From 9882bbe5d5051cac9c46233e36795c0aec3e379c Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sun, 9 Aug 2026 12:26:56 +1000 Subject: [PATCH] Fix cert-manager recursive-nameserver ControllerConfiguration field Why: - The cert-manager v1.20.2 controller crashloops: strict decoding of its ControllerConfiguration rejects the unknown field `acmeDNS01`, so /var/cert-manager/config/config.yaml fails to load and the controller never starts; the stuck rollout leaves only the old pod serving. - PR #337 placed the DNS-01 recursive-nameserver settings under `acmeDNS01`, but the field in the controller.config.cert-manager.io/v1alpha1 schema is `acmeDNS01Config`. How: - Rename the config block `acmeDNS01` to `acmeDNS01Config`, keeping `recursiveNameservers` (8.8.8.8:53, 1.1.1.1:53) and `recursiveNameserversOnly: true` so DNS-01 resolution and self-checks still use the public DNS view for the split-horizon delegation. --- apps/overlays/au-syd1/cert-manager/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/overlays/au-syd1/cert-manager/values.yaml b/apps/overlays/au-syd1/cert-manager/values.yaml index 3e94eb4..9c30ac3 100644 --- a/apps/overlays/au-syd1/cert-manager/values.yaml +++ b/apps/overlays/au-syd1/cert-manager/values.yaml @@ -5,7 +5,7 @@ config: apiVersion: controller.config.cert-manager.io/v1alpha1 kind: ControllerConfiguration enableGatewayAPI: true - acmeDNS01: + acmeDNS01Config: recursiveNameservers: - "8.8.8.8:53" - "1.1.1.1:53" -- 2.47.3