feat(base-cluster/cert-manager): use oci repository#1650
Conversation
WalkthroughThe repository URL for the "jetstack" Helm chart source was switched from an HTTPS URL to an OCI registry URL, and the "cert-manager" chart version string was updated from "1.17.2" to "v1.17.2" in the Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Suggested labels
Suggested reviewers
Poem
Note ⚡️ Unit Test Generation is now available in beta!Learn more here, or try it out under "Finishing Touches" below. 📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (1)
🧰 Additional context used🧠 Learnings (6)📓 Common learnings📚 Learning: in the teutonet-helm-charts base-cluster chart, secret names like "external-dns" for cloudflare prov...Applied to files:
📚 Learning: official helm charts like oauth2-proxy manage image versioning automatically through their chart.yam...Applied to files:
📚 Learning: the official kubernetes-sigs/metrics-server helm chart pins the image tag to a specific version in i...Applied to files:
📚 Learning: in charts/base-cluster/templates/dns/external-dns.yaml, the dns.provider field in values.yaml has al...Applied to files:
📚 Learning: the kubernetes-sigs/metrics-server helm chart uses `v{{ .chart.appversion }}` as the default image t...Applied to files:
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
🔇 Additional comments (1)
✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Pull Request Overview
This PR updates the cert-manager Helm chart configuration to use the OCI (Open Container Initiative) registry instead of the traditional Helm chart repository, following the official cert-manager documentation recommendation.
- Migrates from HTTPS-based Helm repository to OCI registry at quay.io
- Updates cert-manager version format to include 'v' prefix as required by OCI registry
🤖 I have created a release *beep* *boop* --- ## [9.2.0](base-cluster-v9.1.1...base-cluster-v9.2.0) (2025-08-14) ### Features * **base-cluster/cert-manager:** enableCertificateOwnerRef ([#1653](#1653)) ([283d86f](283d86f)) * **base-cluster/cert-manager:** use oci repository ([#1650](#1650)) ([ef6382d](ef6382d)) * **base-cluster/kyverno:** enable policyExceptions for kyverno ([#1655](#1655)) ([2029bcb](2029bcb)) ### Bug Fixes * **base-cluster/certificates:** certificate for `baseDomain` is not used ([#1644](#1644)) ([6a3ccae](6a3ccae)) * **base-cluster/dns:** only deploy external-dns HelmRepository if needed ([#1645](#1645)) ([7d313f2](7d313f2)) * **base-cluster/ingress-nginx:** set a couple of timeouts in the loadbalancer to the maximum value ([#1571](#1571)) ([bc6fe78](bc6fe78)) * **base-cluster/monitoring:** remove versions from datasources so they always take precedence ([#1651](#1651)) ([6821ed8](6821ed8)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - New Features - Cert-manager: option to set certificate owner references. - Cert-manager: support for pulling from an OCI repository. - Kyverno: ability to enable policy exceptions. - Bug Fixes - Corrected use of the base domain certificate. - External DNS repository now created only when required. - Ingress load balancer timeouts set to maximum to prevent premature terminations. - Monitoring datasources prioritized by removing version pinning. - Chores - Bumped base-cluster chart to 9.2.0 and updated release notes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
See https://cert-manager.io/docs/installation/helm/#installing-from-the-oci-registry
Summary by CodeRabbit