Skip to content

K8s: add let's encrypt limitation to cert-manager page#3472

Merged
kaitlynmichael merged 2 commits into
mainfrom
DOC-6737
Jun 11, 2026
Merged

K8s: add let's encrypt limitation to cert-manager page#3472
kaitlynmichael merged 2 commits into
mainfrom
DOC-6737

Conversation

@kaitlynmichael

@kaitlynmichael kaitlynmichael commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

DOC-6737


Note

Low Risk
Documentation-only edits with no runtime, security, or application code changes.

Overview
Updates the Use production certificate authorities section on the Kubernetes cert-manager docs (versioned and default paths) so ACME/Let’s Encrypt is no longer presented as a plug-and-play setup.

The Let’s Encrypt subsection is renamed to Let’s Encrypt and ACME issuers and the sample ClusterIssuer / Certificate YAML is removed. The text now states that ACME issuers typically leave ca.crt without the root CA, so cert-manager secrets may lack the full chain Redis Software needs, and documents a three-step workaround: build the full chain, store it in a Kubernetes secret, and point the Redis custom resource at that secret instead of the cert-manager-generated one. A note generalizes this to any issuer that omits the root in ca.crt, and a short contrast clarifies that private CA or Vault paths that supply the full chain need no extra steps.

Reviewed by Cursor Bugbot for commit e57cfb9. Bugbot is set up for automated code reviews on this repo. Configure here.

@kaitlynmichael kaitlynmichael requested review from a team and heinrich-redislabs June 9, 2026 19:43
@kaitlynmichael kaitlynmichael self-assigned this Jun 9, 2026
@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

DOC-6737

@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

@jit-ci

jit-ci Bot commented Jun 9, 2026

Copy link
Copy Markdown

🛡️ Jit Security Scan Results

CRITICAL HIGH MEDIUM

✅ No security findings were detected in this PR


Security scan by Jit

@dwdougherty dwdougherty left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@heinrich-redislabs heinrich-redislabs left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a comment explaining what is the problem that users will have to understand if the cert-manager does not populate the ca.crt field with their specific certificate issuer.

Comment thread content/operate/kubernetes/8.0.18/security/cert-manager.md Outdated
@kaitlynmichael kaitlynmichael merged commit 4a692ff into main Jun 11, 2026
73 checks passed
@kaitlynmichael kaitlynmichael deleted the DOC-6737 branch June 11, 2026 15:34
EliShteinman added a commit to EliShteinman/docs that referenced this pull request Jun 11, 2026
Documents a Let's Encrypt limitation on the cert-manager docs page.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants