Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/cert-manager/cert-manager

Automatically provision and manage TLS certificates in Kubernetes
https://github.com/cert-manager/cert-manager

Merge pull request #5674 from maelvls/upgrade-vcert

vcert: upgrade to v4.23.0 to fix certificate renewal stuck on TPP errors ("Click Retry" and "Web...

98498ef17e621e3b6f4499848f796b701eda8455 authored about 2 years ago
update LICENSES (make update-licenses)

Signed-off-by: Maël Valais <[email protected]>

6403091073b3602aa90065a236425ffd2539128a authored about 2 years ago
vcert: upgrade to v4.23.0 to fix "Click Retry" and "WebSDK CertRequest"

cert-manager was not able to retry failed TPP certificates due to the
fact that TPP will not res...

dcab0d2e3f98c4f5cac8100aa1848b3be4a82541 authored about 2 years ago
fix(AzureDNS): suppress original message in adal.TokenRefreshError to prevent early CR reconciliations due to unique data (timestamp, Trace ID) that lands to CR status

Signed-off-by: Igor Beliakov <[email protected]>

1c0197381374c5d9254c25512a5d49f26c8adb87 authored about 2 years ago
Merge pull request #5554 from camptocamp/helm-add-acme-http01-solver-image-override-option

helm: add option to override ACME HTTP-01 solver image

2a7fabd5ca26adfb892235d13848d2151d353b87 authored about 2 years ago
helm: add option to override ACME HTTP-01 solver image

Signed-off-by: Yann Soubeyrand <[email protected]>

ea0bea9db054b73fca78e90dd815312a0b1c3593 authored about 2 years ago
Merge pull request #5661 from SgtCoDFish/helmchartversionfix

Bump supported versions of k8s mentioned in the helm chart

ca318f1d4150279a2215e3764737fe05ce051950 authored about 2 years ago
Bump sigs.k8s.io deps

Signed-off-by: Luca Comellini <[email protected]>

dbd6dc9b16a0a7542ab74d775a35e6f764f2aa6e authored about 2 years ago
Bump supported versions of k8s mentioned in the helm chart

This reflects the latest supported releases as of an update on
2022-12-16

See https://github.co...

1a63cba52a62d0b417317004acd35ef0142883bb authored about 2 years ago
Merge pull request #5644 from SgtCoDFish/acmeissuerbundle

Add CABundle for ACME Servers

8deaca755d54a7aee5cf1a3f68a7f952924f6302 authored about 2 years ago
Merge pull request #5655 from wallrj/images-push

Experimental make targets for pushing images to a Docker registry and redeploying cert-manager

9a68a86ac6c38b973dbbcbb5f1fbcccc38394c69 authored about 2 years ago
Add some experimental ko based build and deploy tools

Signed-off-by: Richard Wall <[email protected]>

755fec117085cadf07275ff4895b32b53fa5d2fc authored about 2 years ago
Merge pull request #5659 from SgtCoDFish/bumpbase

Update base images to latest

a7671cf205669727c33afb2aeefe85eae0c6e118 authored about 2 years ago
Merge pull request #5641 from cert-manager/dependabot/go_modules/helm.sh/helm/v3-3.10.3

Bump helm.sh/helm/v3 from 3.10.0 to 3.10.3

8641c4a6975c39e80a9ba65bcd6321b88ca5c503 authored about 2 years ago
Merge pull request #5658 from SgtCoDFish/harmonizecontour

Bump version of contour helm chart + images

6e0f99de815faf5ee50b2f6be14e7ce4306ef775 authored about 2 years ago
update base images to latest

Signed-off-by: Ashley Davis <[email protected]>

a08cf19aa7734078cea888083cf1bef55dd95dcc authored about 2 years ago
Bump version of contour helm chart + images

Also adds a note about how to update the helm chart version, in the
future

Signed-off-by: Ashle...

31a3edf03117f060fc09ffc17f9183d255ae47d6 authored about 2 years ago
Add ko tool

Signed-off-by: Richard Wall <[email protected]>

2eef0dad06071ed08910d3bbfcc7809be593cde0 authored about 2 years ago
Merge pull request #5656 from SgtCoDFish/trivydec

Bump golang.org/x/net version to fix trivy vulns

8a3811314f98c485ec8430d317aaf2fb1aa0a649 authored about 2 years ago
bump golang.org/x/net version to fix trivy vulns

Signed-off-by: Ashley Davis <[email protected]>

12e0e0a9eb3a5e853edb39600c5470c325a066c9 authored about 2 years ago
Merge pull request #5654 from SgtCoDFish/updatesec

Update SECURITY policy to exclude vuln reports

c27b7cea6a7f9282c445c677dad7050b5828df4b authored about 2 years ago
update SECURITY policy to exclude vuln reports

Signed-off-by: Ashley Davis <[email protected]>

1542ea0492a8b519855605da57272fc5584d1945 authored about 2 years ago
Merge pull request #5646 from SgtCoDFish/k8s1.26

Enable + use k8s 1.26 for e2e tests by default

501f4928ea75cea0bcb316fe3f9bac2d2bbe612b authored about 2 years ago
Enable + use k8s 1.26 for e2e tests by default

Signed-off-by: Ashley Davis <[email protected]>

1e419a468f105cf95b2d1fbff84be02d743a43ab authored about 2 years ago
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.10.0 to 3.10.3.

- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/[email protected])...

ff6fec9088c82761040e4bdbe95008404b0525be authored about 2 years ago
add + use CABundle field for ACME servers in issuers

Previously it wasn't possible to set a custom CA bundle for an ACME
server, leading users to eit...

c5924f54a1efb07b4f75797c2ca79b5f144ab16d authored about 2 years ago
change wording on descriptions for Vault and TPP 'CABundle' fields

Clarifies language a little; makes it clearer that the bundle
should be base64 encoded. Previous...

f68693bb6ac9ab5a6d6a14ab8028f88c632874d2 authored about 2 years ago
Merge pull request #5637 from RomanenkoDenys/fix-kubebuilder-sha

fix kubebuilder tools arm64 sha256sum

6806035cb7b3366fedecce5a6bc320f77e0d5bac authored about 2 years ago
Merge pull request #5629 from lucacome/bump-k8s-deps

Bump k8s.io deps to v0.26.0

a5a21693bcd726737cca2f352fa9610712c52185 authored about 2 years ago
Update controller-runtime to v0.14.0

Signed-off-by: Luca Comellini <[email protected]>

bb252356a28546219e95288efd5616c707e0ffe7 authored about 2 years ago
Bump k8s.io deps to v0.26.0

Signed-off-by: Luca Comellini <[email protected]>

c99c147059d10271e4c27c59d197ed260bfb0fdc authored about 2 years ago
add WithLegacy function to our fake discovery client

Signed-off-by: Tim Ramlot <[email protected]>
Signed-off-by: Luca Comelli...

26d04f3d8aff1b4e6cf80bffff4e48ab003ec93f authored about 2 years ago
kubebuilder did not yet create a 1.26 release

Signed-off-by: Tim Ramlot <[email protected]>
Signed-off-by: Luca Comelli...

8baaffc02b4f746ad1fd9bafe8fe5705d0c148e8 authored about 2 years ago
Merge pull request #5638 from lvyanru8200/maxconcurrent

feat: Add max-concurrent-challenges parameter to helm

19d433da1530fba0b466fee9a912c4b2d259b45c authored about 2 years ago
Merge pull request #5604 from maelvls/upgrade-vault-in-e2e

End-to-end tests: use Vault 1.12.1 instead of the outdated Vault 1.2.3

a1391d699514c27275e78b763eabd7e804404bd4 authored about 2 years ago
feat: Add max-concurrent-challenges parameter to helm

Set the max-concurrent-challenges value with -set maxConcurrentChallenges=value when deploying w...

2f0d49203603cebe47551a9ed940fbfd26ac9715 authored about 2 years ago
fix kubebuilder tools arm64 sha256sum

Signed-off-by: Denis Romanenko <[email protected]>

d62bf032f51abd5a2915d5f4ada0a6f3b0f2f014 authored about 2 years ago
Merge pull request #5632 from SgtCoDFish/fixtrivy

Bump dep versions to fix trivy-reported vulns

a72095b8000e49d1896665cba5ea31795b3c44c8 authored about 2 years ago
bump dep versions to fix trivy-reported vulns

```text
{
"VulnerabilityID": "CVE-2022-41717",
"PkgName": "golang.org/x/net",
"InstalledVe...

a099eb306a54ff5e35cadaa09230a7b8881014e6 authored about 2 years ago
Merge pull request #5628 from yk/patch-1

Fixed a typo in helm chart values

7ef91210aea15dec5890a0bb17f283094e2173e2 authored about 2 years ago
Fixed a typo in helm chart values

Signed-off-by: Yannic Kilcher <[email protected]>

5ce5129a3cde361605fe5868e67f1111b1abd379 authored about 2 years ago
Merge pull request #5618 from SgtCoDFish/no-licenses-ci-presubmit

Remove verify-licenses from ci-presubmit

2f24231383173cf8ef66858c24e7d2f01c699219 authored about 2 years ago
Merge pull request #5619 from SgtCoDFish/bumpgo

Bump go to 1.19.4

cb4d9b566deb9772c0f57b0d1e64dccbd51dd48a authored about 2 years ago
bump go to 1.19.4

Signed-off-by: Ashley Davis <[email protected]>

22f3a6152d49202cd1a6d6a8098b7814e538667c authored about 2 years ago
Merge pull request #5597 from sathyanarays/keystore_fix

Refreshing secrets if keystore format change

0fa83c3f88034053a0ccad07107e39eb5ba57fb6 authored about 2 years ago
remove verify-licenses from ci-presubmit

see https://github.com/cert-manager/release/pull/111

Signed-off-by: Ashley Davis <ashley.davis@...

79bd127d3b16f1d41181933589a4b22ca37f0f28 authored about 2 years ago
Addressing review comments

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

94fa9eeee62eb14ba3c0a15e45820e411a54da87 authored about 2 years ago
Update internal/controller/certificates/policies/checks.go

Co-authored-by: Richard Wall <[email protected]>
Signed-off-by: Sathyanarayanan Sa...

4a6bae60bed2784974ec7f90bbe234eee85f31f0 authored about 2 years ago
Refreshing secrets when the keystore fields change

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

42ae76ae3016ad2a889a74db451d4c4ea32708e2 authored about 2 years ago
Updating CRDs

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

5aabf625855bc3e4a634803795aa795fd6480966 authored about 2 years ago
Addressing review comments

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

f719247d2b5f24a38a76e30d0ec68f3152d0c8f2 authored about 2 years ago
Merge pull request #5595 from irbekrm/update_gwapi_install

Updates Gateway API test setup

37ae8b2773c44e48df85d974ea9ea79dbacadea2 authored about 2 years ago
Gateway and GatewayClass for tests are created against beta Gateway API

Signed-off-by: irbekrm <[email protected]>

c60a181baf94762e346c4da210eb232349f247bf authored about 2 years ago
Corrects test Gateway resources

TLS block is only valid for TLS listeners

Signed-off-by: irbekrm <[email protected]>

0c8aa75b181d8b08e54c74855d9b64af75cb2b70 authored about 2 years ago
Tests download Gateway installation bundle

Rather than whole gateway git repo

Signed-off-by: irbekrm <[email protected]>

bc7023325636959ce52025ef13c90fcfba356bac authored about 2 years ago
Update reference to HTTPRoute docs

Signed-off-by: irbekrm <[email protected]>

486c72f12224f1613742878c83ade6b331c7dfc6 authored about 2 years ago
Removes unused check

current cert-manager version no longer supports Kubernetes 1.19

Signed-off-by: irbekrm <irbekrm...

9709833bb66ceee243321fb4ab2da5d390b76cfb authored about 2 years ago
Updates Gateway API test dependency

Signed-off-by: irbekrm <[email protected]>

75e2d1145aa39381147e6c614fda9fd81de563a3 authored about 2 years ago
Bumps Contour Helm chart version

Signed-off-by: irbekrm <[email protected]>

608c3a1df0cb615d924749fbee9837ce7083d54d authored about 2 years ago
Merge pull request #5583 from lvyanru8200/uodateGwVerison

feature: update gateway api to v1beta1

6ec8da3366b197598b7f6075cc608949662c696f authored about 2 years ago
feature: update gateway api to v1beta1

Signed-off-by: lvyanru <[email protected]>

feature: update gateway api to v1beta1

Signed-of...

a13c76d3127f4bef2bb60716f1934c39b3d7ae5b authored about 2 years ago
Merge pull request #5613 from mmontes11/master

Return error when Gateway has a cross-namespace secret ref

3ed4621c02bfe7f461330694118d6a1602c2efcc authored about 2 years ago
e2e: use Vault 1.12.1 instead of the outdated 1.2.3

The main reason for bumping Vault's version is because 1.2.3 is not
compatible with the config p...

f4f72c16e64a217479c7785c0391c6cc46fc97e3 authored about 2 years ago
Return error when Gateway has a cross-namespace secret ref

Signed-off-by: Martín Montes <[email protected]>

f884dac55575bbdba962245a15a0ba72834d0950 authored about 2 years ago
Merge pull request #5570 from weisdd/feature/azure-workload-identity

feat(AzureDNS): Add support for Workload Identity

77c410f5cb99501e80dbdfcf8530a05610b165df authored about 2 years ago
Merge pull request #5605 from SgtCoDFish/normmake

Use distinct manifest dirs for signed / unsigned manifests

f85c8c98cb90f0ce7afafc461b22a5a44e44188e authored about 2 years ago
Use distinct manifest dirs for signed / unsigned manifests

This avoids a race condition with the `release-manifests` and
`release-manifests-signed` targets...

4d12251fa790f9cd7a242a07dcd0f3918f7eb1a7 authored about 2 years ago
Merge pull request #5587 from SpectralHiss/SpectralHiss/add-fields-to-subject-rdn

Add support for required LDAP (rfc4514) RDNs in LiteralSubject

43e13bfa0dce9184681621a7e85b769276e015fb authored about 2 years ago
Add boilerplate comment

Signed-off-by: SpectralHiss <[email protected]>

d56c51092a56cc7f3a1760923896aac73446ee47 authored about 2 years ago
Add error case + list all supported OIDs in cannonical order

Signed-off-by: SpectralHiss <[email protected]>

182275ed449a631add2064001910952e9fec031a authored about 2 years ago
Make test assertion more specific to slice, need to verify ordering of rdns

Signed-off-by: SpectralHiss <[email protected]>

410ac12c02a79ca1b9a67dd72f23f787a9045348 authored about 2 years ago
e2e test confirming LDAP rdn literalsubject in generated certificate

* Enabled feature flag for literalsubject in e2e test runner
* Added "happy path" test

Signed-o...

c7952fd054aeb6033f0418d8a7e7d2b81e10ff2b authored about 2 years ago
chore(AzureDNS): added more comments as requested by @wallrj

Signed-off-by: Igor Beliakov <[email protected]>

df20fcd3e40accfb4310617f42560afd9a56996d authored about 2 years ago
Merge pull request #5591 from wallrj/fix-vault-namespace-rjw

Set the Vault namespace using vault SDK client methods instead of using raw request object

d85e424cd0741bdb0fd4a5837d376c690e80fb9f authored about 2 years ago
Recreate the original behaviour of sending a Vault token to the unauthenticated sys/health endpoint.

Signed-off-by: Richard Wall <[email protected]>

e1740afedfb4fa18a1797242a06fb2134025a8b1 authored about 2 years ago
Test that the Sign function *does* use the Vault namespace

Signed-off-by: Richard Wall <[email protected]>

75b2ba12dc0e9437d3b2a6f4133572f194416ba0 authored about 2 years ago
Test

Signed-off-by: Richard Wall <[email protected]>

51ac6fe181fe95bc6714c7e53a8fb7c243af1a51 authored about 2 years ago
Remove unused Sys methods

Signed-off-by: Richard Wall <[email protected]>

23437dfbbcc87c42e74ffda88081c9a42ecb491d authored about 2 years ago
Remove unused Token method

Signed-off-by: Richard Wall <[email protected]>

6b2c3b5295a83bbac052c3ce01a1be1730aa566f authored about 2 years ago
Set the Vault namespace using the official method in the vault SDK

Signed-off-by: Richard Wall <[email protected]>

6e05f43f8e5beeacfe998a75b4987b9499257324 authored about 2 years ago
Gofmt files

Signed-off-by: Houssem El Fekih <[email protected]>

8af2d64f3b6374735b0204f173ceb78d066a30ff authored about 2 years ago
Add support for required LDAP (rfc4514) RDNs in LiteralSubject

* Add OID translation for mandatory DC component
* Used extensively in LDAP certificates, also r...

f41cf33efe24f99a7fe9a1cf890460ad76849fdc authored about 2 years ago
feat(AzureDNS): add a test for federated SPT

Signed-off-by: Igor Beliakov <[email protected]>

964f4bbd8d034fa997550878d37f49425a47dc7e authored about 2 years ago
Merge pull request #5584 from lvyanru8200/chartchange

fix: featureGates add webhook deployment in chart yaml

2884bee3f86329440d081de1cbaf937e634d2ccd authored about 2 years ago
fix: featureGates add webhook deployment in chart yaml

Signed-off-by: lvyanru <[email protected]>

bf2db73f71e2028534b70e413fce026f6ae0cc60 authored about 2 years ago
Merge pull request #5546 from cmcga1125/5295

Adding support to elevate acme-solver pod to root during testing

7df63ae94b251ff001ffe54d03f5a9729fc27d7c authored about 2 years ago
updating to match feedback and adjust the RunAsNonRoot options for http01 solver to be more descriptive

Signed-off-by: Corey McGalliard <[email protected]>

7e6e0940a2a4a31aa120a7980319cf2cd5ad0a1c authored about 2 years ago
Merge pull request #5571 from inteon/cleanup_csr_generation

Improve gen.CSR and use it in all tests

95dc198cd68220d6c792826c43b20fba018a12b7 authored about 2 years ago
Merge pull request #5571 from inteon/cleanup_csr_generation

Improve gen.CSR and use it in all tests

95dc198cd68220d6c792826c43b20fba018a12b7 authored about 2 years ago
fail in case of invalid IP address

Signed-off-by: Tim Ramlot <[email protected]>

c0dc705c24d3e0013f6da678b11282022233bba3 authored about 2 years ago
fail in case of invalid IP address

Signed-off-by: Tim Ramlot <[email protected]>

c0dc705c24d3e0013f6da678b11282022233bba3 authored about 2 years ago
Merge pull request #5573 from SgtCoDFish/basicConstraintsExt

Enable basicConstraints feature in e2e environments by default

6c5189c916dc17860680eb633fa8c7a4f40fa1b4 authored about 2 years ago
Merge pull request #5573 from SgtCoDFish/basicConstraintsExt

Enable basicConstraints feature in e2e environments by default

6c5189c916dc17860680eb633fa8c7a4f40fa1b4 authored about 2 years ago
enable basicConstraints feature in e2e environments by default

Signed-off-by: Ashley Davis <[email protected]>

d2aab5f0d3d060be747ec90a262bf478656ce3ab authored about 2 years ago
enable basicConstraints feature in e2e environments by default

Signed-off-by: Ashley Davis <[email protected]>

d2aab5f0d3d060be747ec90a262bf478656ce3ab authored about 2 years ago
Merge pull request #5552 from sathyanarays/isCaFix

Fixing CA flag in basic constraints extension

4ffd6213e7d835701a03c2aee7fc96694b998ee7 authored about 2 years ago
Merge pull request #5552 from sathyanarays/isCaFix

Fixing CA flag in basic constraints extension

4ffd6213e7d835701a03c2aee7fc96694b998ee7 authored about 2 years ago
Addressing review comments

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

860ba8465a9fc5f680743f1f7e3888f98573cfcc authored about 2 years ago
Addressing review comments

Signed-off-by: Sathyanarayanan Saravanamuthu <[email protected]>

860ba8465a9fc5f680743f1f7e3888f98573cfcc authored about 2 years ago
improve gen.CSR and use it everywhere

Signed-off-by: Tim Ramlot <[email protected]>

b9997498547e8143566a52258019748cdd6ced7d authored about 2 years ago