Zum Inhalt springen

cert-manager Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge cert-manager, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.18.4

Version 1.18.4 aktualisiert Go auf v1.24.11 zur Behebung von CVE-2025-61727 und CVE-2025-61729, behandelt falsch positive Trivy-Meldungen zu CVE-2025-47914 und CVE-2025-58181 und aktualisiert den ACME-Client sowie die Debian-12-Distroless-Basisimages.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We updated Go to fix some vulnerabilities in the standard library.

📖 Read the full 1.18 release notes on the cert-manager.io website before upgrading.

Changes since v1.18.3

Bug or Regression

  • Address false positive vulnerabilities CVE-2025-47914 and CVE-2025-58181 which were reported by Trivy. (#8282, @SgtCoDFish)
  • Update Go to v1.24.11 to fix CVE-2025-61727 and CVE-2025-61729 (#8295, @wallrj-cyberark)

Other (Cleanup or Flake)

  • Update cert-manager's ACME client, forked from golang/x/crypto (#8271, @SgtCoDFish)
  • Updated Debian 12 distroless base images (#8328, @wallrj-cyberark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.20.0-alpha.0 (Vorabversion)

Die Vorabversion 1.20.0-alpha.0 bringt eingebaute Ready-Status-Metriken für Issuer und ClusterIssuer, imagePullSecrets für den startupapicheck-Job sowie mehrere Fehlerbehebungen, etwa zu unerwarteten Zertifikatserneuerungen und DigitalOcean-DNS-01-Retries.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

⚠️ This is a pre-release. For testing only!

Changes since v1.19.0

Feature

  • Add built-in "Ready" status metrics for ClusterIssuer and Issuer resources. (#8188, @mikeluttikhuis)
  • Add support for specifying imagePullSecrets in the startupapicheck-job Helm template to enable pulling images from private registries. (#8186, @mathieu-clnk)

Bug or Regression

  • Adds logs for cases when acme server returns us a fatal error in the order controller (#8199, @Peac36)
  • BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#8160, @inteon)
  • Fix unregulated retries with the DigitalOcean DNS-01 solver (#8221, @wallrj-cyberark)
  • Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging (#8221, @wallrj-cyberark)
  • Revert API defaults for issuer reference kind and group introduced in 0.19.0 (#8173, @erikgb)
  • When Prometheus monitoring is enabled, the metrics label is now set to the intended value of cert-manager. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). (#8162, @LiquidPL)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.19.1

Version 1.19.1 macht die in 1.19.0 eingeführten API-Defaults für issuerRef rückgängig, behebt unerwartete Zertifikatserneuerungen nach dem Upgrade und aktualisiert Go auf 1.25.3 zur Behebung mehrerer Sicherheitslücken.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We reverted the CRD-based API defaults for Certificate.Spec.IssuerRef and CertificateRequest.Spec.IssuerRef after they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager 1.20. We fixed a bug that caused certificates to be re-issued unexpectedly if the issuerRef kind or group was changed to one of the "runtime" default values. We upgraded Go to 1.25.3 to address the following security vulnerabilities: CVE-2025-61724, CVE-2025-58187, CVE-2025-47912, CVE-2025-58183, CVE-2025-61723, CVE-2025-58186, CVE-2025-58185, CVE-2025-58188, and CVE-2025-61725.

📖 Read the full 1.19 release notes on the cert-manager.io website before upgrading.

Changes since v1.19.0:

Bug or Regression

  • BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#8175, @cert-manager-bot)
  • Bump Go to 1.25.3 to fix a backwards incompatible change to the validation of DNS names in X.509 SAN fields which prevented the use of DNS names with a trailing dot (#8177, @wallrj-cyberark)
  • Revert API defaults for issuer reference kind and group introduced in 0.19.0 (#8178, @cert-manager-bot)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.18.3

Version 1.18.3 behebt unerwartete Zertifikatsneuausstellungen bei geänderter issuerRef, erhöht die Größenlimits beim Parsen von PEM-Zertifikatsketten, verbessert Fehlermeldungen und aktualisiert Go auf 1.24.9 für Sicherheitskorrekturen.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug which caused certificates to be re-issued unexpectedly, if the issuerRef kind or group was changed to one of the "runtime" default values. We increased the size limit when parsing PEM certificate chains to handle leaf certificates with large numbers of DNS named or other identities. We upgraded Go to 1.24.9 to fix various non-critical security vulnerabilities.

📖 Read the full 1.18 release notes on the cert-manager.io website before upgrading.

Changes since v1.18.2:

Bug or Regression

  • BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#8174, @cert-manager-bot)
  • Bump Go to 1.24.9. Fixes the following vulnerabilities: CVE-2025-61724, CVE-2025-58187, CVE-2025-47912, CVE-2025-58183, CVE-2025-61723, CVE-2025-58186, CVE-2025-58185, CVE-2025-58188, CVE-2025-61725 (#8176, @wallrj-cyberark)
  • Increase maximum sizes of PEM certificates and chains which can be parsed in cert-manager, to handle leaf certificates with large numbers of DNS names or other identities (#7966, @cert-manager-bot)

Other (Cleanup or Flake)

  • Improve error messages when certificates, CRLs or private keys fail admission due to malformed or missing PEM data (#7964, @cert-manager-bot) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.19.0

Version 1.19.0 erweitert Plattformkompatibilität, Deployment-Flexibilität und Beobachtbarkeit, unter anderem mit IPv6-Regeln in der Netzwerkrichtlinie, global.nodeSelector im Helm-Chart, neuen Prometheus-Metriken und einem protocol-Feld für den rfc2136-DNS01-Provider, hat aber ein bekanntes Problem mit unerwarteten Zertifikatserneuerungen, das in 1.19.1 behoben ist.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

⚠️ Known issues: The following known issues are fixed in v1.19.1:

This release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues.

📖 Read the full release notes at cert-manager.io: https://cert-manager.io/docs/releases/release-notes/release-notes-1.19

Changes since v1.18.0:

Feature

  • Add IPv6 rules to the default network policy (#7726, @jcpunk)
  • Add global.nodeSelector to helm chart to allow for a single nodeSelector to be set across all services. (#7818, @StingRayZA)
  • Add a feature gate to default to Ingress pathType Exact in ACME HTTP01 Ingress challenge solvers. (#7795, @sspreitzer)
  • Add generated applyconfigurations allowing clients to make type-safe server-side apply requests for cert-manager resources. (#7866, @erikgb)
  • Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). (#7414, @erikgb)
  • Added certmanager_certificate_challenge_status Prometheus metric. (#7736, @hjoshi123)
  • Added protocol field for rfc2136 DNS01 provider (#7881, @hjoshi123) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.19.0-alpha.0 (Vorabversion)

Die Vorabversion 1.19.0-alpha.0 enthält neue Funktionen wie IPv6-Regeln in der Netzwerkrichtlinie, global.nodeSelector im Helm-Chart, generierte applyconfigurations, API-Defaults für Issuer-Referenzen, eine neue Prometheus-Metrik und ein protocol-Feld für rfc2136.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

⚠️ This is a pre-release. For testing only!

Changes since v1.18.0:

Feature

  • Add IPv6 rules to the default network policy (#7726, @jcpunk)
  • Add global.nodeSelector to helm chart to allow for a single nodeSelector to be set across all services. (#7818, @StingRayZA)
  • Add generated applyconfigurations allowing clients to make type safe server-side apply requests for cert-manager resources. (#7866, @erikgb)
  • Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). (#7414, @erikgb)
  • Added certmanager_certificate_challenge_status Prometheus metric. (#7736, @hjoshi123)
  • Added protocol field for rfc2136 DNS01 provider (#7881, @hjoshi123) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.18.2

Version 1.18.2 behebt einen Fehler, bei dem erlaubte URI-Domains fälschlich als ausgeschlossene Domains in den Name Constraints der CSR gesetzt wurden, und nimmt die Helm-Option global.rbac.disableHTTPChallengesRole wieder zurück.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the NameConstraints feature gate). We dropped the new global.rbac.disableHTTPChallengesRole Helm option due to a bug we found, this feature will be released in v1.19 instead.

Changes since v1.18.1:

Bug or Regression

  • BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints (#7833, @cert-manager-bot)
  • Reverted adding the global.rbac.disableHTTPChallengesRole Helm option. (#7837, @cert-manager-bot)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.17.4

Version 1.17.4 behebt einen Fehler, bei dem erlaubte URI-Domains fälschlich als ausgeschlossene Domains in den Name Constraints der CSR gesetzt wurden (nur mit aktiviertem NameConstraints-Feature-Gate).

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the NameConstraints feature gate).

Changes since v1.17.3:

Bug or Regression

  • BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints (#7832, @cert-manager-bot)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.18.1

Version 1.18.1 führt das Feature-Gate ACMEHTTP01IngressPathTypeExact ein, mit dem sich das neue Standardverhalten PathType Exact abschalten lässt, und erhöht das Timeout für die ACME-Challenge-Autorisierung auf zwei Minuten.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We have added a new feature gate ACMEHTTP01IngressPathTypeExact, to allow ingress-nginx users to turn off the new default Ingress PathType: Exact behavior, in ACME HTTP01 Ingress challenge solvers. This change fixes the following issue: #7791

We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (error waiting for authorization), which has been reported by multiple users, since the release of cert-manager v1.16.0. This change should fix the following issues: #7337, #7444, and #7685.

ℹ️ Be sure to review all new features and changes below, and read the full release notes carefully before upgrading.

Changes since v1.18.0:

Feature

  • Added a new feature gate ACMEHTTP01IngressPathTypeExact, to allow ingress-nginx users to turn off the new default Ingress PathType: Exact behavior, in ACME HTTP01 Ingress challenge solvers. (#7810, @sspreitzer)

Bug or Regression

  • ACME: Increased challenge authorization timeout to 2 minutes to fix error waiting for authorization. (#7801, @hjoshi123)

Other (Cleanup or Flake) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

cert-manager

cert-manager v1.17.3

Version 1.17.3 behebt per Go-Update auf 1.23.10 mehrere von Trivy gemeldete Schwachstellen und erhöht das Timeout für die ACME-Challenge-Autorisierung auf zwei Minuten.

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23.

We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (error waiting for authorization), which has been reported by multiple users, in: #7337, #7444, and #7685.

ℹ️ Be sure to review all new features and changes below, and read the full release notes carefully before upgrading.

Changes since v1.17.2:

Bug or Regression

  • Bump Go to 1.23.10 to fix GO-2025-3749, GO-2025-3750, and GO-2025-3751 (#7799, @wallrj)
  • ACME: Increased challenge authorization timeout to 2 minutes to fix error waiting for authorization (#7798, @hjoshi123)

Other (Cleanup or Flake)

  • Use the latest version of ingress-nginx in E2E tests to ensure compatibility (#7808, @wallrj)

Originalquelle(öffnet in neuem Tab)Problem melden