Issues that may be waiting for our response NOTE: for this to work properly, GitHub token must have read access to read organization members
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 9034 | helm chart: add network policy for `startupapicheck` job | 2d | 2d | 2d |
kind/feature
|
recv
|
||||
| 9029 | respect owner references | 3d | 3d | 3d |
kind/feature
|
pr-unreviewed recv
|
||||
| 9026 | Publish webhook ACME API in a distinct go module | 4d | 4d | 4d |
kind/feature
|
recv
|
||||
| 8763 | Minimize cert-manager and trust-manager Controller Privileges | 2mo | 2mo | 2mo |
kind/feature
|
recv
|
||||
| 8716 | Feature Request: Add a CMPv2 issuer for certificate enrollment and renewal (RFC 4210) | 3mo | 10d | 3mo |
kind/feature
|
commented recv recv-q
|
||||
| 8679 | Allow managing SSH-CA | 3mo | 3wk | 3mo |
kind/feature
|
recv
|
||||
| 8530 | Allow usage of the new DNS-PERSIST-01 challange for ACME |
21
|
4mo | 4mo | 4mo |
kind/feature
|
recv similar
|
|||
| 8522 | Support pulling additional fields from secret when using external account binding |
2
|
5mo | 5mo | 5mo |
kind/feature
|
recv recv-q
|
|||
| 8479 | Subject Key Identifier (SKI) missing on issued certificates by self-signed CA | 5mo | 5mo | 5mo |
kind/feature
|
pr-new-commits recv
|
||||
| 8458 | Vault approle configuration |
|
5mo | 5mo | 5mo |
kind/feature
|
recv
|
|||
| 8441 | Add instrumentation to Vault issuer Sign() operation | 5mo | 5mo | 5mo |
good first issue
kind/feature
priority/backlog
|
assigned assignee-updated commented contributor-last pr-unreviewed recv recv-q
|
||||
| 8402 | ZeroSSL issues all certs with the same hour (yyyy-mm-ddT15:59:59Z) | 6mo | 3mo | 3mo |
kind/feature
priority/important-longterm
|
commented recv
|
||||
| 8372 | HTTP-01 challenge: support stateless http-01 challenge | 6mo | 19d | 6mo |
kind/feature
lifecycle/stale
|
contributor-last recv
|
||||
| 8235 | Cert-manager support for Issuer-managed keys | 8mo | 6wk | 8mo |
kind/feature
lifecycle/stale
|
commented recv
|
||||
| 8209 | Add revocation at certificate deletion |
3
|
8mo | 6wk | 8mo |
kind/feature
|
recv similar
|
|||
| 8121 | Support for Creating CertificateRequest from Kubernetes Secret | 9mo | 2mo | 9mo |
kind/feature
lifecycle/stale
triage/needs-information
|
contributor-last recv recv-q similar
|
||||
| 7914 | Output tls.crt in CA cert to another secret | 11mo | 2mo | 11mo |
kind/feature
lifecycle/rotten
|
contributor-last recv
|
||||
| 7868 | Metrics for webhook certificate |
3
|
1y | 2mo | 1y |
kind/feature
lifecycle/stale
|
contributor-last recv
|
|||
| 7834 | Provide race condition mitigation support | 1y | 16d | 1y |
kind/feature
lifecycle/stale
|
contributor-last recv
|
||||
| 8373 | DNS-PERSIST-01 challenge support (planned for late Q1 2026) |
7
3
3
184
|
6mo | 2mo | 6mo |
kind/feature
|
recv recv-q similar
|
|||
| 7788 | Be able to default `acme.cert-manager.io/http01-edit-in-place: "true"` behavior in deployment/chart values |
5
|
1y | 7wk | 7mo |
kind/feature
|
commented recv
|
|||
| 7766 | Certificate: Let me specify the concatenation order for CombinedPEM output format |
|
1y | 4mo | 1y |
kind/feature
|
recv recv-q
|
|||
| 7751 | Custom key usage extensions | 1y | 4mo | 5mo |
kind/feature
|
commented recv recv-q
|
||||
| 7747 | [suggestion] Add Kustomize install documentation |
5
6
|
1y | 5wk | 1y |
kind/feature
lifecycle/rotten
|
commented contributor-last recv recv-q
|
|||
| 8835 | Make signatureAlgorithm configurable | 7wk | 6d | 7wk |
kind/feature
|
recv recv-q
|
||||
| 7536 | Digicert ACME order is failing due to invalid validity_years |
2
|
1y | 6d | 7mo |
good first issue
lifecycle/frozen
kind/feature
priority/backlog
area/acme
|
commented recv recv-q
|
|||
| 7422 | Please provide standalone helm chart for CRDs |
20
|
2y | 6wk | 2y |
kind/feature
lifecycle/rotten
|
contributor-last recv
|
|||
| 7311 | helm schema validation should validate `featureGates` |
|
2y | 6mo | 1y |
lifecycle/frozen
kind/feature
priority/backlog
|
commented contributor-last recv
|
|||
| 6662 | support overriding of ttl in cloudflare |
2
|
2y | 5wk | 2y |
kind/feature
priority/backlog
|
commented recv
|
|||
| 6472 | Create TLSA records automatically |
15
|
2y | 6d | 2y |
kind/feature
priority/backlog
|
contributor-last recv
|
|||
| 7561 | Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued | 1y | 2mo | 8mo |
kind/feature
|
commented recv recv-q
|
||||
| 5540 | Changelog annotations to chart |
|
3y | 5mo | 3y |
kind/feature
priority/backlog
|
recv
|
|||
| 6010 |
Support the ACME Renewal Information (ARI) extension
|
4
4
21
|
3y | 4d | 1y |
lifecycle/frozen
kind/feature
|
commented contributor-last pr-merged recv recv-q similar
|
|||
| 3706 | renewal-hooks |
4
3
22
|
5y | 6wk | 6wk |
kind/feature
priority/important-longterm
lifecycle/rotten
|
commented recv recv-q
|
|||
| 8895 | [HELM]: add flag to skip deployment of webhook | 4wk | 4wk | 4wk |
kind/feature
|
pr-unreviewed recv
|
||||
| 7514 | Replace some of the webhook functionality with `ValidatingAdmissionPolicy` & CEL |
|
2y | 5mo | 11mo |
kind/feature
priority/important-longterm
|
commented recv
|
|||
| 886 |
Allow creating `ClusterRole` aggregations
|
5mo | 5mo | 5mo |
kind/feature
|
pr-merged recv
|
||||
| 742 | Add option to disable webhook in Helm chart | 10mo | 6wk | 10mo |
kind/feature
|
commented recv
|
||||
| 306 | [FEATURE]Enable setting private key encoding via annotation | 7mo | 7mo | 7mo |
kind/feature
|
pr-reviewed-with-comment recv
|