cert-manager Operator for Red Hat OpenShift release notes¶
The cert-manager Operator for Red Hat OpenShift is a cluster-wide service that provides application certificate lifecycle management.
These release notes track the development of cert-manager Operator for Red Hat OpenShift.
For more information, see About the cert-manager Operator for Red Hat OpenShift.
cert-manager Operator for Red Hat OpenShift 1.20.1¶
Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.20.1 to learn what is new and updated with this release.
Issued: 28 September 2026
The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.20.1:
Version v1.20.1 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.20.4. For more information, see the cert-manager project release notes for v1.20.4.
CVEs¶
- CVE-2026-84445
- CVE-2026-73500
- CVE-2026-29181
- CVE-2026-46600
- CVE-2026-42508
- CVE-2026-39832
- CVE-2026-33818
- CVE-2026-56862
- CVE-2026-56858
- CVE-2026-56853
- CVE-2026-56859
- CVE-2026-56860
- CVE-2026-41178
- CVE-2026-56852
- CVE-2026-71235
cert-manager Operator for Red Hat OpenShift 1.20.0¶
Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.20.0 to learn what is new and updated with this release.
Issued: 2 July 2026
The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.20.0:
Version 1.20.0 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.20.3. For more information, see the cert-manager project release notes for v1.20.3.
New features and enhancements¶
Warning
TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.
- TrustManager Technology Preview no longer requires a cluster preview FeatureSet
-
With this release, the cert-manager Operator for Red Hat OpenShift no longer requires the
featuregates.config.openshift.io/clusterobject to use a previewFeatureSet, such asTechPreviewNoUpgrade, in order to enable the TrustManager Technology Preview operand.Previously, enabling TrustManager required both of the following conditions to be met:
- The cluster
FeatureSetmust be set to a preview value, such asTechPreviewNoUpgrade,DevPreviewNoUpgrade, orCustomNoUpgrade. - The Operator subscription must opt in to TrustManager by setting
UNSUPPORTED_ADDON_FEATURES=TrustManager=true.
Customers running clusters with the
DefaultFeatureSetwere unable to evaluate TrustManager without first switching the cluster to a previewFeatureSet, which is a disruptive, cluster-wide change that prevents upgrades.With this update, the cluster
FeatureSetrequirement is removed. Enabling TrustManager now requires only that the Operator subscription includesUNSUPPORTED_ADDON_FEATURES=TrustManager=true. TrustManager remains a Technology Preview feature and is disabled by default.For more information, see Enabling the TrustManager Operand.
- The cluster
- New performance-tuning override arguments for the cert-manager controller
-
With this release, the cert-manager Operator for Red Hat OpenShift supports configuring performance-tuning parameters for the cert-manager controller by using the
overrideArgsfield of theCertManagercustom resource (CR). Previously, users had to rely onspec.unsupportedConfigOverridesto tune these settings.You can now set the following arguments under
spec.controllerConfig.overrideArgs:--concurrent-workers: The number of concurrent workers for each controller. The default value is5.--kube-api-qps: The maximum number of queries per second sent to the Kubernetes API server. The default value is20.--kube-api-burst: The maximum burst of queries per second sent to the Kubernetes API server. Must be greater than or equal to--kube-api-qps. The default value is50.--max-concurrent-challenges: The maximum number of ACME challenges that can be scheduled as processing at the same time. The default value is60.
The Operator validates that
--kube-api-burstis greater than or equal to--kube-api-qpswhen both values are set. If this constraint is not met, the Operator sets theDegradedcondition on theCertManagerCR and does not apply the invalid configuration to the controller deployment.For more information, see Overridable arguments for the cert-manager components.
- Cluster TLS security profile applied to cert-manager operands
-
With this release, the cert-manager Operator for Red Hat OpenShift can read the cluster TLS security profile from the
apiserver.config.openshift.io/clusterobject and automatically apply the corresponding TLS configuration to the cert-manager controller, webhook, and CA injector deployments.Previously, the TLS configuration for cert-manager operands was not tied to the cluster-wide TLS security profile. Cluster administrators who configured a stricter TLS profile at the cluster level had no automated mechanism to propagate those settings to cert-manager operands, creating a gap in cluster-wide TLS posture enforcement.
With this update, when the
spec.tlsAdherencefield of theCertManagercustom resource (CR) is set toStrictAllComponents, the Operator reads thespec.tlsSecurityProfilevalue fromapiserver.config.openshift.io/clusterand applies the corresponding TLS arguments to the cert-manager operand deployments. The Operator reconciles the deployments whenever the cluster TLS profile changes.TLS arguments are applied per operand component as follows:
cert-manager-webhook: serving TLS flags and metrics endpoint TLS flags.cert-manager(controller): metrics endpoint TLS flags only.cert-manager-cainjector: metrics endpoint TLS flags only.
TLS profile enforcement is not yet supported for the IstioCSR and TrustManager operands.
To support this feature, the Operator now requires
get,list, andwatchpermissions on theapiserversresource in theconfig.openshift.ioAPI group.This feature is gated by the
TLSAdherencefeature gate. To use this feature, you must enable theTechPreviewNoUpgradefeature set. For more information, see Understanding feature gates.Note
Elliptic curve preferences are not configurable because cert-manager does not yet support specifying curve preferences upstream.
Warning
TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.
Fixed issues¶
- Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters with the Console capability disabled because the
ConsoleYAMLSampleresources were missing the required capability annotation. With this release, the Operator installs successfully on Console-less clusters. (OCPBUGS-85579)
cert-manager Operator for Red Hat OpenShift 1.19.2¶
Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.2 to learn what is new and updated with this release.
Issued: 3 September 2026
The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.2:
Version 1.19.2 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.19.6. For more information, see the cert-manager project release notes for v1.19.6.
CVEs¶
- CVE-2026-11822
- CVE-2026-11824
- CVE-2026-15588
- CVE-2026-1965
- CVE-2026-29181
- CVE-2026-3783
- CVE-2026-39883
- CVE-2026-46600
- CVE-2026-54371
- CVE-2026-56852
- CVE-2026-58010
- CVE-2026-58011
- CVE-2026-58012
- CVE-2026-58013
- CVE-2026-58014
- CVE-2026-58015
- CVE-2026-58055
- CVE-2026-8286
- CVE-2026-9547
cert-manager Operator for Red Hat OpenShift 1.19.1¶
Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.1 to learn what is new and updated with this release.
Issued: 13 August 2026
The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.1:
Version 1.19.1 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.19.6. For more information, see the cert-manager project release notes for v1.19.6.
Fixed issues¶
- Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters without the console capability because the OLM bundle included
ConsoleYAMLSampleandConsoleQuickStartresources that require theconsole.openshift.ioAPIs. With this release, the Operator creates the console resources at runtime only when the required APIs are available, ensuring successful installation. (OCPBUGS-85579)
CVEs¶
- CVE-2026-33186
- CVE-2026-46595
- CVE-2026-39821
- CVE-2026-39828
- CVE-2026-39830
- CVE-2026-42499
- CVE-2026-25681
- CVE-2026-39820
- CVE-2026-46597
- CVE-2026-27145
- CVE-2026-42504
- CVE-2026-27136
- CVE-2026-42502
cert-manager Operator for Red Hat OpenShift 1.19.0¶
Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.0 to learn what is new and updated with this release.
Issued: 20 April 2026
The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.0:
Version 1.19.0 of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version v1.19.4. For more information, see the cert-manager project release notes for v1.19.4.
New features and enhancements¶
- Distribution of trust bundles with the trust manager operand (Technology Preview)
- In this release, the cert-manager Operator for Red Hat OpenShift adds support for the trust-manager operand as a Technology Preview feature. You can now install the trust-manager operand to automate the secure distribution of trust bundles, such as certificate authority (CA) certificates, to application namespaces across your cluster. For more information, see Distributing certificates by using trust-manager operand.
- Support for configuring the certificate request backoff duration
- In this release, the cert-manager Operator for Red Hat OpenShift adds support for the
--certificate-request-minimum-backoff-durationflag. With this flag, you can configure the minimum backoff period for certificate requests by overriding the default configuration. For more information, see Overridable arguments for the cert-manager components.
Fixed issues¶
- Before this update, the ClusterIssuer form view lacked an option to remove the self-signed field. As a consequence, you could not create issuer types other than self-signed. With this release, the form view sets the certificate authority (CA) as the default issuer type. As a result, you can switch to other issuer types by using the form view. (OCPBUGS-65620)