8732, @ThatsMrTalbot)
v1.19.5
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.
Changes by Kind
Other (Cleanup or Flake)
v1.20.2
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config
and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies
to address reported vulnerabilities.
Changes by Kind
Bug or Regression
- Helm: Fix invalid YAML generated when both
webhook.configandwebhook.volumesare defined. (#8665, @cert-manager-bot)