queue to be emptied once a day

Unprioritized issues older than 7 days (224)

Resolution: Add a priority/ or triage/ label

Average age: 430.2d, Avg wait: 208.8d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8227 [HELM] startupapicheck is not using correct name 11d 11d 11d
kind/bug
author-last
recv
8235 Cert-manager support for Issuer-managed keys 9d 4d 5d
kind/feature
author-last
commented
recv
8213 Duration and renew-before annotation changes in ingress resources don't trigger certificate updates
2
18d 16d 18d
help wanted
kind/bug
contributor-last
pr-unreviewed
recv
8218 Include Vault hostname as default JWT audiences
15d 8d 8d
kind/feature
assigned
assignee-updated
commented
member-last
pr-reviewed-with-comment
send
8209 Add revocation at certificate deletion
3
19d 18d 19d
kind/feature
recv
similar
8201 Timeout contacting Cloudflare API during cert-manager DNS-01 challenge 3wk 4d 3wk
recv
8200 Add commonLabels support for acmesolver 3wk 3wk 3wk
kind/feature
recv
8183 Add helm diff output to cert-manager PRs 4wk 15d 4wk
cybr
assigned
assignee-updated
commented
contributor-last
send
8194 Update e2e Documentation - for the make e2e-setup command 3wk 3wk 3wk
kind/feature
contributor-last
recv
8110 Add ability to be a incoming `HTTP-01` to outgoing `DNS-01` proxy 7wk 7wk 7wk
kind/feature
recv
8102 cert-manager-startupapicheck erroring while installation
2
7wk 7wk 7wk
kind/bug
recv
recv-q
8095 DNS-01 Delegated zone is not following CNAME and creating wrong records
3
1mo 16d 1mo
kind/bug
author-last
recv
recv-q
8094 HTTP-01 challenge returns 502 with App Gateway (works with NGINX ingress controller) 1mo 1mo 1mo
recv
8234 Vault Issuer: certmanager spams thousands of CertificateRequest resources if Issuer is configured to use the Vault issue endpoint rather than the sign endpoint
9d 8d 8d
kind/bug
commented
member-last
send
8082 EOF during self check with Pomerium 2mo 2mo 2mo
recv
8023 ACME issuer fails when CA includes Name Constraints with x509: unhandled critical extension 2mo 2mo 2mo
author-last
commented
recv
recv-q
7959 Failed to generate serving certificate, retrying..." err="no tls.Certificate available yet, try again later"
3mo 2mo 2mo
kind/bug
commented
send
similar
7914 Output tls.crt in CA cert to another secret 3mo 3mo 3mo
kind/feature
recv
7873 Add labels to leases managed by cert-manager
2
3mo 2mo 2mo
kind/feature
assigned
assignee-updated
commented
member-last
pr-unreviewed
7868 Metrics for webhook certificate
3
3mo 16d 3mo
kind/feature
author-last
recv
7864 failed to call webhook: certificate has expired or is not yet valid
2
4mo 3mo 4mo
kind/bug
recv
recv-q
7862 Requesting a certificate from ZeroSSL sometimes takes more than 10 minutes to complete
4
4mo 6wk 4mo
kind/bug
recv
7834 Provide race condition mitigation support 4mo 4mo 4mo
kind/feature
recv
7829 Support to auto delete Certificaterequest
4mo 4mo 4mo
kind/feature
commented
contributor-last
send
similar
7828 Cert-manager created multiple CertificateRequests (over 30k) for a valid certificate
4mo 9d 3mo
kind/bug
commented
send
7822 Tracking: Kubernetes Gateway API follow up tasks
5
4mo 4mo 4mo
recv
7821 Request to support AWS ACM Exportable certificates
56
4mo 5d 5wk
kind/feature
commented
send
similar
7817 Support `global.nodeSelector` in the Helm chart
5mo 3wk 5mo
kind/feature
contributor-last
pr-merged
recv
7788 Be able to default `acme.cert-manager.io/http01-edit-in-place: "true"` behavior in deployment/chart values
3
5mo 3wk 5mo
kind/feature
assigned
assignee-updated
recv
recv-q
7779 RevisionHistoryLimit should follow Kubernetes definition 5mo 5mo 5mo
recv
7772 Reviewing the use of https://github.com/SSLMate/go-pkcs12 5mo 5mo 5mo
kind/feature
contributor-last
recv
recv-q
7768 Stuck in a loop with `multiple challenge solver pods found for challenge` 5mo 5mo 5mo
kind/bug
recv
7766 Certificate: Let me specify the concatenation order for CombinedPEM output format 5mo 5mo 5mo
kind/feature
author-last
recv
recv-q
7765 Propagation tests fails when using IPv6 recursive DNS nameservers
5mo 5mo 5mo
kind/bug
recv
7760 Is the zone responsible for a domain changes, cert-manager will not pick it up 6mo 6mo 6mo
kind/bug
author-last
recv
7755 cert-manager-challenges Error presenting challenge: expected array of Record 6mo 6mo 6mo
recv
recv-q
7751 Custom key usage extensions 6mo 3d 6mo
kind/feature
recv
7749 Http and PROXY protocol
5
6mo 2d 6mo
lifecycle/stale
contributor-last
recv
7747 [suggestion] Add Kustomize install documentation
2
2
6mo 2mo 6mo
kind/feature
commented
recv
recv-q
7741 Certmanager attempts infinite renewals if the Issuer Certificate read from Vault has expired
3
6mo 2d 6mo
kind/bug
lifecycle/stale
commented
contributor-last
recv
7717 After uninstalling cert-manager, ingress resources can still only be accessed via https 6mo 17d 6mo
lifecycle/stale
contributor-last
recv
7691 Why is the value of the certificate expiration time captured in blackbox different from the value of the certificate expiration time exposed by certmanager 7mo 4wk 7mo
lifecycle/rotten
commented
contributor-last
send
7688 Feature Request: Vertical Pod Autoscaler Support for cert-manager
3
7mo 4wk 7mo
kind/feature
lifecycle/rotten
commented
contributor-last
pr-new-commits
send
similar
7687 Webhook refusing connection even when Ready 7mo 4wk 7mo
kind/bug
lifecycle/rotten
contributor-last
recv
8040 Dependency Dashboard
2mo 1d 2mo
pr-merged
recv
7673 Support for acmesolver.tolerations/affinity/nodeSelector 7mo 4wk 7mo
kind/feature
lifecycle/rotten
contributor-last
recv
recv-q
7660 cert-manager produces invalid (per RFC5280) certificates when `cert sign` usage is set along with another usage 7mo 3d 7mo
kind/bug
lifecycle/stale
contributor-last
recv
recv-q
7659 Challenge and resolver pod/ingress killed too soon
2
7mo 17d 7mo
lifecycle/stale
contributor-last
recv
7649 [GKE][Cert-Manager]Document Might Need Implementation Details Update to GSA/KSA Integration 7mo 5mo 7mo
kind/bug
author-last
recv
recv-q
7648 Solver selector issue 7mo 4wk 7mo
kind/bug
lifecycle/rotten
contributor-last
recv
7647 Support GatewayAPI's XGateway
7mo 4mo
lifecycle/frozen
kind/feature
contributor-last
7645 Support cross-signed intermediate CAs issued with Vault
2
7mo 4mo 7mo
kind/feature
author-last
recv
7636 cermanager order in pending state 7mo 1mo 7mo
lifecycle/rotten
contributor-last
recv
7635 Mirroring bind9 image for e2e tests 8mo 1mo
lifecycle/rotten
contributor-last
7625 Clean install fails to create Issuer
4
8mo 2wk 8mo
kind/bug
lifecycle/stale
contributor-last
recv
recv-q
7594 Cloudflare delegated domains returns Found no Zones for domain _acme-challenge.mydomain.com
8mo 19d 8mo
kind/bug
lifecycle/stale
contributor-last
recv
7572 Certificate Issuance takes long time up to 50 minutes when attempting to create 40+ certificates
2
9mo 7wk 9mo
lifecycle/rotten
contributor-last
recv
7561 Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued 9mo 6d 6d
kind/feature
author-last
commented
recv
recv-q
7551 Unhelpful log messages 9mo 5mo
contributor-last
7536 Digicert ACME order is failing due to invalid validity_years 9mo 17d 9mo
lifecycle/stale
contributor-last
recv
7531 punycode issue 9mo 18d 9mo
author-last
recv
7522 Non standard "cert-manager.io" used in event "Reason" 9mo 3wk 6mo
lifecycle/frozen
kind/bug
commented
contributor-last
recv
7520 ClusterIssuer read caBundle from Secret
4
9mo 3wk 6mo
kind/feature
lifecycle/stale
commented
contributor-last
pr-unreviewed
send
7510 Key Size for Acme Account Key
10mo 5mo 10mo
kind/feature
pr-new-commits
recv
7684 Add support for namespaced deployment
7mo 4mo 7mo
kind/feature
contributor-last
pr-merged
recv
recv-q
similar
7506 Issues with new PEM maximum sizes
6
10mo 4wk 4wk
kind/bug
commented
member-last
pr-merged
pr-reviewed-with-comment
send
7486 `"Unhandled Error" err="ingress '...' in work queue no longer exists"` should be handled (clean up dangling `Certificate`)
6
10mo 8d 10mo
lifecycle/frozen
kind/bug
contributor-last
recv
recv-q
7492 `UseCertificateRequestBasicConstraints` should probably add `Critical` for `isCA` 10mo 10d 6mo
lifecycle/frozen
commented
contributor-last
recv
7476 [Helm Chart] - Wrong handling of image registry and repository
4
11mo 3mo 11mo
kind/bug
recv
recv-q
7422 Please provide standalone helm chart for CRDs
15
1y 2mo 1y
kind/feature
recv
7438 certificate not updated after enabling SSA 11mo 5mo 11mo
kind/bug
author-last
recv
7388 Kid missing in the new order request
2
1y 16h 1y
kind/bug
recv
recv-q
6622 `make update-licenses` is non-deterministic.
2y 5mo 5mo
kind/bug
commented
member-last
pr-merged
pr-unreviewed
6160 Helm Chart global repository
2
2y 9mo 9mo
lifecycle/frozen
commented
member-last
pr-reviewed-with-comment
send
6010 Support the ACME Renewal Information (ARI) extension
7
2y 5mo 5mo
kind/feature
author-last
commented
recv
recv-q
5904 Support Azure Private DNS Zones for DNS Challenge
4
6
19
2y 4mo 4mo
kind/feature
commented
contributor-last
recv-q
send
7656 Add multiple DNS provider resolvers to an single webhook not working 7mo 6wk 7mo
lifecycle/rotten
contributor-last
pr-unreviewed
recv
5566 upload Helm charts to OCI registry and sign them with cosign
4
55
3y 5wk 5wk
kind/feature
commented
member-last
pr-merged
send
4749 rfc2136 seems to not work with deep subdomains
3y 18d 3y
kind/bug
area/acme/dns01
recv
recv-q
7668 Allow custom values in Helm chart schema by relaxing additionalProperties: false
2
7mo 5wk 7mo
lifecycle/rotten
contributor-last
pr-unreviewed
recv
8086 ACME ClusterIssuer not recovering after Vault restart 1mo 1mo 1mo
kind/bug
recv
7473 Create certificate based on HTTPRoute configuration
33
2
63
11mo 1d 5wk
kind/feature
assigned
assignee-updated
author-last
commented
pr-closed
pr-reviewed-with-comment
recv
6224 Option to store certificate history in individual secrets
2
2y 2mo 2mo
kind/feature
commented
contributor-last
recv-q
send
5864 Certmgr allows creating certificates expiring after ca expiration.
4
31
2y 4wk 6mo
lifecycle/frozen
kind/bug
cybr
commented
pr-new-commits
recv-q
send
1822 RFC 2136 description of rate limits is misleading 17d 17d 17d
recv
1806 Tutorial depends on no longer available image of kuard
3
4wk 4wk 4wk
recv
1802 Invalid certificate 5wk 5wk 5wk
recv
1758 Dependency Dashboard 2mo 17h 2mo
recv
1715 The ingress annotation `cert-manager.io/secret-template` is not documented
2
5mo 5mo
contributor-last
1643 Let's Encrypt Ending Support for Notification Emails 9mo 3mo 9mo
recv
1625 Configuration issue potentially leading to a memory leak 9mo 9mo 9mo
recv
1623 Claim about v1beta1/v1alpha2 support for gateway api is misleading 9mo 9mo 9mo
recv
1620 Cert Manager allows the creation of Illegal wilcard SANs 10mo 10mo 10mo
recv
1609 Azure DNS Documentation Update
11mo 10mo 10mo
author-last
commented
recv
similar
1608 Renaming Securing NGINX-ingress to ingress-nginx 11mo 11mo 11mo
recv
1596 Wrong key for cloudflare secret ref in DNS Validation tutorial page 1y 1y 1y
recv
1586 Now that cert-manager 1.16 has been released, `--set config.enableGatewayAPI=true` is now the recommended approach for projects that show instructions on how to enable cert-manager's gateway API support, especially on visible projects like Cilium:
1y 1y
pr-merged
1585 Broken install instructions due wrong cert_manager_latest_version - v1.16.1 1y 1y 1y
recv
1546 Self upgrade PRs don't run checks
1y 4wk 1y
cybr
commented
member-last
1490 GKE tutorial falsely claims it's possible to create LE certificate without domain (only IP) 1y 1y 1y
author-last
recv
944 Document how to install cert-manager in a different namespace
3
3y 2y 3y
good first issue
recv
recv-q
697 [IRSA] Needs `runAsUser: 1001`
4y 1y 1y
commented
member-last
pr-merged
send
501 Error logs not very helpful 9mo 8mo 9mo
recv
619 Dependency Dashboard 2mo 1d 2mo
recv
431 istio-csr pod healthz check fails for long time in v0.11.0 and v0.12.0 1y 11mo 1y
recv
recv-q
413 Panic: runtime error on new installation 1y 1y 1y
author-last
recv
recv-q
287 Getting Readiness probe failed when using cert-manager-istio-csr 2y 1y 2y
author-last
recv
recv-q
similar
244 Populate Subject Fields in Certificate
2y 1y 2y
recv
283 Document / improve that sometimes the issuer needs to set `ca.crt`
2y 2y
223 False positive warnings from trivy and dependabot
7
2y 2y
153 It is possible to have several CAs within the same cluster.
3
3y 1y 2y
commented
send
137 Documentation on rotating the root certificate
3y 6mo 3y
recv
recv-q
130 Document best-practices for minimal vault role configuration for istio-csr 3y 2y 3y
recv
recv-q
176 certificateDuration is not used for the Istio CSR generated certificate requests
3y 2mo 3y
pr-closed
recv
recv-q
84 csr readiness probe failed, istio ingress pod also failed
2
4y 2y 4y
support
recv
recv-q
similar
113 Integrating with istio helm chart installs
15
4y 1y 4y
recv
recv-q
713 Remove deprecated approverpolicy_certificaterequest_ metrics 2mo 2mo
667 Cannot create secret cert-manager-approver-policy-tls 3mo 2mo 3mo
commented
contributor-last
recv
similar
638 Approver cannot find applicable policy 5mo 4mo 5mo
author-last
recv
recv-q
394 Limit number of SANs by policy
2y 2y 2y
commented
member-last
send
288 Feature: Take control of approval for the whole cluster
2
2y 2y 2y
commented
member-last
203 Improve CRD fields for specifying key requirements
3
2y 11mo 11mo
commented
member-last
send
169 Webhook Custom CA 2y 6mo 6mo
help wanted
commented
contributor-last
recv-q
send
700 Dependency Dashboard 2mo 1d 2mo
recv
466 Document How to Configure Common Scenarios 1y 1y 1y
recv
559 Flakey Tests in pull-cert-manager-approver-policy-test 10mo 10mo
similar
452 CRDs in the Release files
3
1y 1y 1y
recv
216 Simplify configuration by creating RBAC by default
2
2y 7mo 7mo
help wanted
commented
contributor-last
pr-merged
pr-unreviewed
recv-q
send
761 Feat: Add a namespaced trust bundle CRD alongside the cluster-scoped Bundle 6wk 6wk 6wk
commented
contributor-last
recv
778 Add option to use a specific issuer in the helm chart 3wk 3wk 3wk
recv
742 Add option to disable webhook in Helm chart 2mo 2mo 2mo
kind/feature
commented
member-last
send
741 Using an Image Volume to deploy certifiats 2mo 2mo 2mo
commented
member-last
send
733 Dependency Dashboard 2mo 1d 2mo
recv
650 Pod goes out of readiness 4mo 4mo 4mo
recv
645 Unable to pass helm lint due to certificate yaml stripping too much whitespace 4mo 4mo 4mo
commented
member-last
send
629 The crds is not installed automatically when trust-manager is a sub-chart 6mo 4mo 6mo
recv
recv-q
750 Feat: Emit Events on the controller Pod instead of cluster-scoped Bundle 1mo 7wk 7wk
commented
contributor-last
recv
592 Feature: ClusterTrustBundle as Sources
7mo 2wk 2wk
commented
member-last
send
similar
588 Add ability to monitor validity period for CAs in bundle
5
7mo 3mo 3mo
kind/feature
help wanted
commented
member-last
send
560 Support rotated certificate sources
29
9mo 4mo 8mo
commented
recv
recv-q
465 Installing trust-manager just after installing cert-manager makes it FAIL forever 1y 6wk 7wk
lifecycle/stale
author-last
commented
recv
301 Add support for kubectl installation 2y 10mo 2y
lifecycle/frozen
author-last
commented
open-milestone
recv
recv-q
similar
591 Feature: ClusterTrustBundle as Target
8
7mo 19d 19d
commented
member-last
pr-merged
send
similar
245 Split Bundle controller into multiple controllers
2y 10mo 10mo
lifecycle/frozen
commented
member-last
pr-merged
send
142 expose bundles CRD as release artifact
10
2y 3mo 3mo
help wanted
commented
contributor-last
recv-q
send
131 Feature: per namespace trust bundle
6
2y 7wk 4mo
lifecycle/frozen
commented
send
99 Allow removing Bundles whilst keeping the synced CA certs
5
2y 6mo 6mo
lifecycle/frozen
commented
member-last
pr-unreviewed
63 nit: Rename "Bundle" to "ClusterBundle"
18
3y 4mo 4mo
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
60 overriding trusted namespace
10
17
3y 3mo 7mo
commented
recv-q
send
39 Don't sync targets to all namespaces by default
8
3y 6mo 6mo
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
4 Feature: By default, require only self-signed certificates in a bundle
4y 4mo 4mo
kind/feature
help wanted
good first issue
commented
member-last
send
242 New version of Bundle API
2
4
2y 7mo 1y
lifecycle/frozen
commented
pr-closed
pr-merged
222 [Feature] - Ability to inject a CA cert into a cert-manager managed secret resource
16
2y 2mo 2mo
commented
member-last
pr-merged
send
205 Allow to select multiple "trust" namespaces
46
2y 3mo 4mo
commented
send
243 More flexible and better organized target specification in API
4
2y 3wk 3wk
lifecycle/frozen
commented
member-last
pr-merged
279 Persisting identifiers for retry calls to Sign() 3mo 3mo 3mo
author-last
recv
recv-q
314 Dependency Dashboard 2mo 1d 2mo
recv
204 clarify SetCAOnCertificateRequest deprecation status 10mo 5mo 5mo
commented
member-last
send
231 ### Question about Configuring Retries in cert-manager 7mo 7mo 7mo
recv
385 Helm Install of cert-manager-csi-driver Fails on Minikube with /dev/bus/usb Errors 7mo 7mo 7mo
author-last
recv
471 Dependency Dashboard 2mo 2d 2mo
recv
267 Does cert-manager-csi-driver support AWS EKS with AWS Fargate nodes? 1y 1y 1y
recv
171 E2E Test Cleanup 2y 2y 2y
good first issue
commented
member-last
130 JKS support
6
2y 2y 2y
recv
recv-q
264 Certificate renewal doesn't change file 'modified date'
1y 1y 1y
recv
256 Broken comma-separated splitting logic 2y 2y
353 mismatch between the key and the certificate signature algorithm
10mo 10mo 10mo
recv
241 Missing cert-manager.io/revision-history-limit volume attributes for CSI-Driver
6
2y 2y 2y
recv
383 [Feature Request] Adding attributes that available in Certificate CRD to CSI Driver
8mo 8mo 8mo
recv
17 ability to specify pod IP in volume attributes
7
5y 11mo 5y
commented
recv
recv-q
354 Dependency Dashboard 2mo 1d 2mo
recv
128 Incorrect logger initialisation 2y 2y
41 The default `csiDataDir` value might collide with csi-driver
2y 5wk
contributor-last
pr-merged
recv-q
247 Dependency Dashboard 2mo 17h 2mo
recv
174 Standby Replicas without lease use lots of CPU 7mo 7mo 7mo
recv
116 Release static manifests (no helm) for v0.6.0-alpha.0+
1y 1y 1y
recv
58 certificate cannot be renewed, error message: "key does not match certificate"
4
2y 2y 2y
recv
recv-q
56 Support for destinationCaCertificate / Reencrypt Routes
2
2y 2y 2y
recv
similar
38 Route with cert-manager annotations is not created
4
2y 5mo 2y
commented
send
204 Support for creating certificate for wildcard route 4mo 4mo 4mo
recv
similar
54 Same certificate in path based Routes
2
2y 8mo 2y
pr-closed
recv
70 OLM deployment with ArgoCD is OutOfSync
3y 3y 3y
commented
send
46 Cert-manager operator fails to issue certificates 4y 4y 4y
recv
17 Operator prevents passing extraArgs helm value
7
5y 2y 5y
recv
recv-q
22 Customize the deployment of cert-manager installed via OLM
5
6
4y 1y 3y
commented
recv
recv-q
108 Dependency Dashboard 2mo 1d 2mo
recv
74 Consistency issues due to the use of mount binds 11mo 11mo 11mo
author-last
commented
recv
recv-q
40 Optional auto rotating/renewing certificates 3y 2y 3y
contributor-last
recv
recv-q
similar
67 Dependency Dashboard 2mo 5wk 2mo
recv
56 Struggling to get controller running in local KIND cluster
8mo 6mo 6mo
commented
member-last
send
63 Is it possible to only create Issuer and remove the CluserIssuer 5mo 5mo 5mo
recv
62 Limit the controller-manager to access secrets only from specific namespace 5mo 5mo 5mo
recv
301 Dependency Dashboard 2mo 1d 2mo
recv
264 commands should provide help when called w/o arguments if they require inputs 3mo 3mo 3mo
commented
member-last
send
128 cmctl always reports v0.0.0 in the user-agent header 1y 8mo
122 asdf cmctl installer issues
2
1y 1y 1y
author-last
commented
recv
59 Process regarding worrying emails sent to the maintainers mailing list
2mo 2mo 2mo
commented
member-last
451 Re-enable testing with specific kubernetes versions in subprojects 4wk 4wk 4wk
cybr
commented
member-last
send
295 `make generate-golangci-lint-config` clobbers local exclusions added to the local config. 5mo 5mo
202 Makefile Modules, Go Versions and Vendoring
1y 1y 1y
commented
contributor-last
154 Publish SBOMs 1y 1y 1y
kind/feature
good first issue
commented
member-last
send
379 Dependency Dashboard
2mo 12h 2mo
pr-merged
recv
25 helm-tool inject sometimes omits the context (prefix) of commented out values in the generated markdown 2y 2y
kind/bug
contributor-last
141 Dependency Dashboard 2mo 6d 2mo
recv
26 helm-tool inject adds trailing white space to the generated markdown 2y 2y
kind/bug
62 Lazy vote: Enhancing the triaging process 9d 9d
60 Lazy vote: Zoom for standup meetings to be able to add the standups to the LFX calendar
9d 1d 1d
commented
member-last
35 Post-Graduation Suggestion Tracker
1y 1y 1y
commented
member-last
pr-merged
63 CNCF-paid GitHub Actions runners 8d 8d
81 How to enable leader election in the webhook? 9mo 9mo 9mo
recv
37 Add logging example
3y 1y 3y
pr-closed
recv
2 Set up basic e2e test that deploys the webhook and ensures we can POST a challenge
6y 5wk
contributor-last
pr-closed
recv-q
80 How to deal with K8s timelimit in 30s ? 11mo 11mo 11mo
recv
72 readyz and healthz api 1y 1y 1y
recv
74 Why cert-manager looks for a CNAME record instead of a TXT record? 1y 1y 1y
recv
46 Code reference a pull request to be merged, but the pull request was closed by a robot 2y 2y 2y
recv
8 Find solution for automatically disabled GitHub Actions 1y 1y
18 Feature: Git bundles? 8mo 8mo
197 Kubectl One-line Installation Support 1y 1y 1y
commented
member-last
send
similar
315 Dependency Dashboard 2mo 1d 2mo
recv
162 Issue: Broken config when using commonLabels 2y 2y 2y
recv
148 Certificate chain is not split correctly
5
2y 2y 2y
author-last
pr-reviewed-with-comment
recv
recv-q
similar
133 Allow to use a custom Service Account
5
2y 1y 2y
pr-unreviewed
recv
102 certificate renewal does not work in due to auth issue to privatecaapi end point 2y 1y 2y
recv

Uncommented older than 7 days (161)

Resolution: Add a priority/ or triage/ label

Average age: 483.8d, Avg wait: 437.5d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8121 Support for Creating CertificateRequest from Kubernetes Secret 6wk 16d 6wk
kind/feature
triage/needs-information
contributor-last
recv
recv-q
similar
8085 Feature Request: Add annotation to disable automatic certificate renewal
1mo 5wk 1mo
priority/important-longterm
pr-closed
recv
similar
8058 Cert-manager fails to import ECDSA private keys generated by openssl 2mo 5wk 2mo
kind/bug
priority/important-longterm
pr-changes-requested
recv
7890 Cluster issuer for HTTP-01 gatewayHTTPRoute should not require a gateway parentRef
3
3mo 2mo 3mo
kind/feature
priority/awaiting-more-evidence
contributor-last
recv
recv-q
7879 Remove no-op certificate metrics controller 3mo 5wk 3mo
kind/feature
priority/backlog
assigned
assignee-updated
recv
7846 ClusterIssuer.Status.Acme.URI disappeared
4mo 7wk 4mo
good first issue
kind/bug
priority/awaiting-more-evidence
area/acme
triage/needs-information
assigned
assignee-updated
contributor-last
recv
recv-q
7845 ClusterIssuer.cert-manager.io "letsencrypt" is invalid: spec.acme.privateKeySecretRef: Required value...
6
4mo 7wk 4mo
kind/bug
priority/awaiting-more-evidence
area/acme
triage/needs-information
contributor-last
recv
recv-q
7826 If issuer is incorrect, it is still shown as READY 4mo 3wk 4mo
kind/bug
priority/important-longterm
assigned
assignee-updated
author-last
recv
recv-q
7699 Adding Helm Unittest to all certmanager projects 6mo 5wk 6mo
priority/backlog
assigned
assignee-updated
recv
7288 Missing UID in webhook challenge request 1y 3d 1y
kind/bug
priority/backlog
lifecycle/stale
contributor-last
recv
6820 Ongoing dependency evaluation
2y 1y 2y
lifecycle/frozen
priority/important-longterm
contributor-last
recv
6754 Schedule certificate renewal outside business hours
12
2y 5mo 2y
kind/feature
priority/important-longterm
pr-closed
pr-reviewed-with-comment
pr-unreviewed
recv
recv-q
6741 ACME account private key and URI are not updated if the path of the ACME server is changed
5
2y 1y 2y
lifecycle/frozen
kind/bug
priority/important-soon
contributor-last
recv
6472 Create TLSA records automatically
14
2y 3mo 2y
kind/feature
priority/backlog
author-last
recv
7218 cert-manager set don't fragment (DF) bit 1y 6wk 1y
kind/bug
priority/important-longterm
lifecycle/rotten
assigned
assignee-updated
contributor-last
recv
recv-q
5917 Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated
39
2y 2mo 2y
kind/bug
priority/important-longterm
assigned
assignee-updated
recv
recv-q
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together
2y 3d 2y
lifecycle/frozen
kind/bug
priority/important-soon
author-last
recv
recv-q
5540 Changelog annotations to chart 3y 3mo 3y
kind/feature
priority/backlog
author-last
recv
1549 Brand guideline page 1y 1y 1y
priority/backlog
author-last
recv
1473 Add ArtifactHub packages to website 2y 1y 2y
priority/backlog
recv
1063 "Securing Ingresses with Venafi" tutorial contains link to missing manifest
3y 1y 3y
priority/important-longterm
author-last
pr-merged
recv
850 Document available cert-manager Prometheus metrics
3y 2y 3y
documentation
good first issue
priority/important-longterm
recv
recv-q
354 DigitalOcean access-token should not be base64-encoded 5y 4y 5y
priority/awaiting-more-evidence
author-last
recv
recv-q
237 docs for ACMEChallengeSolverHTTP01Ingress doesn't specify what `class` values are available
5y 5y 5y
priority/backlog
kind/documentation
contributor-last
pr-closed
recv
232 Document keystored in usage/certificate 5y 5y 5y
priority/backlog
kind/documentation
contributor-last
recv
228 Documentation needs correction for external-account-bindings
5y 7mo 5y
good first issue
priority/backlog
kind/documentation
contributor-last
pr-merged
recv
197 Document ACME account mismatch 5y 9mo 5y
good first issue
priority/backlog
kind/documentation
recv
recv-q
130 FAQ: How does cert-manager handle ingresses with valid TLS secrets? 5y 5y 5y
help wanted
priority/backlog
kind/documentation
contributor-last
recv
76 Upgrading from v0.10 to v0.11 - missing cainjector annotation 5y 5y 5y
priority/backlog
kind/documentation
contributor-last
recv
3 Restrict operator RBAC permissions
5y 1y 5y
priority/backlog
pr-merged
recv
83 As cmctl user, I want to use different kubectl context on command line ( --context='kubectl-context-abc' )
2
1y 1y 1y
priority/important-longterm
recv
693 Set up periodics against 'previous previous' branch 3y 1y 3y
priority/backlog
recv
594 Document infra image bumps and versioning 4y 1y 4y
priority/backlog
recv
690 Clean up Presets
3y 1y 3y
priority/backlog
pr-merged
recv
38 Set repository to be a GitHub template repository
3y 1y 3y
priority/important-longterm
recv
126 previously listed items omitted

Important soon, but no updates in 90 days (16)

Resolution: Downgrade to important-longterm

Average age: 1229.0d, Avg wait: 47.3d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6741 ACME account private key and URI are not updated if the path of the ACME server is changed
5
2y 1y 2y
lifecycle/frozen
kind/bug
priority/important-soon
contributor-last
recv
5867 Controller can't handle hitting request rate limits of zerossl ACME API
7
12
31
2y 7mo 1y
lifecycle/frozen
kind/bug
priority/important-soon
commented
pr-closed
pr-merged
recv-q
send
5298 Complete the Migration Away From Jetstack Names 3y 1y 2y
lifecycle/frozen
kind/cleanup
priority/important-soon
commented
member-last
send
3381 Setup separate package for cert-manager API
5
5y 10mo 10mo
lifecycle/frozen
kind/feature
priority/important-soon
assigned
assignee-updated
commented
member-last
send
2930 Mirror to gcr.io or dockerhub
2
29
5y 8mo 11mo
lifecycle/frozen
kind/feature
priority/important-soon
area/deploy
assigned
assignee-updated
commented
contributor-last
send
7234 Stale/Stuck Challenges should be deleted after a given timeout
4
1y 3mo 1y
kind/bug
priority/important-soon
assigned
assignee-updated
commented
contributor-last
open-milestone
pr-closed
pr-new-commits
pr-reviewed-with-comment
recv
recv-q
6709 1.14 Release Review
3
2y 1y 2y
lifecycle/frozen
priority/important-soon
commented
contributor-last
send
6331 CSR not signed by referenced private key
10
2y 5mo 2y
kind/bug
priority/important-soon
commented
recv-q
send
2239 Create a CertificatePreset resource type to allow configurable defaulting
2
3
99
6y 5mo 5mo
area/api
kind/feature
priority/backlog
priority/important-soon
commented
member-last
pr-closed
pr-unreviewed
send
1425 The `issuer.vault.spec.caBundleSecretRef` docs are missing 2y 1y
priority/important-soon
955 Document when the vault pki role required setting `require_cn=false`
3y 1y
priority/important-soon
174 Add documentation for CRD conversion webhook ca injection 5y 5y 5y
help wanted
priority/important-soon
kind/documentation
commented
member-last
send
802 Spelling errors are unclear in pull request CI results and spell checker is unmaintained
3y 1y
kind/bug
priority/important-soon
contributor-last
pr-merged
195 Document keystores 5y 2y 5y
priority/important-soon
kind/documentation
commented
contributor-last
send
1174 Document the docker images and how to find them
2y 2y 2y
good first issue
priority/important-soon
kind/documentation
commented
member-last
send
127 cmctl version reports only the old CRD version if I upgrade cert-manager without including the CRDs 1y 1y
priority/important-soon

Important longterm, but no updates in 180 days (20)

Resolution: Downgrade to backlog

Average age: 1278.5d, Avg wait: 227.5d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
6969 Should upgrade status managed fields from CSA to SSA when ServerSideApply feature gate enabled 2y 1y 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
send
5959 `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries
22
2y 1y 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
recv-q
send
4191 Setting default values for Pod's "resources"?
7
4y 1y 1y
lifecycle/frozen
priority/important-longterm
commented
contributor-last
recv-q
send
2525 Better support multi-namespace & single-namespace deployments
26
5y 6mo 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/deploy
commented
contributor-last
open-milestone
pr-closed
send
similar
2178 Handling 'unregistering' certificates from Venafi TPP
22
6y 1y 1y
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
commented
member-last
send
4950 General flakiness of our end-to-end suite
3
3y 1y 3y
lifecycle/frozen
priority/important-longterm
kind/flake
commented
member-last
pr-closed
pr-merged
send
1194 Confusing paragraph - cert-manager integration. 2y 1y 2y
documentation
priority/important-longterm
commented
member-last
send
1186 Document that/why we don't use Helm's CRD installation mechanism 2y 1y 1y
good first issue
priority/important-longterm
kind/documentation
assigned
assignee-updated
commented
member-last
send
223 Document wildcard certificate tutorial 5y 5y 5y
priority/important-longterm
kind/documentation
commented
contributor-last
send
975 Some pages do not make it clear what the user should read next 3y 1y
priority/important-longterm
401 Bring tutorials up to date 4y 2y 2y
priority/important-longterm
commented
member-last
send
58 Support injection pem into an existing configmap
8
3y 6mo 6mo
priority/important-longterm
lifecycle/frozen
assigned
assignee-updated
commented
member-last
pr-closed
pr-merged
pr-unreviewed
send
129 Increase e2e test timeouts 2y 1y
priority/important-longterm
98 Document new release process for all repos 2y 1y
priority/important-longterm
assigned
3 Make unit testing easier/make examples work
6y 1y 3y
priority/important-longterm
commented
member-last
pr-closed
send
5 previously listed items omitted: #6820 #1063 #850 #83 #38

Pull Requests: Review Ready (42)

Resolution: Review requests or mark them as do-not-merge/work-in-progress

Average age: 272.3d, Avg wait: 176.6d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8244 feat: Support Ingress annotation override for HTTP-01 ingressClassName 4d 2d 4d
size/L
release-note
area/api
kind/feature
area/acme
dco-signoff: yes
commented
member-last
reviewed-with-comment
8228 feat(vault): add server as default audience 10d 2d 2d
release-note
area/api
kind/feature
size/M
dco-signoff: yes
ok-to-test
area/deploy
commented
contributor-last
recv
reviewed-with-comment
8010 feat: Add client verification for webhook server
4
2mo 2d 2mo
size/L
release-note-none
area/api
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
author-last
new-commits
recv
recv-q
7327 add more detailed logging when service certificate is generated
1y 5d 11d
release-note-none
approved
lgtm
size/S
dco-signoff: yes
ok-to-test
needs-kind
approved
commented
contributor-last
recv
recv-q
7614 Lower the minimum certificate duration from 1 hour to 5 minutes 8mo 11d 8mo
release-note
size/S
area/api
kind/feature
dco-signoff: yes
ok-to-test
contributor-last
recv
recv-q
unreviewed
8232 Add checks for Duration/RenewBefore changes when determining if an ingress/gateway-api change should trigger a certificate update 10d 10d 10d
size/L
release-note
kind/bug
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
7646 Support custom ACME account key type.
2
7mo 4wk 5mo
size/L
release-note
area/api
area/acme
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
author-last
commented
new-commits
recv
recv-q
8071 Handle ACME Accept asynchronously 2mo 5wk 2mo
size/L
release-note
area/api
needs-ok-to-test
area/acme
dco-signoff: yes
area/testing
area/deploy
needs-kind
author-last
recv
recv-q
unreviewed
7450 Make ACME Authorization Timeout Configurable 11mo 3mo 11mo
size/L
release-note
area/api
needs-ok-to-test
area/acme
dco-signoff: yes
area/acme/http01
area/deploy
needs-kind
commented
contributor-last
new-commits
recv
recv-q
similar
7689 Add Vertical Pod Autoscaler
2
7mo 4mo 6mo
size/L
release-note
approved
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
author-last
commented
new-commits
recv
recv-q
7289 Design proposal for delayed certificate activation 1y 5mo 9mo
size/L
release-note-none
kind/design
needs-ok-to-test
dco-signoff: yes
commented
contributor-last
open-milestone
recv
recv-q
reviewed-with-comment
7733 fixes #5864: cert-manager CA to issue certs after verify with CA Certs Validity
6mo 5mo 5mo
size/L
release-note
kind/bug
kind/feature
dco-signoff: yes
ok-to-test
author-last
commented
new-commits
recv
recv-q
7439 helm: add checksum/config annotations 11mo 5mo 11mo
release-note-none
size/S
kind/feature
needs-ok-to-test
dco-signoff: yes
area/deploy
author-last
recv
recv-q
unreviewed
7583 Support for ACME servers that don't finalize within the ACME client finalizer retry window 8mo 5mo 8mo
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
author-last
recv
recv-q
unreviewed
1827 Update NetworkPolicy guidelines to reflect the correct namespace 13d 9d 13d
size/XS
dco-signoff: yes
author-last
recv
recv-q
reviewed-with-comment
1824 Fix wording in rfc2136 documentation on rate limits 16d 16d 16d
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
1602 acme troubleshooting: how to fix errored challenges 11mo 2mo 11mo
size/XS
dco-signoff: yes
contributor-last
recv
recv-q
reviewed-with-comment
1721 Remove whitespace-nowrap from Toc component 4mo 4mo 4mo
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
1607 Document Log Level settings. Document DNS01 delegation using multiple providers. 11mo 11mo 11mo
dco-signoff: yes
size/M
recv
recv-q
unreviewed
1587 Custom Certificate Support for cert-manager Webhook Endpoint 1y 1y 1y
dco-signoff: yes
size/S
recv
recv-q
unreviewed
1259 Fixed Azure Workload identity doc 2y 2y 2y
dco-signoff: yes
size/S
recv
unreviewed
1841 feat: add cert-manager-webhook-regery to docs 5d 5d 5d
dco-signoff: yes
size/S
recv
recv-q
unreviewed
672 Remove grouping of Istio dependencies 6h 6h
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
683 feat: Add a very basic pre-commit configuration 3mo 2mo 2mo
dco-signoff: yes
size/XS
commented
member-last
new-commits
762 Add support for injecting CA from secret for trust manager Webhook 6wk 6wk 6wk
dco-signoff: yes
needs-ok-to-test
size/S
author-last
commented
recv
unreviewed
188 Remove SetCertificateRequestConditionError 11mo 4mo
dco-signoff: yes
size/XL
contributor-last
recv-q
unreviewed
148 limit-namespaces for namespace-scope deployments
9mo 9mo 9mo
dco-signoff: no
size/S
needs-ok-to-test
author-last
recv
recv-q
unreviewed
71 Refactor filesystem.go and adapt tests to use a real file system 11mo 4mo 4mo
dco-signoff: yes
size/L
commented
member-last
reviewed-with-comment
1088 Update k8s-infra-prow images, k8s-staging-test-infra images, cert-manager-infra-images images as needed 7mo 4d 7mo
dco-signoff: yes
size/M
contributor-last
recv
recv-q
unreviewed
1119 Disable DCO for Copilot-authored PRs 5d 5d
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
470 feat(helm): adding `helm-diff` target 12d 1d 1d
dco-signoff: yes
size/S
cybr
ok-to-test
assigned
assignee-updated
commented
contributor-last
new-commits
recv
recv-q
479 chore(deps): update dependency helm/helm to v4 12h 12h 12h
dco-signoff: yes
size/S
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
310 Add generate-applyconfigurations target to controller-gen module 4mo 3mo
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
55 feat: add test module 2y 2y 2y
dco-signoff: yes
size/M
commented
contributor-last
recv
reviewed-with-comment
64 Add imagePullSecrets to template 2y 2y 2y
size/XS
dco-signoff: yes
needs-ok-to-test
contributor-last
recv
unreviewed
79 Bump github.com/cert-manager/cert-manager from 1.15.1 to 1.15.4 in the go_modules group across 1 directory 11mo 11mo 11mo
size/XS
dco-signoff: yes
needs-ok-to-test
dependencies
contributor-last
recv
recv-q
unreviewed
59 cleanup: remove unused NOTES.txt file 2y 2y 2y
size/XS
dco-signoff: yes
needs-ok-to-test
contributor-last
recv
unreviewed
1 Manage the cert-manager GitHub organisation from this repo 1y 1y 1y
dco-signoff: yes
size/XXL
commented
member-last
unreviewed
4 Add support for custom license templates 2y 3mo
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
143 feat: allow creating or reusing an existing sa 2y 6mo 2y
ok-to-test
recv
recv-q
unreviewed
345 chore: add existing securityContext settings to values 4wk 4wk 4wk
size/M
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
141 re-adding required clusterrole permission 2y 9mo 2y
size/XS
author-last
recv
unreviewed

Unkinded Issues (205)

Resolution: Add a kind/ or triage/support label

Average age: 606.3d, Avg wait: 266.7d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8252 Implement XListenerSet 1d 1d
cybr
8251 Top-level ticket: XListenerSet 1d 1d
cybr
8241 PrivateKeyEncoding PKCS1 is misleading for EC keys 5d 5d 5d
recv
7895 if certificate is already expired, it shown like a True
2
3mo 16d 7wk
help wanted
priority/important-soon
commented
contributor-last
recv
6799 ACME challenges stopped working after 1.13/1.14 update
2y 5mo 2y
priority/critical-urgent
commented
recv
recv-q
3992 Add non-CRD yaml file
4
4y 1d 1y
priority/important-soon
area/deploy
author-last
commented
recv
6179 CRDs shouldn't be templated in Helm
5
2
30
2y 2mo 2mo
priority/backlog
commented
recv-q
send
1101 Feature request for updating documentation. 3y 1y 1y
priority/backlog
commented
member-last
send
similar
1262 v1.9 to v1.10 upgrade instructions does not mention container name change
2y 8mo 1y
priority/backlog
assigned
assignee-updated
commented
member-last
send
320 Document how to install cert-manager using gitops and known issues with particular gitops implementations
5
5y 2y 5y
documentation
help wanted
priority/backlog
commented
pr-merged
recv-q
2 Set up periodic job to publish an experimental release build
5y 4y
priority/backlog
assigned
contributor-last
297 Allow all resources to be namespaced
7
2y 2mo 2mo
priority/backlog
commented
member-last
send
33 Support CRDs as target
5
3y 4mo 4mo
priority/backlog
commented
member-last
send
45 Unable to mount and read only file error
5
4y 1y 1y
priority/awaiting-more-evidence
commented
send
132 Investigate test timeouts 2y 1y
priority/backlog
33 Create e2e test to validate CertificateRequest garbage collection 3y 1y 1y
priority/backlog
assigned
commented
member-last
send
60 Support prometheus metrics
2y 1y 1y
priority/backlog
commented
member-last
pr-reviewed-with-comment
send
81 Configuring Peribolos for Github org management 7y 1y 1y
priority/backlog
commented
member-last
send
3 Migrating all cert-manager sub-projects to "Makefile modules" 2y 4mo 4mo
priority/backlog
commented
member-last
43 Allow non-Venafi employee maintainers full release capabilities
3
11mo 9d 9d
priority/backlog
cybr
commented
member-last
send
27 failed with: OpenAPI spec does not exist
2
6
4y 1y 2y
priority/critical-urgent
commented
pr-closed
pr-unreviewed
send
361 [Helm] allow `enabled` as key in values schema 2d 2d 2d
recv
183 previously listed items omitted

Unprioritized Recent Issues (229)

Resolution: Add a priority/ or triage/ label

Average age: 420.8d, Avg wait: 204.3d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
8247 Graduate otherNames feature gate from alpha to beta 3d 3d 3d
kind/feature
recv
228 previously listed items omitted

Uncommented Recent Issues (3)

Resolution: Add a comment

Average age: 3.6d, Avg wait: 3.5d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
3 previously listed items omitted: #8241 #8247 #361
New, has multiple reactions, but not important-soon: No matching items
New, has multiple commenters, but not important-soon: No matching items

needs information, has update (3)

Resolution: Comment and remove triage/needs-information tag

Average age: 102.8d, Avg wait: 101.4d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
3 previously listed items omitted: #8121 #7846 #7845

Recently updated issue has a question (2)

Resolution: Add an answer

Average age: 652.1d, Avg wait: 4.6d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
7561 Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued 9mo 6d 6d
kind/feature
author-last
commented
recv
recv-q
5751 Wildcard DNS domains and `cnameStrategy: Follow` don't work nicely together
2y 3d 2y
lifecycle/frozen
kind/bug
priority/important-soon
author-last
recv
recv-q
Triage Party v1.4.0