Open PRs (112)

Resolution:

Average age: 203.2d, Avg wait: 31.3d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6376 WIP: Add OCSP stapling functionality 17h 17h 17h
size/XL
release-note-none
area/api
do-not-merge/work-in-progress
kind/feature
needs-ok-to-test
dco-signoff: no
collaborator-last
recv
unreviewed
6348 Replace governance documents with link to cert-manager community documents. 13d 19h 19h
size/L
release-note-none
approved
do-not-merge/hold
kind/cleanup
dco-signoff: yes
commented
member-last
new-commits
6192 Remove conflicting labels from CRDs 3mo 22h 3mo
release-note-none
size/S
needs-ok-to-test
lifecycle/stale
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
recv
unreviewed
5158 Added certificate owner ref field
6
1y 22h 3mo
release-note
approved
area/api
kind/feature
size/XXL
dco-signoff: yes
area/testing
ok-to-test
area/deploy
assigned
assignee-updated
collaborator-last
commented
recv
reviewed-with-comment
similar
5777 helm: Add option to keep CRDs when helm chart is uninstalled
3
7mo 1d 1d
release-note
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
commented
send
unreviewed
6344 Upgrade all dependencies 14d 1d 13d
release-note-none
needs-rebase
kind/cleanup
size/XXL
area/acme
dco-signoff: yes
area/testing
collaborator-last
commented
open-milestone
unreviewed
6365 update revisionhistoryLimit for deployment
1d 1d 1d
release-note-none
size/S
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
commented
member-last
send
similar
unreviewed
6351 Handle multiple concurrent Azure DNS01 challenges for the same FQDN 9d 1d 2d
size/L
release-note
ok-to-test
author-last
commented
recv
similar
unreviewed
5823 Make it possible to split a cert-manager installation over multiple Helm releases. 7mo 2d 4wk
do-not-merge/release-note-label-needed
needs-rebase
size/S
needs-ok-to-test
dco-signoff: no
area/deploy
needs-kind
assigned
assignee-updated
collaborator-last
commented
recv
recv-q
unreviewed
6228 Issue 5514 read cabundle from kube objects - design doc
3
2mo 2d 7d
size/L
release-note-none
kind/design
needs-ok-to-test
dco-signoff: no
assigned
assignee-updated
author-last
commented
new-commits
open-milestone
recv
recv-q
6345 Introduce config file for cainjector options 14d 2d
release-note
area/api
kind/feature
size/XXL
dco-signoff: yes
area/deploy
collaborator-last
unreviewed
6001 Improve verify-chart scripts & add helmchk 5mo 3d 5mo
release-note-none
needs-rebase
approved
kind/cleanup
size/M
lifecycle/rotten
dco-signoff: yes
collaborator-last
commented
new-commits
5446 Allow concurrent same-FQDN DNS-01 challenges when using route53 1y 3d 5mo
release-note
size/M
area/acme
lifecycle/rotten
dco-signoff: yes
area/testing
ok-to-test
needs-kind
collaborator-last
commented
open-milestone
reviewed-with-comment
send
similar
5356 Allow ECDSA for ACME client keys
2
4
1y 3d 4mo
size/L
release-note
needs-rebase
area/api
kind/feature
area/acme
lifecycle/rotten
dco-signoff: yes
area/testing
ok-to-test
area/deploy
collaborator-last
commented
reviewed-with-comment
send
5373 Allow config of http01 solver pod security context
2
1y 3d 5mo
size/L
release-note
needs-rebase
area/api
kind/feature
area/acme
lifecycle/rotten
dco-signoff: yes
ok-to-test
area/acme/http01
area/deploy
collaborator-last
commented
recv-q
send
unreviewed
6355 WIP: Make issuerRef group default to cert-manager.io 4d 4d 4d
size/XS
release-note-none
area/api
do-not-merge/work-in-progress
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
draft
recv
unreviewed
6248 feat: allow changing the default Deployment revisionHistoryLimit 1mo 5d 1mo
release-note
size/S
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
recv
similar
unreviewed
6003 move pkg/issuer/acme/http/solver to cmd/acmesolver/solver 5mo 6d
release-note-none
approved
size/S
kind/cleanup
area/acme
lifecycle/rotten
dco-signoff: yes
area/acme/http01
collaborator-last
unreviewed
6186 feat: Add OwnerReference to the secrets created by ACME ClusterIssuer and Issuer 3mo 6d 2mo
size/XS
release-note-none
needs-ok-to-test
area/acme
dco-signoff: yes
needs-kind
commented
send
unreviewed
6028 Fix runtime.Scheme errors in tests 4mo 6d
size/L
release-note-none
kind/cleanup
lifecycle/stale
area/acme
dco-signoff: yes
area/testing
collaborator-last
open-milestone
unreviewed
6190 Adds ingress annotation support for alt-names 3mo 6d 6d
release-note
size/S
needs-ok-to-test
dco-signoff: yes
area/testing
needs-kind
commented
member-last
send
similar
unreviewed
6347 Do not process non-HTTPS listeners on Gateways 13d 13d 13d
size/XS
release-note
needs-ok-to-test
dco-signoff: yes
needs-kind
collaborator-last
recv
unreviewed
6314 Upgrade go-licenses to the latest master version 3wk 15d 3wk
release-note-none
needs-rebase
approved
kind/cleanup
size/M
area/acme
dco-signoff: yes
area/testing
collaborator-last
commented
unreviewed
5420 Add SkipTLSVerify option to Vault issuer
2
1y 18d 2mo
release-note
size/S
area/api
needs-ok-to-test
dco-signoff: no
needs-kind
author-last
commented
new-commits
recv
recv-q
5324 Create 20220720-per-certificate-owner-ref.md
6
1y 3wk 3wk
size/L
release-note-none
approved
kind/design
lifecycle/rotten
dco-signoff: yes
commented
member-last
reviewed-with-comment
similar
5743 Add MaxPathLen and add EncodeBasicConstraintsInRequest option to Certificate and CertificateRequest resources 8mo 3wk 6wk
release-note
size/XL
needs-rebase
approved
area/api
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
area/deploy
collaborator-last
commented
new-commits
open-milestone
6315 Upgrade go to 1.21 3wk 3wk
size/L
release-note-none
needs-rebase
kind/cleanup
area/acme
dco-signoff: yes
area/testing
collaborator-last
unreviewed
6103 Unify semver version logic 4mo 4wk
size/L
release-note-none
approved
kind/cleanup
dco-signoff: yes
collaborator-last
open-milestone
unreviewed
5848 WIP: Design: core-issuers 6mo 4wk 3mo
release-note-none
approved
lgtm
do-not-merge/work-in-progress
do-not-merge/hold
kind/design
size/M
dco-signoff: yes
collaborator-last
commented
reviewed-with-comment
send
5383 Generate applyconfigurations and Apply functions 1y 4wk 7mo
release-note
needs-rebase
approved
area/api
do-not-merge/work-in-progress
priority/important-longterm
size/XXL
dco-signoff: yes
needs-kind
changes-requested
collaborator-last
commented
draft
5447 Allow extra DNS-01 propagation time to be configured
1y 4wk 1y
release-note
needs-rebase
size/S
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
needs-kind
collaborator-last
commented
open-milestone
recv
unreviewed
5567 Certificates: preventing CertificateRequest creation runaway 10mo 4wk 3mo
release-note
needs-rebase
approved
area/api
kind/feature
size/XXL
dco-signoff: yes
area/testing
area/deploy
assigned
assignee-updated
collaborator-last
commented
open-milestone
reviewed-with-comment
6002 Move pkg/controller/cainjector to cmd/cainjector/controller 5mo 4wk 4mo
release-note-none
needs-rebase
approved
size/S
kind/cleanup
dco-signoff: yes
collaborator-last
commented
unreviewed
6102 Move ctl utils to cmd/ctl 4mo 4wk
size/L
release-note-none
needs-rebase
approved
kind/cleanup
dco-signoff: yes
area/testing
collaborator-last
unreviewed
6145 Improve Trigger, Readiness and PostIssuance Policy chains 3mo 4wk 3mo
size/L
release-note-none
approved
do-not-merge/work-in-progress
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
collaborator-last
commented
draft
unreviewed
6155 Add Certificate Hash 3mo 4wk
size/L
release-note-none
needs-rebase
approved
area/api
do-not-merge/work-in-progress
kind/feature
dco-signoff: yes
collaborator-last
draft
unreviewed
6120 add comments explaining the Sync function & small test bugfix 3mo 5wk 2mo
release-note-none
approved
lgtm
size/S
kind/cleanup
dco-signoff: yes
assigned
assignee-updated
commented
member-last
open-milestone
reviewed-with-comment
5860 Fix helm loglevel parsing 6mo 5wk 4mo
size/XS
release-note-none
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
commented
member-last
open-milestone
reviewed-with-comment
send
6277 ControllerConfiguration fuzzer, only set the value in case the random value is empty 6wk 5wk
size/L
release-note-none
approved
area/api
kind/cleanup
dco-signoff: yes
area/testing
collaborator-last
unreviewed
6266 fix(rbac): add patch verb on secrets to issuer clusterrole 6wk 6wk 6wk
size/XS
release-note-none
do-not-merge/hold
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
approved
commented
member-last
send
6124 Add design/20230601.gateway-route-hostnames. 3mo 6wk 3mo
size/L
release-note-none
kind/design
needs-ok-to-test
dco-signoff: yes
collaborator-last
new-commits
recv
recv-q
6053 Make KeyUsage and BasicConstraints Critical extensions 4mo 6wk
release-note
approved
kind/bug
size/M
dco-signoff: yes
collaborator-last
open-milestone
unreviewed
4330 Add client certificate auth method for Vault issuer
4
2y 6wk 6mo
release-note
needs-rebase
approved
area/api
kind/feature
size/XXL
area/acme
area/vault
dco-signoff: yes
area/testing
ok-to-test
area/deploy
collaborator-last
commented
open-milestone
recv
recv-q
reviewed-with-comment
similar
6015 add imagePullSecrets clauses to deployments, jobs
4mo 7wk 7wk
release-note
size/S
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
collaborator-last
commented
send
unreviewed
5701 feat: added custom endpoint override flag for http solver 8mo 1mo 8mo
release-note
needs-rebase
kind/feature
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/acme/http01
collaborator-last
recv
recv-q
unreviewed
6146 Add Venafi custom field support to cert-shim 3mo 2mo 2mo
release-note-none
size/S
do-not-merge/hold
needs-ok-to-test
dco-signoff: yes
needs-kind
changes-requested
commented
member-last
send
6122 Improve acmedns so that it honors followCname Setting 3mo 2mo 2mo
size/XS
release-note
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
needs-kind
commented
member-last
send
unreviewed
6193 [feat] when helm set `installCRDs: true`. crds.yaml file must be pre-install and pre-upgrade 3mo 2mo 2mo
release-note
size/S
kind/feature
needs-ok-to-test
dco-signoff: yes
area/deploy
commented
member-last
send
unreviewed
5876 helm: add support for TLS configuration and application protocol
2
6mo 12h 3d
release-note
needs-rebase
size/S
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
assigned
assignee-updated
author-last
commented
recv
reviewed-with-comment
1279 docs: Certificate Defaults Tutorial
7
3wk 1d 1d
dco-signoff: yes
size/XL
needs-rebase
commented
member-last
reviewed-with-comment
1304 WIP: Restructure top level (v2) 2d 2d
dco-signoff: yes
size/XXL
do-not-merge/work-in-progress
unreviewed
1303 Add command-issuer to external issuers list 6d 6d 6d
size/XS
dco-signoff: yes
recv
unreviewed
1289 Add diagrams to explain all the "requesting certificates"/ "obtaining certificates" flows 2wk 6d
dco-signoff: yes
size/XL
unreviewed
1291 Reorganise the usage section & move missing topics to this section 2wk 6d
dco-signoff: yes
size/L
unreviewed
1276 Release-process: sed command not compatible with BSD sed and other improvements
3wk 12d 12d
approved
dco-signoff: yes
lgtm
do-not-merge/hold
size/L
approved
commented
contributor-last
1260 WIP: Clearer top-level menu layout 2mo 3wk 2mo
approved
dco-signoff: yes
size/XL
needs-rebase
do-not-merge/work-in-progress
assigned
assignee-updated
commented
contributor-last
reviewed-with-comment
send
1283 Run "npm update" 3wk 3wk 3wk
approved
dco-signoff: yes
size/XXL
do-not-merge/work-in-progress
commented
draft
unreviewed
1253 Remove Bitnami kubeprod as installation method 3mo 3wk 3wk
dco-signoff: yes
size/S
commented
member-last
reviewed-with-comment
send
790 Update route53.md 2y 3wk 3wk
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
changes-requested
commented
member-last
send
1259 Fixed Azure Workload identity doc 2mo 2mo 2mo
dco-signoff: yes
size/S
recv
unreviewed
1249 Correct `kubectl operator install` for latest version of operator-sdk 3mo 3mo 3mo
size/XS
dco-signoff: yes
changes-requested
commented
member-last
send
1234 Correct the cmctl release generation flow 4mo 3mo 4mo
approved
dco-signoff: yes
needs-rebase
size/S
contributor-last
recv
unreviewed
1075 Move Issuer / ClusterIssuer and Certificate resource content to a sub-folder of configuration/ 1y 3mo
approved
dco-signoff: yes
size/L
needs-rebase
changes-requested
contributor-last
948 add note to ingress class definition 1y 4mo 4mo
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
assigned
commented
contributor-last
send
unreviewed
1213 Draft of tutorial for Google's Public CA 5mo 4mo 4mo
dco-signoff: yes
size/L
ok-to-test
commented
member-last
reviewed-with-comment
send
1071 Improved the summary on the docs homepage
2
1y 4mo 4mo
approved
dco-signoff: yes
size/S
commented
contributor-last
reviewed-with-comment
send
1202 Add section about client cert authentication for vault 6mo 5mo 5mo
dco-signoff: yes
do-not-merge/work-in-progress
size/M
commented
contributor-last
draft
new-commits
send
similar
1197 doc about new option default-cleanup-policy
6mo 5mo 5mo
approved
dco-signoff: yes
size/M
commented
member-last
new-commits
send
1199 Webhook troubleshooting: advise people to set `timeoutSeconds` to 30 seconds 6mo 6mo
approved
dco-signoff: yes
size/M
unreviewed
548 Move the "Approval API" documentation to /concepts/certificaterequest
2y 7mo 2y
approved
dco-signoff: yes
kind/cleanup
size/XL
needs-rebase
assigned
assignee-updated
changes-requested
commented
contributor-last
send
859 Move the meetings and slack information to a separate page
2y 1y 1y
approved
dco-signoff: yes
needs-rebase
size/M
changes-requested
commented
member-last
send
701 Issuer with IRSA needs ambient credentials flag
2y 1y 2y
dco-signoff: no
size/S
ok-to-test
commented
contributor-last
new-commits
send
528 Update "Setting Nameservers for DNS01 Self Check" example 2y 2y 2y
size/XS
dco-signoff: yes
needs-rebase
needs-ok-to-test
contributor-last
recv
unreviewed
1305 Update latest cm version from v1.13.0 to v1.13.1 22h 18h
approved
dco-signoff: yes
lgtm
do-not-merge/hold
size/M
approved
contributor-last
17 Add image validation for Docker architecture 3y 2y 2y
dco-signoff: yes
lgtm
size/L
needs-rebase
assigned
assignee-updated
commented
contributor-last
new-commits
send
43 No more requirement "be in the release folder" to run cmrel, remove the flag --cloudbuild 2y 2y
dco-signoff: yes
approved
size/M
needs-rebase
contributor-last
unreviewed
36 Add the "cmrel update-release-branch" command 2y 2y 2y
dco-signoff: yes
approved
size/M
needs-rebase
do-not-merge/work-in-progress
commented
contributor-last
draft
unreviewed
128 Bump google.golang.org/grpc from 1.49.0 to 1.53.0 2mo 2mo 2mo
dco-signoff: yes
size/XL
dependencies
ok-to-test
commented
member-last
send
unreviewed
204 Add "inner workings" section to README.md 4mo 4mo 4mo
dco-signoff: yes
approved
size/XS
commented
member-last
unreviewed
187 Add the ability to ignore cluster scoped resources. 9mo 4mo 7mo
dco-signoff: yes
size/XS
ok-to-test
commented
contributor-last
recv
recv-q
reviewed-with-comment
202 Support adding pod annotations 6mo 6mo 6mo
dco-signoff: yes
size/XS
needs-ok-to-test
contributor-last
recv
similar
unreviewed
216 feat: add the ability to specify certificate usages 2mo 6d 2mo
dco-signoff: yes
size/M
needs-ok-to-test
contributor-last
recv
unreviewed
256 CEL expressions approver design
6
2mo 4d 5d
dco-signoff: yes
approved
needs-ok-to-test
size/XL
do-not-merge/hold
commented
contributor-last
new-commits
recv
229 feat: fix app label of metrics svc for ServiceMonitor discovery
2
5mo 4mo 4mo
dco-signoff: yes
size/XS
ok-to-test
commented
member-last
reviewed-with-comment
send
273 Bump the all group with 1 update 2d 2d 2d
dco-signoff: yes
size/XS
needs-ok-to-test
dependencies
go
contributor-last
recv
unreviewed
184 Add certificates deduplication feature
5
4d 1d 2d
dco-signoff: yes
size/L
ok-to-test
author-last
commented
recv
recv-q
reviewed-with-comment
108 Supporting a secret target
4
8mo 3d 4mo
dco-signoff: yes
size/XL
ok-to-test
needs-rebase
assigned
assignee-updated
commented
contributor-last
recv-q
reviewed-with-comment
send
157 Add support for generating certificates with helm 7wk 3d 6wk
dco-signoff: yes
approved
size/M
commented
contributor-last
unreviewed
156 Allow enabling hostNetwork mode in Helm chart 7wk 5d 7wk
dco-signoff: yes
size/XS
lgtm
ok-to-test
approved
recv
recv-q
116 feat: add support for additional pod annotations/labels 7mo 10d 5wk
dco-signoff: yes
approved
ok-to-test
size/S
assigned
assignee-updated
commented
contributor-last
recv
similar
unreviewed
176 Allow configuring of the priorityClass 2wk 19d 2wk
dco-signoff: yes
size/XS
ok-to-test
contributor-last
recv
unreviewed
151 Respect seccomp toggle in init container 2mo 4wk 4wk
size/XS
needs-ok-to-test
dco-signoff: no
commented
member-last
send
unreviewed
149 Add Configurable Common Labels and Add a PDB 2mo 5wk 2mo
dco-signoff: yes
size/M
needs-ok-to-test
needs-rebase
contributor-last
recv
recv-q
unreviewed
147 Add ability to set pod level securityContext 3mo 3mo 3mo
dco-signoff: yes
size/XS
needs-ok-to-test
contributor-last
recv
unreviewed
118 Make seccompProfile optional in initContainer 5mo 4mo 4mo
dco-signoff: yes
size/XS
ok-to-test
needs-rebase
commented
member-last
send
unreviewed
98 Cert formats proposal 8mo 8mo
dco-signoff: yes
approved
size/L
contributor-last
unreviewed
186 Bump version to v0.7.0-alpha.1 2d 13h 2d
dco-signoff: yes
size/XS
commented
contributor-last
unreviewed
139 Bump golang.org/x/text from 0.3.7 to 0.3.8 in /hack/tools
7mo 16d 16d
dco-signoff: yes
size/S
ok-to-test
dependencies
commented
member-last
send
unreviewed
135 Added options to all containers 8mo 7mo 7mo
dco-signoff: yes
size/L
needs-rebase
ok-to-test
assigned
commented
contributor-last
send
unreviewed
129 Add attribute support for certificate subject
9mo 10d 10d
dco-signoff: yes
size/L
ok-to-test
commented
member-last
reviewed-with-comment
send
25 Fix default renewal period
5mo 12d 12d
dco-signoff: yes
size/XS
commented
member-last
reviewed-with-comment
send
32 Allow installation in a custom namespace
3mo 12d 12d
dco-signoff: yes
size/L
commented
member-last
send
unreviewed
40 Make it possible to install openshift-routes in a different namespace than "cert-manager" 12d 12d
dco-signoff: no
do-not-merge/work-in-progress
size/L
contributor-last
draft
unreviewed
29 Additional support for subject annotations
3
3mo 12d 12d
dco-signoff: yes
size/XXL
commented
member-last
reviewed-with-comment
send
similar
24 Document release process and update the versions of the GitHub Actions workflows 6mo 4mo
dco-signoff: yes
size/M
approved
contributor-last
unreviewed
28 add support for ecdsa keys
4
3mo 9d 12d
dco-signoff: yes
size/XXL
commented
contributor-last
new-commits
recv
46 Add timeout to renewal issuance logic
7mo 3wk 3wk
dco-signoff: yes
size/M
ok-to-test
commented
contributor-last
new-commits
recv
48 Retry pending request when issue is called 7mo 3wk 3wk
dco-signoff: yes
size/L
ok-to-test
assigned
assignee-updated
commented
member-last
new-commits
send
34 WIP: E2E testing boilerplate
1y 7mo 1y
size/XXL
dco-signoff: yes
do-not-merge/hold
approved
do-not-merge/work-in-progress
needs-rebase
commented
contributor-last
new-commits
recv
recv-q
28 Include Pod UID on CertificateRequest resources
1y 1y 1y
dco-signoff: yes
do-not-merge/hold
approved
size/XS
ok-to-test
assigned
contributor-last
recv
recv-q
unreviewed
51 add pending request cache to allow for resuming in-flight requests that take longer than a single issuance cycle
6
3wk 14d 3wk
dco-signoff: yes
size/L
changes-requested
commented
contributor-last
recv-q
42 Switch sample-external-issuer to issuer-lib 6wk 19d
do-not-merge/work-in-progress
dco-signoff: yes
size/XXL
contributor-last
draft
unreviewed

Open Issues (358)

Resolution:

Average age: 455.4d, Avg wait: 167.0d
<
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6375 cert-manager cannot connect to Vault through HTTPS when using a certificate signed with CA with X509v3 Name Constraints extension 20h 20h 20h
recv
6364 Enabling ServerSideApply feature gate changes status conditions behavior
1d 18h 1d
kind/bug
commented
contributor-last
recv
6363 Unable to set revisionHistoryLimit on the deployments 1d 1d 1d
kind/bug
pr-unreviewed
recv
6361 Allow `cert-manager.io/allow-direct-injection` annotation on `Certificate` `Secret`s 1d 1d
good first issue
6356 Graduate AdditionalCertificateOutputFormats feature gate
4d 4d 4d
kind/feature
recv
similar
6353 Docs: Wrong example Code for creating Issuers 7d 5d 5d
kind/bug
author-last
commented
recv
recv-q
6350 Webhook inject-ca-from annotation causes downtime
4
12d 2d 7d
kind/bug
author-last
commented
recv
6346 Webhook feature gates only set if controller feature gates are 14d 3d 12d
good first issue
kind/bug
priority/important-soon
collaborator-last
commented
send
6343 [Helm: possible improvement] Controller ConfigMap is created even if .Values.config is not set
14d 5d 5d
kind/cleanup
commented
contributor-last
pr-merged
recv
6334 Query recursive nameservers for DNS01 challenge in round robin fashion 16d 13d 16d
kind/feature
recv
6331 CSR not signed by referenced private key
2
16d 15d 15d
author-last
commented
recv
6327 wrong status code '404', expected '200' with one specific Ingress 18d 18d 18d
kind/bug
recv
6325 The RSA-SHA signature algorithm is not correctly mapped to the certificate. 2wk 13d 15d
assigned
assignee-updated
author-last
commented
recv
6323 Even if CA is expired, cert-manager allows to issue client cert with expired CA 3wk 3wk 3wk
recv
6312 Report issuer/clusterissuer status as a metric 4wk 4wk 4wk
kind/feature
recv
6309 How to pass ServiceAccountName to the acme-http01-solver pod. 4wk 19d 4wk
author-last
recv
6308 Route53 challenges not regulating failed requests with exponential backoffs
4wk 15h 4wk
recv
recv-q
6307 Certificates only issued for ingress in default namespace 4wk 4wk 4wk
kind/bug
recv
6305 Error "Waiting for DNS-01 challenge propagation: dial udp: address udp/53': unknown port" 4wk 4wk 4wk
recv
6294 Helm chart deployment is failing on update to k8s 1.25 4wk 4wk 4wk
triage/needs-information
commented
member-last
send
6288 Generate cert-manager secret with certificate,key and password 5wk 5wk 5wk
kind/feature
recv
6286 Remove dependencies on hashicorp libraries after the recent license change
3
5wk 4wk 4wk
triage/support
commented
member-last
send
6284 cert-manager PEM format certificate to support private key encryption 5wk 5wk 5wk
kind/feature
recv
6283 JWK(S) support
2
5wk 4wk 5wk
recv
similar
6282 The certificate request has failed... order is in "invalid" state 5wk 5wk 5wk
recv
similar
6281 secretName uniqueness not validated 5wk 4wk 4wk
kind/bug
commented
member-last
send
6279 ServiceTemplate for solver HTTP01 6wk 6wk 6wk
recv
6274 Vault Issuer - Secretless Authentication with a Service Account doesn't work
6wk 6wk 6wk
recv
6273 Solver RFC2136 without TSIG 6wk 4wk 4wk
kind/feature
author-last
commented
recv
6270 Feature Request/Idea - Cert-Manager saves TLS Secret to Azure KeyVault 6wk 6wk 6wk
kind/feature
recv
6269 Allow hardcoded JKS passwords
6wk 2d 2d
kind/feature
commented
6254 Logging-format json sometimes drops plaintext messages 7wk 7wk 7wk
kind/bug
recv
6246 Write documentation for the new DNS-over-HTTPS feature
1mo 5wk
kind/documentation
open-milestone
6245 Missing docs for #5337 1mo 5wk
open-milestone
6240 API docs state an out-of-date minimum time before renewal 2mo 4wk 4wk
commented
member-last
send
6238 cattle-cluster-agent error: x509: certificate signed by unknown authority with Letsencrypt 2mo 4wk 4wk
commented
member-last
send
6230 cert-manager DDoSes DNS-01 solver - infinite rate limiting 2mo 11d 2mo
kind/bug
area/acme/dns01
recv
recv-q
6229 Race condition when two identical certificate requests are made from different clusters
5
2mo 3wk 2mo
help wanted
kind/bug
priority/important-longterm
area/acme/dns01
commented
pr-unreviewed
recv-q
send
6224 Option to store certificate history in individual secrets
2mo 2mo 2mo
kind/feature
author-last
commented
recv
recv-q
6215 The default `Cluster Resource Namespace` is `kube-system`, not `cert-manager` 2mo 4wk 4wk
kind/bug
commented
member-last
send
6213 Unable to install cert-manager with argo-cd because helm chart is v1 2mo 2mo 2mo
kind/bug
commented
member-last
send
6210 Flag to write/sync secrets to a namespace other than the namespace where the Certificate object is created
3
2mo 3wk 2mo
kind/feature
commented
recv
recv-q
6205 How to check the version/build info? 2mo 3d 3d
kind/feature
collaborator-last
commented
send
6212 Default duration field in cmctl check api
2mo 3wk 4wk
kind/feature
author-last
commented
pr-merged
recv
6194 Certificates stayed in False not change its state 3mo 3h 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6185 Ingress-gce:"Error syncing to GCP: error running load balancer syncing routine"
3mo 10d 3mo
kind/bug
recv
recv-q
6184 Conflicting ingressClassName http01 issuer spec and acme.cert-manager.io/http01-ingress-class annotation
4
3mo 2d 3mo
kind/bug
recv
recv-q
similar
6181 helm repo add jetstack https://charts.jetstack.io with errors, certificate has expired or is not yet valid 3mo 1mo 3mo
kind/bug
recv
6179 CRDs shouldn't be templated in Helm...
12
3mo 3wk 7wk
commented
send
6175 `region` should be optional in a Route53 dns solver 3mo 6d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6174 Certificates Ready : False 3mo 2mo 3mo
kind/bug
recv
recv-q
similar
6163 is there a way to save dhparam with certificat
3mo 16d 3mo
recv
6161 certificate lost Subject Key Identifier 3mo 11d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6160 Helm Chart global repository 3mo 3d 3mo
contributor-last
recv
6158 Had to apply static installation file twice 3mo 14d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6211 cert-manager conformance tests
2mo 2mo
kind/feature
6141 Consider exposing previous certificates/keys in the kubernetes secret so that workloads can implement a grace period when a certificate rotates
2
3mo 14d 3mo
kind/feature
lifecycle/stale
collaborator-last
commented
recv
6139 Include 3rd party CA's in generated certificate 3mo 2wk 3mo
kind/feature
lifecycle/stale
collaborator-last
recv
6138 allow unencrypted private keys for PKCS12 output
3
3mo 3d 3mo
kind/feature
author-last
recv
6134 cert-manager-cainjector process is stopped by leader election lost, but not start again 3mo 3wk 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6133 The `spec.duration` in `Certificate` resource seems to be ignored and default to 31 days 3mo 15d 3mo
kind/bug
lifecycle/stale
collaborator-last
commented
send
6195 logLevel information in logs
2mo 2mo 2mo
kind/bug
recv
6377 Restrict access to a list of namespaces 13h 13h 13h
kind/feature
recv
6113 Integrate with Istio multi-cluster certificate management 4mo 1d 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
6112 DigiCert error setting up issuer 4mo 4wk 4wk
kind/bug
commented
member-last
send
6111 ACME Route53 dns01 resolver doesn't find private hosted zones when `hostedZoneID` is omitted
4mo 15h 4mo
lifecycle/rotten
collaborator-last
recv
6106 Controller can't handle hitting request rate limits when is registering the issuer
4mo 3d 4mo
kind/bug
commented
contributor-last
pr-closed
recv
recv-q
similar
6096 Sporadic failures at the order lever with CAA errors 4mo 6d 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
6074 Graduate SecretsFilteredCaching feature gate to beta 4mo 14d 14d
kind/feature
collaborator-last
commented
6071 [helm] Allow usage of initContainers for cert-manager
4mo 14d 3mo
kind/feature
lifecycle/stale
collaborator-last
commented
send
similar
6065 acme-http01-edit-in-place is ignored when edit ingress resource - has to be re-added
5
4mo 11d 4mo
kind/bug
recv
recv-q
6051 Detecting Gateway hostnames based on attached HTTPRoutes 4mo 4wk 4mo
kind/feature
lifecycle/stale
author-last
pr-new-commits
recv
recv-q
6021 Make it possible to specify logging options for the ACME solver 4mo 3wk
kind/feature
lifecycle/rotten
collaborator-last
6016 add imagePullSecrets clauses to helm deployment, job templates 4mo 3wk 4mo
kind/feature
author-last
pr-unreviewed
recv
6010 Support the ACME Renewal Information (ARI) extension 4mo 3wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
commented
recv
6007 support HA acme service with freeipa
4mo 4wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
6005 Venafi custom field ca-dn ignored 4mo 4wk 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
6004 Support TLS-ALPN-01 challenges
2
4mo 4wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
5998 Failed post-install: timed out waiting for the condition 5mo 6d 5mo
kind/bug
lifecycle/stale
collaborator-last
recv
similar
5987 Orders sent by cert-manager using a cluster-issuer with an EAB are not RFC8555 compliant | Step-CA private ACME Server
14
5mo 3wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5982 Conflict errors on certificaterequest updates with kubernetes 1.25
3
5mo 1d 4mo
triage/support
lifecycle/stale
collaborator-last
commented
recv
recv-q
5974 Issue with version upgrade causing multiple containers in deployment
6
5mo 2wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5973 Graduate AdditionalCertificateOutputFormats feature 5mo 5wk 5mo
kind/feature
contributor-last
recv
similar
5959 `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries
6
5mo 7wk 5mo
kind/bug
contributor-last
recv
recv-q
5957 Support Secure (non-legacy) OpenSSL v3 PKCS12 Algorithms
10
5mo 15d 5mo
kind/feature
recv
5942 ClusterIssuer with auth kubernetes not working
5mo 15d 3mo
kind/bug
lifecycle/stale
collaborator-last
commented
pr-unreviewed
send
6150 (Cluster)Issuer with vault auth and serviceAccountRef is not accepted by cluster due to audience
2
7
3mo 1d 2d
author-last
commented
open-milestone
pr-unreviewed
recv
recv-q
similar
5925 Use readOnlyRootFilesystem: true for all containers
6
5mo 3d 5mo
good first issue
help wanted
kind/feature
collaborator-last
recv
5917 Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated
3
5mo 9min 5mo
kind/bug
lifecycle/stale
assigned
assignee-updated
collaborator-last
commented
recv
recv-q
similar
5900 [FR] Allow the Chart to create extra manifest 6mo 1d 6mo
kind/feature
author-last
recv
5897 "cert-manager.io/alt-names" annotation under Ingress resources
6mo 14d 5mo
triage/support
lifecycle/stale
collaborator-last
commented
pr-unreviewed
recv
recv-q
5926 OwnerReference be added to the privateKeySecretRef secret created by the ACME ClusterIssuer and Issuer 5mo 10d 3mo
good first issue
help wanted
kind/feature
lifecycle/stale
triage/needs-information
collaborator-last
commented
pr-unreviewed
send
5864 Certmgr allows creating certificates expiring after ca expiration.
4
6mo 3wk 6mo
kind/bug
recv
5862 http01.ingress.class doesn't work
4
6mo 2wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
commented
recv-q
send
5851 CA cert in Secret not updated when self-signed CA itself gets renewed.
14
6mo 2wk 5wk
kind/bug
commented
recv-q
send
5846 Failed to create certificate for my domain 6mo 3wk 6mo
triage/support
lifecycle/rotten
collaborator-last
commented
recv-q
send
5821 Allow renewBefore to be a percentage 7mo 5wk 7mo
kind/feature
author-last
recv
5803 Set the User-Agent for cert-manager including version
7mo 6wk 6wk
kind/feature
priority/backlog
area/venafi
commented
member-last
5785 Store OCSP response in kubernetes secret
3
7mo 1d 4wk
kind/feature
commented
contributor-last
pr-closed
pr-unreviewed
recv-q
send
5783 Add k8s.io/client-go/applyconfigurations style *ApplyConfigurations for the included CRDs
7mo 6wk 7mo
kind/feature
author-last
commented
pr-changes-requested
recv
5782 Misleading error for Vault issuer 7mo 2mo 4mo
good first issue
kind/feature
area/vault
commented
send
5774 Add descriptions for container image repos 7mo 3wk 4mo
good first issue
kind/documentation
lifecycle/rotten
collaborator-last
commented
5772 Develop new Helm chart for cert-manager CRD manifests
7mo 7wk 7wk
kind/feature
commented
member-last
send
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together 8mo 3wk 8mo
kind/bug
recv
recv-q
5697 Support PodSecurityAdmission
6
8mo 2mo 8mo
kind/feature
recv
recv-q
5665 Allow defining keystore password as litteral instead of SecretRef 9mo 8d 9mo
kind/feature
author-last
recv
recv-q
5643 AdditionalOutputFormat is still in alpha
9mo 7d 6mo
kind/feature
lifecycle/rotten
collaborator-last
commented
send
5590 Configure cluster resource namespace in ClusterIssuer spec
2
10mo 3d 10mo
triage/support
lifecycle/stale
collaborator-last
recv
5566 upload Helm charts to OCI registry and sign them with cosign
7
10mo 7d 6mo
kind/feature
lifecycle/stale
collaborator-last
commented
send
5557 error instantiating route53 challenge solver: unable to assume role: AccessDenied:
8
10mo 6wk 10mo
kind/bug
recv
recv-q
similar
5540 Changelog annotations to chart 11mo 2mo 11mo
kind/feature
author-last
recv
5538 Unable to set IPv6 podDNS config from values 11mo 5wk 11mo
kind/bug
author-last
recv
5516 Forbidden: seccomp may not be set pod.metadata.annotations
3
13
11mo 12h 11mo
kind/bug
lifecycle/stale
collaborator-last
recv
5515 stuck on propagation check failed DNS record not yet propagated
12
11mo 3wk 11mo
kind/bug
lifecycle/rotten
recv
similar
5867 Controller can't handle hitting request rate limits of zerossl ACME API
2
10
19
6mo 2mo 5mo
kind/bug
commented
pr-closed
pr-merged
recv-q
send
similar
5514 Venafi Issuer Read `caBundle` from Configmap or Secret
4
8
11mo 3wk 2mo
good first issue
kind/feature
assigned
assignee-updated
commented
pr-new-commits
similar
5486 Aggressive Retries from "error instantiating route53 challenge solver"
4
11mo 15h 11mo
kind/bug
recv
recv-q
similar
5298 Complete the Migration Away From Jetstack Names 1y 2mo 2mo
kind/cleanup
commented
member-last
5430 Improving DNS-01 challenge performance
3
1y 2mo 1y
kind/feature
pr-reviewed-with-comment
pr-unreviewed
recv
5220 Investigate improving resource consumption and performance in clusters with large amount of resources
11
1y 22h 11mo
kind/feature
lifecycle/stale
collaborator-last
commented
pr-merged
recv-q
5171 TPP Allowed Domains can cause valid certificate to error
1y 14d 8mo
kind/bug
lifecycle/rotten
area/venafi
collaborator-last
commented
5074 Race condition between issuers, certificates, and secrets
1y 8mo 1y
lifecycle/frozen
kind/bug
priority/important-soon
commented
member-last
pr-closed
send
5282 cert-manager-webhook deployment spontaneously deleted
1y 3wk 4wk
kind/bug
triage/not-reproducible
author-last
commented
recv
similar
5048 certificate not renewed for ingress with multiple hosts and http01-edit-in-place
3
1y 4wk 1y
kind/bug
priority/backlog
commented
recv
recv-q
5031 ValidateCAA test function is flaky
1y 6d 4mo
kind/bug
lifecycle/stale
kind/flake
flake/test-logic
collaborator-last
commented
send
5066 Threat model for cert-manager
2
1y 3wk 7mo
kind/feature
priority/backlog
commented
4846 More than one Certificate nominating same Secret induces runaway creation of many CertificateRequests and Orders
5
2y 7wk 10mo
kind/bug
priority/important-soon
commented
contributor-last
pr-closed
pr-reviewed-with-comment
recv
4797 Automatically renew certificates if OCSP indicates that it was revoked
11
2y 5d 2y
kind/feature
area/acme
author-last
commented
recv
recv-q
4749 rfc2136 seems to not work with deep subdomains 2y 6wk 2y
kind/bug
area/acme/dns01
collaborator-last
commented
recv
recv-q
4685 Unexpected EOF during watch stream event decoding: unexpected EOF
8
2y 9mo 2y
lifecycle/frozen
kind/bug
recv
recv-q
4620 Vault Issuer does not retry signing CertificateRequests if the status is pending
9
2y 2mo 7mo
kind/bug
priority/important-longterm
area/vault
commented
send
similar
4950 General flakiness of our end-to-end suite
3
2y 1y 1y
lifecycle/frozen
kind/flake
commented
member-last
pr-closed
pr-merged
send
4594 TLS handshake error: EOF
20
2y 4wk 1y
kind/bug
lifecycle/stale
collaborator-last
commented
recv-q
send
4349 allowing greater configuration for the cloud provider tests
2y 1y 1y
lifecycle/frozen
kind/feature
collaborator-last
commented
send
4033 Automated updates of base images
2y 19d 2mo
kind/feature
priority/important-soon
commented
contributor-last
pr-merged
recv-q
3992 Add non-CRD yaml file
3
2y 6wk 2y
priority/important-soon
area/deploy
author-last
commented
recv
4423 Cert renewal loop
2
2y 2mo 2y
kind/bug
author-last
commented
recv
recv-q
3896 Cert Manager failing to renew certificate
18
2y 2wk 2y
kind/bug
area/acme/dns01
commented
recv-q
send
similar
3748 Cert-manager causes API server panic on clusters with more than 20000 secrets.
13
2y 7wk 2y
kind/bug
triage/needs-information
commented
pr-merged
send
3958 Sane defaults for Certificate revision history limit
12
2y 9d 10mo
kind/feature
lifecycle/stale
collaborator-last
commented
recv-q
send
3655 Specify Name Constraints in CA Certificate
48
2y 6wk 6wk
kind/feature
priority/backlog
commented
member-last
send
3521 Integration with ExternalDNS
4
31
2y 7mo 1y
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
commented
recv-q
send
3381 Setup separate package for cert-manager API
4
2y 5wk 5wk
kind/feature
priority/important-soon
assigned
assignee-updated
commented
member-last
send
3103 Adding probes to the cert-manager pods
9
3y 1d 2d
good first issue
help wanted
kind/feature
priority/important-longterm
area/deploy
commented
member-last
send
2722 Inject CA certificate into Secrets with cainjector
22
3y 17d 2y
kind/feature
priority/awaiting-more-evidence
commented
recv-q
send
3640 Challenge Records Not Always Cleaned Up
2y 2mo 8mo
kind/bug
priority/important-longterm
area/acme
commented
pr-closed
pr-merged
2538 cert-manager does not use ingress.class from Ingress annotated with cert-manager.io/cluster-issuer
61
3y 2mo 2y
area/api
kind/feature
priority/backlog
commented
recv
recv-q
similar
2380 Helm chart version is not SemVer-compatible
7
3y 1d 1d
kind/bug
lifecycle/rotten
commented
contributor-last
send
2334 Add network policy allowance into documentation
20
3y 14d 2y
good first issue
help wanted
kind/documentation
priority/backlog
area/deploy
commented
pr-merged
recv
recv-q
2478 Allow CA issuer secret rotation
53
3y 7wk 3y
kind/feature
priority/important-longterm
area/ca
commented
recv-q
send
2178 Handling 'unregistering' certificates from Venafi TPP
21
4y 2mo 3y
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
commented
recv-q
1888 Certificate not matching private key when creating multiple ingress resources
15
4y 5wk 1y
good first issue
help wanted
kind/bug
priority/important-soon
area/acme
commented
recv
6117 Vault Issuer Read caBundle from ConfigMap
3
4mo 14d 14d
area/api
kind/feature
lifecycle/stale
area/vault
commented
member-last
send
similar
6201 Configure retry strategy 2mo 2mo 2mo
recv
6197 Securing Gateway resources with non HTTPS listeners generate BadConfig events
6
2mo 2mo 2mo
kind/bug
pr-unreviewed
recv
1292 Allowing skipping HTTP01 and DNS01 self-check on a per-solver basis
11
173
4y 4wk 2y
area/api
help wanted
kind/feature
priority/important-longterm
area/acme
commented
pr-closed
recv-q
send
6132 Checklist: CNCF Graduation
3mo 14d 14d
commented
member-last
pr-unreviewed
1168 docs: Add info about client side certificate rotation best practices.
23
4y 3y 3y
help wanted
lifecycle/frozen
kind/documentation
priority/backlog
collaborator-last
commented
pr-closed
send
2239 Create a CertificatePreset resource type to allow configurable defaulting
2
75
4y 3wk 3wk
area/api
kind/feature
priority/backlog
priority/important-soon
commented
pr-closed
pr-reviewed-with-comment
pr-unreviewed
send
1294 Replace and update Jetstack image and copy on cert-manager support page 15d 15d 15d
recv
1261 Switch to Docusaurus? 2mo 2mo
1257 ErrRegisterACMEAccount 3mo 3mo 3mo
recv
1255 helm install cert-manager with errors 3mo 2mo 2mo
commented
member-last
send
similar
1241 Remove Bitnami kubeprod as installation method 3mo 3mo 3mo
recv
1194 Confusing paragraph - cert-manager integration. 6mo 2mo 2mo
documentation
commented
member-last
send
1186 Document that/why we don't use Helm's CRD installation mechanism 7mo 2mo 2mo
good first issue
kind/documentation
assigned
assignee-updated
commented
member-last
send
1174 Document the docker images and how to find them
8mo 7mo 7mo
good first issue
priority/important-soon
kind/documentation
commented
member-last
send
1168 Rendering issues for generated API docs
8mo 8mo 8mo
commented
member-last
pr-merged
1159 Why the sample issuer still uses kubebuilder version 2 ? 8mo 8mo 8mo
recv
1132 New version of adcs-issuer
9mo 7mo 8mo
priority/backlog
commented
member-last
send
1125 Describe cert-manager feature policy 9mo 8mo 9mo
contributor-last
recv
recv-q
1101 Feature request for updating documentation. 10mo 10mo 10mo
recv
1063 "Securing Ingresses with Venafi" tutorial contains link to missing manifest
1y 1y 1y
author-last
pr-merged
recv
1062 Document process for offboarding maintainers 1y 1y 1y
recv
similar
1061 Document onboarding process for new maintainers 1y 1y 1y
recv
similar
1054 Run spell checker in a pre-commit hook 1y 1y 1y
good first issue
kind/cleanup
recv
998 Documentation venafi configuration references venafi documentation page which returns 403 1y 1y 1y
contributor-last
recv
993 Document which resources do/do not get garbage collected 1y 1y 1y
good first issue
contributor-last
recv
981 The `kubectl operator install` instructions are broken (after upgrading kubectl operator v0.3.0 -> v0.4.0)
2
1y 1y 1y
commented
member-last
pr-changes-requested
975 Some pages do not make it clear what the user should read next 1y 1y
974 Investigate styled 404 page 1y 1y
955 Document when the vault pki role required setting `require_cn=false`
1y 11mo
944 Document how to install cert-manager in a different namespace
3
1y 1mo 1y
good first issue
recv
recv-q
931 Improve upgrade instructions using helm
1y 1y 1y
recv
899 Upgrading from v1.7 to v1.8 check command should exclude null.
2
1y 1y 1y
recv
recv-q
868