fix(container): update image quay.io/jetstack/charts/cert-manager (v1.21.1 ➔ v1.21.2) #2055
No reviewers
Labels
No labels
area/bootstrap
area/ci
area/kubernetes
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
renovate/container
renovate/github-action
renovate/github-release
renovate/grafana-dashboard
renovate/helm
renovate/terraform
type/digest
type/major
type/minor
type/patch
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
GiorgioAresu/home-ops!2055
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/quay.io-jetstack-charts-cert-manager-1.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.21.1→v1.21.2Release Notes
cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)
v1.21.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.
All users should upgrade.
Changes by Kind
Bug or Regression
replacesfield was being populated for the wrong issuer on issuer changes (#9236, @hjoshi123)spec.vault.servercould be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. (#9262, @FelixPhipps)Challenge.status.reason, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. (#9232, @FelixPhipps)vaultissuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespacedIssuer, unless ambient credentials are explicitly enabled via--issuer-ambient-credentials.ClusterIssuerand explicitserviceAccountRef(IRSA) configurations are unaffected. (#9231, @FelixPhipps)Other (Cleanup or Flake)
google.golang.org/grpcto v1.83.2 to fix reported security vulnerabilities (#9255, #9317)golang.org/x/cryptoto v0.56.0 to fix reported security vulnerabilities (#9265)v1.21.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.
All users should upgrade.
Changes by Kind
Bug or Regression
replacesfield was being populated for the wrong issuer on issuer changes (#9236, @hjoshi123)spec.vault.servercould be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. (#9262, @FelixPhipps)Challenge.status.reason, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. (#9232, @FelixPhipps)vaultissuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespacedIssuer, unless ambient credentials are explicitly enabled via--issuer-ambient-credentials.ClusterIssuerand explicitserviceAccountRef(IRSA) configurations are unaffected. (#9231, @FelixPhipps)Other (Cleanup or Flake)
google.golang.org/grpcto v1.83.2 to fix reported security vulnerabilities (#9255, #9317)golang.org/x/cryptoto v0.56.0 to fix reported security vulnerabilities (#9265)Configuration
📅 Schedule: (in timezone Europe/Rome)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
⚠ Caution
Job cert-manager/cert-manager-startupapicheck:spec.templatechanged; immutable on Job; the apply fails until the resource is recreated (or Flux force is enabled)5 resources changed across 2 apps
Blast radius
Kustomization cert-manager/cert-manager: 1 dependent (kube-system/k8tz)quay.io/jetstack/cert-manager-cainjectorv1.21.1v1.21.2quay.io/jetstack/cert-manager-controllerv1.21.1v1.21.2quay.io/jetstack/cert-manager-startupapicheckv1.21.1v1.21.2quay.io/jetstack/cert-manager-webhookv1.21.1v1.21.2konflate 0.6.4 · rendered
1e4d8ec· full diff →✅ Automated recommendation: APPROVE
Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)
Review: cert-manager v1.21.1 → v1.21.2 patch update
Recommendation: Approve
This is a straightforward Renovate-generated patch update for the cert-manager Helm chart. The single-line OCI repository tag change (
v1.21.1→v1.21.2) correctly propagates to all four cert-manager container images via the Helm chart's values.Changed Files
kubernetes/apps/cert-manager/cert-manager/app/ocirepository.yamlv1.21.1→v1.21.2Non-Blocking Caveats
Immutable Job warning (konflate): The
cert-manager-startupapicheckJob'sspec.templatechanges as a side effect of the chart update. Kubernetes Jobs are immutable — Flux will need to delete and recreate the Job on apply. This is expected behavior for cert-manager startup checks and typically causes no disruption; the Job is a one-shot validation run.OCI artifact pinning: Per AGENTS.md conventions, OCI artifacts pulled via
OCIRepositoryare correctly pinned by tag/version rather than SHA digest. No action needed.Why Approve
The v1.21.2 release contains multiple bug fixes and security patches (ACME response body handling, webhook panics, data races, Go dependency updates) that are important for a critical cluster component managing TLS certificates. No issues identified in the diff or konflate render output that would preclude merge.