Fix cert-manager recursive-nameserver ControllerConfiguration field #347

Merged
benvin merged 1 commits from benvin/certmanager-fix-recursive-ns into main 2026-08-09 12:35:38 +10:00
Owner

Why

  • The cert-manager v1.20.2 controller crashloops: strict decoding of its ControllerConfiguration rejects the unknown field acmeDNS01 (failed to load config file ... strict decoding error: unknown field "acmeDNS01"), so /var/cert-manager/config/config.yaml fails to load and the controller never starts. The rollout is stuck with only the old pod running.
  • PR #337 placed the DNS-01 recursive-nameserver settings under acmeDNS01, but the field in the controller.config.cert-manager.io/v1alpha1 schema is acmeDNS01Config (ACMEDNS01Config, with recursiveNameservers / recursiveNameserversOnly). The recursive-ns settings belong in the config file, not extraArgs; the CLI flags feed the same struct but the chart already renders a --config ControllerConfiguration, so the correct fix is the correct field name.

How

  • Rename the config: block acmeDNS01 to acmeDNS01Config, keeping recursiveNameservers (8.8.8.8:53, 1.1.1.1:53) and recursiveNameserversOnly: true so DNS-01 resolution and self-checks still use the public DNS view for the split-horizon delegation.

Rendered kustomize build --enable-helm confirms the ConfigMap config.yaml now carries a valid acmeDNS01Config block and no longer contains the invalid acmeDNS01; the cert-manager overlay is kubeconform-clean (55 valid, 0 invalid).

## Why - The cert-manager v1.20.2 controller crashloops: strict decoding of its ControllerConfiguration rejects the unknown field `acmeDNS01` (`failed to load config file ... strict decoding error: unknown field "acmeDNS01"`), so `/var/cert-manager/config/config.yaml` fails to load and the controller never starts. The rollout is stuck with only the old pod running. - PR #337 placed the DNS-01 recursive-nameserver settings under `acmeDNS01`, but the field in the `controller.config.cert-manager.io/v1alpha1` schema is `acmeDNS01Config` (`ACMEDNS01Config`, with `recursiveNameservers` / `recursiveNameserversOnly`). The recursive-ns settings belong in the config file, not `extraArgs`; the CLI flags feed the same struct but the chart already renders a `--config` ControllerConfiguration, so the correct fix is the correct field name. ## How - Rename the `config:` block `acmeDNS01` to `acmeDNS01Config`, keeping `recursiveNameservers` (`8.8.8.8:53`, `1.1.1.1:53`) and `recursiveNameserversOnly: true` so DNS-01 resolution and self-checks still use the public DNS view for the split-horizon delegation. Rendered `kustomize build --enable-helm` confirms the ConfigMap `config.yaml` now carries a valid `acmeDNS01Config` block and no longer contains the invalid `acmeDNS01`; the cert-manager overlay is kubeconform-clean (55 valid, 0 invalid).
unkinben added 1 commit 2026-08-09 12:27:11 +10:00
Fix cert-manager recursive-nameserver ControllerConfiguration field
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
9882bbe5d5
Why:
- The cert-manager v1.20.2 controller crashloops: strict decoding of its
  ControllerConfiguration rejects the unknown field `acmeDNS01`, so
  /var/cert-manager/config/config.yaml fails to load and the controller
  never starts; the stuck rollout leaves only the old pod serving.
- PR #337 placed the DNS-01 recursive-nameserver settings under `acmeDNS01`,
  but the field in the controller.config.cert-manager.io/v1alpha1 schema is
  `acmeDNS01Config`.

How:
- Rename the config block `acmeDNS01` to `acmeDNS01Config`, keeping
  `recursiveNameservers` (8.8.8.8:53, 1.1.1.1:53) and
  `recursiveNameserversOnly: true` so DNS-01 resolution and self-checks
  still use the public DNS view for the split-horizon delegation.
benvin merged commit 4d58f37ea5 into main 2026-08-09 12:35:38 +10:00
benvin deleted branch benvin/certmanager-fix-recursive-ns 2026-08-09 12:35:38 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#347