Skip to content

Merge 2.6.2 to main - #78

Merged
indrora merged 5 commits into
mainfrom
release-2.6
Sep 21, 2026
Merged

indrora merged 5 commits into
mainfrom
release-2.6

Conversation

@indrora

@indrora indrora commented Sep 21, 2026

Copy link
Copy Markdown
Member

Merge release-2.6 to main - Automated PR

irby and others added 4 commits June 3, 2026 13:31
…hcheck Interval, Updated Service Account Token Lifecycle (#70)

* feat: Add volume and volume mount for service token

* chore: fix sources and add changelog

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* updated error messaging on csr enrollment

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore: update docs + add e2e test for optional CA

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* feat(healthcheck): bump default healthcheck interval from 1m to 10m

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(deps): bump go version to 1.26

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore: address copilot feedback. update linter version

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore(ci): bump controller tools version

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(docs): document new Helm chart values for serviceAccount

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
#74)

* command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70) (#71)

* feat: Add volume and volume mount for service token

* chore: fix sources and add changelog



* feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns



* updated error messaging on csr enrollment



* Update generated docs

* chore: update docs + add e2e test for optional CA



* Update generated docs

* feat(healthcheck): bump default healthcheck interval from 1m to 10m



* chore(deps): bump go version to 1.26



* Update generated docs

* chore: address copilot feedback. update linter version



* Update generated docs

* chore(ci): bump controller tools version



* chore(docs): document new Helm chart values for serviceAccount



---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Add priorityClassName

* remove quote

* Update README

* chore(AB#89226): add docs on how to contribute to the project

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore: update CHANGELOG

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: slammajamma28 <slammajamma28@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…tion (#77)

* Merge 2.6.1 to main (#75)

* command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70)

* feat: Add volume and volume mount for service token

* chore: fix sources and add changelog

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* updated error messaging on csr enrollment

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore: update docs + add e2e test for optional CA

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* feat(healthcheck): bump default healthcheck interval from 1m to 10m

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(deps): bump go version to 1.26

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore: address copilot feedback. update linter version

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Update generated docs

* chore(ci): bump controller tools version

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(docs): document new Helm chart values for serviceAccount

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* command-cert-manger-issuer v2.6.1: Add priorityClassName to Deployment (#74)

* command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70) (#71)

* feat: Add volume and volume mount for service token

* chore: fix sources and add changelog



* feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns



* updated error messaging on csr enrollment



* Update generated docs

* chore: update docs + add e2e test for optional CA



* Update generated docs

* feat(healthcheck): bump default healthcheck interval from 1m to 10m



* chore(deps): bump go version to 1.26



* Update generated docs

* chore: address copilot feedback. update linter version



* Update generated docs

* chore(ci): bump controller tools version



* chore(docs): document new Helm chart values for serviceAccount



---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Add priorityClassName

* remove quote

* Update README

* chore(AB#89226): add docs on how to contribute to the project

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore: update CHANGELOG

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: slammajamma28 <slammajamma28@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: slammajamma28 <slammajamma28@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* temp: log expiration of access token generated by ambient credentials

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* fix(oauth): add external token source to abstract ambient token credential generation

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore: bump crypto depenedency. address copilot feedback

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(deps): bump auth library to v1.5.1

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

* chore(docs): update CHANGELOG

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>

---------

Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: slammajamma28 <slammajamma28@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 21, 2026 22:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

GCP ambient token refreshes use an unbounded context, allowing stalled token requests to block cached clients indefinitely.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Merges v2.6.2 changes into main, primarily adding automatic ambient credential refresh and Helm priority class configuration.

Changes:

  • Replaces static ambient tokens with refreshing Azure/GCP OAuth token sources.
  • Upgrades authentication and SDK dependencies.
  • Adds priorityClassName Helm support and updates documentation.
File Description
internal/​command/​command.go Configures external ambient token sources.
internal/​command/​client.go Implements Azure and GCP token refresh sources.
go.mod Updates dependencies.
go.sum Updates dependency checksums.
deploy/​charts/​command-cert-manager-issuer/​values.yaml Adds priority class value.
deploy/​charts/​command-cert-manager-issuer/​templates/​deployment.yaml Renders priority class configuration.
deploy/​charts/​command-cert-manager-issuer/​README.md Documents chart settings.
CONTRIBUTING.md Updates contribution and development guidance.
CHANGELOG.md Records v2.6.1 and v2.6.2 changes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


// Use credentials to generate a JWT (requires a service account)
tokenSource, err := idtoken.NewTokenSource(ctx, aud, idtoken.WithCredentialsJSON(credentials.JSON))
ts, err := idtoken.NewTokenSource(g.ctx, aud, idtoken.WithCredentialsJSON(creds.JSON))
@indrora
indrora merged commit 069e2d2 into main Sep 21, 2026
21 of 22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants