Reference Package catalog
cert-manager
Auto-generated from cert-manager package options. Do not edit by hand.
cainjector.extraArgs
Section titled “cainjector.extraArgs”Flags appended to the cainjector container’s arguments. A
repeated scalar flag such as --v takes the last value; list and map
flags such as --feature-gates accumulate. A flag the package
derives is refused, and the error says what to do instead.
Type: list of string
Default:
[ ]cainjector.image
Section titled “cainjector.image”Image of the CA injector.
Type: submodule
Default:
{ digest = "sha256:c85268c64f2e0e76684bf5fe8906caff34b82523561c6affe0fae3546bd87562"; pullPolicy = "IfNotPresent"; repository = "quay.io/jetstack/cert-manager-cainjector"; tag = config.image.tag;}cainjector.image.digest
Section titled “cainjector.image.digest”Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.
Type: null or string
Default:
the package’s digest while tag is the package’s tag, otherwise null
cainjector.image.note
Section titled “cainjector.image.note”Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.
Type: null or string
Default:
nullcainjector.image.promotedBy
Section titled “cainjector.image.promotedBy”Who resolved this pin, for the record. Null when unknown.
Type: null or string
Default:
nullcainjector.image.pullPolicy
Section titled “cainjector.image.pullPolicy”imagePullPolicy for containers using this image. Null leaves it to Kubernetes.
Type: null or string
Default:
"IfNotPresent"cainjector.image.repository
Section titled “cainjector.image.repository”Image repository, registry host included.
Type: string
Default:
"quay.io/jetstack/cert-manager-cainjector"cainjector.image.resolvedAt
Section titled “cainjector.image.resolvedAt”When this pin was resolved, RFC 3339. Null when unknown.
Type: null or string
Default:
nullcainjector.image.sourceRev
Section titled “cainjector.image.sourceRev”Revision of the source the image was built from, when Kix built it. Null for upstream images.
Type: null or string
Default:
nullcainjector.image.tag
Section titled “cainjector.image.tag”Image tag. What was asked for.
Type: string
Default:
config.image.tagcainjector.resources
Section titled “cainjector.resources”Resource requests and limits for the CA-injector container. The
512Mi memory limit suits a small cluster. cainjector’s cache grows
with the Secrets, CRDs, and webhook configurations it watches, so
raise limits.memory on a large one (cert-manager’s installation
best-practice guide, “Scalability”). Each field keeps its default
until set, and null removes a default.
Type: submodule
Default:
{ limits = { cpu = "500m"; memory = "512Mi"; }; requests = { cpu = "10m"; memory = "64Mi"; };}cainjector.resources.claims
Section titled “cainjector.resources.claims”Dynamic resource claims the container uses. Null leaves it unset.
Type: null or (list of (submodule))
Default:
nullcainjector.resources.claims.*.name
Section titled “cainjector.resources.claims.*.name”Name of an entry in the pod’s resourceClaims.
Type: string
cainjector.resources.claims.*.request
Section titled “cainjector.resources.claims.*.request”Request within the claim to use. Null uses the whole claim.
Type: null or string
Default:
nullcainjector.resources.limits
Section titled “cainjector.resources.limits”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }cainjector.resources.limits.cpu
Section titled “cainjector.resources.limits.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"500m"cainjector.resources.limits.ephemeral-storage
Section titled “cainjector.resources.limits.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullcainjector.resources.limits.memory
Section titled “cainjector.resources.limits.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"512Mi"cainjector.resources.requests
Section titled “cainjector.resources.requests”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }cainjector.resources.requests.cpu
Section titled “cainjector.resources.requests.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"10m"cainjector.resources.requests.ephemeral-storage
Section titled “cainjector.resources.requests.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullcainjector.resources.requests.memory
Section titled “cainjector.resources.requests.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"64Mi"Extra environment variables for the controller, such as
HTTPS_PROXY and NO_PROXY for ACME and DNS provider egress. A
value is a string, a fieldRef source, or a secretKeyRef source
naming a Secret managed outside Kix with kix.untrackedRef. The
package sets POD_NAMESPACE.
Type: attribute set of (null or string or env var source with `valueFrom`)
Default:
{ }extraArgs
Section titled “extraArgs”Flags appended to the controller container’s arguments, such as --dns01-recursive-nameservers=1.1.1.1:53, --dns01-recursive-nameservers-only, --enable-gateway-api, or --v=4. A
repeated scalar flag such as --v takes the last value; list and map
flags such as --feature-gates accumulate. A flag the package
derives is refused, and the error says what to do instead.
Type: list of string
Default:
[ ]Image of the controller. Its major.minor must match the vendored CRDs and RBAC; the other images follow its tag.
Type: submodule
Default:
{ digest = "sha256:70f532fd9cfde0b09d55687200942399d89838bc2d5d5b45152eb799a15912b8"; pullPolicy = "IfNotPresent"; repository = "quay.io/jetstack/cert-manager-controller"; tag = "v1.21.2";}image.digest
Section titled “image.digest”Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.
Type: null or string
Default:
the package’s digest while tag is the package’s tag, otherwise null
image.note
Section titled “image.note”Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.
Type: null or string
Default:
nullimage.promotedBy
Section titled “image.promotedBy”Who resolved this pin, for the record. Null when unknown.
Type: null or string
Default:
nullimage.pullPolicy
Section titled “image.pullPolicy”imagePullPolicy for containers using this image. Null leaves it to Kubernetes.
Type: null or string
Default:
"IfNotPresent"image.repository
Section titled “image.repository”Image repository, registry host included.
Type: string
Default:
"quay.io/jetstack/cert-manager-controller"image.resolvedAt
Section titled “image.resolvedAt”When this pin was resolved, RFC 3339. Null when unknown.
Type: null or string
Default:
nullimage.sourceRev
Section titled “image.sourceRev”Revision of the source the image was built from, when Kix built it. Null for upstream images.
Type: null or string
Default:
nullimage.tag
Section titled “image.tag”Image tag. What was asked for.
Type: string
Default:
"v1.21.2"metrics.enabled
Section titled “metrics.enabled”Enable metrics endpoint and monitoring resources (ServiceMonitor, PrometheusRules) when prometheus is available.
Type: boolean
Default:
truemetrics.interval
Section titled “metrics.interval”Scrape interval (e.g. “30s”). Null = use Prometheus default.
Type: null or string
Default:
nulloperandImages.acmesolver
Section titled “operandImages.acmesolver”Image of the ACME HTTP-01 solver pods the controller launches (--acme-http01-solver-image).
Type: submodule
Default:
{ digest = "sha256:699b40d622211ab7accad8a21b04c5fbaa1841ef7a12621e8de492dbe27b2503"; pullPolicy = "IfNotPresent"; repository = "quay.io/jetstack/cert-manager-acmesolver"; tag = config.image.tag;}operandImages.acmesolver.digest
Section titled “operandImages.acmesolver.digest”Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.
Type: null or string
Default:
the package’s digest while tag is the package’s tag, otherwise null
operandImages.acmesolver.note
Section titled “operandImages.acmesolver.note”Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.
Type: null or string
Default:
nulloperandImages.acmesolver.promotedBy
Section titled “operandImages.acmesolver.promotedBy”Who resolved this pin, for the record. Null when unknown.
Type: null or string
Default:
nulloperandImages.acmesolver.pullPolicy
Section titled “operandImages.acmesolver.pullPolicy”imagePullPolicy for containers using this image. Null leaves it to Kubernetes.
Type: null or string
Default:
"IfNotPresent"operandImages.acmesolver.repository
Section titled “operandImages.acmesolver.repository”Image repository, registry host included.
Type: string
Default:
"quay.io/jetstack/cert-manager-acmesolver"operandImages.acmesolver.resolvedAt
Section titled “operandImages.acmesolver.resolvedAt”When this pin was resolved, RFC 3339. Null when unknown.
Type: null or string
Default:
nulloperandImages.acmesolver.sourceRev
Section titled “operandImages.acmesolver.sourceRev”Revision of the source the image was built from, when Kix built it. Null for upstream images.
Type: null or string
Default:
nulloperandImages.acmesolver.tag
Section titled “operandImages.acmesolver.tag”Image tag. What was asked for.
Type: string
Default:
config.image.tagresources
Section titled “resources”Resource requests and limits for the controller container. The
512Mi memory limit suits a small cluster. The controller caches the
TLS Secrets its Certificates own, so its memory grows roughly with
their total size (cert-manager’s “Scaling cert-manager” guide); raise
limits.memory on a cluster with many certificates or large RSA keys.
Each field keeps its default until set, and null removes a default.
Type: submodule
Default:
{ limits = { cpu = "500m"; memory = "512Mi"; }; requests = { cpu = "10m"; memory = "64Mi"; };}resources.claims
Section titled “resources.claims”Dynamic resource claims the container uses. Null leaves it unset.
Type: null or (list of (submodule))
Default:
nullresources.claims.*.name
Section titled “resources.claims.*.name”Name of an entry in the pod’s resourceClaims.
Type: string
resources.claims.*.request
Section titled “resources.claims.*.request”Request within the claim to use. Null uses the whole claim.
Type: null or string
Default:
nullresources.limits
Section titled “resources.limits”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }resources.limits.cpu
Section titled “resources.limits.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"500m"resources.limits.ephemeral-storage
Section titled “resources.limits.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullresources.limits.memory
Section titled “resources.limits.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"512Mi"resources.requests
Section titled “resources.requests”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }resources.requests.cpu
Section titled “resources.requests.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"10m"resources.requests.ephemeral-storage
Section titled “resources.requests.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullresources.requests.memory
Section titled “resources.requests.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"64Mi"startupapicheck.image
Section titled “startupapicheck.image”Image of the API-check Job. Its pull policy follows the controller’s.
Type: submodule
Default:
{ digest = "sha256:46e75b6866359ffb5d82624f41e3ed1c70b2994982702ced547ce5edb418a8f5"; pullPolicy = "IfNotPresent"; repository = "quay.io/jetstack/cert-manager-startupapicheck"; tag = config.image.tag;}startupapicheck.image.digest
Section titled “startupapicheck.image.digest”Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.
Type: null or string
Default:
the package’s digest while tag is the package’s tag, otherwise null
startupapicheck.image.note
Section titled “startupapicheck.image.note”Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.
Type: null or string
Default:
nullstartupapicheck.image.promotedBy
Section titled “startupapicheck.image.promotedBy”Who resolved this pin, for the record. Null when unknown.
Type: null or string
Default:
nullstartupapicheck.image.pullPolicy
Section titled “startupapicheck.image.pullPolicy”imagePullPolicy for containers using this image. Null leaves it to Kubernetes.
Type: null or string
Default:
"IfNotPresent"startupapicheck.image.repository
Section titled “startupapicheck.image.repository”Image repository, registry host included.
Type: string
Default:
"quay.io/jetstack/cert-manager-startupapicheck"startupapicheck.image.resolvedAt
Section titled “startupapicheck.image.resolvedAt”When this pin was resolved, RFC 3339. Null when unknown.
Type: null or string
Default:
nullstartupapicheck.image.sourceRev
Section titled “startupapicheck.image.sourceRev”Revision of the source the image was built from, when Kix built it. Null for upstream images.
Type: null or string
Default:
nullstartupapicheck.image.tag
Section titled “startupapicheck.image.tag”Image tag. What was asked for.
Type: string
Default:
config.image.tagwebhook.extraArgs
Section titled “webhook.extraArgs”Flags appended to the webhook container’s arguments. A
repeated scalar flag such as --v takes the last value; list and map
flags such as --feature-gates accumulate. A flag the package
derives is refused, and the error says what to do instead.
Type: list of string
Default:
[ ]webhook.image
Section titled “webhook.image”Image of the admission webhook.
Type: submodule
Default:
{ digest = "sha256:a60e2dac46dbb8a7f3df95c54ce941012f54c2fe022f0ee55aaa1ab40ed957ae"; pullPolicy = "IfNotPresent"; repository = "quay.io/jetstack/cert-manager-webhook"; tag = config.image.tag;}webhook.image.digest
Section titled “webhook.image.digest”Resolved manifest digest, sha256: followed by 64 hex characters. What will actually run. Null means not resolved.
Type: null or string
Default:
the package’s digest while tag is the package’s tag, otherwise null
webhook.image.note
Section titled “webhook.image.note”Whatever a person wanted to say about this pin. Kix never reads it and a promotion never discards it. Declared here for the same reason as the three fields above: a pin carries its own record-keeping, and the option accepts the whole pin rather than a subset of it.
Type: null or string
Default:
nullwebhook.image.promotedBy
Section titled “webhook.image.promotedBy”Who resolved this pin, for the record. Null when unknown.
Type: null or string
Default:
nullwebhook.image.pullPolicy
Section titled “webhook.image.pullPolicy”imagePullPolicy for containers using this image. Null leaves it to Kubernetes.
Type: null or string
Default:
"IfNotPresent"webhook.image.repository
Section titled “webhook.image.repository”Image repository, registry host included.
Type: string
Default:
"quay.io/jetstack/cert-manager-webhook"webhook.image.resolvedAt
Section titled “webhook.image.resolvedAt”When this pin was resolved, RFC 3339. Null when unknown.
Type: null or string
Default:
nullwebhook.image.sourceRev
Section titled “webhook.image.sourceRev”Revision of the source the image was built from, when Kix built it. Null for upstream images.
Type: null or string
Default:
nullwebhook.image.tag
Section titled “webhook.image.tag”Image tag. What was asked for.
Type: string
Default:
config.image.tagwebhook.resources
Section titled “webhook.resources”Resource requests and limits for the webhook container. Each field keeps its default until set, and null removes a default.
Type: submodule
Default:
{ limits = { cpu = "200m"; memory = "128Mi"; }; requests = { cpu = "10m"; memory = "32Mi"; };}webhook.resources.claims
Section titled “webhook.resources.claims”Dynamic resource claims the container uses. Null leaves it unset.
Type: null or (list of (submodule))
Default:
nullwebhook.resources.claims.*.name
Section titled “webhook.resources.claims.*.name”Name of an entry in the pod’s resourceClaims.
Type: string
webhook.resources.claims.*.request
Section titled “webhook.resources.claims.*.request”Request within the claim to use. Null uses the whole claim.
Type: null or string
Default:
nullwebhook.resources.limits
Section titled “webhook.resources.limits”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }webhook.resources.limits.cpu
Section titled “webhook.resources.limits.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"200m"webhook.resources.limits.ephemeral-storage
Section titled “webhook.resources.limits.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullwebhook.resources.limits.memory
Section titled “webhook.resources.limits.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"128Mi"webhook.resources.requests
Section titled “webhook.resources.requests”Resource quantities by name.
Type: open submodule of attribute set of Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
{ }webhook.resources.requests.cpu
Section titled “webhook.resources.requests.cpu”The cpu quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"10m"webhook.resources.requests.ephemeral-storage
Section titled “webhook.resources.requests.ephemeral-storage”The ephemeral-storage quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
nullwebhook.resources.requests.memory
Section titled “webhook.resources.requests.memory”The memory quantity. Null leaves it unset.
Type: null or Kubernetes quantity, such as “500m” or “1Gi” (a non-negative decimal or integer with an optional suffix m, k, M, G, T, P, E, Ki, Mi, Gi, Ti, Pi or Ei)
Default:
"32Mi"webhook.securePort
Section titled “webhook.securePort”Port the webhook serves admission requests on. It sets
--secure-port, the containerPort, and the Service’s targetPort.
Change it where the kubelet holds 10250 on the pod network, as on
EKS Fargate.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
10250