Commit Graph

3462 Commits

Author SHA1 Message Date
Nicolas Fischer
aefa3c9660 add securityContext.enabled deprecation doc to the design folder
Signed-off-by: Nicolas Fischer <nicolas@emberspark.io>
2020-01-10 10:15:42 +00:00
Nicolas Fischer
3b838758a3 support an arbitrary SecurityContext block for the main deployment
Signed-off-by: Nicolas Fischer <nicolas@emberspark.io>
2020-01-10 10:15:42 +00:00
jetstack-bot
b7390818af
Merge pull request #2489 from czunker/fix_2293
Add configuration switch for use of apparmor in PSP
2020-01-09 15:14:13 +00:00
jetstack-bot
3ec12c3534
Merge pull request #2481 from cpu/cpu-use-upstream-pebble-v2.3.0
Use upstream Pebble v2.3.0 for E2E tests.
2020-01-09 12:04:14 +00:00
Christian Zunker
7f5ac29d2f Add configuration switch for use of apparmor in PSP
Fixes #2293

Signed-off-by: Christian Zunker <christian.zunker@codecentric.cloud>
2020-01-08 06:42:28 +01:00
Daniel
ecb250ce9d
Merge remote-tracking branch 'jetstack/master' into cpu-use-upstream-pebble-v2.3.0
Signed-off-by: Daniel McCarney cpu@letsencrypt.org
2020-01-07 09:35:02 -05:00
jetstack-bot
9ca34f773f
Merge pull request #2470 from munnerz/remove-misleading-errors
Don't log misleading error messages
2020-01-07 14:24:19 +00:00
jetstack-bot
66d45afcdb
Merge pull request #2501 from munnerz/update-codegen-year
Bump generated files copyright header year
2020-01-07 13:32:18 +00:00
James Munnelly
d3b785c263 Bump generated files copyright header year
Signed-off-by: James Munnelly <james@munnelly.eu>
2020-01-07 12:43:44 +00:00
Daniel
6a775423c3
Use upstream Pebble v2.3.0 for E2E tests.
This is a follow-up from 0f196a5 which temporarily switched the Pebble
image to a fork. The required functionality landed in the upstream
v2.3.0 release and so the E2E tests can be switched back to the
upstream repo.

Signed-off-by: Daniel McCarney <cpu@letsencrypt.org>
2019-12-18 15:05:02 -05:00
jetstack-bot
8d6e86468d
Merge pull request #2460 from greywolve/fix-ensure-ingress-for-service-name-changing
ACME HTTP01 solver: clean up ingresses if the service name changes
2019-12-17 15:35:09 +00:00
jetstack-bot
8809f7e031
Merge pull request #2469 from munnerz/temp-certs-dont-overwrite
Don't overwrite existing certificates when issuing a temporary certificate
2019-12-17 14:30:09 +00:00
James Munnelly
361fdfac3f Don't log misleading error messages
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-16 16:31:18 +00:00
James Munnelly
9daad6dd93 Update tests to ensure temporary certificates are not re-issued when dnsNames mismatch
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-16 15:11:07 +00:00
James Munnelly
7076041de6 Don't overwrite existing certificates when issuing a temporary certificate
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-16 13:53:38 +00:00
jetstack-bot
dc9b4766e9
Merge pull request #2467 from munnerz/webhook-ticker
webhook: don't use time.Tick to prevent leaks
2019-12-16 13:19:17 +00:00
James Munnelly
df27fff9ce Don't use time.Tick to prevent leaks
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-16 12:45:49 +00:00
jetstack-bot
45785999f9
Merge pull request #2465 from munnerz/v0130alpha
Bump Helm chart strings for v0.13.0-alpha.0
2019-12-16 11:16:17 +00:00
James Munnelly
ff8ebef492 Bump Helm chart strings for v0.13.0-alpha.0
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-16 09:29:50 +00:00
Oliver Powell
7611f78793 ACME HTTP01 solver: clean up ingresses if the service name changes
Signed-off-by: Oliver Powell <oliver@opowell.com>
2019-12-14 10:05:51 +02:00
jetstack-bot
b365021dc8
Merge pull request #2428 from haines/remove-nameserver-ip-address-validation
Remove IP address validation on dns01-recursive-nameservers to allow domain names
2019-12-12 16:31:14 +00:00
jetstack-bot
adce70f649
Merge pull request #2436 from ttarczynski/patch-1
Bump default 'image.tag' value in helm chart README.md
2019-12-12 15:32:15 +00:00
jetstack-bot
02ee550c5d
Merge pull request #2447 from UKHomeOffice/issue-2443
issue 2443 - annotations for cert-manager deployments
2019-12-11 16:41:33 +00:00
jetstack-bot
90bf960c1e
Merge pull request #2450 from munnerz/webhook-pprof
webhook: register http handlers for pprof debug endpoints
2019-12-11 15:59:33 +00:00
Nicolas Fischer
f8c83a1411 issue 2443 - annotations for cert-manager deployments
Signed-off-by: Nicolas Fischer <nicolas@emberspark.io>
2019-12-11 15:37:21 +00:00
jetstack-bot
6544ab93c5
Merge pull request #2449 from UKHomeOffice/issue-2448
issue 2448 - Optional securityContext for cainjector and webhook char…
2019-12-11 15:27:32 +00:00
jetstack-bot
9d95d2b4dd
Merge pull request #2392 from JoshVanL/acme-external-account-binding
acme: external account binding support
2019-12-11 14:53:56 +00:00
James Munnelly
ff8c68348a Update checks.go for external account bindings
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:37:36 +00:00
James Munnelly
5c4e27830f Use enum for HMAC algorithm field
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly
3f212844a7 Fix apiext.JSON fuzzer
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly
fd306c538c acme: Add support for external account binding
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly
4930a0e8d8 Add end-to-end tests using EAB
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly
0f196a57dc Use forked pebble with support for EABs
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 12:28:49 +00:00
James Munnelly
861e0f95c6 Use fork of x/crypto with support for EAB
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 10:37:16 +00:00
James Munnelly
80bc253d74 acme: Add API fields for ExternalAccountBinding
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-11 10:37:16 +00:00
jetstack-bot
4073080089
Merge pull request #2416 from munnerz/fixup-expiry-metrics
Fix certificate controller expiry metrics
2019-12-10 17:25:15 +00:00
jetstack-bot
901d7e05f5
Merge pull request #2422 from munnerz/x-crypto-acmev2
Switch to using upstream golang.org/x/crypto
2019-12-10 16:56:15 +00:00
James Munnelly
f3a58ed991 webhook: register pprof http handlers
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-10 16:54:15 +00:00
Nicolas Fischer
b574c4f16d issue 2448 - Optional securityContext for cainjector and webhook chart deployments
Signed-off-by: Nicolas Fischer <nicolas@emberspark.io>
2019-12-10 16:12:47 +00:00
jetstack-bot
667c7e2a61
Merge pull request #2427 from munnerz/pebble-upgrade
Upgrade to Pebble containing letsencrypt/pebble#294
2019-12-10 16:02:15 +00:00
jetstack-bot
e6bf2c0ace
Merge pull request #2383 from colek42/fix-2375-falsy-fields
Fixes false/null fields in the helm chart.
2019-12-10 12:15:14 +00:00
Tomasz Tarczynski
6c97c2472e
Bump devault image.tag value in README.md
I think the default value of `image.tag` is now `v0.12.0`
2019-12-06 12:24:32 +01:00
Andrew Haines
3edb4c3c6c
Remove IP address validation on dns01-recursive-nameservers to allow domain names
Signed-off-by: Andrew Haines <andrew@haines.org.nz>
2019-12-05 13:34:55 +00:00
James Munnelly
dc95d9597d Upgrade to Pebble containing letsencrypt/pebble#294
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-05 12:22:50 +00:00
Cole Kennedy
036d6ea4aa This commit fixes false/null fields in the helm charts
Signed-off-by: Cole Kennedy <colek42@gmail.com>

Signed-off-by: Cole Kennedy <colek42@gmail.com>
2019-12-04 09:25:27 -06:00
James Munnelly
1f3b883cfd Don't overwrite order.status.url if return Order's URI is empty
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-03 16:49:31 +00:00
James Munnelly
9d28261da5 Properly handle ErrNoAccount
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-03 16:49:31 +00:00
James Munnelly
641fe0da7c Switch to using upstream golang.org/x/crypto
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-12-03 16:49:31 +00:00
James Munnelly
698e7a522a Fix certificate controller expiry metrics
Signed-off-by: James Munnelly <james@munnelly.eu>
2019-11-29 18:29:23 +00:00
jetstack-bot
ba354e4078
Merge pull request #2410 from munnerz/fixup-redirects
Fixup redirects to point to cert-manager.io
2019-11-28 14:17:29 +00:00