queue to be emptied once a day

Unprioritized issues older than 7 days (252)

Resolution: Add a priority/ or triage/ label

Average age: 522.0d, Avg wait: 257.7d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8993 Update outdated ARI information on certificate renewal
9d 6d 6d
kind/feature
assigned
assignee-updated
collaborator-last
commented
send
similar
8960 Concurrent ACME Order finalization failure when issuing identical Certificates with different privateKey algorithms (RSA vs ECDSA) 19d 18d 19d
kind/bug
pr-new-commits
recv
8929 Post-Quantum Cryptography: Plan ML-DSA certificate support for Go 1.27 3wk 3wk 3wk
recv
8895 [HELM]: add flag to skip deployment of webhook 4wk 4wk 4wk
kind/feature
pr-unreviewed
recv
8884 Deprecate and remove HMAC-MD5 and HMAC-SHA1 support from the RFC2136 DNS01 solver 4wk 4wk 4wk
recv
8876 cert-manage - random high cpu usage 4wk 4wk 4wk
kind/bug
author-last
recv
8853 Gateway-derived Certificate includes hostnames already covered by wildcard listener, causing ACME Order failure 6wk 3wk 3wk
kind/bug
collaborator-last
commented
send
8847 Certificate Stuck In Failed Renewal State 6wk 3wk 6wk
kind/bug
recv
8835 Make signatureAlgorithm configurable 7wk 6d 7wk
kind/feature
recv
recv-q
8785 Server-Side Apply paths drop several fields that non-SSA Update paths correctly persist
2mo 1mo 1mo
kind/bug
assigned
assignee-updated
commented
member-last
pr-new-commits
8776 When performing DNS challenges, the Describe Domains interface is subject to rate limiting 2mo 4wk 2mo
kind/bug
recv
recv-q
8767 Add support for CRLDistributionPoints on Certificate resources
2mo 2mo 2mo
kind/feature
commented
member-last
pr-closed
send
similar
8763 Minimize cert-manager and trust-manager Controller Privileges 2mo 2mo 2mo
kind/feature
recv
8756 cert-manager: SSRF via `Issuer.spec.vault.server` 2mo 2mo 2mo
recv
8754 Test Flake: TestDynamicAuthorityMulti: authority_test.go:175: Timeout waiting for rotation 2mo 2mo 2mo
kind/flake
recv
8745 helm verify fails due to filename containing a 'v' prefix on the version in the provenance file 2mo 2mo 2mo
kind/bug
author-last
recv
8733 Updates or removal of solver ingress class annotations on ingresses are not propagated to existing certificates
3mo 2mo 2mo
kind/bug
commented
member-last
pr-new-commits
send
8716 Feature Request: Add a CMPv2 issuer for certificate enrollment and renewal (RFC 4210) 3mo 10d 3mo
kind/feature
author-last
commented
recv
recv-q
8702 202 Accepted Response - Certificate Request failed - Unexpected status code on TPP Certificate Request. 3mo 3mo 3mo
recv
8679 Allow managing SSH-CA 3mo 3wk 3mo
kind/feature
recv
8672 Allow specifying the secret namespace for CA issuer spec 3mo 3mo 3mo
commented
member-last
pr-unreviewed
send
8659 v1.20.1 release progress tracking 3mo 3mo
8656 v1.20.0 release progress tracking 3mo 3mo
8641 ContribFest KubeCon EU 2026 - Amsterdam (March 24, 2026) 3mo 3mo 3mo
kind/documentation
commented
member-last
8611 Move from LetsEncrypt staging endpoint to production endpoint causes loop of the same error
3
2
4mo 3mo 3mo
kind/bug
commented
member-last
pr-closed
send
8586 Misconfiguration caused hammering of DigitalOcean API 4mo 4mo 4mo
kind/bug
pr-unreviewed
recv
8572 Solver ingressTemplate annotations are not applied to existing Ingress resources when acme.cert-manager.io/http01-edit-in-place: 'true' is set
4mo 4mo 4mo
kind/bug
author-last
pr-closed
pr-unreviewed
recv
similar
8530 Allow usage of the new DNS-PERSIST-01 challange for ACME
21
4mo 4mo 4mo
kind/feature
recv
similar
8522 Support pulling additional fields from secret when using external account binding
2
5mo 5mo 5mo
kind/feature
recv
recv-q
8512 ArtifactHub install command causes Helm fallback warning due to missing v prefix 5mo 2mo 5mo
recv
8493 cloudflare DNS01 - Client.Timeout exceeded while awaiting headers
4
11
5mo 3mo 4mo
good first issue
help wanted
kind/bug
assigned
assignee-updated
commented
pr-unreviewed
recv-q
send
8458 Vault approle configuration
5mo 5mo 5mo
kind/feature
recv
8450 Introducing DelayedInformers for CRD check 5mo 5mo 5mo
kind/feature
assigned
assignee-updated
commented
contributor-last
send
8416 Make Venafi client timeout configurable for slower servers 6mo 5mo 5mo
kind/feature
commented
member-last
send
8378 Support `PodCertificateRequest`
2
3
6mo 2mo 6mo
kind/feature
commented
send
similar
8499 Add custom labels to be exposed in prometheus metrics 5mo 4wk 4wk
kind/feature
area/monitoring
assigned
assignee-updated
commented
member-last
pr-closed
pr-reviewed-with-comment
send
8372 HTTP-01 challenge: support stateless http-01 challenge 6mo 19d 6mo
kind/feature
lifecycle/stale
contributor-last
recv
8364 Replace Hetzner DNS01 Webhook 6mo 2wk 6mo
lifecycle/stale
commented
contributor-last
send
8340 Top-level: CA Issuer rotation problem 7mo 5wk
lifecycle/stale
cybr
contributor-last
8373 DNS-PERSIST-01 challenge support (planned for late Q1 2026)
7
3
3
184
6mo 2mo 6mo
kind/feature
recv
recv-q
similar
8319 Improve cert-manager's event handler to allow us to selectively skip some reconciliations 7mo 4wk
lifecycle/stale
cybr
contributor-last
8309 Dependency Dashboard 7mo 7h 7mo
recv
8280 Unblocking SSA: Document changes in SSA-by-default 7mo 7wk
lifecycle/stale
cybr
contributor-last
8277 Unblocking Server Side Apply (SSA) by Default 7mo 5mo 5mo
cybr
commented
member-last
8279 Unblocking SSA: Fix unit tests 7mo 7wk
lifecycle/stale
cybr
contributor-last
8235 Cert-manager support for Issuer-managed keys 8mo 6wk 8mo
kind/feature
lifecycle/stale
commented
recv
8234 Vault Issuer: certmanager spams thousands of CertificateRequest resources if Issuer is configured to use the Vault issue endpoint rather than the sign endpoint
8mo 2mo 8mo
kind/bug
lifecycle/stale
commented
contributor-last
pr-unreviewed
send
8209 Add revocation at certificate deletion
3
8mo 6wk 8mo
kind/feature
author-last
recv
similar
8194 Update e2e Documentation - for the make e2e-setup command 9mo 2mo 9mo
kind/feature
lifecycle/stale
commented
contributor-last
send
8183 Add helm diff output to cert-manager PRs 9mo 7wk 8mo
lifecycle/stale
assigned
assignee-updated
commented
contributor-last
send
8095 DNS-01 Delegated zone is not following CNAME and creating wrong records
5
10mo 7d 9d
kind/bug
commented
contributor-last
send
8094 HTTP-01 challenge returns 502 with App Gateway (works with NGINX ingress controller) 10mo 5mo 10mo
recv
recv-q
8086 ACME ClusterIssuer not recovering after Vault restart 10mo 4wk 10mo
kind/bug
lifecycle/rotten
contributor-last
recv
8082 EOF during self check with Pomerium 10mo 4wk 10mo
lifecycle/rotten
contributor-last
recv
8023 ACME issuer fails when CA includes Name Constraints with x509: unhandled critical extension 10mo 6wk 10mo
lifecycle/rotten
commented
contributor-last
recv
recv-q
7914 Output tls.crt in CA cert to another secret 11mo 2mo 11mo
kind/feature
lifecycle/rotten
contributor-last
recv
7868 Metrics for webhook certificate
3
1y 2mo 1y
kind/feature
lifecycle/stale
contributor-last
recv
8970 Configurable PEM size limits (#7642) are not honored by the validation webhook 16d 10d 16d
kind/bug
pr-reviewed-with-comment
recv
7862 Requesting a certificate from ZeroSSL sometimes takes more than 10 minutes to complete
7
1y 16d 1y
kind/bug
lifecycle/rotten
contributor-last
recv
7834 Provide race condition mitigation support 1y 16d 1y
kind/feature
lifecycle/stale
contributor-last
recv
7828 Cert-manager created multiple CertificateRequests (over 30k) for a valid certificate
1y 2mo 11mo
kind/bug
lifecycle/stale
commented
contributor-last
send
7822 Tracking: Kubernetes Gateway API follow up tasks
5
1y 7wk 7mo
lifecycle/frozen
commented
contributor-last
pr-merged
send
7821 Request to support AWS ACM Exportable certificates
58
1y 3wk 9mo
kind/feature
commented
send
similar
7788 Be able to default `acme.cert-manager.io/http01-edit-in-place: "true"` behavior in deployment/chart values
5
1y 7wk 7mo
kind/feature
author-last
commented
recv
7779 RevisionHistoryLimit should follow Kubernetes definition 1y 6wk 6wk
commented
contributor-last
recv-q
send
7768 Stuck in a loop with `multiple challenge solver pods found for challenge` 1y 5wk 1y
kind/bug
lifecycle/stale
contributor-last
recv
7766 Certificate: Let me specify the concatenation order for CombinedPEM output format
1y 4mo 1y
kind/feature
author-last
recv
recv-q
7751 Custom key usage extensions 1y 4mo 5mo
kind/feature
commented
recv
recv-q
7747 [suggestion] Add Kustomize install documentation
5
6
1y 5wk 1y
kind/feature
lifecycle/rotten
commented
contributor-last
recv
recv-q
8251 Top-level ticket: ListenerSet
8
8mo 2mo 4mo
cybr
commented
pr-merged
recv-q
send
7561 Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued 1y 2mo 8mo
kind/feature
author-last
commented
recv
recv-q
7551 Unhelpful log messages 1y 7mo
lifecycle/frozen
contributor-last
7645 Support cross-signed intermediate CAs issued with Vault
5
1y 3mo 5mo
kind/feature
commented
pr-unreviewed
send
7531 punycode issue 1y 2mo 1y
author-last
recv
7522 Non standard "cert-manager.io" used in event "Reason" 2y 8mo 1y
lifecycle/frozen
kind/bug
commented
contributor-last
recv
7492 `UseCertificateRequestBasicConstraints` should probably add `Critical` for `isCA` 2y 8mo 1y
lifecycle/frozen
commented
contributor-last
recv
7486 `"Unhandled Error" err="ingress '...' in work queue no longer exists"` should be handled (clean up dangling `Certificate`)
6
2y 8mo 2y
lifecycle/frozen
kind/bug
contributor-last
recv
recv-q
7520 ClusterIssuer read caBundle from Secret
7
2y 6wk 1y
kind/feature
lifecycle/stale
commented
contributor-last
pr-closed
send
7864 failed to call webhook: certificate has expired or is not yet valid
2
1y 19d 1y
kind/bug
assigned
assignee-updated
author-last
recv
recv-q
similar
7438 certificate not updated after enabling SSA 2y 2mo 2mo
kind/bug
assigned
assignee-updated
commented
member-last
pr-new-commits
send
7422 Please provide standalone helm chart for CRDs
20
2y 6wk 2y
kind/feature
lifecycle/rotten
contributor-last
recv
7476 [Helm Chart] - Wrong handling of image registry and repository
4
2y 4mo 7mo
kind/bug
commented
pr-closed
send
7473 Create certificate based on HTTPRoute configuration
65
7
102
2y 3mo 3mo
kind/feature
assigned
assignee-updated
commented
pr-closed
pr-merged
send
6010 Support the ACME Renewal Information (ARI) extension
4
4
21
3y 4d 1y
lifecycle/frozen
kind/feature
commented
contributor-last
pr-merged
recv
recv-q
similar
6224 Option to store certificate history in individual secrets
2
3y 4wk 10mo
kind/feature
commented
recv-q
send
4749 rfc2136 seems to not work with deep subdomains
4y 2mo 4y
kind/bug
lifecycle/stale
area/acme/dns01
contributor-last
recv
recv-q
8939 ACME with let's encrypt: treat 404 statuses as retryable errors
3wk 3wk 3wk
kind/bug
pr-reviewed-with-comment
pr-unreviewed
recv
7388 Kid missing in the new order request
2
2y 2mo 2y
kind/bug
lifecycle/stale
contributor-last
pr-unreviewed
recv
recv-q
8481 FYI: cert-manager-webhook-libdns
5mo 5mo 5mo
recv
8479 Subject Key Identifier (SKI) missing on issued certificates by self-signed CA 5mo 5mo 5mo
kind/feature
pr-new-commits
recv
5864 Certmgr allows creating certificates expiring after ca expiration.
4
33
3y 9mo 1y
lifecycle/frozen
kind/bug
cybr
commented
pr-closed
recv-q
send
2019 Add ENISA NIS2 reference to best practice intro 3mo 3mo 3mo
recv
2061 Tutorial: `cert-manager` on Google Kubernetes Engine - Remove Google Domains 3mo 3mo 3mo
author-last
pr-reviewed-with-comment
recv
1935 add third party cert-manager-webhook-infomaniak 5mo 5mo 5mo
recv
1874 Dependency Dashboard 7mo 3h 7mo
recv
1926 Change the Cert Manager Webhook DNS01 of Hetzner Cloud
5mo 5mo 5mo
author-last
pr-closed
recv
1806 Tutorial depends on no longer available image of kuard
4
9mo 9mo 9mo
recv
1643 Let's Encrypt Ending Support for Notification Emails 1y 11mo 1y
recv
1625 Configuration issue potentially leading to a memory leak 2y 2y 2y
recv
1715 The ingress annotation `cert-manager.io/secret-template` is not documented
2
1y 1y
contributor-last
pr-unreviewed
similar
1623 Claim about v1beta1/v1alpha2 support for gateway api is misleading 2y 2y 2y
recv
1620 Cert Manager allows the creation of Illegal wilcard SANs 2y 2y 2y
recv
1586 Now that cert-manager 1.16 has been released, `--set config.enableGatewayAPI=true` is now the recommended approach for projects that show instructions on how to enable cert-manager's gateway API support, especially on visible projects like Cilium:
2y 2y
pr-merged
1608 Renaming Securing NGINX-ingress to ingress-nginx 2y 18d 2y
contributor-last
pr-unreviewed
recv
1585 Broken install instructions due wrong cert_manager_latest_version - v1.16.1 2y 2y 2y
recv
1546 Self upgrade PRs don't run checks
2y 9mo 2y
cybr
commented
member-last
1490 GKE tutorial falsely claims it's possible to create LE certificate without domain (only IP) 2y 2y 2y
author-last
recv
944 Document how to install cert-manager in a different namespace
4
4y 2y 4y
good first issue
recv
recv-q
2009 The flag description "Enable client cert authenticate of apiserver to webhooks." is ungrammatical/unclear 4mo 4mo
697 [IRSA] Needs `runAsUser: 1001`
4y 2y 2y
commented
member-last
pr-merged
send
209 Dependency Dashboard
7mo 1d 7mo
pr-merged
recv
501 Error logs not very helpful
2
1y 1y 1y
recv
826 feat: add more logs to readiness healthchecks 5wk 5wk 5wk
recv
431 istio-csr pod healthz check fails for long time in v0.11.0 and v0.12.0 2y 2y 2y
recv
recv-q
287 Getting Readiness probe failed when using cert-manager-istio-csr 2y 2y 2y
author-last
recv
recv-q
similar
244 Populate Subject Fields in Certificate
2y 2y 2y
recv
283 Document / improve that sometimes the issuer needs to set `ca.crt`
2y 2y
223 False positive warnings from trivy and dependabot
7
2y 2y
153 It is possible to have several CAs within the same cluster.
3
4y 2y 3y
commented
send
137 Documentation on rotating the root certificate
3
4y 1y 4y
recv
recv-q
130 Document best-practices for minimal vault role configuration for istio-csr 4y 2y 4y
recv
recv-q
176 certificateDuration is not used for the Istio CSR generated certificate requests
4y 11mo 4y
pr-closed
recv
recv-q
84 csr readiness probe failed, istio ingress pod also failed
2
5y 2y 5y
support
recv
recv-q
similar
113 Integrating with istio helm chart installs
15
4y 2y 4y
recv
recv-q
687 Dependency Dashboard 7mo 1d 7mo
recv
786 Support explicit TLS min version, cipher suites, and curves for istio-csr
2mo 4d 2mo
pr-changes-requested
recv
803 Request to build images for main
5mo 3mo 3mo
commented
member-last
send
761 Dependency Dashboard 7mo 2d 7mo
recv
667 Cannot create secret cert-manager-approver-policy-tls 11mo 6wk 2mo
commented
send
466 Document How to Configure Common Scenarios 2y 2y 2y
recv
782 Ensuring approver-policy is ready to accept CRDs after install 6mo 6mo
good first issue
similar
394 Limit number of SANs by policy
2y 2y 2y
commented
member-last
send
452 CRDs in the Release files
3
2y 2y 2y
recv
288 Feature: Take control of approval for the whole cluster
2
2y 2y 2y
commented
member-last
203 Improve CRD fields for specifying key requirements
3
3y 2y 2y
commented
member-last
send
169 Webhook Custom CA 3y 1y 1y
help wanted
commented
contributor-last
recv-q
send
869 [Feature Request] Support Annotations in Approval Policies 3mo 3mo 3mo
author-last
commented
pr-reviewed-with-comment
recv
recv-q
216 Simplify configuration by creating RBAC by default
2
3y 1y 1y
help wanted
commented
contributor-last
pr-merged
pr-unreviewed
recv-q
send
841 Does trust-manager require cluster level permissions to read secrets?
6mo 3mo 3mo
commented
member-last
send
886 Allow creating `ClusterRole` aggregations
5mo 5mo 5mo
kind/feature
pr-merged
recv
837 Ensuring trust-manager is ready to accept CRDs after install 6mo 4d
good first issue
lifecycle/stale
contributor-last
pr-unreviewed
similar
805 Dependency Dashboard 7mo 2d 7mo
recv
778 Add option to use a specific issuer in the helm chart 9mo 2mo 9mo
lifecycle/stale
contributor-last
recv
800 When creating a trust bundle with additionalFormats/pkcs12, no pkcs12 is produced
7mo 4mo 4mo
commented
send
750 Feat: Emit Events on the controller Pod instead of cluster-scoped Bundle 10mo 3wk 9mo
lifecycle/rotten
commented
contributor-last
recv
742 Add option to disable webhook in Helm chart 10mo 6wk 10mo
kind/feature
author-last
commented
recv
741 Using an Image Volume to deploy certifiats
10mo 4wk 10mo
lifecycle/rotten
commented
contributor-last
send
761 Feat: Add a namespaced trust bundle CRD alongside the cluster-scoped Bundle 9mo 6wk 6wk
commented
member-last
send
591 Feature: ClusterTrustBundle as Target
13
1y 2mo 8mo
lifecycle/stale
commented
contributor-last
pr-merged
send
similar
588 Add ability to monitor validity period for CAs in bundle
5
1y 4mo 6mo
kind/feature
help wanted
assigned
assignee-updated
commented
pr-new-commits
send
592 Feature: ClusterTrustBundle as Sources
1y 7d 7d
assigned
assignee-updated
commented
member-last
send
similar
301 Add support for kubectl installation
2y 2y 2y
lifecycle/frozen
author-last
commented
open-milestone
recv
recv-q
similar
560 Support rotated certificate sources
40
1y 12d 1y
lifecycle/stale
commented
contributor-last
pr-reviewed-with-comment
recv
recv-q
similar
245 Split Bundle controller into multiple controllers
2y 2y 2y
lifecycle/frozen
commented
member-last
pr-merged
send
similar
243 More flexible and better organized target specification in API
5
2y 6mo 8mo
lifecycle/frozen
commented
pr-merged
222 [Feature] - Ability to inject a CA cert into a cert-manager managed secret resource
16
2y 6wk 10mo
lifecycle/rotten
commented
contributor-last
pr-merged
send
848 Request for cryptographic mechanisms used in cert-manager-trust-manager 5mo 5mo 5mo
recv
142 expose bundles CRD as release artifact
2
12
3y 4d 11mo
help wanted
lifecycle/rotten
commented
contributor-last
pr-unreviewed
recv
recv-q
99 Allow removing Bundles whilst keeping the synced CA certs
5
3y 1y 1y
lifecycle/frozen
commented
member-last
pr-unreviewed
63 nit: Rename "Bundle" to "ClusterBundle"
19
3y 1y 1y
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
60 overriding trusted namespace
10
18
3y 4mo 1y
commented
recv-q
send
242 New version of Bundle API
2
4
2y 16d 2y
lifecycle/frozen
commented
pr-closed
pr-merged
39 Don't sync targets to all namespaces by default
8
4y 1y 1y
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
881 Helm install fails when extraObjects contains Bundles 5mo 5mo 5mo
recv
205 Allow to select multiple "trust" namespaces
50
2y 2mo 1y
commented
send
131 Feature: per namespace trust bundle
9
3y 9mo 1y
lifecycle/frozen
commented
send
279 Persisting identifiers for retry calls to Sign() 11mo 6mo 6mo
commented
member-last
send
231 ### Question about Configuring Retries in cert-manager 1y 6mo 6mo
commented
member-last
send
362 Dependency Dashboard 7mo 2d 7mo
recv
204 clarify SetCAOnCertificateRequest deprecation status 2y 1y 1y
commented
member-last
send
636 Cert fails to issue, but main container starts anyway 2mo 2mo 2mo
recv
530 Dependency Dashboard 7mo 2d 7mo
recv
521 RFC: Cert-Manager CSI Driver as Secret Store Provider
7mo 7mo 7mo
recv
385 Helm Install of cert-manager-csi-driver Fails on Minikube with /dev/bus/usb Errors 1y 1y 1y
author-last
recv
383 [Feature Request] Adding attributes that available in Certificate CRD to CSI Driver
6
1y 1y 1y
recv
353 mismatch between the key and the certificate signature algorithm
2y 2y 2y
recv
267 Does cert-manager-csi-driver support AWS EKS with AWS Fargate nodes? 2y 2y 2y
recv
264 Certificate renewal doesn't change file 'modified date'
2y 2y 2y
recv
256 Broken comma-separated splitting logic 2y 2y
241 Missing cert-manager.io/revision-history-limit volume attributes for CSI-Driver
6
2y 2y 2y
recv
171 E2E Test Cleanup 2y 6wk 2y
good first issue
commented
recv-q
130 JKS support
6
3y 2y 3y
recv
recv-q
583 Security Posture improvements 4mo 4wk 4wk
commented
member-last
pr-unreviewed
send
613 Support POD_HOSTNAME as a variable 3mo 3mo 3mo
recv
17 ability to specify pod IP in volume attributes
8
6y 2y 6y
commented
recv
recv-q
411 Dependency Dashboard
7mo 2d 7mo
pr-merged
recv
41 The default `csiDataDir` value might collide with csi-driver
3y 9mo
contributor-last
pr-merged
recv-q
395 Request v0.9.1 release to address Go stdlib CVEs 4wk 4wk 4wk
recv
295 Dependency Dashboard 7mo 1d 7mo
recv
306 [FEATURE]Enable setting private key encoding via annotation 7mo 7mo 7mo
kind/feature
author-last
pr-reviewed-with-comment
recv
204 Support for creating certificate for wildcard route
1y 7mo 1y
recv
similar
174 Standby Replicas without lease use lots of CPU 1y 1y 1y
recv
58 certificate cannot be renewed, error message: "key does not match certificate"
4
2y 2y 2y
recv
recv-q
116 Release static manifests (no helm) for v0.6.0-alpha.0+
2
2y 2y 2y
recv
56 Support for destinationCaCertificate / Reencrypt Routes
2
2y 2y 2y
recv
similar
38 Route with cert-manager annotations is not created
4
2y 1y 2y
commented
send
54 Same certificate in path based Routes
4
2y 1y 2y
pr-closed
recv
70 OLM deployment with ArgoCD is OutOfSync
4y 3y 4y
commented
send
46 Cert-manager operator fails to issue certificates 4y 4y 4y
recv
17 Operator prevents passing extraArgs helm value
7
5y 3y 5y
recv
recv-q
22 Customize the deployment of cert-manager installed via OLM
5
6
5y 2y 4y
commented
recv
recv-q
74 Consistency issues due to the use of mount binds 2y 2mo 2y
commented
recv
recv-q
40 Optional auto rotating/renewing certificates 3y 2y 3y
contributor-last
recv
recv-q
similar
144 Dependency Dashboard 7mo 2d 7mo
recv
234 Proposal: distinguish gate-pending from issuance-error in the renewal backoff loop
5wk 5wk 5wk
commented
member-last
pr-merged
send
63 Is it possible to only create Issuer and remove the CluserIssuer 1y 1y 1y
recv
100 Dependency Dashboard 7mo 2d 7mo
recv
56 Struggling to get controller running in local KIND cluster
1y 1y 1y
commented
member-last
send
62 Limit the controller-manager to access secrets only from specific namespace 1y 1y 1y
recv
122 asdf cmctl installer issues
2
2y 2y 2y
author-last
commented
recv
361 Dependency Dashboard 7mo 1d 7mo
recv
59 Process regarding worrying emails sent to the maintainers mailing list
10mo 10mo 10mo
commented
member-last
65 Dependency Dashboard 7mo 1d 7mo
recv
1125 Dependency Dashboard 7mo 3wk 7mo
recv
1181 PR history may show revived ProwJob attempts as duplicate build IDs
1mo 1mo
pr-merged
487 Dependency Dashboard 7mo 7h 7mo
recv
451 Re-enable testing with specific kubernetes versions in subprojects 9mo 9mo 9mo
cybr
commented
member-last
send
202 Makefile Modules, Go Versions and Vendoring
2y 2y 2y
commented
contributor-last
154 Publish SBOMs 2y 2y 2y
kind/feature
good first issue
commented
member-last
send
295 `make generate-golangci-lint-config` clobbers local exclusions added to the local config. 1y 1y
481 Embed go version in `go install` binaries in cache 8mo 8mo
26 helm-tool inject adds trailing white space to the generated markdown 2y 2y
kind/bug
263 helm-tool help should be more helpful 2mo 2mo 2mo
recv
202 Dependency Dashboard 7mo 7h 7mo
recv
25 helm-tool inject sometimes omits the context (prefix) of commented out values in the generated markdown 2y 2y
kind/bug
contributor-last
64 Open Standup: Updating an event didn't send new invitations to already registered people
7mo 7mo 7mo
commented
member-last
send
63 CNCF-paid GitHub Actions runners 8mo 7mo 7mo
commented
member-last
60 Lazy vote: Zoom for standup meetings to be able to add the standups to the LFX calendar
8mo 8mo 8mo
commented
member-last
62 Lazy vote: Enhancing the triaging process 8mo 8mo
35 Post-Graduation Suggestion Tracker
2y 2y 2y
commented
member-last
pr-merged
92 Dependency Dashboard 7mo 3d 7mo
recv
81 How to enable leader election in the webhook? 2y 2y 2y
recv
80 How to deal with K8s timelimit in 30s ? 2y 2y 2y
recv
74 Why cert-manager looks for a CNAME record instead of a TXT record? 2y 2y 2y
recv
72 readyz and healthz api 2y 2y 2y
recv
46 Code reference a pull request to be merged, but the pull request was closed by a robot 3y 5mo 3y
recv
37 Add logging example
4y 2y 4y
pr-closed
recv
2 Set up basic e2e test that deploys the webhook and ensures we can POST a challenge
7y 9mo
contributor-last
pr-closed
recv-q
8 Find solution for automatically disabled GitHub Actions 2y 2y
24 Dependency Dashboard 7mo 2d 7mo
recv
22 Dependency Dashboard 7mo 2d 7mo
recv
18 Feature: Git bundles? 1y 1y
7 Dependency Dashboard 7mo 2mo 7mo
recv
500 Feature Request: Support for Failover / Secondary CA Pool in GoogleCASIssuer 2mo 2mo 2mo
recv
487 Helm chart `image` named template conflicts with cert-manager 1.20.x
2
2mo 2mo 2mo
commented
pr-closed
recv-q
send
375 Dependency Dashboard 7mo 1d 7mo
recv
485 [Feature Request] Propagate Kubernetes Metadata to Google Cloud CAS Labels 3mo 2mo 3mo
pr-reviewed-with-comment
recv
197 Kubectl One-line Installation Support 2y 2y 2y
commented
member-last
send
similar
162 Issue: Broken config when using commonLabels 2y 2y 2y
recv
148 Certificate chain is not split correctly
5
2y 2y 2y
author-last
pr-reviewed-with-comment
recv
recv-q
102 certificate renewal does not work in due to auth issue to privatecaapi end point 3y 2y 3y
recv
133 Allow to use a custom Service Account
5
2y 2y 2y
pr-unreviewed
recv

Uncommented older than 7 days (153)

Resolution: Add a priority/ or triage/ label

Average age: 600.3d, Avg wait: 550.1d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8121 Support for Creating CertificateRequest from Kubernetes Secret 9mo 2mo 9mo
kind/feature
lifecycle/stale
triage/needs-information
contributor-last
recv
recv-q
similar
8085 Feature Request: Add annotation to disable automatic certificate renewal
10mo 11d 10mo
priority/important-longterm
lifecycle/rotten
contributor-last
pr-closed
recv
similar
8058 Cert-manager fails to import ECDSA private keys generated by openssl 10mo 11d 10mo
kind/bug
priority/important-longterm
lifecycle/rotten
contributor-last
pr-changes-requested
recv
6820 Ongoing dependency evaluation
2y 2y 2y
lifecycle/frozen
priority/important-longterm
contributor-last
recv
6741 ACME account private key and URI are not updated if the path of the ACME server is changed
7
2y 7mo 2y
lifecycle/frozen
kind/bug
priority/important-soon
pr-unreviewed
recv
6472 Create TLSA records automatically
15
2y 6d 2y
kind/feature
priority/backlog
contributor-last
recv
5917 Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated
43
3y 3mo 3y
kind/bug
priority/important-longterm
assigned
assignee-updated
recv
recv-q
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together
2
3y 8mo 3y
lifecycle/frozen
kind/bug
priority/important-soon
author-last
pr-closed
pr-unreviewed
recv
recv-q
5540 Changelog annotations to chart
3y 5mo 3y
kind/feature
priority/backlog
author-last
recv
1549 Brand guideline page 2y 2y 2y
priority/backlog
contributor-last
recv
1473 Add ArtifactHub packages to website 2y 2y 2y
priority/backlog
recv
1063 "Securing Ingresses with Venafi" tutorial contains link to missing manifest
3y 2y 3y
priority/important-longterm
author-last
pr-merged
recv
850 Document available cert-manager Prometheus metrics
4y 3y 4y
documentation
good first issue
priority/important-longterm
recv
recv-q
354 DigitalOcean access-token should not be base64-encoded 5y 5y 5y
priority/awaiting-more-evidence
author-last
pr-unreviewed
recv
recv-q
130 FAQ: How does cert-manager handle ingresses with valid TLS secrets? 6y 6y 6y
help wanted
priority/backlog
kind/documentation
contributor-last
recv
76 Upgrading from v0.10 to v0.11 - missing cainjector annotation 6y 6y 6y
priority/backlog
kind/documentation
contributor-last
recv
237 docs for ACMEChallengeSolverHTTP01Ingress doesn't specify what `class` values are available
6y 6y 6y
priority/backlog
kind/documentation
contributor-last
pr-closed
recv
197 Document ACME account mismatch 6y 1y 6y
good first issue
priority/backlog
kind/documentation
pr-changes-requested
recv
recv-q
3 Restrict operator RBAC permissions
6y 2y 6y
priority/backlog
pr-merged
recv
83 As cmctl user, I want to use different kubectl context on command line ( --context='kubectl-context-abc' )
5
2y 2y 2y
priority/important-longterm
recv
690 Clean up Presets
4y 2y 4y
priority/backlog
pr-merged
recv
594 Document infra image bumps and versioning 4y 2y 4y
priority/backlog
recv
38 Set repository to be a GitHub template repository
4y 2y 4y
priority/important-longterm
recv
130 previously listed items omitted

Important soon, but no updates in 90 days (13)

Resolution: Downgrade to important-longterm

Average age: 1397.7d, Avg wait: 80.7d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
5298 Complete the Migration Away From Jetstack Names 4y 2y 2y
lifecycle/frozen
kind/cleanup
priority/important-soon
commented
member-last
send
6741 ACME account private key and URI are not updated if the path of the ACME server is changed
7
2y 7mo 2y
lifecycle/frozen
kind/bug
priority/important-soon
pr-unreviewed
recv
6709 1.14 Release Review
3
2y 2y 2y
lifecycle/frozen
priority/important-soon
commented
contributor-last
send
6331 CSR not signed by referenced private key
10
2y 7mo 2y
lifecycle/frozen
kind/bug
priority/important-soon
commented
contributor-last
recv-q
send
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together
2
3y 8mo 3y
lifecycle/frozen
kind/bug
priority/important-soon
author-last
pr-closed
pr-unreviewed
recv
recv-q
5867 Controller can't handle hitting request rate limits of zerossl ACME API
7
12
31
3y 1y 2y
lifecycle/frozen
kind/bug
priority/important-soon
commented
pr-closed
pr-merged
recv-q
send
3381 Setup separate package for cert-manager API
5
5y 2y 2y
lifecycle/frozen
kind/feature
priority/important-soon
assigned
assignee-updated
commented
member-last
send
1425 The `issuer.vault.spec.caBundleSecretRef` docs are missing 2y 2y
priority/important-soon
955 Document when the vault pki role required setting `require_cn=false`
2
4y 2y
priority/important-soon
174 Add documentation for CRD conversion webhook ca injection 6y 6y 6y
help wanted
priority/important-soon
kind/documentation
commented
member-last
send
802 Spelling errors are unclear in pull request CI results and spell checker is unmaintained
4y 2y
kind/bug
priority/important-soon
contributor-last
pr-merged
195 Document keystores 6y 3y 6y
priority/important-soon
kind/documentation
commented
contributor-last
send
127 cmctl version reports only the old CRD version if I upgrade cert-manager without including the CRDs 2y 2y
priority/important-soon

Important longterm, but no updates in 180 days (22)

Resolution: Downgrade to backlog

Average age: 1550.6d, Avg wait: 275.0d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6969 Should upgrade status managed fields from CSA to SSA when ServerSideApply feature gate enabled 2y 2y 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
send
6051 Detecting Gateway hostnames based on attached HTTPRoutes
7
35
3y 11mo 1y
lifecycle/frozen
kind/feature
priority/important-longterm
commented
pr-merged
send
5959 `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries
23
3y 7mo 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
recv-q
send
4950 General flakiness of our end-to-end suite
3
4y 2y 4y
lifecycle/frozen
priority/important-longterm
kind/flake
commented
member-last
pr-closed
pr-merged
send
4685 Unexpected EOF during watch stream event decoding: unexpected EOF -- possibly due to api server upgrades / restarts
12
4y 9mo 9mo
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
recv
4191 Setting default values for Pod's "resources"?
7
5y 2y 2y
lifecycle/frozen
priority/important-longterm
commented
contributor-last
recv-q
send
3521 Integration with ExternalDNS
4
54
5y 10mo 2y
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
commented
recv-q
2525 Better support multi-namespace & single-namespace deployments
29
6y 1y 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/deploy
commented
contributor-last
pr-closed
send
similar
2178 Handling 'unregistering' certificates from Venafi TPP
22
6y 2y 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
commented
member-last
send
1186 Document that/why we don't use Helm's CRD installation mechanism 3y 2y 2y
good first issue
priority/important-longterm
kind/documentation
assigned
assignee-updated
commented
member-last
send
975 Some pages do not make it clear what the user should read next 4y 2y
priority/important-longterm
401 Bring tutorials up to date 5y 3y 3y
priority/important-longterm
commented
member-last
send
223 Document wildcard certificate tutorial 6y 6y 6y
priority/important-longterm
kind/documentation
commented
contributor-last
send
58 Support injection pem into an existing configmap
8
3y 1y 1y
priority/important-longterm
lifecycle/frozen
assigned
assignee-updated
commented
member-last
pr-closed
pr-merged
pr-unreviewed
send
129 Increase e2e test timeouts 2y 2y
priority/important-longterm
98 Document new release process for all repos 2y 2y
priority/important-longterm
assigned
3 Make unit testing easier/make examples work
7y 2y 4y
priority/important-longterm
commented
member-last
pr-closed
send
5 previously listed items omitted: #6820 #1063 #850 #83 #38

Pull Requests: Review Ready (93)

Resolution: Review requests or mark them as do-not-merge/work-in-progress

Average age: 148.0d, Avg wait: 84.4d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
9044 fix(readiness): schedule re-check at cert expiry to update Ready condition 6h 6h 6h
size/L
release-note
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
contributor-last
recv
recv-q
similar
unreviewed
9018 fix(deps): update cloud go deps (master) 6d 7h 6d
size/L
release-note-none
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
9013 fix(cainjector): add liveness and readiness probes to cainjector deployment 8d 6h 8d
release-note
area/api
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
author-last
recv
recv-q
unreviewed
8971 Add support for configurable PEM Limits on the Admissions Webhook. 16d 1d 16d
size/L
release-note
area/api
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
contributor-last
recv
recv-q
reviewed-with-comment
8766 feat: add per-solver DNS01 nameserver configuration 2mo 1d 2mo
release-note
size/XL
area/api
kind/feature
area/acme
dco-signoff: yes
area/testing
area/acme/dns01
area/deploy
commented
contributor-last
recv
recv-q
reviewed-with-comment
9043 Requeue Issuers/ClusterIssuers when ACME DNS-01 solver Secrets change 1d 1d 1d
release-note
size/XL
kind/bug
area/acme
dco-signoff: yes
commented
member-last
reviewed-with-comment
similar
9041 fix(e2e): retry kyverno policy apply to avoid webhook startup race 1d 1d 1d
size/XS
release-note-none
dco-signoff: yes
kind/flake
commented
member-last
unreviewed
9039 fix(deps): update module golang.org/x/text to v0.40.0 (release-1.21) 1d 1d 1d
size/L
release-note-none
approved
lgtm
kind/cleanup
area/acme
dco-signoff: yes
area/testing
approved
commented
contributor-last
recv-q
similar
9042 Re-queue Issuer/ClusterIssuer on ACME DNS-01 solver Secret events 1d 1d 1d
size/L
release-note
kind/bug
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
similar
unreviewed
9005 Fix #8994 (approach B): split informer handler registration 8d 1d 1d
release-note
kind/bug
size/M
dco-signoff: yes
commented
member-last
unreviewed
8935 feat(metrics): instrument Vault issuer Sign() requests 3wk 1d 3wk
release-note
kind/feature
needs-ok-to-test
size/M
area/vault
dco-signoff: yes
area/monitoring
contributor-last
recv
recv-q
similar
unreviewed
9035 fix(acme): don't reflect HTTP-01 self-check response body in Challenge 2d 2d 2d
size/XS
release-note-none
kind/bug
area/acme
dco-signoff: yes
area/acme/http01
commented
contributor-last
recv-q
unreviewed
9030 feat: validate owner reference 3d 3d 3d
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
9027 Design doc tweaks 4d 4d 4d
release-note-none
kind/cleanup
kind/design
size/M
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8367 feat(helm) add startupProbe and readinessProbe to cert-manager-controller 6mo 8d 6mo
release-note-none
kind/feature
needs-ok-to-test
size/M
lifecycle/stale
dco-signoff: yes
area/deploy
commented
contributor-last
recv
recv-q
unreviewed
8844 reject non-context-specific GeneralName class in UnmarshalSANs 6wk 9d 6wk
release-note-none
needs-ok-to-test
size/M
dco-signoff: yes
needs-kind
author-last
recv
recv-q
unreviewed
8837 reject negative arcs in ParseObjectIdentifier 6wk 9d 6wk
release-note
size/S
kind/bug
needs-ok-to-test
dco-signoff: yes
author-last
recv
recv-q
unreviewed
8968 fix(acmeorders): reschedule Order when concurrent finalize returns 403 with processing ACME order 17d 15d 17d
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
new-commits
recv
recv-q
8529 fix: schedule readiness re-evaluation at certificate expiry time 4mo 3wk 3mo
size/L
release-note
kind/bug
dco-signoff: yes
ok-to-test
author-last
commented
new-commits
recv
recv-q
similar
8457 feat(acme): add support for ECDSA account key algorithm in ACME issuers
2
5mo 3wk 2mo
release-note
size/XL
area/api
kind/feature
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/deploy
author-last
commented
new-commits
recv
recv-q
8896 Helm toggle features 4wk 4wk 4wk
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
area/deploy
contributor-last
recv
recv-q
unreviewed
8892 add renderMode options for prometheus monitors 4wk 4wk 4wk
release-note
kind/feature
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
author-last
commented
recv
unreviewed
8262 Bugfix #7388 kid missing issue with Infisical ACME server or any other ACME that requires EAB
8mo 4wk 7mo
size/L
release-note
needs-ok-to-test
lifecycle/stale
area/acme
dco-signoff: yes
needs-kind
commented
contributor-last
recv
unreviewed
8846 fix(selector/dns): normalize dns name before comparing 6wk 4wk 6wk
release-note-none
size/S
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8793 fix: ServerSideApply field loss in certificate-shim and issuing controller
2mo 5wk 5wk
release-note
size/S
kind/bug
dco-signoff: yes
commented
member-last
new-commits
8838 Add support for GN and SN in LiteralSubject 6wk 6wk 6wk
release-note
size/S
kind/feature
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8687 Normalize challenge reason in certmanager_certificate_challenge_status metric
3mo 2mo 3mo
size/L
release-note-none
needs-ok-to-test
dco-signoff: yes
needs-kind
author-last
recv
recv-q
reviewed-with-comment
5743 Add MaxPathLen and add EncodeBasicConstraintsInRequest option to Certificate and CertificateRequest resources 3y 4mo 4mo
size/L
release-note
area/api
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
area/deploy
commented
member-last
reviewed-with-comment
8594 Fix typo "commonname" in PreferredChain field comment 4mo 4mo 4mo
release-note-none
size/S
area/api
kind/cleanup
needs-ok-to-test
dco-signoff: yes
area/deploy
contributor-last
recv
recv-q
unreviewed
2210 Add renewal policy scenarios and link release notes to docs 1d 7h
dco-signoff: yes
size/M
contributor-last
recv-q
reviewed-with-comment
2195 chore(deps): update misc npm packages 13d 3h 13d
dco-signoff: yes
size/L
ok-to-test
dependencies
recv
recv-q
similar
unreviewed
2209 chore(deps): update actions/setup-node action to v7 1d 1d 1d
size/XS
dco-signoff: yes
ok-to-test
dependencies
recv
recv-q
unreviewed
2204 chore(deps): update npm to v12 6d 1d 6d
size/XS
dco-signoff: yes
ok-to-test
dependencies
recv
recv-q
similar
unreviewed
2208 chore(deps): update actions/setup-node action to v6.5.0 1d 1d 1d
size/XS
dco-signoff: yes
ok-to-test
dependencies
recv
recv-q
unreviewed
2205 chore(deps): lock file maintenance 5d 2d 5d
dco-signoff: yes
size/XXL
ok-to-test
dependencies
recv
recv-q
unreviewed
2164 Bump undici from 7.27.2 to 7.28.0 in the npm_and_yarn group across 1 directory 4wk 3wk 4wk
dco-signoff: yes
size/L
dependencies
javascript
recv
recv-q
reviewed-with-comment
2188 docs: rename tutorial 'Securing NGINX-ingress' to 'Securing ingress-nginx' 18d 18d 18d
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
2020 docs: add ENISA NIS2 reference to best practice intro 3mo 4wk 3mo
dco-signoff: yes
size/M
author-last
new-commits
recv
recv-q
2166 netlify: document deploy-preview security for forked pull requests 4wk 4wk 4wk
dco-signoff: yes
size/S
commented
member-last
reviewed-with-comment
2092 docs: add infomaniak third party provider 2mo 4wk 2mo
size/XS
dco-signoff: yes
author-last
recv
recv-q
reviewed-with-comment
2160 docs: document the cert-manager.io/secret-template ingress annotation 4wk 4wk 4wk
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
2159 docs: use stringData in the DigitalOcean DNS01 Secret example 4wk 4wk 4wk
dco-signoff: yes
size/S
recv
recv-q
unreviewed
1602 acme troubleshooting: how to fix errored challenges 2y 4mo 2y
size/XS
dco-signoff: yes
contributor-last
recv
recv-q
reviewed-with-comment
1587 Custom Certificate Support for cert-manager Webhook Endpoint 2y 4mo 2y
dco-signoff: yes
size/S
recv
recv-q
unreviewed
340 Verify staged metadata.json authenticity with a KMS signature 2d 2d
dco-signoff: yes
size/L
contributor-last
recv-q
unreviewed
339 fix(deps): update misc go deps 6d 2d 6d
dco-signoff: yes
size/M
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
336 fix(deps): update module google.golang.org/api to v0.288.0 8d 4d 8d
dco-signoff: yes
size/M
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
329 Add script to ping PR authors and issue reporters after a release 17d 17d
dco-signoff: yes
size/L
contributor-last
recv-q
unreviewed
852 Replace Istio log package with structured logr in auth.go 16d 16d 16d
dco-signoff: yes
size/XS
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
637 Fix/chartadditional annotations for cli args 9mo 7wk 9mo
dco-signoff: yes
size/XS
ok-to-test
commented
contributor-last
recv
recv-q
reviewed-with-comment
768 Add unit tests for pkg/tls Provider 3mo 2mo 3mo
dco-signoff: yes
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
860 feat(chart): expose automountServiceAccountToken in the istio-csr chart 7d 7d 7d
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
918 add bundle metrics
2
3mo 7d 2mo
dco-signoff: yes
size/XL
ok-to-test
author-last
commented
new-commits
recv
recv-q
683 feat: Add a very basic pre-commit configuration 11mo 2mo 11mo
dco-signoff: yes
size/XS
lifecycle/rotten
commented
contributor-last
new-commits
900 chart: add startupapicheck to ensure trust-manager is ready after install 4mo 4mo 4mo
dco-signoff: yes
needs-ok-to-test
size/XL
contributor-last
recv
recv-q
unreviewed
188 Remove SetCertificateRequestConditionError
3
2y 4mo 4mo
dco-signoff: yes
size/XXL
commented
member-last
new-commits
700 feat(chart): expose automountServiceAccountToken in the csi-driver chart 7d 7d 7d
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
682 wire csi-lib GateBackoffConfig as --gate-backoff-* flags and Helm values 3wk 9d 16d
dco-signoff: yes
size/L
ok-to-test
commented
contributor-last
new-commits
recv
672 feat(chart): make pod and sidecar securityContext configurable 4wk 4wk 4wk
dco-signoff: yes
size/L
needs-ok-to-test
author-last
commented
recv
unreviewed
698 fix(deps): update module github.com/cert-manager/cert-manager to v1.21.0 9d 6d 9d
dco-signoff: yes
size/L
ok-to-test
dependencies
skip-review
contributor-last
recv
recv-q
unreviewed
562 fix(deps): update module github.com/cert-manager/cert-manager to v1.21.0 9d 4d 9d
dco-signoff: yes
size/L
ok-to-test
dependencies
skip-review
contributor-last
recv
recv-q
unreviewed
564 feat(chart): expose automountServiceAccountToken in the csi-driver-spiffe chart 7d 7d 7d
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
538 feat(chart): make pod and sidecar securityContext configurable 4wk 4wk 4wk
dco-signoff: yes
size/L
ok-to-test
author-last
commented
new-commits
recv
148 limit-namespaces for namespace-scope deployments
2y 3mo 2y
dco-signoff: no
size/S
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
418 fix(deps): update module github.com/cert-manager/cert-manager to v1.21.0 1d 1d 1d
dco-signoff: yes
dependencies
size/L
ok-to-test
skip-review
contributor-last
recv
recv-q
unreviewed
303 feat: add support for setting private key encoding 7mo 6mo 7mo
dco-signoff: yes
size/L
needs-ok-to-test
recv
recv-q
reviewed-with-comment
258 fix(deps): update module github.com/cert-manager/cert-manager to v1.21.0 9d 6d 9d
dco-signoff: yes
size/L
ok-to-test
dependencies
skip-review
contributor-last
recv
recv-q
unreviewed
223 NodePublishSecretRef 1mo 1mo 1mo
dco-signoff: no
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
211 Fix: concurrent NodePublishVolume calls could mount volume without certificates 2mo 2mo 2mo
dco-signoff: yes
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
71 Refactor filesystem.go and adapt tests to use a real file system 2y 1y 1y
dco-signoff: yes
size/L
commented
member-last
reviewed-with-comment
185 chore(deps): update docker.io/golang docker tag to v1.26.5 6d 6d 6d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
524 fix(deps): update module github.com/cert-manager/cert-manager to v1.21.0 9d 6d 9d
dco-signoff: yes
size/M
dependencies
ok-to-test
skip-review
contributor-last
recv
recv-q
unreviewed
525 chore(deps): update module oras.land/oras-go/v2 to v2.6.2 [security] 8d 6d 8d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
528 fix(deps): update module golang.org/x/crypto to v0.54.0 7d 7d 7d
dco-signoff: yes
size/M
dependencies
ok-to-test
skip-review
contributor-last
recv
recv-q
similar
unreviewed
529 fix(deps): update module helm.sh/helm/v4 to v4.2.3 6d 4d 6d
dco-signoff: yes
size/M
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
88 chore(deps): update terraform google to v7.40.0 4wk 1d 4wk
dco-signoff: yes
size/L
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
1217 Document how to manually rerun periodic Prow jobs 10d 8d
size/L
dco-signoff: yes
contributor-last
recv-q
unreviewed
655 Fix 'make verify' command 3wk 11d 11d
dco-signoff: yes
size/XS
commented
member-last
reviewed-with-comment
658 Fix outdated go.sum file 3wk 11d 11d
dco-signoff: yes
size/XS
commented
member-last
unreviewed
651 Add OSSF Scorecard workflow to gh-workflows module 4wk 11d 11d
dco-signoff: yes
size/L
commented
member-last
new-commits
653 Remove unused olm-bundle module 3wk 3wk 3wk
dco-signoff: yes
size/XL
commented
member-last
unreviewed
470 feat(helm): adding `helm-diff` target
8mo 7mo 7mo
dco-signoff: yes
size/S
cybr
ok-to-test
commented
contributor-last
new-commits
recv
recv-q
55 feat: add test module 2y 2y 2y
dco-signoff: yes
size/M
commented
contributor-last
recv
reviewed-with-comment
677 chore(deps): update renovate/renovate docker tag to v43.264.2 4d 7h 4d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
69 Add auditing tool for confirming who has access to the cert-manager org 4mo 4mo
dco-signoff: yes
size/XL
contributor-last
recv-q
unreviewed
64 Add imagePullSecrets to template 2y 2y 2y
size/XS
dco-signoff: yes
needs-ok-to-test
contributor-last
recv
unreviewed
59 cleanup: remove unused NOTES.txt file 2y 2y 2y
size/XS
dco-signoff: yes
needs-ok-to-test
contributor-last
recv
unreviewed
1 Manage the cert-manager GitHub organisation from this repo 2y 2y 2y
dco-signoff: yes
size/XXL
commented
member-last
unreviewed
65 chore(deps): update chainguard-images/actions action to v1.0.36 2d 2d 2d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
13 Various QA fixes 5mo 5mo 5mo
dco-signoff: yes
size/L
needs-ok-to-test
author-last
commented
new-commits
recv
4 Add support for custom license templates 2y 11mo
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
553 feat(chart): expose automountServiceAccountToken in the google-cas-issuer chart 7d 7d 7d
size/S
dco-signoff: yes
contributor-last
recv
recv-q
similar
unreviewed
141 re-adding required clusterrole permission 2y 1y 2y
size/XS
author-last
recv
unreviewed

Unkinded Issues (221)

Resolution: Add a kind/ or triage/support label

Average age: 729.2d, Avg wait: 326.8d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
9028 It should be possible to disable ARI per Issuer 4d 4d 4d
contributor-last
recv
7699 Adding Helm Unittest to all certmanager projects 1y 2mo 2mo
priority/backlog
assigned
assignee-updated
commented
member-last
send
7895 if certificate is already expired, it shown like a True
2
11mo 2mo 2mo
help wanted
priority/important-soon
collaborator-last
commented
pr-closed
pr-new-commits
pr-unreviewed
send
3992 Add non-CRD yaml file
5
5y 2mo 2y
priority/important-soon
area/deploy
author-last
commented
recv
6179 CRDs shouldn't be templated in Helm
5
2
32
3y 4wk 10mo
priority/backlog
lifecycle/rotten
commented
recv-q
send
1194 Confusing paragraph - cert-manager integration.
3y 3mo 3y
documentation
priority/important-longterm
commented
contributor-last
pr-merged
send
1101 Feature request for updating documentation. 3y 2y 2y
priority/backlog
commented
member-last
send
1262 v1.9 to v1.10 upgrade instructions does not mention container name change
3y 1y 2y
priority/backlog
assigned
assignee-updated
commented
member-last
send
320 Document how to install cert-manager using gitops and known issues with particular gitops implementations
5
5y 2y 5y
documentation
help wanted
priority/backlog
commented
pr-merged
recv-q
2 Set up periodic job to publish an experimental release build
6y 5y
priority/backlog
assigned
contributor-last
297 Allow all resources to be namespaced
6
2y 4wk 10mo
lifecycle/rotten
priority/backlog
commented
send
45 Unable to mount and read only file error
5
5y 2y 2y
priority/awaiting-more-evidence
commented
send
132 Investigate test timeouts 2y 2y
priority/backlog
33 Create e2e test to validate CertificateRequest garbage collection 3y 2y 2y
priority/backlog
assigned
commented
member-last
send
81 Configuring Peribolos for Github org management 7y 2y 2y
priority/backlog
commented
member-last
send
3 Migrating all cert-manager projects to "Makefile modules" 2y 7mo 1y
priority/backlog
commented
member-last
43 Allow non-Venafi employee maintainers full release capabilities
3
2y 7mo 7mo
priority/backlog
assigned
assignee-updated
commented
member-last
27 failed with: OpenAPI spec does not exist
2
6
5y 2y 2y
priority/critical-urgent
commented
pr-closed
pr-unreviewed
send
203 previously listed items omitted

Unprioritized Recent Issues (258)

Resolution: Add a priority/ or triage/ label

Average age: 509.9d, Avg wait: 251.8d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
9034 helm chart: add network policy for `startupapicheck` job 2d 2d 2d
kind/feature
recv
9029 respect owner references 3d 3d 3d
kind/feature
pr-unreviewed
recv
9026 Publish webhook ACME API in a distinct go module 4d 4d 4d
kind/feature
recv
9021 Support global tolerations and affinity similar to nodeSelector in the Helm Chart 4d 2d 2d
kind/feature
commented
member-last
send
9036 cert-manager 1.21: ACME solver Secret changes don't trigger Issuer/ClusterIssuer re-reconciliation (stuck at Ready:False/InvalidSolver) 1d 1d 1d
kind/bug
assigned
assignee-updated
commented
member-last
pr-merged
pr-reviewed-with-comment
pr-unreviewed
253 previously listed items omitted

Uncommented Recent Issues (4)

Resolution: Add a comment

Average age: 3.6d, Avg wait: 3.2d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
4 previously listed items omitted: #9034 #9029 #9028 #9026
New, has multiple reactions, but not important-soon: No matching items
New, has multiple commenters, but not important-soon: No matching items

needs information, has update (1)

Resolution: Comment and remove triage/needs-information tag

Average age: 292.4d, Avg wait: 288.2d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8121 Support for Creating CertificateRequest from Kubernetes Secret 9mo 2mo 9mo
kind/feature
lifecycle/stale
triage/needs-information
contributor-last
recv
recv-q
similar

Recently updated issue has a question (2)

Resolution: Add an answer

Average age: 292.1d, Avg wait: 71.7d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8835 Make signatureAlgorithm configurable 7wk 6d 7wk
kind/feature
recv
recv-q
7536 Digicert ACME order is failing due to invalid validity_years
2
1y 6d 7mo
good first issue
lifecycle/frozen
kind/feature
priority/backlog
area/acme
commented
recv
recv-q
Triage Party v1.4.0