feat(helm): update chart cert-manager ( v1.19.2 ➔ v1.20.2 )#3171
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
feat(helm): update chart cert-manager ( v1.19.2 ➔ v1.20.2 )#3171renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
453ca18 to
a33da38
Compare
civo-mgmt-0 - kustomization--- k8s/base/networking/cert-manager Kustomization: flux-system/networking-cert-manager HelmRelease: networking/cert-manager
+++ k8s/base/networking/cert-manager Kustomization: flux-system/networking-cert-manager HelmRelease: networking/cert-manager
@@ -13,13 +13,13 @@
chart: cert-manager
interval: 5m
sourceRef:
kind: HelmRepository
name: jetstack-charts
namespace: flux-system
- version: v1.19.2
+ version: v1.20.2
install:
crds: CreateReplace
interval: 5m
upgrade:
crds: CreateReplace
values: |
civo-mgmt-0 - helmrelease--- HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-orders
+++ HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-orders
@@ -47,12 +47,19 @@
- acme.cert-manager.io
resources:
- orders/finalizers
verbs:
- update
- apiGroups:
+ - cert-manager.io
+ resources:
+ - clusterissuers/finalizers
+ - issuers/finalizers
+ verbs:
+ - update
+- apiGroups:
- ''
resources:
- secrets
verbs:
- get
- list
--- HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-ingress-shim
+++ HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-ingress-shim
@@ -46,21 +46,23 @@
- update
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways
- httproutes
+ - listenersets
verbs:
- get
- list
- watch
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways/finalizers
- httproutes/finalizers
+ - listenersets/finalizers
verbs:
- update
- apiGroups:
- ''
resources:
- events
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager-cainjector
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager-cainjector
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-cainjector
- image: quay.io/jetstack/cert-manager-cainjector:v1.19.2
+ image: quay.io/jetstack/cert-manager-cainjector:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --leader-election-namespace=kube-system
- --metrics-listen-address=0
env:
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager
@@ -35,20 +35,20 @@
volumes:
- name: config
configMap:
name: cert-manager
containers:
- name: cert-manager-controller
- image: quay.io/jetstack/cert-manager-controller:v1.19.2
+ image: quay.io/jetstack/cert-manager-controller:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --config=/var/cert-manager/config/config.yaml
- --cluster-resource-namespace=$(POD_NAMESPACE)
- --leader-election-namespace=kube-system
- - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.2
+ - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.2
- --dns01-recursive-nameservers=1.1.1.1:53,1.0.0.1:53
- --dns01-recursive-nameservers-only
- --max-concurrent-challenges=60
ports:
- containerPort: 9402
name: http-metrics
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager-webhook
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager-webhook
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-webhook
- image: quay.io/jetstack/cert-manager-webhook:v1.19.2
+ image: quay.io/jetstack/cert-manager-webhook:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --secure-port=10250
- --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
- --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
--- HelmRelease: networking/cert-manager Job: networking/cert-manager-startupapicheck
+++ HelmRelease: networking/cert-manager Job: networking/cert-manager-startupapicheck
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-startupapicheck
- image: quay.io/jetstack/cert-manager-startupapicheck:v1.19.2
+ image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.2
imagePullPolicy: IfNotPresent
args:
- check
- api
- --wait=1m
- -v |
qgr1-cluster-0 - kustomization--- k8s/base/networking/cert-manager Kustomization: flux-system/networking-cert-manager HelmRelease: networking/cert-manager
+++ k8s/base/networking/cert-manager Kustomization: flux-system/networking-cert-manager HelmRelease: networking/cert-manager
@@ -13,13 +13,13 @@
chart: cert-manager
interval: 5m
sourceRef:
kind: HelmRepository
name: jetstack-charts
namespace: flux-system
- version: v1.19.2
+ version: v1.20.2
install:
crds: CreateReplace
interval: 5m
upgrade:
crds: CreateReplace
values: |
qgr1-cluster-0 - helmrelease--- HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-orders
+++ HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-orders
@@ -47,12 +47,19 @@
- acme.cert-manager.io
resources:
- orders/finalizers
verbs:
- update
- apiGroups:
+ - cert-manager.io
+ resources:
+ - clusterissuers/finalizers
+ - issuers/finalizers
+ verbs:
+ - update
+- apiGroups:
- ''
resources:
- secrets
verbs:
- get
- list
--- HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-ingress-shim
+++ HelmRelease: networking/cert-manager ClusterRole: networking/cert-manager-controller-ingress-shim
@@ -46,21 +46,23 @@
- update
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways
- httproutes
+ - listenersets
verbs:
- get
- list
- watch
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways/finalizers
- httproutes/finalizers
+ - listenersets/finalizers
verbs:
- update
- apiGroups:
- ''
resources:
- events
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager-cainjector
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager-cainjector
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-cainjector
- image: quay.io/jetstack/cert-manager-cainjector:v1.19.2
+ image: quay.io/jetstack/cert-manager-cainjector:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --leader-election-namespace=kube-system
- --metrics-listen-address=0
env:
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager
@@ -35,20 +35,20 @@
volumes:
- name: config
configMap:
name: cert-manager
containers:
- name: cert-manager-controller
- image: quay.io/jetstack/cert-manager-controller:v1.19.2
+ image: quay.io/jetstack/cert-manager-controller:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --config=/var/cert-manager/config/config.yaml
- --cluster-resource-namespace=$(POD_NAMESPACE)
- --leader-election-namespace=kube-system
- - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.2
+ - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.2
- --dns01-recursive-nameservers=1.1.1.1:53,1.0.0.1:53
- --dns01-recursive-nameservers-only
- --max-concurrent-challenges=60
ports:
- containerPort: 9402
name: http-metrics
--- HelmRelease: networking/cert-manager Deployment: networking/cert-manager-webhook
+++ HelmRelease: networking/cert-manager Deployment: networking/cert-manager-webhook
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-webhook
- image: quay.io/jetstack/cert-manager-webhook:v1.19.2
+ image: quay.io/jetstack/cert-manager-webhook:v1.20.2
imagePullPolicy: IfNotPresent
args:
- --v=2
- --secure-port=10250
- --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
- --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
--- HelmRelease: networking/cert-manager Job: networking/cert-manager-startupapicheck
+++ HelmRelease: networking/cert-manager Job: networking/cert-manager-startupapicheck
@@ -31,13 +31,13 @@
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: cert-manager-startupapicheck
- image: quay.io/jetstack/cert-manager-startupapicheck:v1.19.2
+ image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.2
imagePullPolicy: IfNotPresent
args:
- check
- api
- --wait=1m
- -v |
a33da38 to
215ba10
Compare
215ba10 to
9135535
Compare
9135535 to
ae9e176
Compare
ae9e176 to
2e10646
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.19.2→v1.20.2Release Notes
cert-manager/cert-manager (cert-manager)
v1.20.2Compare Source
v1.20.2 fixes invalid YAML generated in the Helm chart when both
webhook.configand
webhook.volumesare defined, and bumps Go to 1.26.2 along with dependenciesto address reported vulnerabilities.
Changes by Kind
Bug or Regression
webhook.configandwebhook.volumesare defined. (#8665, @cert-manager-bot)Other (Cleanup or Flake)
v1.20.1Compare Source
v1.20.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.
Changes by Kind
Feature
imagePullSecretsin thestartupapicheck-jobHelm template to enable pulling images from private registries. (#8186, @mathieu-clnk)parentRefoverride annotations on the Certificate resource. (#8518, @hjoshi123)venafi.cert-manager.io/custom-fieldsannotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. (#8301, @k0da)acme.cert-manager.io/http01-ingress-ingressclassnameto overridehttp01.ingress.ingressClassNamefield in HTTP-01 challenge solvers. (#8244, @lunarwhite)global.nodeSelectorto helm chart to perform amergeand allow for a singlenodeSelectorto be set across all services. (#8195, @StingRayZA)XListenerSetsfeature gate (#8394, @hjoshi123)Documentation
Bug or Regression
Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging (#8221, @wallrj-cyberark)
v1.25.5to fixCVE-2025-61727andCVE-2025-61729(#8290, @octo-sts[bot])cert-manager. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). (#8162, @LiquidPL)Other (Cleanup or Flake)
XListenerSetsfeature gate toListenerSets(#8501, @hjoshi123)v1.19.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.
Changes by Kind
Bug or Regression
v1.19.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.