fix(container): update quay.io/jetstack/charts/cert-manager ( v1.21.0 ➔ v1.21.1 ) #1909
No reviewers
Labels
No labels
area/bootstrap
area/ci
area/kubernetes
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
renovate/container
renovate/github-action
renovate/github-release
renovate/grafana-dashboard
renovate/helm
renovate/terraform
type/digest
type/major
type/minor
type/patch
wontfix
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
GiorgioAresu/home-ops!1909
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/quay.io-jetstack-charts-cert-manager-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.21.0→v1.21.1Release Notes
cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)
v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)Configuration
📅 Schedule: (in timezone Europe/Rome)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.
✅ Automated recommendation: APPROVE
Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)
Recommendation: Approve
cert-manager patch update v1.21.0 → v1.21.1
This is a straightforward patch update that bumps the cert-manager Helm chart across two files (
ocirepository.yamlandhelmfile.d/01-apps.yaml) fromv1.21.0tov1.21.1.Changed Files
kubernetes/apps/cert-manager/cert-manager/app/ocirepository.yamltag: v1.21.0→v1.21.1kubernetes/bootstrap/helmfile.d/01-apps.yamlversion: v1.21.0→v1.21.1Caveat
fix(container):which is imprecise for a Helm chart OCI artifact update. This is a cosmetic inconsistency and not a blocker.Non-blocking Notes
golang.org/x/text,google.golang.org/grpc,github.com/google/cel-go,go.opentelemetry.io/otel) and updates distroless base images. This is a security-positive change.spec.renewal.policy: Disabled, log spam regression, and Issuer stuck states — all fixed in this patch.@sha256:digest. The change is consistent across both files.konflate — summary
+0 added · 5 changed · −0 removed — 5 resources · 2 apps
Blast radius
Kustomization cert-manager/cert-manager— 1 dependent (Kustomization kube-system/k8tz)⚠ Caution
Job cert-manager/cert-manager-startupapicheck— spec.template changed — immutable on Job; the apply fails until the resource is recreated (or Flux force is enabled)Image changes
quay.io/jetstack/cert-manager-cainjectorv1.21.0v1.21.1quay.io/jetstack/cert-manager-controllerv1.21.0v1.21.1quay.io/jetstack/cert-manager-startupapicheckv1.21.0v1.21.1quay.io/jetstack/cert-manager-webhookv1.21.0v1.21.1View the full rendered diff →
konflate · rendered
5399976· advisory, not a gate