Issues that may be waiting for our response
NOTE: for this to work properly, GitHub token must have read access to read organization members
Questions awaiting follow-up: No matching items

Bugs awaiting follow-up (42)

Resolution: Comment or close the issue

Average age: 235.5d, Avg wait: 123.6d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6363 Unable to set revisionHistoryLimit on the deployments 1d 1d 1d
kind/bug
pr-unreviewed
recv
6353 Docs: Wrong example Code for creating Issuers 7d 5d 5d
kind/bug
author-last
commented
recv
recv-q
6350 Webhook inject-ca-from annotation causes downtime
4
12d 2d 7d
kind/bug
author-last
commented
recv
6327 wrong status code '404', expected '200' with one specific Ingress 18d 18d 18d
kind/bug
recv
6307 Certificates only issued for ingress in default namespace 4wk 4wk 4wk
kind/bug
recv
6254 Logging-format json sometimes drops plaintext messages 7wk 7wk 7wk
kind/bug
recv
6230 cert-manager DDoSes DNS-01 solver - infinite rate limiting 2mo 11d 2mo
kind/bug
area/acme/dns01
recv
recv-q
6197 Securing Gateway resources with non HTTPS listeners generate BadConfig events
6
2mo 2mo 2mo
kind/bug
pr-unreviewed
recv
6195 logLevel information in logs
2mo 2mo 2mo
kind/bug
recv
6194 Certificates stayed in False not change its state 3mo 2h 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6185 Ingress-gce:"Error syncing to GCP: error running load balancer syncing routine"
3mo 10d 3mo
kind/bug
recv
recv-q
6184 Conflicting ingressClassName http01 issuer spec and acme.cert-manager.io/http01-ingress-class annotation
4
3mo 2d 3mo
kind/bug
recv
recv-q
similar
6181 helm repo add jetstack https://charts.jetstack.io with errors, certificate has expired or is not yet valid 3mo 1mo 3mo
kind/bug
recv
6175 `region` should be optional in a Route53 dns solver 3mo 6d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6174 Certificates Ready : False 3mo 2mo 3mo
kind/bug
recv
recv-q
similar
6161 certificate lost Subject Key Identifier 3mo 11d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6158 Had to apply static installation file twice 3mo 14d 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6134 cert-manager-cainjector process is stopped by leader election lost, but not start again 3mo 3wk 3mo
kind/bug
lifecycle/stale
collaborator-last
recv
6106 Controller can't handle hitting request rate limits when is registering the issuer
4mo 3d 4mo
kind/bug
commented
contributor-last
pr-closed
recv
recv-q
similar
6096 Sporadic failures at the order lever with CAA errors 4mo 6d 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
6065 acme-http01-edit-in-place is ignored when edit ingress resource - has to be re-added
5
4mo 11d 4mo
kind/bug
recv
recv-q
6005 Venafi custom field ca-dn ignored 4mo 4wk 4mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5998 Failed post-install: timed out waiting for the condition 5mo 6d 5mo
kind/bug
lifecycle/stale
collaborator-last
recv
similar
5987 Orders sent by cert-manager using a cluster-issuer with an EAB are not RFC8555 compliant | Step-CA private ACME Server
14
5mo 3wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5974 Issue with version upgrade causing multiple containers in deployment
6
5mo 2wk 5mo
kind/bug
lifecycle/rotten
collaborator-last
recv
5959 `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries
6
5mo 7wk 5mo
kind/bug
contributor-last
recv
recv-q
5917 Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated
3
5mo 3mo 5mo
kind/bug
assigned
assignee-updated
commented
recv
recv-q
similar
5864 Certmgr allows creating certificates expiring after ca expiration.
4
6mo 3wk 6mo
kind/bug
recv
6364 Enabling ServerSideApply feature gate changes status conditions behavior
1d 18h 1d
kind/bug
commented
contributor-last
recv
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together 8mo 3wk 8mo
kind/bug
recv
recv-q
5557 error instantiating route53 challenge solver: unable to assume role: AccessDenied:
8
10mo 6wk 10mo
kind/bug
recv
recv-q
similar
5538 Unable to set IPv6 podDNS config from values 11mo 5wk 11mo
kind/bug
author-last
recv
5515 stuck on propagation check failed DNS record not yet propagated
12
11mo 3wk 11mo
kind/bug
lifecycle/rotten
recv
similar
5486 Aggressive Retries from "error instantiating route53 challenge solver"
4
11mo 15h 11mo
kind/bug
recv
recv-q
similar
5282 cert-manager-webhook deployment spontaneously deleted
1y 3wk 4wk
kind/bug
triage/not-reproducible
author-last
commented
recv
similar
5048 certificate not renewed for ingress with multiple hosts and http01-edit-in-place
3
1y 4wk 1y
kind/bug
priority/backlog
commented
recv
recv-q
4846 More than one Certificate nominating same Secret induces runaway creation of many CertificateRequests and Orders
5
2y 7wk 10mo
kind/bug
priority/important-soon
commented
contributor-last
pr-closed
pr-reviewed-with-comment
recv
4749 rfc2136 seems to not work with deep subdomains 2y 6wk 2y
kind/bug
area/acme/dns01
collaborator-last
commented
recv
recv-q
4685 Unexpected EOF during watch stream event decoding: unexpected EOF
8
2y 9mo 2y
lifecycle/frozen
kind/bug
recv
recv-q
4423 Cert renewal loop
2
2y 2mo 2y
kind/bug
author-last
commented
recv
recv-q
1888 Certificate not matching private key when creating multiple ingress resources
15
4y 5wk 1y
good first issue
help wanted
kind/bug
priority/important-soon
area/acme
commented
recv
5516 Forbidden: seccomp may not be set pod.metadata.annotations
3
13
11mo 11h 11mo
kind/bug
lifecycle/stale
collaborator-last
recv

Features awaiting follow-up (32)

Resolution: Comment or close the issue

Average age: 186.6d, Avg wait: 79.2d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6312 Report issuer/clusterissuer status as a metric 4wk 4wk 4wk
kind/feature
recv
6377 Restrict access to a list of namespaces 12h 12h 12h
kind/feature
recv
6288 Generate cert-manager secret with certificate,key and password 5wk 5wk 5wk
kind/feature
recv
6270 Feature Request/Idea - Cert-Manager saves TLS Secret to Azure KeyVault 6wk 6wk 6wk
kind/feature
recv
6273 Solver RFC2136 without TSIG 6wk 4wk 4wk
kind/feature
author-last
commented
recv
6212 Default duration field in cmctl check api
2mo 3wk 4wk
kind/feature
author-last
commented
pr-merged
recv
6210 Flag to write/sync secrets to a namespace other than the namespace where the Certificate object is created
3
2mo 3wk 2mo
kind/feature
commented
recv
recv-q
6141 Consider exposing previous certificates/keys in the kubernetes secret so that workloads can implement a grace period when a certificate rotates
2
3mo 14d 3mo
kind/feature
lifecycle/stale
collaborator-last
commented
recv
6138 allow unencrypted private keys for PKCS12 output
3
3mo 3d 3mo
kind/feature
author-last
recv
6113 Integrate with Istio multi-cluster certificate management 4mo 1d 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
6224 Option to store certificate history in individual secrets
2mo 2mo 2mo
kind/feature
author-last
commented
recv
recv-q
6051 Detecting Gateway hostnames based on attached HTTPRoutes 4mo 4wk 4mo
kind/feature
lifecycle/stale
author-last
pr-new-commits
recv
recv-q
6010 Support the ACME Renewal Information (ARI) extension 4mo 3wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
commented
recv
6334 Query recursive nameservers for DNS01 challenge in round robin fashion 16d 13d 16d
kind/feature
recv
6004 Support TLS-ALPN-01 challenges
2
4mo 4wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
6007 support HA acme service with freeipa
4mo 4wk 4mo
kind/feature
lifecycle/rotten
collaborator-last
recv
5973 Graduate AdditionalCertificateOutputFormats feature 5mo 5wk 5mo
kind/feature
contributor-last
recv
similar
5957 Support Secure (non-legacy) OpenSSL v3 PKCS12 Algorithms
10
5mo 15d 5mo
kind/feature
recv
6016 add imagePullSecrets clauses to helm deployment, job templates 4mo 3wk 4mo
kind/feature
author-last
pr-unreviewed
recv
5900 [FR] Allow the Chart to create extra manifest 6mo 1d 6mo
kind/feature
author-last
recv
5925 Use readOnlyRootFilesystem: true for all containers
6
5mo 3d 5mo
good first issue
help wanted
kind/feature
collaborator-last
recv
5783 Add k8s.io/client-go/applyconfigurations style *ApplyConfigurations for the included CRDs
7mo 6wk 7mo
kind/feature
author-last
commented
pr-changes-requested
recv
5697 Support PodSecurityAdmission
6
8mo 2mo 8mo
kind/feature
recv
recv-q
5540 Changelog annotations to chart 11mo 2mo 11mo
kind/feature
author-last
recv
5665 Allow defining keystore password as litteral instead of SecretRef 9mo 7d 9mo
kind/feature
author-last
recv
recv-q
5821 Allow renewBefore to be a percentage 7mo 5wk 7mo
kind/feature
author-last
recv
4797 Automatically renew certificates if OCSP indicates that it was revoked
11
2y 5d 2y
kind/feature
area/acme
author-last
commented
recv
recv-q
6284 cert-manager PEM format certificate to support private key encryption 5wk 5wk 5wk
kind/feature
recv
5430 Improving DNS-01 challenge performance
3
1y 2mo 1y
kind/feature
pr-reviewed-with-comment
pr-unreviewed
recv
2538 cert-manager does not use ingress.class from Ingress annotated with cert-manager.io/cluster-issuer
61
3y 2mo 2y
area/api
kind/feature
priority/backlog
commented
recv
recv-q
similar
6356 Graduate AdditionalCertificateOutputFormats feature gate
4d 4d 4d
kind/feature
recv
similar
6139 Include 3rd party CA's in generated certificate 3mo 2wk 3mo
kind/feature
lifecycle/stale
collaborator-last
recv
Items that deserve a follow-up comment: No matching items
Triage Party v1.4.0