cert-manager: 1.19.6 -> 1.20.3
Change-Id: Iabb070751250884fca8064f8b27d0a86a63959af
diff --git a/charts/cert-manager/templates/crd-cert-manager.io_clusterissuers.yaml b/charts/cert-manager/templates/crd-cert-manager.io_clusterissuers.yaml
index a9ecd4f..f5de226 100644
--- a/charts/cert-manager/templates/crd-cert-manager.io_clusterissuers.yaml
+++ b/charts/cert-manager/templates/crd-cert-manager.io_clusterissuers.yaml
@@ -396,6 +396,22 @@
The TenantID of the Azure Service Principal used to authenticate with Azure DNS.
If set, ClientID and ClientSecret must also be set.
type: string
+ zoneType:
+ description: |-
+ ZoneType determines which type of Azure DNS zone to use.
+
+ Valid values are:
+ - AzurePublicZone (default): Use a public Azure DNS zone.
+ - AzurePrivateZone: Use an Azure Private DNS zone.
+
+ If not specified, AzurePublicZone is used.
+
+ Support for Azure Private DNS zones is currently
+ experimental and may change in future releases.
+ enum:
+ - AzurePublicZone
+ - AzurePrivateZone
+ type: string
required:
- resourceGroupName
- subscriptionID
@@ -569,8 +585,8 @@
description: |-
The AccessKeyID is used for authentication.
Cannot be set when SecretAccessKeyID is set.
- If neither the Access Key nor Key ID are set, we fall-back to using env
- vars, shared credentials file or AWS Instance metadata,
+ If neither the Access Key nor Key ID are set, we fall back to using env
+ vars, shared credentials file, or AWS Instance metadata,
see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
type: string
accessKeyIDSecretRef:
@@ -578,8 +594,8 @@
The SecretAccessKey is used for authentication. If set, pull the AWS
access key ID from a key within a Kubernetes Secret.
Cannot be set when AccessKeyID is set.
- If neither the Access Key nor Key ID are set, we fall-back to using env
- vars, shared credentials file or AWS Instance metadata,
+ If neither the Access Key nor Key ID are set, we fall back to using env
+ vars, shared credentials file, or AWS Instance metadata,
see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
properties:
key:
@@ -668,8 +684,8 @@
secretAccessKeySecretRef:
description: |-
The SecretAccessKey is used for authentication.
- If neither the Access Key nor Key ID are set, we fall-back to using env
- vars, shared credentials file or AWS Instance metadata,
+ If neither the Access Key nor Key ID are set, we fall back to using env
+ vars, shared credentials file, or AWS Instance metadata,
see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
properties:
key:
@@ -2026,9 +2042,10 @@
operator:
description: |-
Operator represents a key's relationship to the value.
- Valid operators are Exists and Equal. Defaults to Equal.
+ Valid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod can
tolerate all taints of a particular category.
+ Lt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).
type: string
tolerationSeconds:
description: |-
@@ -3237,9 +3254,10 @@
operator:
description: |-
Operator represents a key's relationship to the value.
- Valid operators are Exists and Equal. Defaults to Equal.
+ Valid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod can
tolerate all taints of a particular category.
+ Lt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).
type: string
tolerationSeconds:
description: |-
@@ -3496,8 +3514,8 @@
properties:
audiences:
description: |-
- TokenAudiences is an optional list of extra audiences to include in the token passed to Vault. The default token
- consisting of the issuer's namespace and name is always included.
+ TokenAudiences is an optional list of extra audiences to include in the token passed to Vault.
+ The default audiences are always included in the token.
items:
type: string
type: array
@@ -3625,16 +3643,16 @@
type: object
venafi:
description: |-
- Venafi configures this issuer to sign certificates using a Venafi TPP
- or Venafi Cloud policy zone.
+ Venafi configures this issuer to sign certificates using a CyberArk Certificate Manager Self-Hosted
+ or SaaS policy zone.
properties:
cloud:
description: |-
- Cloud specifies the Venafi cloud configuration settings.
- Only one of TPP or Cloud may be specified.
+ Cloud specifies the CyberArk Certificate Manager SaaS configuration settings.
+ Only one of CyberArk Certificate Manager may be specified.
properties:
apiTokenSecretRef:
- description: APITokenSecretRef is a secret key selector for the Venafi Cloud API token.
+ description: APITokenSecretRef is a secret key selector for the CyberArk Certificate Manager SaaS API token.
properties:
key:
description: |-
@@ -3652,7 +3670,7 @@
type: object
url:
description: |-
- URL is the base URL for Venafi Cloud.
+ URL is the base URL for CyberArk Certificate Manager SaaS.
Defaults to "https://api.venafi.cloud/".
type: string
required:
@@ -3660,13 +3678,13 @@
type: object
tpp:
description: |-
- TPP specifies Trust Protection Platform configuration settings.
- Only one of TPP or Cloud may be specified.
+ TPP specifies CyberArk Certificate Manager Self-Hosted configuration settings.
+ Only one of CyberArk Certificate Manager may be specified.
properties:
caBundle:
description: |-
Base64-encoded bundle of PEM CAs which will be used to validate the certificate
- chain presented by the TPP server. Only used if using HTTPS; ignored for HTTP.
+ chain presented by the CyberArk Certificate Manager Self-Hosted server. Only used if using HTTPS; ignored for HTTP.
If undefined, the certificate bundle in the cert-manager controller container
is used to validate the chain.
format: byte
@@ -3674,7 +3692,7 @@
caBundleSecretRef:
description: |-
Reference to a Secret containing a base64-encoded bundle of PEM CAs
- which will be used to validate the certificate chain presented by the TPP server.
+ which will be used to validate the certificate chain presented by the CyberArk Certificate Manager Self-Hosted server.
Only used if using HTTPS; ignored for HTTP. Mutually exclusive with CABundle.
If neither CABundle nor CABundleSecretRef is defined, the certificate bundle in
the cert-manager controller container is used to validate the TLS connection.
@@ -3695,7 +3713,7 @@
type: object
credentialsRef:
description: |-
- CredentialsRef is a reference to a Secret containing the Venafi TPP API credentials.
+ CredentialsRef is a reference to a Secret containing the CyberArk Certificate Manager Self-Hosted API credentials.
The secret must contain the key 'access-token' for the Access Token Authentication,
or two keys, 'username' and 'password' for the API Keys Authentication.
properties:
@@ -3709,7 +3727,7 @@
type: object
url:
description: |-
- URL is the base URL for the vedsdk endpoint of the Venafi TPP instance,
+ URL is the base URL for the vedsdk endpoint of the CyberArk Certificate Manager Self-Hosted instance,
for example: "https://tpp.example.com/vedsdk".
type: string
required:
@@ -3718,8 +3736,8 @@
type: object
zone:
description: |-
- Zone is the Venafi Policy Zone to use for this issuer.
- All requests made to the Venafi platform will be restricted by the named
+ Zone is the Certificate Manager Policy Zone to use for this issuer.
+ All requests made to the Certificate Manager platform will be restricted by the named
zone policy.
This field is required.
type: string