queue to be emptied once a day
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 8121 | Support for Creating CertificateRequest from Kubernetes Secret | 11mo | 5wk | 11mo |
kind/feature
triage/needs-information
lifecycle/rotten
|
contributor-last recv recv-q similar
|
|||||
| 8058 | Cert-manager fails to import ECDSA private keys generated by openssl | 1y | 5d | 1y |
kind/bug
priority/important-longterm
|
pr-changes-requested pr-reviewed-with-comment recv recv-q
|
|||||
| 6820 | Ongoing dependency evaluation |
|
2y | 2y | 2y |
lifecycle/frozen
priority/important-longterm
|
contributor-last recv
|
||||
| 6741 | ACME account private key and URI are not updated if the path of the ACME server is changed |
7
|
2y | 9mo | 2y |
lifecycle/frozen
kind/bug
priority/important-soon
|
pr-unreviewed recv
|
||||
| 6472 | Create TLSA records automatically |
18
|
2y | 4wk | 2y |
kind/feature
priority/backlog
|
pr-reviewed-with-comment recv recv-q
|
||||
| 5917 | Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated |
43
|
3y | 5mo | 3y |
kind/bug
priority/important-longterm
|
assigned assignee-updated recv recv-q
|
||||
| 5540 | Changelog annotations to chart |
|
3y | 7mo | 3y |
kind/feature
priority/backlog
|
recv
|
||||
| 1549 | Brand guideline page | 2y | 2y | 2y |
priority/backlog
|
contributor-last recv
|
|||||
| 1473 | Add ArtifactHub packages to website | 2y | 2y | 2y |
priority/backlog
|
recv
|
|||||
| 1063 |
"Securing Ingresses with Venafi" tutorial contains link to missing manifest
|
4y | 2y | 4y |
priority/important-longterm
|
pr-merged recv
|
|||||
| 850 |
Document available cert-manager Prometheus metrics
|
|
4y | 3y | 4y |
documentation
good first issue
priority/important-longterm
|
pr-closed recv recv-q
|
||||
| 354 | DigitalOcean access-token should not be base64-encoded | 5y | 5y | 5y |
priority/awaiting-more-evidence
|
pr-unreviewed recv recv-q
|
|||||
| 237 |
docs for ACMEChallengeSolverHTTP01Ingress doesn't specify what `class` values are available
|
|
6y | 6y | 6y |
priority/backlog
kind/documentation
|
contributor-last pr-closed recv
|
||||
| 197 | Document ACME account mismatch | 6y | 2y | 6y |
good first issue
priority/backlog
kind/documentation
|
pr-changes-requested recv recv-q
|
|||||
| 130 | FAQ: How does cert-manager handle ingresses with valid TLS secrets? | 6y | 6y | 6y |
help wanted
priority/backlog
kind/documentation
|
contributor-last recv
|
|||||
| 76 | Upgrading from v0.10 to v0.11 - missing cainjector annotation | 6y | 6y | 6y |
priority/backlog
kind/documentation
|
contributor-last recv
|
|||||
| 3 |
Restrict operator RBAC permissions
|
6y | 2y | 6y |
priority/backlog
|
pr-merged recv
|
|||||
| 83 | As cmctl user, I want to use different kubectl context on command line ( --context='kubectl-context-abc' ) |
5
|
2y | 2y | 2y |
priority/important-longterm
|
recv
|
||||
| 594 | Document infra image bumps and versioning | 4y | 2y | 4y |
priority/backlog
|
recv
|
|||||
| 690 |
Clean up Presets
|
4y | 2y | 4y |
priority/backlog
|
pr-merged recv
|
|||||
| 38 | Set repository to be a GitHub template repository |
|
4y | 2y | 4y |
priority/important-longterm
|
recv
|
||||
| 127 previously listed items omitted | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 6741 | ACME account private key and URI are not updated if the path of the ACME server is changed |
7
|
2y | 9mo | 2y |
lifecycle/frozen
kind/bug
priority/important-soon
|
pr-unreviewed recv
|
|||
| 5298 | Complete the Migration Away From Jetstack Names | 4y | 2y | 2y |
lifecycle/frozen
kind/cleanup
priority/important-soon
|
commented member-last send
|
||||
| 3992 | Add non-CRD yaml file |
5
|
5y | 3mo | 2y |
priority/important-soon
area/deploy
|
commented recv
|
|||
| 7895 | if certificate is already expired, it shown like a True |
2
|
1y | 4mo | 4mo |
help wanted
priority/important-soon
|
collaborator-last commented pr-closed pr-reviewed-with-comment pr-unreviewed send
|
|||
| 6709 | 1.14 Release Review |
3
|
2y | 2y | 2y |
lifecycle/frozen
priority/important-soon
|
commented contributor-last send
|
|||
| 2930 | Mirror to gcr.io or dockerhub |
2
29
|
6y | 3mo | 2y |
lifecycle/frozen
kind/feature
priority/important-soon
area/deploy
|
assigned assignee-updated commented recv-q send
|
|||
| 3381 | Setup separate package for cert-manager API |
6
|
5y | 2y | 2y |
lifecycle/frozen
kind/feature
priority/important-soon
|
assigned assignee-updated commented member-last send
|
|||
| 5867 |
Controller can't handle hitting request rate limits of zerossl ACME API
|
7
12
31
|
3y | 1y | 2y |
lifecycle/frozen
kind/bug
priority/important-soon
|
commented pr-closed pr-merged recv-q send
|
|||
| 1425 | The `issuer.vault.spec.caBundleSecretRef` docs are missing | 2y | 2y |
priority/important-soon
|
pr-reviewed-with-comment
|
|||||
| 955 | Document when the vault pki role required setting `require_cn=false` |
2
|
4y | 2y |
priority/important-soon
|
|||||
| 802 |
Spelling errors are unclear in pull request CI results and spell checker is unmaintained
|
4y | 2y |
kind/bug
priority/important-soon
|
contributor-last pr-merged
|
|||||
| 195 | Document keystores | 6y | 3y | 6y |
priority/important-soon
kind/documentation
|
commented contributor-last send
|
||||
| 174 | Add documentation for CRD conversion webhook ca injection | 6y | 6y | 6y |
help wanted
priority/important-soon
kind/documentation
|
commented member-last send
|
||||
| 127 | cmctl version reports only the old CRD version if I upgrade cert-manager without including the CRDs | 2y | 2y |
priority/important-soon
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 7514 | Replace some of the webhook functionality with `ValidatingAdmissionPolicy` & CEL |
|
2y | 6mo | 1y |
kind/feature
priority/important-longterm
|
commented recv
|
||||
| 6969 | Should upgrade status managed fields from CSA to SSA when ServerSideApply feature gate enabled | 2y | 2y | 2y |
lifecycle/frozen
kind/bug
priority/important-longterm
|
commented contributor-last send
|
|||||
| 5959 | `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries |
23
|
3y | 9mo | 2y |
lifecycle/frozen
kind/bug
priority/important-longterm
|
commented contributor-last recv-q send
|
||||
| 4191 | Setting default values for Pod's "resources"? |
7
|
5y | 2y | 2y |
lifecycle/frozen
priority/important-longterm
|
commented contributor-last recv-q send
|
||||
| 6051 |
Detecting Gateway hostnames based on attached HTTPRoutes
|
7
35
|
3y | 1y | 1y |
lifecycle/frozen
kind/feature
priority/important-longterm
|
commented pr-merged send
|
||||
| 4685 | Unexpected EOF during watch stream event decoding: unexpected EOF -- possibly due to api server upgrades / restarts |
12
|
4y | 10mo | 10mo |
lifecycle/frozen
kind/bug
priority/important-longterm
|
commented contributor-last recv
|
||||
| 3521 | Integration with ExternalDNS |
4
55
|
5y | 1y | 2y |
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
|
commented recv-q
|
||||
| 2178 | Handling 'unregistering' certificates from Venafi TPP |
22
|
7y | 2y | 2y |
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
|
commented member-last send
|
||||
| 2525 |
Better support multi-namespace & single-namespace deployments
|
30
|
6y | 1y | 2y |
lifecycle/frozen
kind/feature
priority/important-longterm
area/deploy
|
commented contributor-last pr-closed send
|
||||
| 1186 | Document that/why we don't use Helm's CRD installation mechanism | 3y | 2y | 2y |
good first issue
priority/important-longterm
kind/documentation
|
assigned assignee-updated commented member-last send
|
|||||
| 975 | Some pages do not make it clear what the user should read next | 4y | 2y |
priority/important-longterm
|
|||||||
| 401 | Bring tutorials up to date | 5y | 3y | 3y |
priority/important-longterm
|
commented member-last send
|
|||||
| 223 | Document wildcard certificate tutorial | 6y | 6y | 6y |
priority/important-longterm
kind/documentation
|
commented contributor-last send
|
|||||
| 58 | Support injection pem into an existing configmap |
8
|
4y | 1y | 1y |
priority/important-longterm
lifecycle/frozen
|
assigned assignee-updated commented member-last pr-closed pr-merged pr-unreviewed send
|
||||
| 129 | Increase e2e test timeouts | 2y | 2y |
priority/important-longterm
|
|||||||
| 98 | Document new release process for all repos | 2y | 2y |
priority/important-longterm
|
assigned
|
||||||
| 3 |
Make unit testing easier/make examples work
|
7y | 2y | 4y |
priority/important-longterm
|
commented member-last pr-closed send
|
|||||
| 5 previously listed items omitted: #6820 #1063 #850 #83 #38 | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 9317 |
chore(deps): update module google.golang.org/grpc to v1.83.2 [security] (release-1.21)
|
18h | 12h | 18h |
release-note-none
approved
lgtm
size/S
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
dependencies
|
approved contributor-last recv recv-q similar
|
||||
| 9316 |
chore(deps): update module google.golang.org/grpc to v1.83.2 [security] (release-1.20)
|
22h | 12h | 22h |
release-note-none
approved
lgtm
size/S
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
dependencies
|
approved contributor-last recv recv-q similar
|
||||
| 9292 | [release-1.21] fix(acme/ari): adding cert id to status | 2d | 19h | 19h |
release-note
size/XL
area/api
kind/bug
dco-signoff: yes
tide/merge-method-squash
area/deploy
|
assigned assignee-updated commented member-last unreviewed
|
||||
| 9207 | Fix HTTP01 self-check to respect context cancellation | 13d | 1d | 2d |
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/acme/dns01
area/acme/http01
|
commented contributor-last recv reviewed-with-comment
|
||||
| 8722 | fix(dns): propagate caBundle to acmeDNS solver, add per-solver override | 4mo | 1d | 4mo |
release-note
area/api
kind/bug
kind/feature
needs-ok-to-test
size/XXL
area/acme
dco-signoff: yes
area/acme/dns01
area/deploy
|
recv recv-q unreviewed
|
||||
| 9294 | Fix ec parameters parsing with unit test | 2d | 1d | 2d |
release-note
kind/bug
size/M
dco-signoff: yes
ok-to-test
|
contributor-last recv recv-q reviewed-with-comment similar
|
||||
| 9287 | fix(certificates): recover from a CertificateRequest with a failureTime but no Ready condition | 3d | 1d | 3d |
release-note
kind/bug
needs-ok-to-test
size/XXL
dco-signoff: yes
area/testing
|
contributor-last recv recv-q similar unreviewed
|
||||
| 8935 | feat(metrics): instrument Vault issuer Sign() requests | 2mo | 2d | 2mo |
release-note
kind/feature
needs-ok-to-test
size/M
area/vault
dco-signoff: yes
area/monitoring
|
recv recv-q similar unreviewed
|
||||
| 9285 | Add design: publish the ACME webhook API as its own Go module | 4d | 4d |
size/L
release-note-none
kind/design
dco-signoff: yes
|
contributor-last recv-q unreviewed
|
|||||
| 9109 | Fix nil pointer panic on renewal-window errors in the trigger controller |
|
4wk | 4d | 4d |
size/L
release-note
kind/bug
dco-signoff: yes
|
commented member-last reviewed-with-comment
|
|||
| 9224 | Only consume next private key Secrets owned by the Certificate | 9d | 4d | 4d |
release-note
size/XL
kind/bug
dco-signoff: yes
area/testing
|
commented member-last reviewed-with-comment
|
||||
| 9247 | Deflake notAfter assertions in CSR signing tests | 8d | 5d | 5d |
size/L
release-note-none
dco-signoff: yes
kind/flake
|
commented member-last reviewed-with-comment
|
||||
| 9254 | Deflake certificate-shim controller register tests | 8d | 5d | 5d |
release-note-none
size/M
dco-signoff: yes
kind/flake
|
commented member-last similar unreviewed
|
||||
| 8457 | feat(acme): add support for ECDSA account key algorithm in ACME issuers |
3
|
7mo | 6d | 3wk |
release-note
size/XL
area/api
kind/feature
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/deploy
|
commented recv reviewed-with-comment
|
|||
| 9245 | Run dynamic authority tests in a synctest bubble | 8d | 7d | 7d |
release-note-none
size/S
dco-signoff: yes
kind/flake
|
commented member-last reviewed-with-comment
|
||||
| 9241 | Recover DynamicAuthority when the CA Secret create race is lost | 8d | 8d | 8d |
release-note
kind/bug
size/M
dco-signoff: yes
kind/flake
|
commented member-last reviewed-with-comment
|
||||
| 9244 | [release-1.21] fix(digitalocean): paginate TXT record lookups in findTxtRecord | 8d | 8d | 8d |
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
|
assigned assignee-updated commented contributor-last recv-q unreviewed
|
||||
| 9243 | Deflake TestDynamicAuthority | 8d | 8d |
release-note-none
size/S
kind/cleanup
dco-signoff: yes
|
contributor-last recv-q unreviewed
|
|||||
| 8837 | reject negative arcs in ParseObjectIdentifier | 3mo | 15d | 16d |
release-note
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
|
commented recv reviewed-with-comment
|
||||
| 8844 | reject non-context-specific GeneralName class in UnmarshalSANs | 3mo | 15d | 3mo |
release-note-none
needs-ok-to-test
size/M
dco-signoff: yes
needs-kind
|
new-commits recv recv-q
|
||||
| 9056 | fix: don't count terminating HTTP01 solver pods when deciding to create/clean up | 7wk | 15d | 16d |
release-note
kind/bug
size/M
area/acme
dco-signoff: yes
ok-to-test
area/acme/http01
|
assigned assignee-updated commented contributor-last new-commits recv recv-q
|
||||
| 9183 | Route53: resume waiting for a pending record change instead of submitting a duplicate | 19d | 19d | 19d |
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
|
commented member-last new-commits
|
||||
| 9150 | Accept bundles containing cross-signed certificates in ParseSingleCertificateChain | 3wk | 3wk | 3wk |
size/L
release-note
kind/bug
dco-signoff: yes
|
commented member-last reviewed-with-comment
|
||||
| 9082 | test: add regression coverage for deep-subdomain zone lookup (#4749) | 6wk | 4wk | 6wk |
release-note-none
size/S
kind/cleanup
needs-ok-to-test
area/acme
dco-signoff: yes
area/acme/dns01
|
assigned contributor-last recv recv-q reviewed-with-comment
|
||||
| 9110 | Route53: assume the role lazily so the AWS SDK can refresh STS credentials | 4wk | 4wk | 4wk |
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
|
commented member-last reviewed-with-comment
|
||||
| 9013 | fix(cainjector): add liveness and readiness probes to cainjector deployment | 2mo | 4wk | 2mo |
release-note
area/api
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
|
recv recv-q unreviewed
|
||||
| 9097 | fix(keymanager): preserve current private key secret on stale informer cache | 5wk | 5wk | 5wk |
size/L
release-note
needs-ok-to-test
dco-signoff: yes
needs-kind
|
contributor-last recv recv-q unreviewed
|
||||
| 8395 | Clarify code around DNS01 Self Check | 8mo | 7wk | 6mo |
release-note-none
kind/cleanup
size/M
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
|
commented new-commits recv recv-q
|
||||
| 9045 | Fix CertificateRequest approval event reason | 7wk | 7wk | 7wk |
size/XS
release-note
kind/bug
needs-ok-to-test
dco-signoff: yes
|
contributor-last recv recv-q similar unreviewed
|
||||
| 9030 | feat: validate owner reference | 1mo | 1mo | 1mo |
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
|
contributor-last recv recv-q unreviewed
|
||||
| 8367 | feat(helm) add startupProbe and readinessProbe to cert-manager-controller | 8mo | 2mo | 8mo |
release-note-none
kind/feature
needs-ok-to-test
size/M
lifecycle/stale
dco-signoff: yes
area/deploy
|
commented contributor-last recv recv-q unreviewed
|
||||
| 8968 | fix(acmeorders): reschedule Order when concurrent finalize returns 403 with processing ACME order | 2mo | 2mo | 2mo |
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
|
new-commits recv recv-q
|
||||
| 8896 | Helm toggle features | 2mo | 2mo | 2mo |
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
area/deploy
|
contributor-last recv recv-q unreviewed
|
||||
| 8892 | add renderMode options for prometheus monitors | 2mo | 2mo | 2mo |
release-note
kind/feature
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
|
commented recv unreviewed
|
||||
| 8262 | Bugfix #7388 kid missing issue with Infisical ACME server or any other ACME that requires EAB |
|
9mo | 2mo | 9mo |
size/L
release-note
needs-ok-to-test
lifecycle/stale
area/acme
dco-signoff: yes
needs-kind
|
commented contributor-last recv unreviewed
|
|||
| 9171 | Allow configuring concatenation key order for CombinedPEM output format (#7766) |
|
3wk | 8h | 19d |
size/L
release-note
area/api
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
|
commented new-commits recv
|
|||
| 8846 | fix(selector/dns): normalize dns name before comparing | 3mo | 2mo | 3mo |
release-note-none
size/S
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
|
contributor-last recv recv-q unreviewed
|
||||
| 8838 | Add support for GN and SN in LiteralSubject | 3mo | 3mo | 3mo |
release-note
size/S
kind/feature
needs-ok-to-test
dco-signoff: yes
|
contributor-last recv recv-q unreviewed
|
||||
| 8687 | Normalize challenge reason in certmanager_certificate_challenge_status metric |
|
5mo | 4mo | 5mo |
size/L
release-note-none
needs-ok-to-test
dco-signoff: yes
needs-kind
|
recv recv-q reviewed-with-comment
|
|||
| 5743 | Add MaxPathLen and add EncodeBasicConstraintsInRequest option to Certificate and CertificateRequest resources | 3y | 5mo | 5mo |
size/L
release-note
area/api
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
area/deploy
|
commented member-last reviewed-with-comment
|
||||
| 8594 | Fix typo "commonname" in PreferredChain field comment | 6mo | 6mo | 6mo |
release-note-none
size/S
area/api
kind/cleanup
needs-ok-to-test
dco-signoff: yes
area/deploy
|
contributor-last recv recv-q unreviewed
|
||||
| 2273 | chore(deps): update misc npm packages | 2d | 38min | 2d |
dco-signoff: yes
size/XL
ok-to-test
dependencies
|
recv recv-q unreviewed
|
||||
| 2270 | chore(deps): lock file maintenance | 3d | 8h | 3d |
dco-signoff: yes
size/XXL
ok-to-test
dependencies
|
recv recv-q unreviewed
|
||||
| 2227 | fix(deps): update dependency @docsearch/react to v5 | 4wk | 8h | 4wk |
dco-signoff: yes
size/L
ok-to-test
dependencies
|
contributor-last recv recv-q unreviewed
|
||||
| 2239 | Add cmp-issuer to external issuers list | 18d | 5d | 18d |
size/XS
dco-signoff: yes
|
recv recv-q similar unreviewed
|
||||
| 2256 | docs: correct the Gateway API version requirement | 8d | 7d | 8d |
dco-signoff: yes
size/M
|
recv recv-q unreviewed
|
||||
| 2260 | Add an availability and denial of service section to the threat model | 7d | 7d |
dco-signoff: yes
size/M
|
recv-q unreviewed
|
|||||
| 2257 | docs: document the Vault issuer caBundleSecretRef field | 8d | 7d | 8d |
dco-signoff: yes
size/M
|
contributor-last recv recv-q reviewed-with-comment
|
||||
| 2212 | docs: explain installing cert-manager into a different namespace | 7wk | 7wk | 7wk |
dco-signoff: yes
size/S
|
recv recv-q similar unreviewed
|
||||
| 2211 | docs: clarify the webhook --enable-client-verification flag description | 7wk | 7wk | 7wk |
size/XS
dco-signoff: yes
|
recv recv-q unreviewed
|
||||
| 2188 | docs: rename tutorial 'Securing NGINX-ingress' to 'Securing ingress-nginx' | 2mo | 2mo | 2mo |
size/XS
dco-signoff: yes
|
recv recv-q unreviewed
|
||||
| 2166 | netlify: document deploy-preview security for forked pull requests | 2mo | 2mo | 2mo |
dco-signoff: yes
size/S
|
commented member-last reviewed-with-comment
|
||||
| 2092 | docs: add infomaniak third party provider | 4mo | 2mo | 4mo |
size/XS
dco-signoff: yes
|
recv recv-q reviewed-with-comment
|
||||
| 2160 | docs: document the cert-manager.io/secret-template ingress annotation | 2mo | 2mo | 2mo |
size/XS
dco-signoff: yes
|
recv recv-q unreviewed
|
||||
| 2159 | docs: use stringData in the DigitalOcean DNS01 Secret example | 2mo | 2mo | 2mo |
dco-signoff: yes
size/S
|
recv recv-q unreviewed
|
||||
| 1602 | acme troubleshooting: how to fix errored challenges | 2y | 6mo | 2y |
size/XS
dco-signoff: yes
|
contributor-last recv recv-q reviewed-with-comment
|
||||
| 1587 | Custom Certificate Support for cert-manager Webhook Endpoint | 2y | 6mo | 2y |
dco-signoff: yes
size/S
|
recv recv-q unreviewed
|
||||
| 369 | fix(deps): update module cloud.google.com/go/storage to v1.67.0 | 3d | 2d | 3d |
dco-signoff: yes
size/XS
dependencies
ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 329 | Add script to ping PR authors and issue reporters after a release | 2mo | 2mo |
dco-signoff: yes
size/L
|
contributor-last recv-q unreviewed
|
|||||
| 903 | fix(istiodcert): name the DNS name that failed validation | 16d | 16d | 16d |
dco-signoff: yes
size/L
needs-ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 890 | Expand RELEASE.md with the full v0.17.0 release process | 3wk | 3wk |
dco-signoff: yes
size/L
|
contributor-last recv-q unreviewed
|
|||||
| 860 | feat(chart): expose automountServiceAccountToken in the istio-csr chart | 2mo | 2mo | 2mo |
dco-signoff: yes
size/S
needs-ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 852 | Replace Istio log package with structured logr in auth.go | 2mo | 2mo | 2mo |
dco-signoff: yes
size/XS
needs-ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 1021 | Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the go_modules group across 1 directory | 1d | 1d | 1d |
dco-signoff: yes
size/XS
needs-ok-to-test
dependencies
go
|
contributor-last recv recv-q unreviewed
|
||||
| 976 | feat: add startupapicheck Job to verify webhook readiness | 5wk | 2d | 5wk |
dco-signoff: yes
needs-ok-to-test
size/XL
|
recv recv-q similar unreviewed
|
||||
| 1020 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 43min | 1d |
dco-signoff: yes
size/XS
ok-to-test
dependencies
|
contributor-last recv recv-q similar unreviewed
|
||||
| 1097 | chore(deps): update makefile modules to 3802a00 | 1d | 1d | 1d |
dco-signoff: yes
size/M
ok-to-test
dependencies
skip-review
|
contributor-last recv recv-q unreviewed
|
||||
| 508 | Fix certificaterequest denial status | 17d | 17d | 17d |
kind/bug
dco-signoff: yes
size/M
needs-ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 188 | Remove SetCertificateRequestConditionError |
3
|
2y | 6mo | 6mo |
dco-signoff: yes
size/XXL
|
commented member-last new-commits similar
|
|||
| 753 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 41min | 1d |
dco-signoff: yes
size/XS
ok-to-test
dependencies
|
contributor-last recv recv-q similar unreviewed
|
||||
| 700 | feat(chart): expose automountServiceAccountToken in the csi-driver chart | 2mo | 2mo | 2mo |
dco-signoff: yes
size/S
needs-ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 672 | feat(chart): make pod and sidecar securityContext configurable | 2mo | 2mo | 2mo |
dco-signoff: yes
size/L
needs-ok-to-test
|
commented recv unreviewed
|
||||
| 607 | fix(deps): update module github.com/go-jose/go-jose/v4 to v4.1.5 | 3d | 2d | 3d |
dco-signoff: yes
size/XS
ok-to-test
dependencies
|
contributor-last recv recv-q similar unreviewed
|
||||
| 612 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 46min | 1d |
dco-signoff: yes
size/XS
ok-to-test
dependencies
|
contributor-last recv recv-q similar unreviewed
|
||||
| 594 | fix(driver): return an error instead of panicking on a non-PEM issued chain | 16d | 2d | 16d |
dco-signoff: yes
size/L
needs-ok-to-test
|
contributor-last recv recv-q reviewed-with-comment similar
|
||||
| 564 | feat(chart): expose automountServiceAccountToken in the csi-driver-spiffe chart | 2mo | 2mo | 2mo |
dco-signoff: yes
size/S
needs-ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 538 | feat(chart): make pod and sidecar securityContext configurable | 2mo | 2mo | 2mo |
dco-signoff: yes
size/L
ok-to-test
|
commented new-commits recv
|
||||
| 148 | limit-namespaces for namespace-scope deployments |
|
2y | 5mo | 2y |
dco-signoff: no
size/S
needs-ok-to-test
|
contributor-last recv recv-q unreviewed
|
|||
| 303 | feat: add support for setting private key encoding | 9mo | 8mo | 9mo |
dco-signoff: yes
size/L
needs-ok-to-test
|
recv recv-q reviewed-with-comment
|
||||
| 223 | NodePublishSecretRef | 3mo | 3mo | 3mo |
dco-signoff: no
size/L
needs-ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 211 | Fix: concurrent NodePublishVolume calls could mount volume without certificates | 4mo | 4mo | 4mo |
dco-signoff: yes
size/L
needs-ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 71 | Refactor filesystem.go and adapt tests to use a real file system | 2y | 1y | 1y |
dco-signoff: yes
size/L
|
commented member-last reviewed-with-comment
|
||||
| 215 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 41min | 1d |
dco-signoff: yes
size/XS
dependencies
ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 587 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 45min | 1d |
dco-signoff: yes
size/S
dependencies
ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 90 | chore(deps): update terraform google to v8 | 12d | 1d | 12d |
dco-signoff: yes
size/L
dependencies
ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 88 | chore(deps): update terraform google to v7.46.1 | 2mo | 1d | 2mo |
dco-signoff: yes
size/L
dependencies
ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 1236 | Update k8s-infra-prow images as needed | 2d | 1d | 2d |
dco-signoff: yes
size/M
|
contributor-last recv recv-q unreviewed
|
||||
| 739 | chore(deps): update renovate/renovate docker tag to v44.65.5 | 1d | 42min | 1d |
dco-signoff: yes
size/XS
dependencies
ok-to-test
|
contributor-last recv recv-q unreviewed
|
||||
| 723 | feat: add make target to upload SBOMs to GitHub releases | 10d | 2d | 10d |
dco-signoff: yes
size/S
|
recv recv-q reviewed-with-comment
|
||||
| 740 | chore(deps): update module github.com/goreleaser/goreleaser/v2 to v2.18.1 | 1d | 1d | 1d |
dco-signoff: yes
size/XS
dependencies
ok-to-test
|
contributor-last recv recv-q similar unreviewed
|
||||
| 688 | oci-build: add oci-security-scan target and scheduled workflow | 5wk | 3wk | 3wk |
dco-signoff: yes
size/L
|
commented member-last reviewed-with-comment
|
||||
| 655 | Fix 'make verify' command | 2mo | 2mo | 2mo |
dco-signoff: yes
size/XS
|
commented member-last reviewed-with-comment
|
||||
| 55 | feat: add test module | 2y | 2y | 2y |
dco-signoff: yes
size/M
|
commented contributor-last recv reviewed-with-comment
|
||||
| 69 | Add auditing tool for confirming who has access to the cert-manager org | 5mo | 5mo |
dco-signoff: yes
size/XL
|
contributor-last recv-q unreviewed
|
|||||
| 64 | Add imagePullSecrets to template | 2y | 3wk | 2y |
size/XS
dco-signoff: yes
needs-ok-to-test
|
contributor-last new-commits recv recv-q
|
||||
| 147 | chore(deps): update module google.golang.org/grpc to v1.83.2 [security] | 1d | 40min | 1d |
size/XS
dco-signoff: yes
ok-to-test
dependencies
|
contributor-last recv recv-q similar unreviewed
|
||||
| 1 | Manage the cert-manager GitHub organisation from this repo | 2y | 2y | 2y |
dco-signoff: yes
size/XXL
|
commented member-last unreviewed
|
||||
| 4 | Add support for custom license templates | 3y | 1y |
dco-signoff: yes
size/S
|
contributor-last recv-q unreviewed
|
|||||
| 13 | Various QA fixes | 6mo | 6mo | 6mo |
dco-signoff: yes
size/L
needs-ok-to-test
|
commented new-commits recv
|
||||
| 141 | re-adding required clusterrole permission | 2y | 2y | 2y |
size/XS
|
recv unreviewed
|
||||
| 553 | feat(chart): expose automountServiceAccountToken in the google-cas-issuer chart | 2mo | 2mo | 2mo |
size/S
dco-signoff: yes
|
contributor-last recv recv-q similar unreviewed
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 9275 | e2e flake: kind API server drops mid-run, failing hundreds of specs with EOF / connection reset | 5d | 5d | ||||||||
| 7699 | Adding Helm Unittest to all certmanager projects | 1y | 4mo | 4mo |
priority/backlog
|
assigned assignee-updated commented member-last send
|
|||||
| 6179 | CRDs shouldn't be templated in Helm |
5
2
32
|
3y | 2mo | 1y |
priority/backlog
lifecycle/rotten
|
commented recv-q send
|
||||
| 1194 |
Confusing paragraph - cert-manager integration.
|
3y | 5mo | 3y |
documentation
priority/important-longterm
|
commented contributor-last pr-merged send
|
|||||
| 1101 | Feature request for updating documentation. | 3y | 2y | 2y |
priority/backlog
|
commented member-last send
|
|||||
| 1262 | v1.9 to v1.10 upgrade instructions does not mention container name change | 3y | 2y | 2y |
priority/backlog
|
assigned assignee-updated commented member-last send
|
|||||
| 320 |
Document how to install cert-manager using gitops and known issues with particular gitops implementations
|
5
|
6y | 2y | 6y |
documentation
help wanted
priority/backlog
|
commented pr-merged recv-q
|
||||
| 2 | Set up periodic job to publish an experimental release build |
|
6y | 5y |
priority/backlog
|
assigned contributor-last
|
|||||
| 297 | Allow all resources to be namespaced |
6
|
2y | 2mo | 11mo |
lifecycle/rotten
priority/backlog
|
commented send
|
||||
| 45 | Unable to mount and read only file error |
5
|
5y | 2y | 2y |
priority/awaiting-more-evidence
|
commented send
|
||||
| 132 | Investigate test timeouts | 2y | 2y |
priority/backlog
|
|||||||
| 33 | Create e2e test to validate CertificateRequest garbage collection | 4y | 2y | 2y |
priority/backlog
|
assigned commented member-last send
|
|||||
| 81 | Configuring Peribolos for Github org management | 8y | 2y | 2y |
priority/backlog
|
commented member-last send
|
|||||
| 728 | kube-api-linter module: ship a shared default KAL config | 6d | 6d | ||||||||
| 3 | Migrating all cert-manager projects to "Makefile modules" | 2y | 9mo | 1y |
priority/backlog
|
commented member-last
|
|||||
| 43 | Allow non-Venafi employee maintainers full release capabilities |
3
|
2y | 9mo | 9mo |
priority/backlog
|
assigned assignee-updated commented member-last
|
||||
| 27 |
failed with: OpenAPI spec does not exist
|
2
6
|
5y | 2y | 2y |
priority/critical-urgent
|
commented pr-closed pr-unreviewed send
|
||||
| 206 previously listed items omitted | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 9296 | ingress-shim: certNeedsUpdate ignores ipAddresses, so IP SAN changes never reach existing Certificates | 2d | 2d |
kind/bug
|
|||||||
| 9295 | ingress-shim: alt-names and ip-sans annotations re-introduce duplicate SANs after #8978 | 2d | 2d |
kind/bug
|
|||||||
| 9280 |
HTTP-01 self-check custom nameservers do not fail over when one server does not respond
|
4d | 3d |
kind/bug
area/acme
|
pr-merged recv-q
|
||||||
| 9266 |
Enable the race detector in CI: go test -race currently fails in 7 packages
|
6d | 5d |
kind/cleanup
area/testing
|
contributor-last pr-merged
|
||||||
| 9298 | Webhook accepts duplicate dnsNames and ipAddresses, which fail ACME issuance with an opaque badCSR error | 2d | 2d |
kind/bug
|
|||||||
| 1098 | Feature Request: Opt-in mutating webhook to inject trust bundles into Pods via annotations | 16h | 16h | 16h |
kind/feature
|
recv
|
|||||
| 266 previously listed items omitted | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 1098 | Feature Request: Opt-in mutating webhook to inject trust bundles into Pods via annotations | 16h | 16h | 16h |
kind/feature
|
recv
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 8121 | Support for Creating CertificateRequest from Kubernetes Secret | 11mo | 5wk | 11mo |
kind/feature
triage/needs-information
lifecycle/rotten
|
contributor-last recv recv-q similar
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 8716 | Feature Request: Add a CMPv2 issuer for certificate enrollment and renewal (RFC 4210) | 4mo | 5d | 4mo |
kind/feature
|
commented recv recv-q
|
||||
| 8058 | Cert-manager fails to import ECDSA private keys generated by openssl | 1y | 5d | 1y |
kind/bug
priority/important-longterm
|
pr-changes-requested pr-reviewed-with-comment recv recv-q
|