fix(container): update quay.io/jetstack/charts/cert-manager ( v1.21.0 ➔ v1.21.1 ) #1916
No reviewers
Labels
No labels
area/bootstrap
area/ci
area/kubernetes
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
renovate/container
renovate/github-action
renovate/github-release
renovate/grafana-dashboard
renovate/helm
renovate/terraform
type/digest
type/major
type/minor
type/patch
wontfix
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
GiorgioAresu/home-ops!1916
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/quay.io-jetstack-charts-cert-manager-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.21.0→v1.21.1Release Notes
cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)
v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)Configuration
📅 Schedule: (in timezone Europe/Rome)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.
konflate — summary
+0 added · 5 changed · −0 removed — 5 resources · 2 apps
Blast radius
Kustomization cert-manager/cert-manager— 1 dependent (Kustomization kube-system/k8tz)⚠ Caution
Job cert-manager/cert-manager-startupapicheck— spec.template changed — immutable on Job; the apply fails until the resource is recreated (or Flux force is enabled)Image changes
quay.io/jetstack/cert-manager-cainjectorv1.21.0v1.21.1quay.io/jetstack/cert-manager-controllerv1.21.0v1.21.1quay.io/jetstack/cert-manager-startupapicheckv1.21.0v1.21.1quay.io/jetstack/cert-manager-webhookv1.21.0v1.21.1View the full rendered diff →
konflate · rendered
1bc2438· advisory, not a gate✅ Automated recommendation: APPROVE
Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)
Approve — cert-manager patch update v1.21.0 → v1.21.1.
Changed files (2)
kubernetes/apps/cert-manager/cert-manager/app/ocirepository.yaml— tagv1.21.0→v1.21.1kubernetes/bootstrap/helmfile.d/01-apps.yaml— chart versionv1.21.0→v1.21.1Konflate rendered diff — 5 resources updated (cert-manager controller, cainjector, webhook, startupapicheck, OCIRepository). All 4 container images (
cert-manager-controller,cert-manager-cainjector,cert-manager-webhook,cert-manager-startupapicheck) correctly bump tov1.21.1. No render failures.Caveat (non-blocking)
cert-manager-startupapicheckJobspec.templatechanges — Jobs are immutable in Kubernetes, so the upgrade will require the Job to be recreated. This is inherent to any cert-manager version bump and not a PR defect.Standards compliance
v1.21.1) per documented convention; SHA digest not applicable to OCI artifacts.metadata.namespaceabsent onHelmRelease/OCIRepository— intentional, injected at build time.Release quality