Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3103 commits
Select commit Hold shift + click to select a range
76596cd
final rename
iossifbenbassat123 Oct 30, 2025
b6bb253
chore(deps): update github/codeql-action action to v4.31.2
octo-sts[bot] Oct 31, 2025
5f3790c
address test errors
iossifbenbassat123 Oct 31, 2025
fdcb1be
address test errors part 2
iossifbenbassat123 Oct 31, 2025
1b7aad6
address test errors part 3
iossifbenbassat123 Oct 31, 2025
92bc67e
address test errors part 4
iossifbenbassat123 Oct 31, 2025
b618a34
address test errors part 5
iossifbenbassat123 Oct 31, 2025
2006d0b
finish venafi removal and omit cyberark from certificate manager
iossifbenbassat123 Oct 31, 2025
71ee816
finish venafi removal part 2
iossifbenbassat123 Oct 31, 2025
366a671
fix failing test
iossifbenbassat123 Oct 31, 2025
1925034
Update README.md
iossifbenbassat123 Oct 31, 2025
3db822f
revert some of crd changes that relate to field names
iossifbenbassat123 Oct 31, 2025
8186d80
Merge remote-tracking branch 'fork/venafi-cyberark-context-consistenc…
iossifbenbassat123 Oct 31, 2025
750ccb2
revert some of crd changes that relate to field names part 2
iossifbenbassat123 Oct 31, 2025
5c34a01
use CyberArk Certificate Manager
iossifbenbassat123 Oct 31, 2025
0d81877
Merge pull request #8219 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Nov 1, 2025
b22c2f5
add logs for cases when acme server return us fatal error
Peac36 Oct 20, 2025
69b45d5
fix(deps): update module github.com/onsi/ginkgo/v2 to v2.27.2
octo-sts[bot] Nov 2, 2025
5116b46
Merge pull request #8223 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Nov 2, 2025
a9d521f
Deprecate GenericIssuer.GetObjectMeta
erikgb Nov 2, 2025
efc3e4d
Merge pull request #8199 from Peac36/fix/7267
cert-manager-prow[bot] Nov 3, 2025
767bc70
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Nov 4, 2025
0dbf5e7
fix linter issues
inteon Nov 3, 2025
552e2a4
fix(deps): update cloud go deps
octo-sts[bot] Nov 4, 2025
6eb6d40
fix(deps): update module sigs.k8s.io/controller-runtime to v0.22.4
octo-sts[bot] Nov 4, 2025
8f2779c
Centralize error message stabilization
Peac36 Oct 11, 2025
31bc9ae
Merge pull request #8225 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Nov 4, 2025
c2e1b56
Merge pull request #8221 from wallrj-cyberark/route53-error-chain-2
cert-manager-prow[bot] Nov 4, 2025
a190998
Merge pull request #8224 from erikgb/refactor-generic-issuer
cert-manager-prow[bot] Nov 4, 2025
9444aa7
Merge pull request #8214 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Nov 4, 2025
0704fef
Merge pull request #8222 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Nov 4, 2025
5204fba
Update pkg/controller/certificaterequests/venafi/venafi.go
iossifbenbassat123 Nov 5, 2025
53e6888
Update pkg/controller/certificaterequests/venafi/venafi.go
iossifbenbassat123 Nov 5, 2025
df52928
Update pkg/controller/certificatesigningrequests/venafi/venafi.go
iossifbenbassat123 Nov 5, 2025
2cb626e
Update pkg/controller/certificatesigningrequests/venafi/venafi.go
iossifbenbassat123 Nov 5, 2025
81771df
code review fixes
iossifbenbassat123 Nov 5, 2025
2406b82
test fixes
iossifbenbassat123 Nov 5, 2025
f9aa351
test fixes 2
iossifbenbassat123 Nov 5, 2025
f31c5a5
test fixes 4
iossifbenbassat123 Nov 5, 2025
1e42348
code review fixes
iossifbenbassat123 Nov 5, 2025
3f6f56e
revert comment above Venafi struct
iossifbenbassat123 Nov 5, 2025
e5b7e85
Manual self-upgrade to boostrap new GCI imports order
erikgb Nov 5, 2025
b047f5d
revert non-user facing changes
iossifbenbassat123 Nov 5, 2025
56c8ac5
revert changes to e2e tests
iossifbenbassat123 Nov 5, 2025
1c9d4c9
Merge pull request #8215 from iossifbenbassat123/venafi-cyberark-cont…
cert-manager-prow[bot] Nov 5, 2025
2039c4c
Merge pull request #8195 from StingRayZA/stingrayza/move-global-nodes…
cert-manager-prow[bot] Nov 5, 2025
e79a330
added azuredns refactor
hjoshi123 Nov 6, 2025
bb0b765
Merge pull request #8208 from hjoshi123/feat/azuredns-refactor
cert-manager-prow[bot] Nov 6, 2025
ae14cf6
Merge pull request #8231 from erikgb/gci-import-changes
cert-manager-prow[bot] Nov 6, 2025
34a24f9
Partially enable modernize linter
erikgb Nov 8, 2025
23d3567
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Nov 9, 2025
0e821af
Merge pull request #8237 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Nov 9, 2025
67db4c4
fix(deps): update golang.org/x deps
octo-sts[bot] Nov 9, 2025
e23ba2a
Merge pull request #8238 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Nov 9, 2025
4415452
fix(deps): update module github.com/go-openapi/jsonreference to v0.21.3
octo-sts[bot] Nov 10, 2025
deb4d86
fix(deps): update cloud go deps
octo-sts[bot] Nov 10, 2025
8780f3e
Merge pull request #8240 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Nov 10, 2025
a4fd4a7
Merge pull request #8230 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Nov 10, 2025
1b4529f
Merge pull request #8236 from erikgb/enable-modernize
cert-manager-prow[bot] Nov 10, 2025
ed1ac31
Add support for `acme.cert-manager.io/http01-ingress-ingressclassname…
lunarwhite Aug 31, 2025
7a5e628
fix(deps): update golang.org/x deps
octo-sts[bot] Nov 12, 2025
049ae59
Merge pull request #8246 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Nov 12, 2025
15000c2
fix(deps): update kubernetes go patches to v0.34.2
octo-sts[bot] Nov 13, 2025
d00260d
Merge pull request #8249 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Nov 13, 2025
ee3a610
chore(deps): update github/codeql-action action to v4.31.3
octo-sts[bot] Nov 14, 2025
99e4dee
fix(deps): update cloud go deps
octo-sts[bot] Nov 14, 2025
7ea7a69
Merge pull request #8250 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Nov 15, 2025
bc16d0b
Merge pull request #8243 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Nov 15, 2025
d2d8b6b
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Nov 16, 2025
85743ca
Merge pull request #8254 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Nov 16, 2025
3aa6c6e
feat(crd): add selectable fields
Nov 16, 2025
90a10bf
drop .spec.privateKey.algorithm selectablefield
inteon Nov 17, 2025
a4f2dc2
Merge pull request #8256 from tareksha/selectable_fields
cert-manager-prow[bot] Nov 18, 2025
efc33ef
chore(deps): update misc github actions
octo-sts[bot] Nov 19, 2025
8b1c8d9
Merge pull request #8244 from lunarwhite/ingress-anno
cert-manager-prow[bot] Nov 19, 2025
d5a7e62
fix(deps): update module github.com/google/gnostic-models to v0.7.1
octo-sts[bot] Nov 20, 2025
9450790
fix(deps): update module golang.org/x/crypto to v0.45.0
octo-sts[bot] Nov 20, 2025
68ee26d
Merge pull request #8266 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Nov 20, 2025
df530d7
fix make update-third-party on macOS (sed)
SgtCoDFish Nov 20, 2025
dfe47a0
run make update-third-party, which now also removes autocert
SgtCoDFish Nov 20, 2025
9fa47a9
also run third_party tests in CI
SgtCoDFish Nov 20, 2025
20adb33
Merge pull request #8268 from SgtCoDFish/vendored-acme-update
cert-manager-prow[bot] Nov 20, 2025
32444f1
fix(deps): update module sigs.k8s.io/structured-merge-diff/v6 to v6.3.1
octo-sts[bot] Nov 22, 2025
d0b9ff0
fix(deps): update cloud go deps
octo-sts[bot] Nov 22, 2025
d6a08e1
Merge pull request #8273 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Nov 22, 2025
cfd140e
Merge pull request #8260 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Nov 22, 2025
26c388c
Merge pull request #8264 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Nov 22, 2025
5f2485e
chore(deps): update actions/checkout action to v6
octo-sts[bot] Nov 22, 2025
52ddaf8
Merge pull request #8269 from cert-manager/renovate/master-major-misc…
cert-manager-prow[bot] Nov 22, 2025
c8dea94
Merge pull request #8265 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Nov 22, 2025
c658cc8
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Nov 24, 2025
a49ba58
20250703.gatewayapi-listenerset: initial version
maelvls Jul 3, 2025
3b2b289
Update 20250703.gatewayapi-listenerset.md
maelvls Jul 3, 2025
5e6b5db
20250703.gatewayapi-listenerset.md: specify what the annotation behav…
maelvls Jul 4, 2025
7340663
20250703.gatewayapi-listenerset.md: add table
maelvls Jul 7, 2025
dfaee27
20250703.gatewayapi-listenerset.md: address feedback from Richard
maelvls Jul 9, 2025
3064392
20250703.gatewayapi-listenerset.md: use XListenerSet instead of Liste…
maelvls Jul 17, 2025
8d48d3d
20250703.gatewayapi-listenerset.md: remove mention of draft
maelvls Jul 17, 2025
dde7f85
Merge pull request #7327 from Peac36/fix/7138
cert-manager-prow[bot] Nov 24, 2025
8a21b8c
Add client verification for webhook server
shubham14bajpai Aug 26, 2025
202a436
Addressed review comments
shubham14bajpai Aug 29, 2025
91f4c44
fix test failures
shubham14bajpai Oct 18, 2025
47443bd
Apply suggestions from code review
shubham14bajpai Oct 20, 2025
b9cb719
Make CN check optional
shubham14bajpai Nov 11, 2025
83eb3c1
accept multiple client certificate subject names and match CN/DNS SANs
shubham14bajpai Nov 12, 2025
0484e5f
Update comments on helm variable
shubham14bajpai Nov 24, 2025
fee1a92
Set helm template kube-version
erikgb Nov 24, 2025
178a3be
Merge pull request #8274 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Nov 24, 2025
b8cad85
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Nov 25, 2025
fce059e
Merge pull request #8275 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Nov 25, 2025
3b52e7d
design: address PR review comments and add ingress-nginx EOL context
maelvls Nov 24, 2025
6ecaa87
fixing unit test time
SgtCoDFish Nov 19, 2025
b097c97
Merge pull request #8010 from shubham14bajpai/add/webhook-auth
cert-manager-prow[bot] Nov 25, 2025
a7f672a
Merge pull request #8272 from SgtCoDFish/unit-test-time
cert-manager-prow[bot] Nov 25, 2025
a6d680d
use the same diagrams as in the blog post
maelvls Nov 30, 2025
e7307e7
Rename feature gate from XGatewayAPI to XListenerSets
maelvls Nov 30, 2025
5749a0e
Add context on why Gateway API was designed this way
maelvls Nov 30, 2025
3a268f0
Clarify Gateway API's intended wildcard certificate security model
maelvls Nov 30, 2025
3c3f911
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 2, 2025
adba265
Merge pull request #8286 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 2, 2025
97518d6
chore(deps): update github/codeql-action action to v4.31.6
octo-sts[bot] Dec 2, 2025
4d75e48
fix(deps): update cloud go deps
octo-sts[bot] Dec 2, 2025
0ea59f6
Merge pull request #8281 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 2, 2025
6bb9c74
Merge pull request #8276 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 2, 2025
71014c3
Graduate DefaultPrivateKeyRotationPolicyAlways to GA and remove gating
wallrj-cyberark Dec 2, 2025
44f5769
Merge pull request #8287 from wallrj-cyberark/remove-private-key-rota…
cert-manager-prow[bot] Dec 2, 2025
96cd769
Sort missing field list
jsoref Dec 2, 2025
6043501
spelling: invalid oid syntax
jsoref Dec 2, 2025
cdfce67
spelling: parsecertificaterequest
jsoref Dec 2, 2025
13f5f25
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 3, 2025
931f516
spelling: fall back
jsoref Dec 2, 2025
f2da642
spelling: , or
jsoref Dec 2, 2025
8408940
spelling: , or
jsoref Dec 2, 2025
6763632
chore(deps): update actions/checkout action to v6.0.1
octo-sts[bot] Dec 3, 2025
86461e7
fix(deps): update cloud go deps
octo-sts[bot] Dec 3, 2025
2d613f7
Promote OtherNames to Beta and enable by default
wallrj-cyberark Dec 2, 2025
d4dd566
Merge pull request #8288 from wallrj-cyberark/graduate-othernames-fea…
cert-manager-prow[bot] Dec 3, 2025
071a208
Merge pull request #8292 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 3, 2025
f425691
Merge pull request #8293 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 3, 2025
7008892
Merge pull request #8290 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 3, 2025
46dfcb9
chore: Improve vault error message for missing credentials
jsoref Dec 3, 2025
f85d2c7
drop unused DiscoveryClient from context struct
inteon Dec 3, 2025
06fc942
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 4, 2025
7d7e9c8
Merge pull request #8298 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 4, 2025
22e2a8e
fix(deps): update module github.com/spf13/cobra to v1.10.2
octo-sts[bot] Dec 4, 2025
4d0951c
Merge pull request #8297 from jsoref/vault-missing-credentials
cert-manager-prow[bot] Dec 4, 2025
a677cd5
Use constructors to create event handlers
inteon Dec 4, 2025
3979caa
make vendor-go generate
wallrj-cyberark Dec 4, 2025
2899810
Merge pull request #8299 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 4, 2025
49f218c
Merge pull request #8291 from jsoref/minor-tweaks
cert-manager-prow[bot] Dec 4, 2025
bce7706
Event handler: add support for predicate based filtering
inteon Dec 8, 2025
5f3f76b
Merge pull request #8302 from inteon/remove_unused_discovery_client
cert-manager-prow[bot] Dec 4, 2025
fdc7e41
add tests for event handlers
inteon Dec 4, 2025
b210ded
chore(deps): update base images
octo-sts[bot] Dec 5, 2025
f625b7d
venafi: Process custom fields annotations on Issuer
k0da Dec 4, 2025
02d1e19
Merge pull request #8303 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Dec 5, 2025
1be74b4
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 6, 2025
7a2fdab
Merge pull request #8306 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 6, 2025
13ca575
chore(deps): update github/codeql-action action to v4.31.7
octo-sts[bot] Dec 6, 2025
69f1e69
fix(deps): update module sigs.k8s.io/gateway-api to v1.4.1
octo-sts[bot] Dec 6, 2025
f756a9c
fix(deps): update module github.com/cloudflare/cloudflare-go/v6 to v6…
octo-sts[bot] Dec 6, 2025
5a02b6c
Merge pull request #8307 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 6, 2025
0c9a62e
Merge pull request #8305 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 6, 2025
af592c3
Merge pull request #8304 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 6, 2025
cdf0921
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 6, 2025
2225f2f
Merge pull request #8308 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 6, 2025
af55546
fix(deps): update k8s.io/kube-openapi digest to 4e65d59
renovate[bot] Dec 6, 2025
c87b897
Merge pull request #8310 from cert-manager/renovate/master-k8s.io-kub…
cert-manager-prow[bot] Dec 6, 2025
83cb932
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 7, 2025
c2c23e2
Merge pull request #8311 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 7, 2025
89d0a9c
fix(deps): update k8s.io/utils digest to bc988d5
renovate[bot] Dec 8, 2025
efccfbc
Merge pull request #8315 from cert-manager/renovate/master-k8s.io-uti…
cert-manager-prow[bot] Dec 8, 2025
a238c83
fix typos found by copilot
inteon Dec 8, 2025
8318aff
Merge pull request #8314 from inteon/construct_event_handlers
cert-manager-prow[bot] Dec 8, 2025
4c89b11
Merge pull request #8139 from hjoshi123/feat/cert-renewal-drafts
cert-manager-prow[bot] Dec 8, 2025
e484b2c
fix(deps): update github.com/onsi deps
renovate[bot] Dec 8, 2025
ac1f70f
fix(deps): update cloud go deps
renovate[bot] Dec 8, 2025
70a69bc
fix(deps): update golang.org/x deps
renovate[bot] Dec 8, 2025
c0eb769
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 9, 2025
f530e85
fix(deps): update module github.com/go-openapi/jsonreference to v0.21.4
renovate[bot] Dec 9, 2025
227989f
Merge pull request #8322 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 9, 2025
ffd8de8
Merge pull request #8316 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Dec 9, 2025
df59e32
Merge pull request #8321 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 9, 2025
6059764
Merge pull request #8323 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 9, 2025
f545630
Merge pull request #8320 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Dec 9, 2025
33fc9b5
Merge pull request #8261 from inteon/refactor_event_handler
cert-manager-prow[bot] Dec 9, 2025
9098658
Extend makefile-modules Renovate preset
erikgb Dec 9, 2025
ab22b7f
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 10, 2025
26165a4
Merge pull request #8333 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 10, 2025
02d3ae3
Merge pull request #8332 from cert-manager/renovate/reconfigure
cert-manager-prow[bot] Dec 10, 2025
406e2c5
fix(deps): update kubernetes go patches to v0.34.3
renovate[bot] Dec 10, 2025
4414c84
Merge pull request #8335 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 10, 2025
577d52a
fix(deps): update cloud go deps
renovate[bot] Dec 10, 2025
9858f56
Merge pull request #8329 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 10, 2025
fd8417e
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 11, 2025
8670ec8
Merge pull request #8337 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 11, 2025
ab036af
chore: fix some struct comments
changgesi Dec 11, 2025
014d580
run 'make generate'
inteon Dec 10, 2025
23629d5
Merge pull request #7839 from cert-manager/proposal-gatewayapi-listen…
cert-manager-prow[bot] Dec 11, 2025
352de00
fix(deps): update module github.com/miekg/dns to v1.1.69
renovate[bot] Dec 11, 2025
c9d425c
Merge pull request #8341 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 11, 2025
174fde5
Merge pull request #8338 from changgesi/master
cert-manager-prow[bot] Dec 12, 2025
2976330
chore(deps): update github/codeql-action action to v4.31.8
renovate[bot] Dec 12, 2025
c130e53
Merge pull request #8342 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 12, 2025
c468d13
chore(deps): update actions/upload-artifact action to v6
renovate[bot] Dec 12, 2025
35b1995
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 14, 2025
4c44989
Merge pull request #8344 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 14, 2025
c3cb959
fix(deps): update module github.com/venafi/vcert/v5 to v5.12.3
renovate[bot] Dec 14, 2025
9fcf05d
Merge pull request #8345 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 15, 2025
3faec85
Merge pull request #8343 from cert-manager/renovate/master-major-misc…
cert-manager-prow[bot] Dec 15, 2025
c35aa1a
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 16, 2025
27e1261
Merge pull request #8346 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 16, 2025
54b588e
chore(deps): update github/codeql-action action to v4.31.9
renovate[bot] Dec 16, 2025
166f378
fix(deps): update cloud go deps
renovate[bot] Dec 17, 2025
93b7863
Merge pull request #8347 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 17, 2025
f7f75c3
Merge pull request #8348 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 17, 2025
80e0a3b
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 18, 2025
d84ef8d
Merge pull request #8349 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 18, 2025
bee9a6d
chore(deps): update dependency kubernetes-sigs/kind to v0.31.0
renovate[bot] Dec 18, 2025
1a6633e
fix: update helm install NOTES to include GWAPI instructions
jaxels10 Dec 18, 2025
15481ea
fix(deps): update cloud go deps
renovate[bot] Dec 19, 2025
49a0425
Merge pull request #8351 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 19, 2025
2e365c8
Merge pull request #8356 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 20, 2025
9def8f7
Add checks for Duration and RenewBefore changes when determining if a…
eleanor-merry Dec 12, 2025
a66597e
Fix pointer refs for Duration/RenewBefore/RevisionHistoryLimit
eleanor-merry Dec 12, 2025
f4346c0
Move to ptr.Equal
eleanor-merry Dec 22, 2025
f0d2d82
fix(deps): update module software.sslmate.com/src/go-pkcs12 to v0.7.0
renovate[bot] Dec 23, 2025
ff466ee
Merge pull request #8301 from AbsaOSS/venafi_issuer_custom_field
cert-manager-prow[bot] Dec 23, 2025
cac4f59
feat(trigger): adding certificate request backoff duration to trigger…
hjoshi123 Dec 23, 2025
a48898b
Upgrade K8s dependencies to 1.35 (#8358)
erikgb Dec 23, 2025
399a243
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 24, 2025
25fa183
Merge pull request #8365 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 24, 2025
c825445
Merge pull request #8232 from eleanor-merry/notice-duration-changes-o…
cert-manager-prow[bot] Dec 24, 2025
d1a0ad3
Merge pull request #8362 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 25, 2025
3d29a83
Add unhealthyPodEvictionPolicy to supported PDB options
jcpunk Nov 6, 2025
536e74e
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 27, 2025
8fa9f88
Merge pull request #8366 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 27, 2025
886e4b4
Merge pull request #8353 from jaxels10/master
cert-manager-prow[bot] Dec 28, 2025
09600a6
adding 1.35 kind version
hjoshi123 Dec 28, 2025
bde5356
Merge pull request #8371 from hjoshi123/fix/kind-1-35
cert-manager-prow[bot] Dec 28, 2025
e41d1b7
feat(controller): adding labels to lease (#8043)
hjoshi123 Dec 28, 2025
f129792
feat(vault): add server as default audience
terinjokes Nov 4, 2025
c084079
Merge pull request #8228 from terinjokes/vault-default-audiences
cert-manager-prow[bot] Dec 29, 2025
140000a
Merge pull request #7728 from jcpunk/pdb-smarter
cert-manager-prow[bot] Jan 1, 2026
3156023
Replace custom Challenge SSA with upstream
inteon Jan 6, 2026
97c2870
Merge pull request #8377 from erikgb/ssa-apply
cert-manager-prow[bot] Jan 6, 2026
c94a6fc
fix(deps): update module google.golang.org/api to v0.259.0
renovate[bot] Jan 6, 2026
56dfa60
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 7, 2026
8e8448c
Merge pull request #8382 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 7, 2026
fa7ce9b
Merge pull request #8381 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 0 additions & 2 deletions .bazelignore

This file was deleted.

7 changes: 0 additions & 7 deletions .bazelrc

This file was deleted.

9 changes: 9 additions & 0 deletions .clomonitor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# License scanning information
licenseScanning:
# URL with the repository's license scanning results
#
# CLOMonitor can extract license scanning results from FOSSA and Snyk badges
# in the repository README.md file automatically. If your repository uses a
# different scanning solution, this url can be set to pass the corresponding
# check.
url: https://github.com/cert-manager/cert-manager/blob/master/LICENSES
6 changes: 3 additions & 3 deletions .github/ISSUE_TEMPLATE/bug.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ about: Report a bug to help us improve cert-manager
<!--
Bugs should be filed for issues encountered whilst operating cert-manager.
You should first attempt to resolve your issues through the community support
channels, e.g. Slack, in order to rule out individual configuration errors.
channels, e.g., Slack, in order to rule out individual configuration errors.
Please provide as much detail as possible.
-->

Expand All @@ -30,10 +30,10 @@ gain an understanding of the problem.-->

**Anything else we need to know?**:

**Environment details:**:
**Environment details**:
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests

/kind bug
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/feature-request.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ about: Suggest an idea to improve cert-manager
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests


/kind feature
7 changes: 6 additions & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,14 @@ Thanks for opening a pull request! Here are some tips to get everything merged s

### Kind

<!--
The kind(s) listed after "kind" after this comment will be used by a bot to add labels when the PR is opened.
If omitted at PR creation, someone will need to make a new comment with them later (editing the description after the fact will not trigger the bot).
-->
/kind
<!--

Pick a kind which best describes your PR from the following list:
Pick the kind(s) which best describe your PR from the following list:

<cleanup | bug | feature | documentation | design | flake>

Expand Down
10 changes: 10 additions & 0 deletions .github/chainguard/make-self-upgrade.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/chainguard/make-self-upgrade.sts.yaml instead.

issuer: https://token.actions.githubusercontent.com
subject_pattern: ^repo:cert-manager/cert-manager:ref:refs/heads/(main|master)$

permissions:
contents: write
pull_requests: write
workflows: write
79 changes: 79 additions & 0 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
{
$schema: 'https://docs.renovatebot.com/renovate-schema.json',
extends: [
'github>cert-manager/makefile-modules:renovate-config.json5'
],
baseBranchPatterns: [
'master',
'release-1.19',
'release-1.18',
],
addLabels: [
'kind/cleanup',
'release-note-none',
],
customManagers: [
{
customType: 'regex',
managerFilePatterns: [
'make/base_images.mk',
],
matchStrings: [
'(?<depName>gcr\\.io\/[^@]+)@(?<currentDigest>sha256:[a-f0-9]{64})',
],
datasourceTemplate: 'docker',
currentValueTemplate: 'latest'
},
{
customType: 'regex',
managerFilePatterns: [
'hack/latest-kind-images.sh',
],
matchStrings: [
'kind_version=(?<currentValue>.*)',
],
datasourceTemplate: 'github-releases',
depNameTemplate: 'kubernetes-sigs/kind',
},
],
packageRules: [
{
groupName: 'Base Images',
matchManagers: [
'custom.regex',
],
},
{
groupName: null,
matchManagers: [
'custom.regex',
],
matchPackageNames: [
'kubernetes-sigs/kind',
],
postUpgradeTasks: {
commands: [
'hack/latest-kind-images.sh',
],
},
},
{
matchBaseBranches: [
'/^release-.*/',
],
enabled: false,
},
{
matchBaseBranches: [
'/^release-.*/',
],
matchUpdateTypes: [
'patch',
'pin',
'pinDigest',
'digest',
],
enabled: true,
},
],
}
37 changes: 37 additions & 0 deletions .github/workflows/govulncheck.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/go/base/.github/workflows/govulncheck.yaml instead.

# Run govulncheck at midnight every night on the main branch,
# to alert us to recent vulnerabilities which affect the Go code in this
# project.
name: govulncheck
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
govulncheck:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with: { fetch-depth: 0 }

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6.1.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: make verify-govulncheck
114 changes: 114 additions & 0 deletions .github/workflows/make-self-upgrade.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/workflows/make-self-upgrade.yaml instead.

name: make-self-upgrade
concurrency: make-self-upgrade
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
self_upgrade:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

permissions:
id-token: write

env:
SOURCE_BRANCH: "${{ github.ref_name }}"
SELF_UPGRADE_BRANCH: "self-upgrade-${{ github.ref_name }}"

steps:
- name: Fail if branch is not head of branch.
if: ${{ !startsWith(github.ref, 'refs/heads/') && env.SOURCE_BRANCH != '' && env.SELF_UPGRADE_BRANCH != '' }}
run: |
echo "This workflow should not be run on a non-branch-head."
exit 1

- name: Octo STS Token Exchange
uses: octo-sts/action@f603d3be9d8dd9871a265776e625a27b00effe05 # v1.1.1
id: octo-sts
with:
scope: 'cert-manager/cert-manager'
identity: make-self-upgrade

- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with:
fetch-depth: 0
token: ${{ steps.octo-sts.outputs.token }}

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@4dc6199c7b1a012772edbd06daecab0f50c9053c # v6.1.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: |
git checkout -B "$SELF_UPGRADE_BRANCH"

- run: |
make -j upgrade-klone
make -j generate

- id: is-up-to-date
shell: bash
run: |
git_status=$(git status -s)
is_up_to_date="true"
if [ -n "$git_status" ]; then
is_up_to_date="false"
echo "The following changes will be committed:"
echo "$git_status"
fi
echo "result=$is_up_to_date" >> "$GITHUB_OUTPUT"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
run: |
git config --global user.name "cert-manager-bot"
git config --global user.email "[email protected]"
git add -A && git commit -m "BOT: run 'make upgrade-klone' and 'make generate'" --signoff
git push -f origin "$SELF_UPGRADE_BRANCH"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
with:
github-token: ${{ steps.octo-sts.outputs.token }}
script: |
const { repo, owner } = context.repo;
const pulls = await github.rest.pulls.list({
owner: owner,
repo: repo,
head: owner + ':' + process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
state: 'open',
});

if (pulls.data.length < 1) {
const result = await github.rest.pulls.create({
title: '[CI] Merge ' + process.env.SELF_UPGRADE_BRANCH + ' into ' + process.env.SOURCE_BRANCH,
owner: owner,
repo: repo,
head: process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
body: [
'This PR is auto-generated to bump the Makefile modules.',
].join('\n'),
});
await github.rest.issues.addLabels({
owner,
repo,
issue_number: result.data.number,
labels: ['ok-to-test', 'skip-review', 'release-note-none', 'kind/cleanup']
});
}
55 changes: 55 additions & 0 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: Scorecards supply-chain security
on:
# Only the default branch is supported.
branch_protection_rule:
schedule:
- cron: '43 13 * * 6'
push:
branches: [ "master" ]

# Declare default permissions as read only.
permissions: read-all

jobs:
analysis:
name: Scorecards analysis
runs-on: ubuntu-latest
if: github.ref_name == github.event.repository.default_branch
permissions:
# Needed to upload the results to code-scanning dashboard.
security-events: write
# Used to receive a badge.
id-token: write

steps:
- name: "Checkout code"
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif

# Publish the results for public repositories to enable scorecard badges. For more details, see
# https://github.com/ossf/scorecard-action#publishing-results.
# For private repositories, `publish_results` will automatically be set to `false`, regardless
# of the value entered here.
publish_results: true

# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@5d4e8d1aca955e8d8589aabd499c5cae939e33c7 # v4.31.9
with:
sarif_file: results.sarif
4 changes: 2 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,13 @@
/hack/build/dockerfiles/cert-manager-*_*_*
.vscode
.venv
bazel-*
/.settings/
/.project
_artifacts/
/vendor/
bin/
_bin/
.bin/
user.bazelrc
*.bak
/go.work.sum
**/go.work
Loading