Once every quarter, look for stale issues, reprioritize, and de-duplicate.
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 8530 | Allow usage of the new DNS-PERSIST-01 challange for ACME |
27
|
6mo | 19d | 6mo |
kind/feature
lifecycle/stale
|
contributor-last recv similar
|
|||
| 8522 | Support pulling additional fields from secret when using external account binding |
2
|
6mo | 3wk | 6mo |
kind/feature
lifecycle/stale
|
contributor-last recv recv-q
|
|||
| 8458 | Vault approle configuration |
2
|
7mo | 5wk | 7mo |
kind/feature
lifecycle/stale
|
contributor-last recv
|
|||
| 8450 | Introducing DelayedInformers for CRD check | 7mo | 5wk | 7mo |
kind/feature
lifecycle/stale
|
assigned assignee-updated commented contributor-last send
|
||||
| 8479 | Subject Key Identifier (SKI) missing on issued certificates by self-signed CA | 7mo | 5wk | 7mo |
kind/feature
lifecycle/stale
|
contributor-last pr-new-commits recv
|
||||
| 8416 | Make Venafi client timeout configurable for slower servers | 7mo | 5wk | 7mo |
kind/feature
lifecycle/stale
|
commented contributor-last send
|
||||
| 8372 | HTTP-01 challenge: support stateless http-01 challenge | 8mo | 2mo | 8mo |
kind/feature
lifecycle/stale
|
contributor-last recv
|
||||
| 8364 | Replace Hetzner DNS01 Webhook | 8mo | 2mo | 8mo |
lifecycle/stale
|
commented contributor-last send
|
||||
| 8340 | Top-level: CA Issuer rotation problem | 9mo | 2mo |
lifecycle/stale
cybr
|
contributor-last
|
|||||
| 8319 | Improve cert-manager's event handler to allow us to selectively skip some reconciliations | 9mo | 2mo |
lifecycle/stale
cybr
|
contributor-last
|
|||||
| 8296 | HTTP-01 challenge stuck in pending with status code 400 | 9mo | 2mo | 8mo |
triage/support
lifecycle/stale
|
commented contributor-last send
|
||||
| 8183 | Add helm diff output to cert-manager PRs | 10mo | 3d | 3wk |
lifecycle/stale
|
assigned assignee-updated commented send
|
||||
| 8102 | cert-manager-startupapicheck erroring while installation |
4
|
11mo | 3mo | 9mo |
kind/bug
lifecycle/stale
triage/needs-information
|
commented contributor-last send
|
|||
| 8094 | HTTP-01 challenge returns 502 with App Gateway (works with NGINX ingress controller) | 11mo | 5wk | 11mo |
lifecycle/stale
|
contributor-last recv recv-q
|
||||
| 7834 | Provide race condition mitigation support | 1y | 2mo | 1y |
kind/feature
lifecycle/stale
|
contributor-last recv
|
||||
| 8235 | Cert-manager support for Issuer-managed keys | 10mo | 6wk | 10mo |
kind/feature
lifecycle/stale
|
commented recv recv-q
|
||||
| 8586 | Misconfiguration caused hammering of DigitalOcean API | 6mo | 4d | 6mo |
kind/bug
lifecycle/stale
|
contributor-last pr-unreviewed recv
|
||||
| 8441 | Add instrumentation to Vault issuer Sign() operation | 7mo | 4wk | 7mo |
good first issue
kind/feature
priority/backlog
lifecycle/stale
|
assigned assignee-updated commented contributor-last pr-unreviewed recv recv-q
|
||||
| 8504 | WIP: Enable KAL | 7mo | 6d |
release-note-none
do-not-merge/work-in-progress
size/M
lifecycle/stale
dco-signoff: yes
needs-kind
|
contributor-last recv-q unreviewed
|
|||||
| 8438 | POC: single cert-manager binary | 7mo | 6wk |
release-note-none
do-not-merge/work-in-progress
kind/feature
size/XXL
lifecycle/stale
dco-signoff: no
|
contributor-last draft recv-q unreviewed
|
|||||
| 8367 | feat(helm) add startupProbe and readinessProbe to cert-manager-controller | 8mo | 2mo | 8mo |
release-note-none
kind/feature
needs-ok-to-test
size/M
lifecycle/stale
dco-signoff: yes
area/deploy
|
commented contributor-last recv recv-q unreviewed
|
||||
| 8262 | Bugfix #7388 kid missing issue with Infisical ACME server or any other ACME that requires EAB |
|
9mo | 2mo | 9mo |
size/L
release-note
needs-ok-to-test
lifecycle/stale
area/acme
dco-signoff: yes
needs-kind
|
commented contributor-last recv unreviewed
|
|||
| 7886 | Improve array field characteristics in API | 1y | 3wk | 6mo |
size/L
release-note
area/api
do-not-merge/hold
kind/bug
kind/cleanup
lifecycle/stale
dco-signoff: yes
area/deploy
|
commented contributor-last new-commits
|
||||
| 848 | Request for cryptographic mechanisms used in cert-manager-trust-manager | 7mo | 7wk | 7mo |
lifecycle/stale
|
contributor-last recv
|
||||
| 886 |
Allow creating `ClusterRole` aggregations
|
6mo | 3wk | 6mo |
kind/feature
lifecycle/stale
|
contributor-last pr-merged recv
|
||||
| 560 | Support rotated certificate sources |
41
|
2y | 2mo | 1y |
lifecycle/stale
|
commented contributor-last pr-reviewed-with-comment recv recv-q similar
|
|||
| 837 | Ensuring trust-manager is ready to accept CRDs after install | 8mo | 1mo |
good first issue
lifecycle/stale
|
contributor-last pr-closed pr-unreviewed similar
|
|||||
| 395 | WIP: feat: inject bundle data into configmap | 2y | 6wk | 7mo |
dco-signoff: yes
size/L
do-not-merge/work-in-progress
lifecycle/stale
|
commented contributor-last unreviewed
|
||||
| 654 | Add design for trust source plugins |
|
1y | 7wk | 1y |
dco-signoff: yes
size/M
do-not-merge/work-in-progress
lifecycle/stale
|
commented contributor-last draft reviewed-with-comment send
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags |
| 7788 | Be able to default `acme.cert-manager.io/http01-edit-in-place: "true"` behavior in deployment/chart values |
5
|
1y | 3mo | 9mo |
kind/feature
|
commented recv
|
|||
| 7766 | Certificate: Let me specify the concatenation order for CombinedPEM output format |
|
1y | 6mo | 1y |
kind/feature
|
pr-new-commits recv recv-q
|
|||
| 7751 | Custom key usage extensions | 1y | 6mo | 7mo |
kind/feature
|
commented recv recv-q
|
||||
| 7561 | Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued | 2y | 4mo | 10mo |
kind/feature
|
commented recv recv-q
|
||||
| 7514 | Replace some of the webhook functionality with `ValidatingAdmissionPolicy` & CEL |
|
2y | 6mo | 1y |
kind/feature
priority/important-longterm
|
commented recv
|
|||
| 7311 | helm schema validation should validate `featureGates` |
|
2y | 8mo | 1y |
lifecycle/frozen
kind/feature
priority/backlog
|
commented contributor-last recv
|
|||
| 5540 | Changelog annotations to chart |
|
3y | 7mo | 3y |
kind/feature
priority/backlog
|
recv
|
|||
| 3706 | renewal-hooks |
4
3
23
|
5y | 3mo | 3mo |
kind/feature
priority/important-longterm
lifecycle/rotten
|
commented pr-reviewed-with-comment recv recv-q
|
|||
| 8402 | ZeroSSL issues all certs with the same hour (yyyy-mm-ddT15:59:59Z) | 7mo | 5mo | 5mo |
kind/feature
priority/important-longterm
|
commented recv
|
||||
| 8209 | Add revocation at certificate deletion |
3
|
10mo | 3mo | 10mo |
kind/feature
|
recv similar
|
|||
| 8763 | Minimize cert-manager and trust-manager Controller Privileges | 4mo | 4mo | 4mo |
kind/feature
|
recv
|
||||
| 8373 | DNS-PERSIST-01 challenge support (planned for late Q1 2026) |
8
3
3
205
|
8mo | 4mo | 8mo |
kind/feature
|
recv recv-q similar
|
|||
| 742 |
Add option to disable webhook in Helm chart
|
1y | 3mo | 1y |
kind/feature
|
commented pr-closed recv
|
||||
| 306 | [FEATURE]Enable setting private key encoding via annotation | 8mo | 8mo | 8mo |
kind/feature
|
pr-reviewed-with-comment recv
|
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 8767 |
Add support for CRLDistributionPoints on Certificate resources
|
4mo | 4mo | 4mo |
kind/feature
|
commented member-last pr-closed send similar
|
|||||
| 6470 | ingress-shim: allow to impersonate ingress-creator instead of using cert-manager serviceaccount |
2
|
2y | 2y | 2y |
lifecycle/frozen
kind/feature
priority/backlog
|
commented contributor-last send
|
||||
| 3381 | Setup separate package for cert-manager API |
6
|
5y | 2y | 2y |
lifecycle/frozen
kind/feature
priority/important-soon
|
assigned assignee-updated commented member-last send
|
||||
| 2820 |
Add ability to set `pathlen:0` for CA certs in `X509v3 Basic Constraints`
|
|
6y | 5mo | 5mo |
area/api
good first issue
kind/feature
priority/important-longterm
|
assigned assignee-updated commented pr-closed pr-merged recv-q send
|
||||
| 2538 | cert-manager does not use ingress.class from Ingress annotated with cert-manager.io/cluster-issuer |
74
|
6y | 2y | 2y |
area/api
help wanted
lifecycle/frozen
kind/feature
priority/backlog
|
commented send
|
||||
| 3521 | Integration with ExternalDNS |
4
55
|
5y | 1y | 2y |
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
|
commented recv-q
|
||||
| 7890 |
Cluster issuer for HTTP-01 gatewayHTTPRoute should not require a gateway parentRef
|
28
|
1y | 5mo | 5mo |
kind/feature
priority/awaiting-more-evidence
area/acme/http01
|
assigned assignee-updated commented pr-merged send
|
||||
| 2178 | Handling 'unregistering' certificates from Venafi TPP |
22
|
7y | 2y | 2y |
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
|
commented member-last send
|
||||
| 7473 |
Create certificate based on HTTPRoute configuration
|
65
7
102
|
2y | 5mo | 5mo |
kind/feature
|
assigned assignee-updated commented pr-closed pr-merged send
|
||||
| 2478 | Allow CA issuer secret rotation |
2
71
|
6y | 3mo | 3mo |
kind/feature
priority/important-longterm
area/ca
|
commented member-last send
|
||||
| 2525 |
Better support multi-namespace & single-namespace deployments
|
30
|
6y | 1y | 2y |
lifecycle/frozen
kind/feature
priority/important-longterm
area/deploy
|
commented contributor-last pr-closed send
|
||||
| 2930 | Mirror to gcr.io or dockerhub |
2
29
|
6y | 3mo | 2y |
lifecycle/frozen
kind/feature
priority/important-soon
area/deploy
|
assigned assignee-updated commented recv-q send
|
||||
| 6051 |
Detecting Gateway hostnames based on attached HTTPRoutes
|
7
35
|
3y | 1y | 1y |
lifecycle/frozen
kind/feature
priority/important-longterm
|
commented pr-merged send
|
||||
| 155 | Add 'unreleased version' & 'old version' warning banner to non-latest versions of docs | 6y | 6y | 6y |
kind/feature
priority/backlog
|
commented contributor-last
|
|||||
| 588 | Add ability to monitor validity period for CAs in bundle |
5
|
1y | 6mo | 7mo |
kind/feature
help wanted
|
assigned assignee-updated commented pr-new-commits send
|
||||
| 154 | Publish SBOMs | 2y | 2y | 2y |
kind/feature
good first issue
|
commented member-last pr-reviewed-with-comment send
|
|||||
| 14 previously listed items omitted: #8763 #7788 #7751 #7561 #7514 #7766 #7311 #8209 #8402 #5540 #8373 #3706 #742 #306 | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 8493 | cloudflare DNS01 - Client.Timeout exceeded while awaiting headers | 4
11
|
7mo | 5mo | 6mo |
good first issue
help wanted
kind/bug
|
assigned assignee-updated commented pr-unreviewed recv-q send
|
||||
| 7846 | ClusterIssuer.Status.Acme.URI disappeared |
5
|
1y | 2mo | 1y |
good first issue
kind/bug
priority/awaiting-more-evidence
area/acme
triage/needs-information
|
assigned assignee-updated commented send
|
||||
| 7476 |
[Helm Chart] - Wrong handling of image registry and repository
|
4
|
2y | 5mo | 9mo |
kind/bug
|
commented pr-closed send
|
||||
| 6969 | Should upgrade status managed fields from CSA to SSA when ServerSideApply feature gate enabled | 2y | 2y | 2y |
lifecycle/frozen
kind/bug
priority/important-longterm
|
commented contributor-last send
|
|||||
| 6716 | leader election namespace should default to `.Release.Namespace`, not `kube-system` |
3
45
|
2y | 6mo | 2y |
lifecycle/frozen
kind/bug
triage/not-reproducible
|
commented pr-closed pr-unreviewed recv-q send
|
||||
| 5959 | `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries |
23
|
3y | 9mo | 2y |
lifecycle/frozen
kind/bug
priority/important-longterm
|
commented contributor-last recv-q send
|
||||
| 5867 |
Controller can't handle hitting request rate limits of zerossl ACME API
|
7
12
31
|
3y | 1y | 2y |
lifecycle/frozen
kind/bug
priority/important-soon
|
commented pr-closed pr-merged recv-q send
|
||||
| 6230 |
DigitalOcean: cert-manager DDoSes DNS-01 solver - infinite rate limiting
|
6
|
3y | 9mo | 10mo |
lifecycle/frozen
kind/bug
priority/critical-urgent
area/acme/dns01
|
commented member-last pr-closed pr-merged send
|
||||
| 5864 |
Certmgr allows creating certificates expiring after ca expiration.
|
4
33
|
3y | 10mo | 1y |
lifecycle/frozen
kind/bug
cybr
|
commented pr-closed recv-q send
|
||||
| 12 previously listed items omitted: #8960 #8876 #8847 #8745 #8572 #8102 #7862 #7522 #7486 #6741 #5917 #4685 | |||||||||||
| ID | Au | Desc | As | Rea | Cr | Up | Re | Cmntrs | Labels | Tags | |
| 8641 | ContribFest KubeCon EU 2026 - Amsterdam (March 24, 2026) | 5mo | 5mo | 5mo |
kind/documentation
|
commented member-last
|
|||||
| 8251 |
Top-level ticket: ListenerSet
|
8
|
9mo | 4mo | 6mo |
cybr
|
commented pr-merged recv-q send
|
||||
| 6709 | 1.14 Release Review |
3
|
2y | 2y | 2y |
lifecycle/frozen
priority/important-soon
|
commented contributor-last send
|
||||
| 5298 | Complete the Migration Away From Jetstack Names | 4y | 2y | 2y |
lifecycle/frozen
kind/cleanup
priority/important-soon
|
commented member-last send
|
|||||
| 4191 | Setting default values for Pod's "resources"? |
7
|
5y | 2y | 2y |
lifecycle/frozen
priority/important-longterm
|
commented contributor-last recv-q send
|
||||
| 7895 | if certificate is already expired, it shown like a True |
2
|
1y | 4mo | 4mo |
help wanted
priority/important-soon
|
collaborator-last commented pr-closed pr-reviewed-with-comment pr-unreviewed send
|
||||
| 7699 | Adding Helm Unittest to all certmanager projects | 1y | 4mo | 4mo |
priority/backlog
|
assigned assignee-updated commented member-last send
|
|||||
| 7822 |
Tracking: Kubernetes Gateway API follow up tasks
|
5
|
1y | 3mo | 9mo |
lifecycle/frozen
|
commented contributor-last pr-merged send
|
||||
| 1546 | Self upgrade PRs don't run checks |
|
2y | 10mo | 2y |
cybr
|
commented member-last
|
||||
| 1194 |
Confusing paragraph - cert-manager integration.
|
3y | 5mo | 3y |
documentation
priority/important-longterm
|
commented contributor-last pr-merged send
|
|||||
| 1186 | Document that/why we don't use Helm's CRD installation mechanism | 3y | 2y | 2y |
good first issue
priority/important-longterm
kind/documentation
|
assigned assignee-updated commented member-last send
|
|||||
| 1101 | Feature request for updating documentation. | 3y | 2y | 2y |
priority/backlog
|
commented member-last send
|
|||||
| 414 |
Explain cert-manager repo structure
|
2
|
5y | 5y | 5y |
priority/backlog
kind/documentation
|
assigned assignee-updated commented member-last pr-closed pr-merged send
|
||||
| 401 | Bring tutorials up to date | 5y | 3y | 3y |
priority/important-longterm
|
commented member-last send
|
|||||
| 320 |
Document how to install cert-manager using gitops and known issues with particular gitops implementations
|
5
|
6y | 2y | 6y |
documentation
help wanted
priority/backlog
|
commented pr-merged recv-q
|
||||
| 223 | Document wildcard certificate tutorial | 6y | 6y | 6y |
priority/important-longterm
kind/documentation
|
commented contributor-last send
|
|||||
| 195 | Document keystores | 6y | 3y | 6y |
priority/important-soon
kind/documentation
|
commented contributor-last send
|
|||||
| 174 | Add documentation for CRD conversion webhook ca injection | 6y | 6y | 6y |
help wanted
priority/important-soon
kind/documentation
|
commented member-last send
|
|||||
| 1262 | v1.9 to v1.10 upgrade instructions does not mention container name change | 3y | 2y | 2y |
priority/backlog
|
assigned assignee-updated commented member-last send
|
|||||
| 234 |
Backup and Restore Resources
|
3
|
6y | 5y | 5y |
priority/backlog
kind/documentation
|
commented member-last pr-merged send
|
||||
| 153 | It is possible to have several CAs within the same cluster. |
3
|
4y | 2y | 3y |
commented send
|
|||||
| 803 | Request to build images for main |
2
|
7mo | 5mo | 5mo |
commented member-last send
|
|||||
| 394 | Limit number of SANs by policy |
|
2y | 2y | 2y |
commented member-last send
|
|||||
| 288 | Feature: Take control of approval for the whole cluster |
2
|
2y | 2y | 2y |
commented member-last
|
|||||
| 203 | Improve CRD fields for specifying key requirements |
3
|
3y | 2y | 2y |
commented member-last send
|
|||||
| 169 | Webhook Custom CA | 3y | 1y | 1y |
help wanted
|
commented contributor-last recv-q send
|
|||||
| 216 | Simplify configuration by creating RBAC by default |
2
|
3y | 1y | 1y |
help wanted
|
commented contributor-last pr-merged pr-unreviewed recv-q send
|
||||
| 667 | Cannot create secret cert-manager-approver-policy-tls | 1y | 3mo | 4mo |
commented send
|
||||||
| 761 | Feat: Add a namespaced trust bundle CRD alongside the cluster-scoped Bundle | 11mo | 3mo | 3mo |
commented member-last send
|
||||||
| 245 |
Split Bundle controller into multiple controllers
|
|
2y | 2y | 2y |
lifecycle/frozen
|
commented member-last pr-merged send
|
||||
| 243 |
More flexible and better organized target specification in API
|
5
|
2y | 8mo | 10mo |
lifecycle/frozen
|
commented pr-merged
|
||||
| 841 | Does trust-manager require cluster level permissions to read secrets? |
|
7mo | 5mo | 5mo |
commented member-last send
|
|||||
| 205 | Allow to select multiple "trust" namespaces |
50
|
2y | 4mo | 1y |
commented send
|
|||||
| 131 | Feature: per namespace trust bundle |
9
|
3y | 11mo | 1y |
lifecycle/frozen
|
commented send
|
||||
| 99 |
Allow removing Bundles whilst keeping the synced CA certs
|
5
|
3y | 1y | 1y |
lifecycle/frozen
|
commented member-last pr-unreviewed
|
||||
| 39 |
Don't sync targets to all namespaces by default
|
8
|
4y | 1y | 1y |
lifecycle/frozen
|
commented member-last open-milestone pr-merged send
|
||||
| 58 | Support injection pem into an existing configmap |
8
|
4y | 1y | 1y |
priority/important-longterm
lifecycle/frozen
|
assigned assignee-updated commented member-last pr-closed pr-merged pr-unreviewed send
|
||||
| 60 | overriding trusted namespace |
10
18
|
3y | 6mo | 1y |
commented recv-q send
|
|||||
| 63 |
nit: Rename "Bundle" to "ClusterBundle"
|
19
|
3y | 1y | 1y |
lifecycle/frozen
|
commented member-last open-milestone pr-merged send
|
||||
| 279 | Persisting identifiers for retry calls to Sign() | 1y | 7mo | 7mo |
commented member-last send
|
||||||
| 204 | clarify SetCAOnCertificateRequest deprecation status | 2y | 1y | 1y |
commented member-last send
|
||||||
| 231 | ### Question about Configuring Retries in cert-manager | 1y | 7mo | 7mo |
commented member-last send
|
||||||
| 171 | E2E Test Cleanup | 2y | 3mo | 2y |
good first issue
|
commented recv-q
|
|||||
| 45 | Unable to mount and read only file error |
5
|
5y | 2y | 2y |
priority/awaiting-more-evidence
|
commented send
|
||||
| 38 | Route with cert-manager annotations is not created |
4
|
3y | 1y | 2y |
commented send
|
|||||
| 70 | OLM deployment with ArgoCD is OutOfSync |
|
4y | 4y | 4y |
commented send
|
|||||
| 33 | Create e2e test to validate CertificateRequest garbage collection | 4y | 2y | 2y |
priority/backlog
|
assigned commented member-last send
|
|||||
| 234 |
Proposal: distinguish gate-pending from issuance-error in the renewal backoff loop
|
3mo | 3mo | 3mo |
commented member-last pr-merged send
|
||||||
| 56 | Struggling to get controller running in local KIND cluster |
|
2y | 1y | 1y |
commented member-last send
|
|||||
| 59 | Process regarding worrying emails sent to the maintainers mailing list |
|
1y | 1y | 1y |
commented member-last
|
|||||
| 81 | Configuring Peribolos for Github org management | 8y | 2y | 2y |
priority/backlog
|
commented member-last send
|
|||||
| 451 | Re-enable testing with specific kubernetes versions in subprojects | 10mo | 10mo | 10mo |
cybr
|
commented member-last send
|
|||||
| 3 | Migrating all cert-manager projects to "Makefile modules" | 2y | 9mo | 1y |
priority/backlog
|
commented member-last
|
|||||
| 63 | CNCF-paid GitHub Actions runners | 10mo | 9mo | 9mo |
commented member-last
|
||||||
| 64 | Open Standup: Updating an event didn't send new invitations to already registered people |
|
9mo | 9mo | 9mo |
commented member-last send
|
|||||
| 60 | Lazy vote: Zoom for standup meetings to be able to add the standups to the LFX calendar |
|
10mo | 9mo | 9mo |
commented member-last
|
|||||
| 43 | Allow non-Venafi employee maintainers full release capabilities |
3
|
2y | 9mo | 9mo |
priority/backlog
|
assigned assignee-updated commented member-last
|
||||
| 35 |
Post-Graduation Suggestion Tracker
|
|
2y | 2y | 2y |
commented member-last pr-merged
|
|||||
| 27 |
failed with: OpenAPI spec does not exist
|
2
6
|
5y | 2y | 2y |
priority/critical-urgent
|
commented pr-closed pr-unreviewed send
|
||||
| 3 |
Make unit testing easier/make examples work
|
7y | 2y | 4y |
priority/important-longterm
|
commented member-last pr-closed send
|
|||||
| 487 |
Helm chart `image` named template conflicts with cert-manager 1.20.x
|
2
|
4mo | 4mo | 4mo |
commented pr-closed recv-q send
|
|||||
| 197 | Kubectl One-line Installation Support | 2y | 2y | 2y |
commented member-last send similar
|
||||||
| 79 previously listed items omitted | |||||||||||