# cert-manager

## acmesolver

ACME-solver image used by cert-manager to spin up HTTP-01
challenge-response pods. Image attrset with `repository` and `tag`.

*Type:*
anything

*Default:*

```nix
{
  image = {
    repository = "quay.io/jetstack/cert-manager-acmesolver";
    tag = "v1.17.1";
  };
}
```

## cainjector

CA-injector component config. Sets the `image` attrset and
`replicaCount` for the controller that injects CA bundles into
webhooks, APIServices, and CRDs. The replica count defaults from the
cluster’s availability level (v2\_discussions/145).

*Type:*
anything

*Default:*

```nix
{
  image = {
    repository = "quay.io/jetstack/cert-manager-cainjector";
    tag = "v1.17.1";
  };
  replicaCount = 1;
}
```

## dns01RecursiveNameservers

Comma-separated list of recursive nameservers used to verify DNS-01
ACME challenges (e.g. `8.8.8.8:53,1.1.1.1:53`). Empty string falls
back to the system resolver.

*Type:*
string

*Default:*

```nix
""
```

## dns01RecursiveNameserversOnly

If `true`, only the nameservers in `dns01RecursiveNameservers` are
used for DNS-01 self-checks (skipping cluster DNS entirely).

*Type:*
boolean

*Default:*

```nix
false
```

## image

Image for the cert-manager controller `Deployment`. Attrset with
`repository`, `tag`, and `pullPolicy` keys.

*Type:*
anything

*Default:*

```nix
{
  pullPolicy = "IfNotPresent";
  repository = "quay.io/jetstack/cert-manager-controller";
  tag = "v1.17.1";
}
```

## installCRDs

Whether kix should emit the cert-manager CRDs (`Certificate`,
`Issuer`, `Challenge`, etc.). Set to `false` when CRDs are managed
out-of-band.

*Type:*
boolean

*Default:*

```nix
true
```

## prometheus

Prometheus scrape config for cert-manager. When `enabled` is true,
kix wires up the metrics endpoint annotations on the controller
`Service`.

*Type:*
anything

*Default:*

```nix
{
  enabled = false;
}
```

## replicaCount

Number of replicas for the cert-manager controller `Deployment`.
Defaults from the cluster’s availability level (v2\_discussions/145).

*Type:*
signed integer

*Default:*

```nix
1
```

## resources

Optional resource requests/limits attrset applied to the controller
container. `null` leaves the container’s resource block unset.

*Type:*
null or anything

*Default:*

```nix
null
```

## webhook

Webhook component config. Sets the `image` attrset and
`replicaCount` for the admission webhook that validates and mutates
cert-manager CRs. The replica count defaults from the cluster’s
availability level (v2\_discussions/145).

*Type:*
anything

*Default:*

```nix
{
  image = {
    repository = "quay.io/jetstack/cert-manager-webhook";
    tag = "v1.17.1";
  };
  replicaCount = 1;
}
```