cert-manager Operator for Red Hat OpenShift release notes
Esc
Start typing to search...
On this page

cert-manager Operator for Red Hat OpenShift release notes

The cert-manager Operator for Red Hat OpenShift is a cluster-wide service that provides application certificate lifecycle management.

These release notes track the development of cert-manager Operator for Red Hat OpenShift.

For more information, see About the cert-manager Operator for Red Hat OpenShift.

cert-manager Operator for Red Hat OpenShift 1.20.0

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.20.0 to learn what is new and updated with this release.

Issued: 2 July 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.20.0:

Version v1.20.0 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.20.3. For more information, see the cert-manager project release notes for v1.20.3.

New features and enhancements

Important

TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.

For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.

TrustManager Technology Preview no longer requires a cluster preview FeatureSet

With this release, the cert-manager Operator for Red Hat OpenShift no longer requires the featuregates.config.openshift.io/cluster object to use a preview FeatureSet, such as TechPreviewNoUpgrade, in order to enable the TrustManager Technology Preview operand.

Previously, enabling TrustManager required both of the following conditions to be met:

  • The cluster FeatureSet must be set to a preview value, such as TechPreviewNoUpgrade, DevPreviewNoUpgrade, or CustomNoUpgrade.
  • The Operator subscription must opt in to TrustManager by setting UNSUPPORTED_ADDON_FEATURES=TrustManager=true.

Customers running clusters with the Default FeatureSet were unable to evaluate TrustManager without first switching the cluster to a preview FeatureSet, which is a disruptive, cluster-wide change that prevents upgrades.

With this update, the cluster FeatureSet requirement is removed. Enabling TrustManager now requires only that the Operator subscription includes UNSUPPORTED_ADDON_FEATURES=TrustManager=true. TrustManager remains a Technology Preview feature and is disabled by default.

For more information, see Enabling the TrustManager Operand.

New performance-tuning override arguments for the cert-manager controller

With this release, the cert-manager Operator for Red Hat OpenShift supports configuring performance-tuning parameters for the cert-manager controller by using the overrideArgs field of the CertManager custom resource (CR). Previously, users had to rely on spec.unsupportedConfigOverrides to tune these settings.

You can now set the following arguments under spec.controllerConfig.overrideArgs:

  • --concurrent-workers: The number of concurrent workers for each controller. The default value is 5.
  • --kube-api-qps: The maximum number of queries per second sent to the Kubernetes API server. The default value is 20.
  • --kube-api-burst: The maximum burst of queries per second sent to the Kubernetes API server. Must be greater than or equal to --kube-api-qps. The default value is 50.
  • --max-concurrent-challenges: The maximum number of ACME challenges that can be scheduled as processing at the same time. The default value is 60.

The Operator validates that --kube-api-burst is greater than or equal to --kube-api-qps when both values are set. If this constraint is not met, the Operator sets the Degraded condition on the CertManager CR and does not apply the invalid configuration to the controller deployment.

For more information, see Overridable arguments for the cert-manager components.

Cluster TLS security profile applied to cert-manager operands

With this release, the cert-manager Operator for Red Hat OpenShift can read the cluster TLS security profile from the apiserver.config.openshift.io/cluster object and automatically apply the corresponding TLS configuration to the cert-manager controller, webhook, and CA injector deployments.

Previously, the TLS configuration for cert-manager operands was not tied to the cluster-wide TLS security profile. Cluster administrators who configured a stricter TLS profile at the cluster level had no automated mechanism to propagate those settings to cert-manager operands, creating a gap in cluster-wide TLS posture enforcement.

With this update, when the spec.tlsAdherence field of the CertManager custom resource (CR) is set to StrictAllComponents, the Operator reads the spec.tlsSecurityProfile value from apiserver.config.openshift.io/cluster and applies the corresponding TLS arguments to the cert-manager operand deployments. The Operator reconciles the deployments whenever the cluster TLS profile changes.

TLS arguments are applied per operand component as follows:

  • cert-manager-webhook: serving TLS flags and metrics endpoint TLS flags.
  • cert-manager (controller): metrics endpoint TLS flags only.
  • cert-manager-cainjector: metrics endpoint TLS flags only.

TLS profile enforcement is not yet supported for the IstioCSR and TrustManager operands.

To support this feature, the Operator now requires get, list, and watch permissions on the apiservers resource in the config.openshift.io API group.

This feature is gated by the TLSAdherence feature gate. To use this feature, you must enable the TechPreviewNoUpgrade feature set. For more information, see Understanding feature gates.

Note

Elliptic curve preferences are not configurable because cert-manager does not yet support specifying curve preferences upstream.

Important

TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.

For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.

Fixed issues

  • Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters with the Console capability disabled because the ConsoleYAMLSample resources were missing the required capability annotation. With this release, the Operator installs successfully on Console-less clusters. (OCPBUGS-85579)

cert-manager Operator for Red Hat OpenShift 1.19.1

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.1 to learn what is new and updated with this release.

Issued: 13 August 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.1:

Version v1.19.6 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.19.6. For more information, see the cert-manager project release notes for v1.19.6.

Fixed issues

  • Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters without the console capability because the OLM bundle included ConsoleYAMLSample and ConsoleQuickStart resources that require the console.openshift.io APIs. With this release, the Operator creates the console resources at runtime only when the required APIs are available, ensuring successful installation. (OCPBUGS-85579)

CVEs

cert-manager Operator for Red Hat OpenShift 1.19.0

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.0 to learn what is new and updated with this release.

Issued: 20 April 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.0:

Version v1.19.4 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.19.4. For more information, see the cert-manager project release notes for v1.19.4.

New features and enhancements

Distribution of trust bundles with the trust manager operand (Technology Preview)

In this release, the cert-manager Operator for Red Hat OpenShift adds support for the trust-manager operand as a Technology Preview feature. You can now install the trust-manager operand to automate the secure distribution of trust bundles, such as certificate authority (CA) certificates, to application namespaces across your cluster. For more information, see Distributing certificates by using trust-manager operand.

Support for configuring the certificate request backoff duration

In this release, the cert-manager Operator for Red Hat OpenShift adds support for the --certificate-request-minimum-backoff-duration flag. With this flag, you can configure the minimum backoff period for certificate requests by overriding the default configuration. For more information, see Overridable arguments for the cert-manager components.

Fixed issues

  • Before this update, the ClusterIssuer form view lacked an option to remove the self-signed field. As a consequence, you could not create issuer types other than self-signed. With this release, the form view sets the certificate authority (CA) as the default issuer type. As a result, you can switch to other issuer types by using the form view. (OCPBUGS-65620)