jetstack/cert-manager@v1.20.2 Production Packet

A repository document, rendered for the site. View source markdown.

What this command does. cub installer is a released, open-source plugin for the cub CLI. cub installer setup pulls a catalog package and writes its Kubernetes files locally. It does not apply those files to a cluster; use kubectl, Argo CD, or Flux for delivery. The generated scripts stop before doing any work when the plugin or kustomize is missing.

New to cub? Install the cub CLI first. You can pull and render public catalog packages without an account. Commands that save or change ConfigHub data require you to sign in.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated packet summarizes the current support story for a hard chart. It is a navigation surface over existing evidence, not a new support decision.

Current Answer

FieldValue
Supported basecrds-enabled
Support decisionsupported
Production dispositionblocked
Target scopecub-lk-kind-vanilla; namespace=cert-manager; delivery=confighub-oci; controller=argo
Delivery pathconfighub-oci
Evidence count16
Strongest user-facing evidencelive-helm-vs-confighub-parity
Live summarylocal:2/2 gitops:2/2 live-parity:2/2 two-cluster:2/2

Why This Chart Is Hard

CRD-owning certificate controller with webhook readiness, startup API checks, lifecycle ordering, and issuer/certificate follow-on configuration.

What A User Can Safely Do Today

Use crds-enabled as the first supported base. Treat issuer/provider/hardened resource shapes as separate bases or derived variants with fresh target evidence.

What Remains Before Broader Production Use

Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate issuer, certificate, provider, or hardened resource bases for real customer certificate workloads.

Bases

BaseUser readinessLane summaryTarget factsCommand
crds-enabledstart-hererender=pass; confighub=pass; local=pass; gitops=pass; live-parity=pass; two-cluster=pass; lifecycle=passnonecub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/jetstack-cert-manager:v1.20.2 --base crds-enabled --work-dir <tmp> --non-interactive --namespace cert-manager
defaultstart-hererender=pass; confighub=pass; local=pass; gitops=pass; live-parity=pass; two-cluster=pass; lifecycle=passrequired CRD challenges.acme.cert-manager.io; required CRD orders.acme.cert-manager.io; required CRD certificaterequests.cert-manager.io; required CRD certificates.cert-manager.io; required CRD clusterissuers.cert-manager.io; required CRD issuers.cert-manager.iocub installer setup --pull oci://europe-west1-docker.pkg.dev/nth-fort-499605-q5/helm-expt/jetstack-cert-manager:v1.20.2 --base default --work-dir <tmp> --non-interactive --namespace cert-manager

Quirks And Inputs

FieldValue
Quirks surfacedextension-slots
User must providenothing beyond a cluster and namespace
ConfigHub / installer absorbsexact rendered objects with render parity and receipts; extension slots routed to reviewed bases
Extension slot routenone recorded

Decision Details

DecisionState
Image policymutable-image-exception-accepted-for-target-scope
Scan policyresource-policy-accepted-for-target-scope
Lifecycle policylifecycle-observed-for-proof-scope
Target factsno-unresolved-target-prerequisite-in-candidate-base
Live evidencefresh-target-evidence-passed

Regenerate:

npm run hard-charts:packets
npm run hard-charts:packets:verify