Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 11 additions & 4 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -57,9 +57,9 @@ endif
# --- Operand Versions ---

# Versions of the cert-manager components managed by this operator
CERT_MANAGER_VERSION ?= v1.19.2
ISTIO_CSR_VERSION ?= v0.15.0
TRUST_MANAGER_VERSION ?= "v0.20.3"
CERT_MANAGER_VERSION ?= v1.19.4
ISTIO_CSR_VERSION ?= v0.16.0
TRUST_MANAGER_VERSION ?= v0.20.3

# --- Test Versions ---

Expand Down Expand Up @@ -88,6 +88,9 @@ else
GOBIN := $(shell go env GOBIN)
endif

# Tool versions
YQ_VERSION := v4.52.4

# Tool binary paths (all built from vendor for consistency and performance)
CONTROLLER_GEN := $(BIN_DIR)/controller-gen
GOLANGCI_LINT := $(BIN_DIR)/golangci-lint
Expand All @@ -99,6 +102,7 @@ OPM := $(BIN_DIR)/opm
SETUP_ENVTEST := $(BIN_DIR)/setup-envtest
JSONNET := $(BIN_DIR)/jsonnet
GINKGO := $(BIN_DIR)/ginkgo
YQ = $(BIN_DIR)/yq

# ============================================================================
# Image Configuration
Expand Down Expand Up @@ -210,6 +214,7 @@ help: ## Display this help.
# Include the library makefiles
include $(addprefix ./vendor/github.com/openshift/build-machinery-go/make/, \
targets/openshift/bindata.mk \
targets/openshift/yq.mk \
)

# Generate bindata targets
Expand Down Expand Up @@ -430,7 +435,7 @@ govulncheck: $(GOVULNCHECK) $(OUTPUT_DIR) ## Run govulncheck vulnerability scan.
update: generate update-manifests update-bindata ## Update all generated code and manifests.

.PHONY: update-manifests
update-manifests: $(HELM) $(JSONNET) ## Update cert-manager and istio-csr operand manifests.
update-manifests: $(HELM) $(JSONNET) $(YQ) ## Update cert-manager and istio-csr operand manifests.
hack/update-cert-manager-manifests.sh $(CERT_MANAGER_VERSION)
hack/update-istio-csr-manifests.sh $(ISTIO_CSR_VERSION)
hack/update-trust-manager-manifests.sh $(TRUST_MANAGER_VERSION)
Expand Down Expand Up @@ -511,6 +516,8 @@ $(BIN_DIR):
$(OUTPUT_DIR):
@mkdir -p $(OUTPUT_DIR)

$(YQ): ensure-yq ## Download yq locally if necessary.

# Tools built from vendor
$(CONTROLLER_GEN): $(BIN_DIR) ## Build controller-gen from vendor.
$(call go-install-tool,$(CONTROLLER_GEN),sigs.k8s.io/controller-tools/cmd/controller-gen)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector
namespace: cert-manager
spec:
Expand All @@ -27,7 +27,7 @@ spec:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
spec:
containers:
- args:
Expand All @@ -40,7 +40,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: quay.io/jetstack/cert-manager-cainjector:v1.19.2
image: quay.io/jetstack/cert-manager-cainjector:v1.19.4
imagePullPolicy: IfNotPresent
name: cert-manager-cainjector
ports:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector:leaderelection
namespace: kube-system
roleRef:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector:leaderelection
namespace: kube-system
rules:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,6 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector
namespace: cert-manager
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cainjector
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cainjector
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-cainjector
namespace: cert-manager
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cert-manager
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-approve:cert-manager-io
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cert-manager
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-approve:cert-manager-io
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cert-manager
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-certificatesigningrequests
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: cert-manager
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-certificatesigningrequests
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
rbac.authorization.k8s.io/aggregate-to-cluster-reader: "true"
name: cert-manager-cluster-view
rules:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-certificates
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-certificates
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-challenges
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-challenges
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-clusterissuers
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-clusterissuers
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-ingress-shim
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-ingress-shim
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-issuers
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-issuers
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-orders
rules:
- apiGroups:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-controller-orders
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager
namespace: cert-manager
spec:
Expand All @@ -27,14 +27,14 @@ spec:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
spec:
containers:
- args:
- --v=2
- --cluster-resource-namespace=$(POD_NAMESPACE)
- --leader-election-namespace=kube-system
- --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.2
- --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.4
- --max-concurrent-challenges=60
- --feature-gates=ACMEHTTP01IngressPathTypeExact=false
command:
Expand All @@ -44,7 +44,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: quay.io/jetstack/cert-manager-controller:v1.19.2
image: quay.io/jetstack/cert-manager-controller:v1.19.4
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
rbac.authorization.k8s.io/aggregate-to-admin: "true"
rbac.authorization.k8s.io/aggregate-to-edit: "true"
name: cert-manager-edit
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager:leaderelection
namespace: kube-system
roleRef:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager:leaderelection
namespace: kube-system
rules:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,6 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager
namespace: cert-manager
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager
namespace: cert-manager
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-tokenrequest
namespace: cert-manager
roleRef:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
name: cert-manager-tokenrequest
namespace: cert-manager
rules:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: cert-manager
app.kubernetes.io/name: cert-manager
app.kubernetes.io/version: v1.19.2
app.kubernetes.io/version: v1.19.4
rbac.authorization.k8s.io/aggregate-to-admin: "true"
rbac.authorization.k8s.io/aggregate-to-cluster-reader: "true"
rbac.authorization.k8s.io/aggregate-to-edit: "true"
Expand Down
Loading