Open PRs (100)

Resolution:

Average age: 189.2d, Avg wait: 37.0d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
5843 Design: Go Module Proliferation 2wk 9h 9h
size/L
release-note-none
approved
lgtm
do-not-merge/hold
kind/design
dco-signoff: yes
assigned
assignee-updated
collaborator-last
commented
reviewed-with-comment
send
5337 WIP: Support loading controller configuration from a versioned file
2
8mo 5h 2d
release-note-none
area/api
do-not-merge/work-in-progress
needs-ok-to-test
size/XXL
dco-signoff: yes
needs-kind
collaborator-last
commented
new-commits
recv
5876 helm: add support for TLS configuration and application protocol
2d 11h 18h
release-note
size/S
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
assigned
assignee-updated
author-last
commented
recv
unreviewed
5880 Separate binaries/tests into separate modules with minimal dependencies 14h 9h
release-note
approved
kind/feature
size/XXL
area/acme
dco-signoff: yes
area/testing
collaborator-last
unreviewed
5824 Controller partial metadata 3wk 16h 17h
release-note
approved
area/api
kind/cleanup
size/XXL
area/acme
area/ca
area/vault
dco-signoff: yes
area/testing
area/acme/dns01
area/acme/http01
collaborator-last
commented
open-milestone
unreviewed
4330 Add client certificate auth method for Vault issuer
4
2y 13h 19h
release-note
size/XL
approved
area/api
kind/feature
area/acme
area/vault
dco-signoff: yes
area/testing
ok-to-test
area/deploy
author-last
commented
recv
recv-q
reviewed-with-comment
similar
5158 Added certificate owner ref field
5
10mo 16h 1d
release-note
size/XL
approved
area/api
kind/feature
dco-signoff: yes
area/testing
ok-to-test
area/deploy
assigned
assignee-updated
commented
contributor-last
recv
reviewed-with-comment
similar
5879 Deprecate klog flags and add a deprecation message 1d 1d
release-note
approved
kind/cleanup
size/M
dco-signoff: yes
area/testing
collaborator-last
unreviewed
5530 Added support for using env config for configuring Vault issuer. 5mo 1d 1d
size/L
release-note
needs-rebase
area/api
do-not-merge/work-in-progress
needs-ok-to-test
area/vault
dco-signoff: no
area/deploy
needs-kind
assigned
assignee-updated
commented
draft
member-last
send
unreviewed
5828 Add support for json logging format
3wk 1d 1d
release-note-none
kind/feature
size/M
dco-signoff: yes
ok-to-test
commented
member-last
reviewed-with-comment
send
5324 Create 20220720-per-certificate-owner-ref.md
5
8mo 1d 1d
size/L
release-note-none
approved
kind/design
dco-signoff: yes
commented
member-last
new-commits
similar
3931 Added PodDisruptionBudgets to helm chart
7
16
2y 1d 1d
size/L
release-note
approved
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
approved
assigned
assignee-updated
commented
member-last
send
5761 feat: Add option to allow filtering DNS Names by ACME Challenge solvers 7wk 1d 5wk
size/L
release-note-none
needs-rebase
area/api
needs-ok-to-test
area/acme
dco-signoff: yes
needs-kind
collaborator-last
commented
send
unreviewed
5814 WIP: Review make commands on Linux Arm64
3
4wk 2d 4wk
release-note-none
needs-rebase
size/S
do-not-merge/work-in-progress
needs-ok-to-test
dco-signoff: no
needs-kind
collaborator-last
commented
new-commits
recv
5848 WIP: Design: core-issuers 19d 2d 2d
release-note-none
approved
lgtm
do-not-merge/work-in-progress
do-not-merge/hold
kind/design
size/M
dco-signoff: yes
assigned
commented
member-last
reviewed-with-comment
5874 Cleanup certificate request approval webhook 2d 2d 2d
size/L
release-note-none
approved
kind/cleanup
dco-signoff: yes
commented
member-last
unreviewed
4570 `RevisionHistoryLimit` has a default value of 25
1y 3d 8mo
release-note
area/api
size/M
lifecycle/stale
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
assigned
collaborator-last
commented
new-commits
send
5094 WIP server-side apply in tests v2 10mo 3d
size/L
release-note-none
needs-rebase
approved
do-not-merge/work-in-progress
kind/cleanup
lifecycle/stale
dco-signoff: yes
area/testing
collaborator-last
unreviewed
5126 WIP: Only remove the cleanup finalizer if the cleanup succeeds 10mo 3d 10mo
size/L
release-note-none
needs-rebase
approved
do-not-merge/work-in-progress
kind/cleanup
lifecycle/stale
area/acme
dco-signoff: yes
area/testing
collaborator-last
commented
unreviewed
5447 Allow extra DNS-01 propagation time to be configured
6mo 3d 6mo
release-note
size/S
lifecycle/stale
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
needs-kind
collaborator-last
commented
recv
unreviewed
5378 Unify semver version generation 7mo 3d 6mo
size/L
release-note-none
needs-rebase
approved
do-not-merge/work-in-progress
kind/cleanup
lifecycle/stale
dco-signoff: yes
changes-requested
collaborator-last
commented
draft
5436 Move CSR resource in design to GA
6mo 3d 6mo
release-note
approved
size/S
kind/design
lifecycle/stale
dco-signoff: yes
collaborator-last
commented
reviewed-with-comment
send
5860 Fix helm loglevel parsing 11d 6d 6d
size/XS
release-note-none
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
commented
reviewed-with-comment
send
5383 Generate applyconfigurations and Apply functions 7mo 12d 5wk
release-note
approved
area/api
do-not-merge/work-in-progress
priority/important-longterm
size/XXL
dco-signoff: yes
needs-kind
commented
draft
member-last
unreviewed
5766 Cainjector limit controllers 7wk 13d 13d
size/L
release-note
approved
do-not-merge/hold
kind/feature
dco-signoff: yes
collaborator-last
commented
new-commits
open-milestone
5003 Implement the DNS-over-HTTPS check
2
11mo 17d 7mo
release-note-none
needs-rebase
do-not-merge/work-in-progress
size/XXL
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/acme/dns01
needs-kind
commented
draft
recv
recv-q
unreviewed
5093 Add relabeling and metricRelabelings settings for ServiceMonitor. 10mo 2wk 10mo
release-note
size/S
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
assigned
recv
recv-q
similar
unreviewed
5777 helm: Add option to keep CRDs when helm chart is uninstalled
3
6wk 3wk 4wk
release-note
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
needs-kind
author-last
commented
recv
recv-q
unreviewed
5823 [master] added if enabled for certManager and webhooks resource 4wk 3wk 3wk
do-not-merge/release-note-label-needed
size/S
needs-ok-to-test
dco-signoff: no
area/deploy
needs-kind
assigned
author-last
commented
recv
unreviewed
5830 WIP: ocsp stapling for certificates 3wk 3wk 3wk
size/L
release-note-none
do-not-merge/work-in-progress
needs-ok-to-test
dco-signoff: yes
needs-kind
collaborator-last
commented
draft
reviewed-with-comment
send
5829 Graduate SSA 3wk 3wk 3wk
size/XS
release-note
approved
kind/feature
dco-signoff: yes
collaborator-last
commented
send
unreviewed
5542 [helm] Introduce cert-manager-resources helm chart 4mo 3wk 4mo
size/L
do-not-merge/release-note-label-needed
needs-ok-to-test
lifecycle/rotten
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
recv
unreviewed
5446 Allow concurrent same-FQDN DNS-01 challenges when using route53 6mo 4wk 5mo
release-note
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/testing
needs-kind
author-last
commented
recv
reviewed-with-comment
5778 [helm] Add support for relabelings and metricRelabelings an serviceMonitor 6wk 5wk 5wk
size/L
release-note
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
commented
contributor-last
recv
similar
unreviewed
5670 feat(chart): support probes for cert-manager and cainjector
2mo 5wk 5wk
release-note
kind/feature
size/M
triage/needs-information
dco-signoff: yes
ok-to-test
area/deploy
assigned
assignee-updated
changes-requested
collaborator-last
commented
send
5373 Allow config of http01 solver pod security context
2
7mo 5wk 2mo
size/L
release-note
needs-rebase
area/api
kind/feature
area/acme
dco-signoff: yes
ok-to-test
area/acme/http01
area/deploy
collaborator-last
commented
open-milestone
send
unreviewed
5356 Allow ECDSA for ACME client keys
7mo 5wk 5wk
size/L
release-note
needs-rebase
area/api
kind/feature
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/deploy
commented
member-last
reviewed-with-comment
send
5669 Added the ability to disable controllers via helm
3
2mo 5wk 7wk
release-note
needs-rebase
kind/feature
size/XXL
dco-signoff: yes
ok-to-test
area/deploy
assigned
assignee-updated
changes-requested
collaborator-last
commented
send
5747 BUGFIX: if a LiteralSubject is set, the RequestMatchesSpec function does skip too many checks 1mo 7wk
release-note-none
approved
kind/bug
kind/cleanup
kind/design
kind/documentation
kind/feature
size/M
dco-signoff: yes
collaborator-last
unreviewed
5743 WIP: Certificate Generation improvements 2mo 7wk
size/L
release-note-none
approved
area/api
do-not-merge/work-in-progress
kind/cleanup
dco-signoff: yes
area/testing
collaborator-last
draft
unreviewed
5701 feat: added custom endpoint override flag for http solver 2mo 2mo 2mo
release-note
kind/feature
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/acme/http01
recv
recv-q
unreviewed
5452 Update Azure SDK and remove deprecated autorest dependency
6mo 2mo 3mo
size/L
release-note-none
needs-rebase
do-not-merge/work-in-progress
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
needs-kind
commented
contributor-last
draft
new-commits
send
5174 Add support for restricting the secrets watch list in cainjector
7
9mo 2mo 3mo
release-note
needs-rebase
kind/feature
size/M
dco-signoff: yes
ok-to-test
collaborator-last
commented
send
unreviewed
4810 Server Side Apply: Adds support for CA Injector controller to use SSA with Feature Gate
4
1y 2mo 4mo
size/L
release-note
needs-rebase
approved
kind/feature
priority/important-soon
dco-signoff: yes
area/deploy
collaborator-last
commented
reviewed-with-comment
send
5567 WIP: Certificates: preventing CertificateRequest creation runaway 4mo 2mo 2mo
release-note
approved
area/api
do-not-merge/work-in-progress
kind/feature
size/XXL
dco-signoff: yes
area/testing
area/deploy
commented
member-last
open-milestone
reviewed-with-comment
send
5686 Add missing healthz port to PSP in Helm Chart when hostNetwork is used 2mo 2mo 2mo
size/XS
release-note
needs-ok-to-test
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
recv
unreviewed
1203 Clarify ingress-shim annotations 8h 8h 8h
approved
dco-signoff: yes
size/S
recv
unreviewed
1202 Add section about client cert authentication for vault 13h 13h 13h
dco-signoff: yes
do-not-merge/work-in-progress
size/M
draft
recv
similar
unreviewed
1197 doc about new option default-cleanup-policy 10d 16h 16h
approved
dco-signoff: yes
size/M
author-last
commented
new-commits
recv
1199 Webhook troubleshooting: advise people to set `timeoutSeconds` to 30 seconds 17h 16h
approved
dco-signoff: yes
size/M
unreviewed
1201 Faster ./scripts/gendocs/generate script 16h 16h
approved
dco-signoff: yes
size/L
unreviewed
1198 Bump webpack from 5.70.0 to 5.76.1 8d 8d 8d
dco-signoff: yes
size/M
dependencies
recv
unreviewed
1196 Document the `ingressClassName` field
15d 12d 12d
approved
dco-signoff: yes
size/L
changes-requested
commented
member-last
send
1192 release-process: explain how and when to merge master into release-next 3wk 12d 12d
approved
dco-signoff: yes
size/S
commented
member-last
new-commits
1195 Fix description of what happens to denied CertificateRequest 19d 19d 19d
approved
dco-signoff: yes
size/S
recv
unreviewed
1048 [WIP] Document structure updates 7mo 5wk 7mo
dco-signoff: yes
size/XXL
needs-rebase
do-not-merge/work-in-progress
ok-to-test
assigned
assignee-updated
commented
contributor-last
send
unreviewed
1183 Docs: Clarify zeroSSL setup instructions 5wk 5wk 5wk
size/XS
dco-signoff: yes
assigned
author-last
recv
recv-q
unreviewed
548 Move the "Approval API" documentation to /concepts/certificaterequest
2y 3wk 2y
approved
dco-signoff: yes
kind/cleanup
size/XL
needs-rebase
assigned
assignee-updated
changes-requested
commented
contributor-last
send
982 WIP: [GSOD] Define our audiences 10mo 1mo 1mo
approved
dco-signoff: yes
lgtm
do-not-merge/work-in-progress
size/M
assigned
assignee-updated
commented
member-last
send
unreviewed
1075 Move Issuer / ClusterIssuer and Certificate resource content to a sub-folder of configuration/ 6mo 5mo
approved
dco-signoff: yes
size/L
needs-rebase
contributor-last
reviewed-with-comment
1071 Improved the summary on the docs homepage
2
6mo 6mo 6mo
approved
dco-signoff: yes
size/S
commented
contributor-last
new-commits
recv-q
1005 Route53 accessKeyIDSecretRef docs 9mo 9mo 9mo
size/XS
dco-signoff: yes
needs-ok-to-test
recv
unreviewed
948 add note to ingress class definition 10mo 10mo 10mo
dco-signoff: no
size/XS
needs-ok-to-test
assigned
author-last
recv
unreviewed
859 Move the meetings and slack information to a separate page
1y 10mo 10mo
approved
dco-signoff: yes
needs-rebase
size/M
changes-requested
commented
member-last
send
701 Issuer with IRSA needs ambient credentials flag
2y 11mo 1y
dco-signoff: no
size/S
ok-to-test
commented
contributor-last
new-commits
send
446 Add multiple ingresses usage section 2y 11mo 2y
size/XS
dco-signoff: yes
needs-rebase
needs-ok-to-test
changes-requested
commented
contributor-last
send
790 Update route53.md 1y 11mo 1y
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
changes-requested
commented
contributor-last
send
751 Added kubectl config for recursive nameservers 1y 11mo 1y
dco-signoff: no
size/XS
needs-rebase
ok-to-test
approved
commented
contributor-last
send
451 update to ingress. 2y 1y 2y
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
contributor-last
recv
unreviewed
528 Update "Setting Nameservers for DNS01 Self Check" example 2y 1y 2y
size/XS
dco-signoff: yes
needs-rebase
needs-ok-to-test
contributor-last
recv
unreviewed
121 Bump golang.org/x/net from 0.0.0-20220225172249-27dd8689420f to 0.7.0 16d 16d 16d
dco-signoff: yes
needs-ok-to-test
size/S
dependencies
contributor-last
recv
similar
unreviewed
120 Bump golang.org/x/text from 0.3.7 to 0.3.8 3wk 3wk 3wk
dco-signoff: yes
needs-ok-to-test
size/S
dependencies
contributor-last
recv
similar
unreviewed
118 Bump helm.sh/helm/v3 from 3.9.4 to 3.11.1 6wk 6wk 6wk
dco-signoff: yes
needs-ok-to-test
size/L
dependencies
contributor-last
recv
unreviewed
17 Add image validation for Docker architecture 2y 1y 2y
dco-signoff: yes
lgtm
size/L
needs-rebase
assigned
assignee-updated
commented
contributor-last
new-commits
send
43 No more requirement "be in the release folder" to run cmrel, remove the flag --cloudbuild 2y 2y
dco-signoff: yes
approved
size/M
needs-rebase
contributor-last
unreviewed
36 Add the "cmrel update-release-branch" command 2y 2y 2y
dco-signoff: yes
approved
size/M
needs-rebase
do-not-merge/work-in-progress
commented
contributor-last
draft
unreviewed
202 Support adding pod annotations 8d 8d 8d
dco-signoff: yes
size/XS
needs-ok-to-test
contributor-last
recv
similar
unreviewed
187 Add the ability to ignore cluster scoped resources. 3mo 3wk 4wk
dco-signoff: yes
size/XS
ok-to-test
commented
contributor-last
recv
recv-q
reviewed-with-comment
194 Add IstioOperator CR for v1.17.0 4wk 4wk
dco-signoff: yes
size/M
contributor-last
recv-q
unreviewed
179 Allow ECDSA serving certificate 6mo 4wk 5wk
dco-signoff: yes
lgtm
approved
size/S
ok-to-test
assigned
assignee-updated
commented
contributor-last
new-commits
send
208 Templating in policy
18d 2d 2d
dco-signoff: yes
size/L
ok-to-test
author-last
commented
recv
unreviewed
117 fixes #13 - Allow node selection based on nodeSelector, tolerations, affinities and topologySpreadConstraints 1d 1d 1d
dco-signoff: yes
size/M
needs-ok-to-test
contributor-last
recv
unreviewed
116 feat: add support for additional pod annotations/labels 4wk 4wk 4wk
dco-signoff: yes
needs-ok-to-test
size/S
contributor-last
recv
similar
unreviewed
89 WIP: use SSA 2mo 6wk 7wk
dco-signoff: yes
do-not-merge/work-in-progress
needs-rebase
size/XXL
commented
contributor-last
new-commits
108 Supporting a secret target
3
7wk 4wk 4wk
dco-signoff: yes
size/XL
ok-to-test
assigned
assignee-updated
commented
member-last
reviewed-with-comment
send
98 Cert formats proposal 2mo 2mo
dco-signoff: yes
approved
size/L
contributor-last
unreviewed
43 Add a design for public trust bundles
4
7mo 6wk 2mo
dco-signoff: yes
approved
size/L
commented
contributor-last
new-commits
129 Add attribute support for certificate subject 3mo 3wk 2mo
dco-signoff: yes
size/L
ok-to-test
author-last
commented
recv
reviewed-with-comment
139 Bump golang.org/x/text from 0.3.7 to 0.3.8 in /hack/tools 3wk 3wk 3wk
dco-signoff: yes
size/S
needs-ok-to-test
dependencies
contributor-last
recv
similar
unreviewed
138 Bump golang.org/x/net from 0.2.0 to 0.7.0 4wk 4wk 4wk
dco-signoff: yes
size/S
needs-ok-to-test
dependencies
contributor-last
recv
similar
unreviewed
135 Added options to all containers 2mo 4wk 5wk
dco-signoff: yes
size/L
needs-rebase
ok-to-test
assigned
commented
contributor-last
send
unreviewed
24 Add missing --csi-driver-name option to daemonset 1mo 3wk 5wk
dco-signoff: yes
size/XS
ok-to-test
commented
contributor-last
new-commits
send
24 Document release process and update the versions of the GitHub Actions workflows 1d 1d
dco-signoff: yes
size/M
approved
contributor-last
unreviewed
48 Retry pending request when issue is called 3wk 9d 3wk
dco-signoff: yes
size/L
needs-ok-to-test
assigned
assignee-updated
contributor-last
new-commits
recv
recv-q
46 Add timeout to renewal issuance logic 3wk 9d 3wk
dco-signoff: yes
size/M
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
28 Include Pod UID on CertificateRequest resources
8mo 8mo 8mo
dco-signoff: yes
do-not-merge/hold
approved
size/XS
ok-to-test
assigned
contributor-last
recv
recv-q
unreviewed
34 WIP: E2E testing boilerplate
6mo 4wk 6mo
size/XXL
dco-signoff: yes
do-not-merge/hold
approved
do-not-merge/work-in-progress
needs-rebase
commented
contributor-last
new-commits
recv
recv-q
29 WIP: Provide Linux Arm64 Image 3wk 3wk 3wk
do-not-merge/work-in-progress
dco-signoff: yes
size/L
contributor-last
recv
unreviewed
28 Cleanup make files 7mo 7mo
dco-signoff: yes
size/XL
contributor-last
unreviewed
10 Generate Kubernetes Events 2y 1y
dco-signoff: yes
size/L
needs-rebase
contributor-last
unreviewed

Open Issues (337)

Resolution:

Average age: 392.4d, Avg wait: 130.4d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
5881 Whats the impact of removing the auto mount of access token for cert manager service accounts. 2h 2h 2h
recv
5877 Adding Domains.Google.com as an option for DNS-01 2d 2d 2d
kind/feature
recv
5873 cert-manager failing to generate certificate in kubernetes, how to fix that? 2d 1d 1d
triage/support
collaborator-last
commented
send
similar
5872 Ingress Cluster-Issuer Annotation with out-of-tree issuer is not possible 2d 2d 2d
good first issue
kind/documentation
priority/important-longterm
collaborator-last
commented
send
5867 Controller can't handle hitting request rate limits of zerossl ACME API 6d 2d 2d
kind/bug
collaborator-last
commented
send
5862 http01.ingress.class doesn't work 8d 5d 8d
kind/bug
recv
5864 Certmgr allows creating certificates expiring after ca expiration. 8d 8d 8d
kind/bug
recv
5861 cert manager API showing error - "x509: certificate has expired or is not yet valid" 8d 2d 8d
triage/support
author-last
commented
recv
recv-q
5851 CA cert in Secret not updated when self-signed CA itself gets renewed.
6
16d 9d 9d
kind/bug
collaborator-last
commented
send
5850 error when creating "test1": Internal error occurred: failed calling webhook "webhook.cert-manager.io": failed to call webhook: Post "https://cert-manager-webhook.cert-manager.svc:443/mutate?timeout=10s": EOF 16d 13d 13d
triage/support
collaborator-last
commented
send
similar
5855 DNS-01 : error : Found recursive CNAME record to 13d 9d 11d
commented
member-last
send
5846 Failed to create certificate for my domain 19d 13d 13d
triage/support
collaborator-last
commented
send
5844 Error when trying to create a ClusterIssuer object 2wk 19d 19d
triage/support
collaborator-last
commented
send
5839 pods "cm-acme-http-solver-cnj26" is forbidden 3wk 13d 13d
triage/support
collaborator-last
commented
send
5847 Issuance flow is not consistent in non-success cases (i.e denied CRs) 19d 14h
kind/bug
5838 Limit to number of entities (Certificates & CertRequets)? 3wk 3wk 3wk
kind/documentation
priority/important-longterm
triage/needs-information
collaborator-last
commented
send
5826 ACMEDNS, cnameStrategy: Follow (follow CNAME records recursively), dns01-recursive-nameservers-only - NXDOMAIN 3wk 3wk 3wk
kind/bug
recv
5825 [HELP] "DeltaFIFO Pop Process" - Reason:slow event handlers blocking the queue 3wk 6d 6d
triage/support
collaborator-last
commented
send
5821 Allow renewBefore to be a percentage 4wk 4wk 4wk
kind/feature
recv
5818 Remove code-level dependency on Helm where possible 4wk 3wk
kind/feature
5817 Uninstalling the cert-manager Helm chart removes all my Issuers and Certificate/ CertificateRequest CRs 4wk 4wk 4wk
collaborator-last
commented
send
5809 Ability to reference EAB key secret in other namespaces
2
4wk 4wk 4wk
kind/feature
triage/needs-information
collaborator-last
commented
send
5807 Certificate.Spec.secretTample.annotations are not reflected in the secret created 4wk 4wk 4wk
triage/support
collaborator-last
commented
send
5806 CA Injector MinimumReplicasUnavailable 5wk 4wk 4wk
kind/bug
collaborator-last
commented
send
5803 Set the User-Agent for cert-manager including version
5wk 5wk 5wk
kind/feature
priority/backlog
area/venafi
commented
member-last
send
5802 Sometimes the tls-secret cannot be found by the nginx ingress 5wk 5wk 5wk
triage/support
collaborator-last
commented
send
5799 kubectl apply error couldn't get resource list for external.metrics.k8s.io/v1beta1: Got empty response for: external.metrics.k8s.io/v1beta1 5wk 5wk 5wk
triage/not-reproducible
collaborator-last
commented
send
5794 `helm show crds` does not show cert-manager CRDs
5wk 5wk 5wk
triage/support
author-last
commented
recv
5792 Helm CVE-2023-25165 5wk 5wk 5wk
recv
5785 Store OCSP response in kubernetes secret
6wk 3wk 4wk
kind/feature
commented
pr-reviewed-with-comment
send
5784 After migration from 1.6.1 to 1.8.2 cainjector remains in crashloopbackoff - OOMKill 6wk 5wk 5wk
kind/bug
collaborator-last
commented
send
5783 Add k8s.io/client-go/applyconfigurations style *ApplyConfigurations for the included CRDs
6wk 5wk 5wk
kind/feature
collaborator-last
commented
pr-unreviewed
send
5782 Misleading error for Vault issuer 6wk 6wk 6wk
commented
member-last
send
5780 error instantiating route53 challenge solver: unable to assume role: AccessDenied 6wk 6wk 6wk
author-last
recv
similar
5836 Setting logLevel to 0 (as integer) in helm chart values doesn't render into container args
2
3wk 8d 8d
kind/bug
priority/important-longterm
collaborator-last
commented
pr-reviewed-with-comment
send
5779 cloudDNS 's hostedZoneName is not sufficient to replace the dns01-recursive-nameservers flag 6wk 6wk 6wk
kind/bug
recv
5774 Add descriptions for container image repos 6wk 6wk
good first issue
kind/documentation
5773 add support for encrypted Private keys in PKCS8 format 7wk 7wk 7wk
recv
5772 Develop new Helm chart for cert-manager CRD manifests 7wk 7wk 7wk
kind/feature
recv
5771 Certificate issue problems not reported back to user, Ingress `status` field does not show errors 7wk 4wk 4wk
triage/support
author-last
commented
recv
5767 force renew others when root cert renews 7wk 7wk 7wk
kind/feature
recv
5760 Feature/Bug: Filter Ingress Url by ACME Solvers 7wk 7wk 7wk
kind/bug
kind/feature
pr-unreviewed
recv
5756 Challenge is stuck at "Waiting for DNS-01 challenge propagation"
7wk 7wk 7wk
kind/bug
author-last
commented
recv
similar
5775 Atos IDnomic ACME Gateway 6wk 3wk 5wk
kind/bug
area/acme
author-last
commented
recv
5752 Waiting for HTTP-01 challenge propagation: wrong status code '404', expected '200'
1mo 1mo 1mo
kind/bug
recv
similar
5755 JKS truststore.jks not found in resulting secret in v1.11.0
3
7wk 4wk 7wk
kind/bug
pr-unreviewed
recv
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together 1mo 6wk 1mo
kind/bug
recv
recv-q
5741 Log which alpha/beta feature gates are enabled on controller and webhook startup 2mo 4wk 1mo
good first issue
kind/feature
priority/backlog
assigned
assignee-updated
collaborator-last
commented
5729 Cert-manager http01 challenge 404 authorization error 2mo 3wk 2mo
triage/support
author-last
commented
recv
recv-q
5717 clarification on semantic versioning 2mo 2mo 2mo
commented
member-last
send
5750 Tag associated with Fix for pavlo-v-chernykh/keystore-go library version
1mo 7wk 7wk
kind/feature
commented
member-last
pr-merged
send
5708 Cert Manager working with only example.com not with svc.cluster.local 2mo 2mo 2mo
kind/bug
collaborator-last
recv
5700 Support for issuing public certs using AWS ACM and DNS verification
2mo 2mo 2mo
kind/feature
author-last
recv
5699 Customize Cloudflare base url 2mo 2mo 2mo
kind/feature
contributor-last
recv
5697 Support PodSecurityAdmission
4
2mo 7d 2mo
kind/feature
author-last
recv
recv-q
5673 Error presenting challenge: init sdk: get token: extract secret: resource name may not be empty 2mo 2mo 2mo
author-last
recv
5665 Allow defining keystore password as litteral instead of SecretRef 2mo 2mo 2mo
kind/feature
recv
5664 Error: INSTALLATION FAILED: failed post-install: timed out waiting for the condition 3mo 4wk 3mo
kind/bug
recv
recv-q
5650 provider rfc2136 send updates to top level zone
3mo 5d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
similar
5643 AdditionalOutputFormat is still in alpha
3mo 1d 1d
kind/feature
commented
open-milestone
send
5630 provider rfc2136: updates are sent to wrong dns zone 3mo 12d 3mo
lifecycle/stale
collaborator-last
recv
similar
5716 Certificate renewal fails during DNS challenge with Route53 2mo 1mo 2mo
kind/bug
recv
similar
5626 Helm: Allow configuration of readiness, liveness and startup probes for all created Pods 3mo 2mo 2mo
kind/feature
author-last
commented
pr-changes-requested
recv
5615 Integrate cert-manager with DigitalOcean LBs 3mo 17d 3mo
kind/feature
lifecycle/stale
collaborator-last
recv
5611 ACME HTTP challenge pods blocked by OpenShift 3mo 12d 3mo
kind/bug
author-last
recv
5608 Unable to inject linkerd sidecar proxy to Cert-Manager pods 3mo 3wk 3mo
lifecycle/stale
collaborator-last
recv
recv-q
5596 Current PSP is not sufficient to work with CSI volume 3mo 4wk 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
5594 Graduate ExperimentalGatewayAPISupport feature to beta 4mo 17d
kind/feature
lifecycle/stale
collaborator-last
5590 Configure cluster resource namespace in ClusterIssuer spec
2
4mo 4d 4mo
lifecycle/rotten
collaborator-last
recv
5588 --must-staple attribute for OCSP Stapling
4mo 6wk 4mo
good first issue
kind/feature
commented
member-last
send
5585 ClusterIssuer cannot read the ServiceAccount token secret 4mo 5d 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5581 Best way to migrate a Nginx ingress to cert-manager without downtime 4mo 17d 3mo
lifecycle/stale
collaborator-last
commented
send
5580 Mounting emptyDir to /tmp directory (webhook) 4mo 5wk 4mo
kind/feature
author-last
recv
5572 Add the possibility to use two cluster issuers in a single ingress 4mo 12d 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
5566 upload Helm charts to OCI registry and sign them with cosign
4
4mo 4wk 3mo
kind/feature
lifecycle/stale
collaborator-last
commented
send
5565 cert-manager aws route53 hosted zone automatically add records. 4mo 14d 4mo
lifecycle/rotten
collaborator-last
recv
5558 Will auto-renewal of the root certificate automatically renew the certificate issued by the root certificate? 4mo 7wk 4mo
recv
similar
5557 error instantiating route53 challenge solver: unable to assume role: AccessDenied:
4
4mo 4wk 4mo
kind/bug
recv
recv-q
similar
5549 unknown field "enabled" in io.k8s.api.core.v1.PodSecurityContext
2
4mo 11h 4mo
lifecycle/stale
collaborator-last
recv
recv-q
5553 Cert manager is looking for wrong service name
2
4mo 19d 4mo
lifecycle/rotten
collaborator-last
recv
5548 Pod is not running due to AppArmor not Enabled
4mo 3d 4mo
lifecycle/rotten
collaborator-last
recv
recv-q
5545 openssl version used 4mo 3wk 4mo
lifecycle/rotten
collaborator-last
recv
5540 Changelog annotations to chart 4mo 1mo 4mo
kind/feature
author-last
recv
5543 Using Azure workload identity instead of AAD Pod Identities to configure the AzureDNS DNS01 challenge. 4mo 16d 4mo
kind/feature
lifecycle/stale
collaborator-last
recv
recv-q
5538 Unable to set IPv6 podDNS config from values 4mo 1mo 4mo
kind/bug
author-last
recv
5537 Left over artifacts from cert-manager 4mo 3wk 4mo
lifecycle/rotten
contributor-last
recv
recv-q
5536 Challenge stack on self check when host is unavailable from cluster. 4mo 3wk 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5531 Question regarding Apigee Hybrid cert-manager webhook support with CSI driver 5mo 3wk 5mo
lifecycle/rotten
collaborator-last
recv
5520 CrashLoopBackOff after restart of all deployments 5mo 3wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
recv-q
5524 cert-manager v1.10.0 always tries to access clusterissuers at cluster scope 5mo 5d 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
recv-q
5516 Forbidden: seccomp may not be set pod.metadata.annotations
2
10
5mo 2mo 5mo
kind/bug
author-last
recv
5515 stuck on propagation check failed DNS record not yet propagated
5mo 19h 5mo
kind/bug
recv
5514 Venafi Issuer Read `caBundle` from Configmap or Secret 5mo 1mo 5mo
kind/feature
contributor-last
recv
5486 Aggressive Retries from "error instantiating route53 challenge solver"
2
5mo 6wk 5mo
kind/bug
recv
recv-q
similar
5480 Route53 solver's STS certificate chain is not being trusted by the cert-manager pod 5mo 5wk 5wk
kind/bug
kind/documentation
priority/backlog
collaborator-last
commented
send
5513 Deploy of cert-manager-webhook/cainjector:v1.9.1 got permission error
5mo 4wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
recv-q
5433 Support certs that live for < 1h
3
6mo 9d 6mo
kind/feature
author-last
recv
similar
5437 Issuer/ClusterIssuer support to specify vault token on local filesystem
6mo 3wk 6mo
lifecycle/rotten
collaborator-last
pr-closed
recv
recv-q
5298 Complete the Migration Away From Jetstack Names 8mo 7d 3mo
kind/cleanup
lifecycle/stale
collaborator-last
commented
5267 GKE: cm-acme-http-solver triggers no.scale.down.node.pod.not.backed.by.controller due to lack of PodDisruptionBudget
7
8mo 5wk 5wk
good first issue
kind/bug
priority/backlog
commented
member-last
send
5430 Improving DNS-01 challenge performance
6mo 11d 6mo
kind/feature
pr-reviewed-with-comment
pr-unreviewed
recv
5220 Investigate improving resource consumption and performance in clusters with large amount of resources
10
9mo 3wk 5mo
kind/feature
lifecycle/stale
collaborator-last
commented
pr-merged
recv-q
5197 cert-manager-webhook to provide logs when handling a k8s api-server request
3
9mo 5wk 5wk
good first issue
help wanted
kind/feature
assigned
assignee-updated
commented
send
5171 TPP Allowed Domains can cause valid certificate to error 9mo 4wk 9mo
kind/bug
area/venafi
recv
5160 Support loading controller configuration from a versioned file
2
9mo 13d 13d
help wanted
kind/feature
assigned
assignee-updated
collaborator-last
commented
pr-new-commits
5074 Race condition between issuers, certificates, and secrets
10mo 2mo 6mo
lifecycle/frozen
kind/bug
priority/important-soon
commented
member-last
pr-closed
send
5069 Error presenting challenge: the server could not find the requested resource even though resource exists 10mo 2mo 10mo
kind/bug
recv
5062 Cert-manager stops processing order request in "processing" status after several attempts 11mo 3wk 3mo
kind/bug
lifecycle/stale
area/acme
collaborator-last
commented
recv
5048 certificate not renewed for ingress with multiple hosts and http01-edit-in-place
3
11mo 3wk 10mo
kind/bug
priority/backlog
commented
recv
5031 ValidateCAA test function is flaky 11mo 6wk 6wk
kind/bug
kind/flake
flake/test-logic
commented
member-last
send
4979 Overhaul the DNS01 solver
5
1y 2h
kind/feature
lifecycle/stale
collaborator-last
pr-closed
4956 cert-manager created multiple CertificateRequest objects with the same certificate-revision
2
2
3
1y 2mo 1y
kind/bug
commented
pr-closed
pr-merged
pr-unreviewed
recv
recv-q
4950 General flakiness of our end-to-end suite
3
1y 8mo 8mo
lifecycle/frozen
kind/flake
commented
member-last
pr-closed
pr-merged
send
4931 Enable Testing on ARM64 1y 1d 1y
kind/feature
lifecycle/stale
collaborator-last
commented
recv
recv-q
4918 Leader election timeout (?) causes exit
2
1y 5wk 5wk
triage/needs-information
commented
member-last
send
4899 Certificate.Spec.RenewEvery instead of RenewBefore 1y 3wk 7mo
kind/feature
commented
contributor-last
4877 HTTP01 solver fails self-check/propagation check on 1.7.1 when used with client-certificate auth on nginx Ingress 1.1.1
1y 11d 1y
kind/bug
lifecycle/rotten
collaborator-last
recv
recv-q
4846 More than one Certificate nominating same Secret induces runaway creation of many CertificateRequests and Orders
3
1y 6wk 4mo
kind/bug
priority/important-soon
commented
contributor-last
pr-closed
pr-reviewed-with-comment
recv
4824 Repo Migration Followup Task List
1y 4wk 2mo
priority/backlog
assigned
assignee-updated
commented
member-last
pr-merged
4797 Automatically renew certificates if OCSP indicates that it was revoked
6
1y 3wk 1y
kind/feature
area/acme
commented
recv
similar
4778 Add cmctl upgrade migrate-api-version --dry-run
4
1y 1mo 11mo
good first issue
help wanted
kind/feature
priority/important-longterm
area/ctl
assigned
assignee-updated
commented
contributor-last
recv
4722 High memory usage on cluster with many secrets
10
1y 4wk 1y
kind/bug
priority/important-soon
assigned
assignee-updated
recv
recv-q
4685 Unexpected EOF during watch stream event decoding: unexpected EOF
5
1y 3mo 1y
lifecycle/frozen
kind/bug
recv
recv-q
4653 Venafi TPP Support for OAuth when authenticating with a username and password
3
1y 3wk 4wk
kind/feature
priority/backlog
commented
member-last
send
5230 Timeouts on Every Controller Reconcile Loop
9mo 4wk 4wk
kind/bug
commented
member-last
pr-merged
4620 Vault Issuer does not retry signing CertificateRequests if the status is pending
6
1y 5d 5wk
kind/bug
priority/important-longterm
area/vault
commented
contributor-last
open-milestone
send
4561 Ability to specify secret ownerReference as part of the Certificate request
3
1y 2mo 1y
kind/feature
recv
4594 TLS handshake error: EOF
15
1y 10d 9mo
kind/bug
commented
recv-q
send
4349 allowing greater configuration for the cloud provider tests
2y 11mo 11mo
lifecycle/frozen
kind/feature
collaborator-last
commented
send
4153 Support DoT (DNS over TLS) for Recursive Nameservers
2y 2mo 10mo
kind/feature
priority/backlog
area/acme/dns01
author-last
commented
recv
4061 Permission denied errors on AWS cause R53 DDoS
2y 5wk 5wk
kind/bug
priority/important-soon
area/acme/dns01
commented
member-last
send
4033 Automated updates of base images
2y 2mo 4mo
kind/feature
priority/important-soon
commented
member-last
pr-merged
3992 Add non-CRD yaml file
2
2y 2mo 2y
priority/important-soon
area/deploy
author-last
commented
recv
5800 Found no Zones for domain _acme-challenge.mydomain.com 5wk 5wk 5wk
recv
3958 Sane defaults for Certificate revision history limit
11
2y 6wk 4mo
kind/feature
commented
recv-q
send
3896 Cert Manager failing to renew certificate
17
2y 11d 2y
kind/bug
area/acme/dns01
commented
recv-q
send
similar
3820 Controller fails to process new certs when there are a large number of pending ones
4
2y 5wk 5wk
kind/bug
priority/important-longterm
area/acme
commented
member-last
send
3748 Cert-manager causes API server panic on clusters with more than 20000 secrets.
13
2y 16d 1y
kind/bug
lifecycle/stale
triage/needs-information
commented
pr-merged
send
3655 Specify Name Constraints in CA Certificate
10
2y 2mo 2y
kind/feature
priority/backlog
contributor-last
recv
3640 Challenge Records Not Always Cleaned Up 2y 5wk 2mo
kind/bug
priority/important-longterm
area/acme
collaborator-last
commented
pr-merged
pr-unreviewed
3592 Ability to not create ca.crt
2
2y 18d 2y
lifecycle/rotten
collaborator-last
commented
recv
4423 Cert renewal loop
2
2y 2mo 1y
kind/bug
author-last
commented
recv
recv-q
3521 Integration with ExternalDNS
3
28
2y 6wk 10mo
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
commented
recv-q
send
3381 Setup separate package for cert-manager API
4
2y 2mo 2mo
kind/feature
priority/important-soon
assigned
assignee-updated
commented
member-last
open-milestone
send
3298 Let's encrypt certificate caching to mitigate rate limits problems
3
13
2y 2wk 1y
help wanted
kind/feature
priority/backlog
lifecycle/stale
collaborator-last
commented
recv-q
send
2930 Mirror to gcr.io or dockerhub
23
2y 2d 14d
kind/feature
priority/important-soon
lifecycle/rotten
area/deploy
assigned
assignee-updated
commented
contributor-last
send
2722 Inject CA certificate into Secrets with cainjector
20
3y 9d 1y
kind/feature
priority/awaiting-more-evidence
commented
recv-q
send
2605 No flag to set structured logging output, e.g. JSON?
2
50
3y 15d 4wk
help wanted
kind/feature
priority/backlog
assigned
assignee-updated
commented
open-milestone
pr-reviewed-with-comment
recv-q
send
2538 cert-manager does not use ingress.class from Ingress annotated with cert-manager.io/cluster-issuer
60
3y 1mo 2y
area/api
kind/feature
priority/backlog
commented
recv
recv-q
2525 Better support multi-namespace & single-namespace deployments
20
3y 13d 13d
kind/feature
priority/important-longterm
area/deploy
collaborator-last
commented
pr-closed
send
2478 Allow CA issuer secret rotation
38
3y 3wk 2y
kind/feature
priority/important-longterm
area/ca
commented
contributor-last
recv-q
send
2380 Helm chart version is not SemVer-compatible
5
3y 19d 2y
kind/bug
commented
recv
recv-q
2334 Add network policy allowance into documentation
16
3y 6d 2y
good first issue
help wanted
kind/documentation
priority/backlog
area/deploy
commented
pr-merged
recv
recv-q
5066 Threat model for cert-manager
2
11mo 5wk 5wk
kind/feature
priority/backlog
collaborator-last
commented
2178 Handling 'unregistering' certificates from Venafi TPP
11
3y 1y 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
commented
recv-q
send
3103 Adding probes to the cert-manager pods
5
2y 10d 8mo
kind/feature
priority/important-longterm
area/deploy
commented
recv-q
send
1888 Certificate not matching private key when creating multiple ingress resources
15
3y 4wk 7mo
good first issue
help wanted
kind/bug
priority/important-soon
area/acme
commented
send
2239 Create a CertificatePreset resource type to allow configurable defaulting
64
3y 1mo 10mo
area/api
kind/feature
priority/backlog
priority/important-soon
commented
pr-closed
pr-unreviewed
recv-q
send
3898 Allow setting PodDisruptionBudget policies via helm chart
4
2y 11d 2y
kind/feature
priority/important-longterm
area/deploy
author-last
pr-approved
pr-closed
recv
5845 Error presenting challenge: Unable to check the TXT record: ### Unexpected HTTP status: 401 during certificate renewal 2wk 2wk 2wk
kind/bug
recv
5616 Allow Gateway API feature to be enabled in clusters that don't have GWAPI CRDs installed
3mo 7d 3mo
kind/feature
lifecycle/stale
collaborator-last
commented
pr-closed
1292 Allowing skipping HTTP01 and DNS01 self-check on a per-solver basis
9
146
4y 2mo 1y
area/api
help wanted
kind/feature
priority/important-longterm
area/acme
assigned
assignee-updated
commented
pr-closed
send
1168 docs: Add info about client side certificate rotation best practices.
21
4y 2y 3y
help wanted
lifecycle/frozen
kind/documentation
priority/backlog
collaborator-last
commented
pr-closed
send
1194 Confusing paragraph - cert-manager integration. 2wk 11h 2wk
documentation
contributor-last
recv
similar
1186 Document that/why we don't use Helm's CRD installation mechanism 4wk 4wk 4wk
good first issue
kind/documentation
recv
1168 Rendering issues for generated API docs
2mo 1mo 1mo
commented
member-last
pr-merged
1159 Why the sample issuer still uses kubebuilder version 2 ? 2mo 2mo 2mo
recv
1132 New version of adcs-issuer
3mo 5wk 2mo
priority/backlog
commented
member-last
send
1125 Describe cert-manager feature policy 3mo 2mo 3mo
contributor-last
recv
recv-q
1101 Feature request for updating documentation. 4mo 4mo 4mo
recv
1063 "Securing Ingresses with Venafi" tutorial contains link to missing manifest
6mo 6mo 6mo
author-last
pr-merged
recv
1062 Document process for offboarding maintainers 6mo 6mo 6mo
recv
similar
1061 Document onboarding process for new maintainers 6mo 6mo 6mo
recv
similar
1054 Run spell checker in a pre-commit hook 7mo 7mo 7mo
good first issue
kind/cleanup
recv
1006 Use descriptive text instead of alt for `feature icon` 9mo 9mo 9mo
recv
998 Documentation venafi configuration references venafi documentation page which returns 403 9mo 6mo 9mo
contributor-last
recv
993 Document which resources do/do not get garbage collected 9mo 9mo 9mo
good first issue
contributor-last
recv
981 The `kubectl operator install` instructions are broken (after upgrading kubectl operator v0.3.0 -> v0.4.0) 10mo 10mo 10mo
commented
member-last
975 Some pages do not make it clear what the user should read next 10mo 10mo
974 Investigate styled 404 page 10mo 10mo
955 Document when the vault pki role required setting `require_cn=false`
10mo 4mo
944 Document how to install cert-manager in a different namespace
2
11mo 9mo 11mo
good first issue
assigned
assignee-updated
contributor-last
recv
recv-q
931 Improve upgrade instructions using helm
11mo 11mo 11mo
recv
899 Upgrading from v1.7 to v1.8 check command should exclude null.
2
11mo 10mo 11mo
recv
recv-q
868 Document RBAC 1y 1y 1y
contributor-last
recv
similar
866 Securing NGINX-ingress 1y 1y 1y
recv
similar
851 create Cilium ingress tls example
3
1y 9mo 1y
assigned
assignee-updated
recv
850 Document available cert-manager Prometheus metrics
1y 5wk 1y
documentation
good first issue
priority/important-longterm
recv
recv-q
similar
847 missing documentation/information olm based installation metric prometheus 1y 1y 1y
contributor-last
recv
844 Document feature gates 1y 1y
similar
841 remove dependency on golang from cmctl and kubectl-plugin installation documentation
1y 1y 1y
contributor-last
pr-merged
recv
recv-q
836 Syncing Secrets Across Namespaces
1y 1y 1y
recv
802 Spelling errors are unclear in pull request CI results and spell checker is unmaintained
1y 1y
kind/bug
contributor-last
pr-merged
776