jetstack/cert-manager v1.20.2 Weirdness And Mitigations

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This note records the Helm pain surfaced during catalog review and where the current ConfigHub/cub installer proof absorbs it.

Support Boundary

FieldValue
Catalog statuscatalog-supported
Support levelsupported-for-declared-scopes
Supported scopeslocal-test
Production readinessproduction-review-ready
Variants in this notedefault, crds-enabled

Production support is not implied by this file. A chart can be supported for local proof/demo use while still needing accepted scan, gate, lifecycle, and operating-policy dispositions plus a final target-scoped support decision.

Chart Notes

Catalog Mitigations

Control Points

Control pointStatusMitigation / evidence
source-lockhandledsource-lock.yaml
dependency-lockhandledchart has no subchart dependencies
capability-profilehandledrender is bound to the named Kubernetes capability profile even though this chart version does not branch on .Capabilities.
capability-profile-live-pruningstrict-live-object-parity-blocked-on-kubernetes-1.30cub-scout live witness on kind Kubernetes 1.30 found four rendered CRDs with spec.versions[0].selectableFields that were absent from the live CRDs after apply; workloads converged, but strict rendered-object/live parity is blocked until the capability/feature-gate route is decided.
crd-policyvariant-controlledCRDs are ordinary rendered objects only in the crds-enabled variant and still need lifecycle/upgrade policy.
hook-policyhandled-for-renderstartup API check Job is a Helm post-install hook and is excluded from the render proof; lifecycle policy must handle it before production.
admission-webhookscan-and-observerecorded in control-points.yaml
cluster-rbacscan-and-reviewscan receipts
tplcontrolled-by-empty-defaultsextraObjects uses tpl; promoted variants do not set that value.
installer-support-objecthandledv1\Namespace\\cert-manager

Control Point Index