Skip to content
kix /docs
Install the CLI

Reference Package catalog

cert-manager

Auto-generated from cert-manager package options. Do not edit by hand.

Flags appended to the cainjector container’s arguments. A repeated scalar flag such as --v takes the last value; list and map flags such as --feature-gates accumulate. A flag the package derives is refused, and the error says what to do instead.

Type: list of string

Default:

[ ]

Image of the CA injector.

Type: submodule

Default:

{
digest = "sha256:c85268c64f2e0e76684bf5fe8906caff34b82523561c6affe0fae3546bd87562";
pullPolicy = "IfNotPresent";
repository = "quay.io/jetstack/cert-manager-cainjector";
tag = config.image.tag;
}

Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.

Type: null or string

Default: the package’s digest while tag is the package’s tag, otherwise null

Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.

Type: null or string

Default:

null

Who resolved this pin, for the record. Null when unknown.

Type: null or string

Default:

null

imagePullPolicy for containers using this image. Null leaves it to Kubernetes.

Type: null or string

Default:

"IfNotPresent"

Image repository, registry host included.

Type: string

Default:

"quay.io/jetstack/cert-manager-cainjector"

When this pin was resolved, RFC 3339. Null when unknown.

Type: null or string

Default:

null

Revision of the source the image was built from, when Kix built it. Null for upstream images.

Type: null or string

Default:

null

Image tag. What was asked for.

Type: string

Default:

config.image.tag

Resource requests and limits for the CA-injector container. The 512Mi memory limit suits a small cluster. cainjector’s cache grows with the Secrets, CRDs, and webhook configurations it watches, so raise limits.memory on a large one (cert-manager’s installation best-practice guide, “Scalability”). Each field keeps its default until set, and null removes a default.

Type: submodule

Default:

{
limits = {
cpu = "500m";
memory = "512Mi";
};
requests = {
cpu = "10m";
memory = "64Mi";
};
}

Dynamic resource claims the container uses. Null leaves it unset.

Type: null or (list of (submodule))

Default:

null

Name of an entry in the pod’s resourceClaims.

Type: string

Request within the claim to use. Null uses the whole claim.

Type: null or string

Default:

null

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"500m"

cainjector.resources.limits.ephemeral-storage

Section titled “cainjector.resources.limits.ephemeral-storage”

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"512Mi"

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"10m"

cainjector.resources.requests.ephemeral-storage

Section titled “cainjector.resources.requests.ephemeral-storage”

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"64Mi"

Extra environment variables for the controller, such as HTTPS_PROXY and NO_PROXY for ACME and DNS provider egress. A value is a string, a fieldRef source, or a secretKeyRef source naming a Secret managed outside Kix with kix.untrackedRef. The package sets POD_NAMESPACE.

Type: attribute set of (null or string or env var source with `valueFrom`)

Default:

{ }

Flags appended to the controller container’s arguments, such as --dns01-recursive-nameservers=1.1.1.1:53, --dns01-recursive-nameservers-only, --enable-gateway-api, or --v=4. A repeated scalar flag such as --v takes the last value; list and map flags such as --feature-gates accumulate. A flag the package derives is refused, and the error says what to do instead.

Type: list of string

Default:

[ ]

Image of the controller. Its major.minor must match the vendored CRDs and RBAC; the other images follow its tag.

Type: submodule

Default:

{
digest = "sha256:70f532fd9cfde0b09d55687200942399d89838bc2d5d5b45152eb799a15912b8";
pullPolicy = "IfNotPresent";
repository = "quay.io/jetstack/cert-manager-controller";
tag = "v1.21.2";
}

Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.

Type: null or string

Default: the package’s digest while tag is the package’s tag, otherwise null

Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.

Type: null or string

Default:

null

Who resolved this pin, for the record. Null when unknown.

Type: null or string

Default:

null

imagePullPolicy for containers using this image. Null leaves it to Kubernetes.

Type: null or string

Default:

"IfNotPresent"

Image repository, registry host included.

Type: string

Default:

"quay.io/jetstack/cert-manager-controller"

When this pin was resolved, RFC 3339. Null when unknown.

Type: null or string

Default:

null

Revision of the source the image was built from, when Kix built it. Null for upstream images.

Type: null or string

Default:

null

Image tag. What was asked for.

Type: string

Default:

"v1.21.2"

Enable metrics endpoint and monitoring resources (ServiceMonitor, PrometheusRules) when prometheus is available.

Type: boolean

Default:

true

Scrape interval (e.g. “30s”). Null = use Prometheus default.

Type: null or string

Default:

null

Image of the ACME HTTP-01 solver pods the controller launches (--acme-http01-solver-image).

Type: submodule

Default:

{
digest = "sha256:699b40d622211ab7accad8a21b04c5fbaa1841ef7a12621e8de492dbe27b2503";
pullPolicy = "IfNotPresent";
repository = "quay.io/jetstack/cert-manager-acmesolver";
tag = config.image.tag;
}

Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.

Type: null or string

Default: the package’s digest while tag is the package’s tag, otherwise null

Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.

Type: null or string

Default:

null

Who resolved this pin, for the record. Null when unknown.

Type: null or string

Default:

null

imagePullPolicy for containers using this image. Null leaves it to Kubernetes.

Type: null or string

Default:

"IfNotPresent"

Image repository, registry host included.

Type: string

Default:

"quay.io/jetstack/cert-manager-acmesolver"

When this pin was resolved, RFC 3339. Null when unknown.

Type: null or string

Default:

null

Revision of the source the image was built from, when Kix built it. Null for upstream images.

Type: null or string

Default:

null

Image tag. What was asked for.

Type: string

Default:

config.image.tag

Resource requests and limits for the controller container. The 512Mi memory limit suits a small cluster. The controller caches the TLS Secrets its Certificates own, so its memory grows roughly with their total size (cert-manager’s “Scaling cert-manager” guide); raise limits.memory on a cluster with many certificates or large RSA keys. Each field keeps its default until set, and null removes a default.

Type: submodule

Default:

{
limits = {
cpu = "500m";
memory = "512Mi";
};
requests = {
cpu = "10m";
memory = "64Mi";
};
}

Dynamic resource claims the container uses. Null leaves it unset.

Type: null or (list of (submodule))

Default:

null

Name of an entry in the pod’s resourceClaims.

Type: string

Request within the claim to use. Null uses the whole claim.

Type: null or string

Default:

null

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"500m"

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"512Mi"

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"10m"

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"64Mi"

Image of the API-check Job. Its pull policy follows the controller’s.

Type: submodule

Default:

{
digest = "sha256:46e75b6866359ffb5d82624f41e3ed1c70b2994982702ced547ce5edb418a8f5";
pullPolicy = "IfNotPresent";
repository = "quay.io/jetstack/cert-manager-startupapicheck";
tag = config.image.tag;
}

Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.

Type: null or string

Default: the package’s digest while tag is the package’s tag, otherwise null

Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.

Type: null or string

Default:

null

Who resolved this pin, for the record. Null when unknown.

Type: null or string

Default:

null

imagePullPolicy for containers using this image. Null leaves it to Kubernetes.

Type: null or string

Default:

"IfNotPresent"

Image repository, registry host included.

Type: string

Default:

"quay.io/jetstack/cert-manager-startupapicheck"

When this pin was resolved, RFC 3339. Null when unknown.

Type: null or string

Default:

null

Revision of the source the image was built from, when Kix built it. Null for upstream images.

Type: null or string

Default:

null

Image tag. What was asked for.

Type: string

Default:

config.image.tag

Flags appended to the webhook container’s arguments. A repeated scalar flag such as --v takes the last value; list and map flags such as --feature-gates accumulate. A flag the package derives is refused, and the error says what to do instead.

Type: list of string

Default:

[ ]

Image of the admission webhook.

Type: submodule

Default:

{
digest = "sha256:a60e2dac46dbb8a7f3df95c54ce941012f54c2fe022f0ee55aaa1ab40ed957ae";
pullPolicy = "IfNotPresent";
repository = "quay.io/jetstack/cert-manager-webhook";
tag = config.image.tag;
}

Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.

Type: null or string

Default: the package’s digest while tag is the package’s tag, otherwise null

Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.

Type: null or string

Default:

null

Who resolved this pin, for the record. Null when unknown.

Type: null or string

Default:

null

imagePullPolicy for containers using this image. Null leaves it to Kubernetes.

Type: null or string

Default:

"IfNotPresent"

Image repository, registry host included.

Type: string

Default:

"quay.io/jetstack/cert-manager-webhook"

When this pin was resolved, RFC 3339. Null when unknown.

Type: null or string

Default:

null

Revision of the source the image was built from, when Kix built it. Null for upstream images.

Type: null or string

Default:

null

Image tag. What was asked for.

Type: string

Default:

config.image.tag

Resource requests and limits for the webhook container. Each field keeps its default until set, and null removes a default.

Type: submodule

Default:

{
limits = {
cpu = "200m";
memory = "128Mi";
};
requests = {
cpu = "10m";
memory = "32Mi";
};
}

Dynamic resource claims the container uses. Null leaves it unset.

Type: null or (list of (submodule))

Default:

null

Name of an entry in the pod’s resourceClaims.

Type: string

Request within the claim to use. Null uses the whole claim.

Type: null or string

Default:

null

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"200m"

webhook.resources.limits.ephemeral-storage

Section titled “webhook.resources.limits.ephemeral-storage”

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"128Mi"

Resource quantities by name.

Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

{ }

The cpu quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"10m"

webhook.resources.requests.ephemeral-storage

Section titled “webhook.resources.requests.ephemeral-storage”

The ephemeral-storage quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

null

The memory quantity. Null leaves it unset.

Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)

Default:

"32Mi"

Port the webhook serves admission requests on. It sets --secure-port, the containerPort, and the Service’s targetPort. Change it where the kubelet holds 10250 on the pod network, as on EKS Fargate.

Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)

Default:

10250