fix(container): update quay.io/jetstack/charts/cert-manager ( v1.21.0 ➔ v1.21.1 ) #1924
No reviewers
Labels
No labels
area/bootstrap
area/ci
area/kubernetes
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
renovate/container
renovate/github-action
renovate/github-release
renovate/grafana-dashboard
renovate/helm
renovate/terraform
type/digest
type/major
type/minor
type/patch
wontfix
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
GiorgioAresu/home-ops!1924
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/quay.io-jetstack-charts-cert-manager-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.21.0→v1.21.1Release Notes
cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)
v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)Configuration
📅 Schedule: (in timezone Europe/Rome)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.
✅ Automated recommendation: APPROVE
Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)
Approve — cert-manager v1.21.0 → v1.21.1 patch update.
Changed files (2):
ocirepository.yaml: tagv1.21.0→v1.21.101-apps.yaml: versionv1.21.0→v1.21.1Fit: The version bump is consistent across the OCIRepository source ref and HelmRelease chart version. No other manifest files reference the old version.
Caveat: OCI artifact (Helm chart) pinned by tag rather than SHA — per AGENTS.md convention this is intentional and correct for OCI artifacts; not a concern.
Konflate: Rendered-diff shows no findings; manifests apply cleanly.
konflate — summary
+0 added · 5 changed · −0 removed — 5 resources · 2 apps
Blast radius
Kustomization cert-manager/cert-manager— 1 dependent (Kustomization kube-system/k8tz)⚠ Caution
Job cert-manager/cert-manager-startupapicheck— spec.template changed — immutable on Job; the apply fails until the resource is recreated (or Flux force is enabled)Image changes
quay.io/jetstack/cert-manager-cainjectorv1.21.0v1.21.1quay.io/jetstack/cert-manager-controllerv1.21.0v1.21.1quay.io/jetstack/cert-manager-startupapicheckv1.21.0v1.21.1quay.io/jetstack/cert-manager-webhookv1.21.0v1.21.1View the full rendered diff →
konflate · rendered
1bc2438· advisory, not a gate