jetstack/cert-manager Production-Readiness Packet

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

Generated. Do not edit by hand. This packet answers the reviewer questions in one place and links the generated evidence; it makes no new claims. Companion navigation packet: hard-chart packet.

Why this chart matters

CRD-heavy controller with webhooks, CA injection, and controller-owned runtime state; the canonical case where 'synced' and 'working' diverge.

What should a serious user try first?

Base crds-enabled - support decision supported, disposition production-review-ready, bounded to target scope: cub-lk-kind-vanilla; namespace=cert-manager; delivery=confighub-oci; controller=argo.

Support decision evidence: fresh-target-evidence-passed (decision).

Quirks

extension-slots

You provide: nothing beyond a cluster and namespace. Absorbed for you: exact rendered objects with render parity and receipts; extension slots routed to reviewed bases.

What is at render parity?

Current lane status is derived from committed receipts and generated matrix rows. Authoritative per-lane rows: outcome coverage.

What is at live parity?

What is only watch, per-target, or manual?

What production support work remains?

The target-scoped support decision is supported. Keep the target-scoped evidence fresh before using this supported scope as a production-support example; create separate issuer, certificate, provider, or hardened resource bases for real customer certificate workloads.

Current work item: supported-scope-evidence - work items.

Claims we must not make yet

The exact next test

keep the target-scoped evidence fresh; create separate issuer, certificate, provider, or hardened resource bases before claiming real customer certificate workflows.