Skip to content

[cert-manager] Set resources requests/limits on cert-manager pods - #2616

Merged
Aleksei Sviridkin (lexfrei) merged 1 commit into
cozystack:mainfrom
matthieu-robin:fix/cert-manager-cainjector-cpu-limit
Jul 3, 2026
Merged

Aleksei Sviridkin (lexfrei) merged 1 commit into
cozystack:mainfrom
matthieu-robin:fix/cert-manager-cainjector-cpu-limit

Conversation

@matthieu-robin

@matthieu-robin Matthieu ROBIN (matthieu-robin) commented May 12, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The upstream cert-manager chart ships with resources: {} for all four workloads, which triggers no CPU limit (and no memory limit) conformance warnings on every pod.

Override packages/system/cert-manager/values.yaml (previously empty) to set sane requests/limits sized to each component's role:

Component requests cpu/mem limits cpu/mem Notes
controller 50m / 128Mi 500m / 512Mi Main workload — issues and renews certs
webhook 10m / 32Mi 200m / 128Mi Admission webhook, short-lived requests
cainjector 10m / 32Mi 200m / 128Mi CA bundle injection, light watch loop
startupapicheck 10m / 16Mi 100m / 64Mi One-shot Job at install time

Requests for cainjector (10m cpu / 32Mi mem) match the example in the upstream values.yaml comment.

Test plan

  • helm template . --namespace cert-manager from packages/system/cert-manager/ renders a resources block on all four pods (verified locally for controller, webhook, cainjector and the startupapicheck Job)
  • Re-run the conformance/lint tool that originally flagged the warnings on cert-manager-cainjector — should be clean on the other three pods too
  • CI passes

Release note

```release-note
Set CPU/memory requests and limits on cert-manager controller, webhook, cainjector and startupapicheck pods to clear "no CPU limit" conformance warnings.
```

Summary by CodeRabbit

  • Chores
    • Added resource allocation configuration for cert-manager deployment, specifying CPU and memory requests and limits for improved system stability and resource management across core components.

Review Change Stack

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This pull request is from a fork — automated review is disabled. A repository maintainer can comment @claude review to run a one-time review.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request updates the cert-manager configuration to include explicit resource requests and limits for its various workloads. By defining these values, the deployment now adheres to cluster conformance standards, preventing warnings related to unbounded resource usage while ensuring each component is appropriately sized for its specific role.

Highlights

  • Resource Configuration: Defined CPU and memory requests and limits for all cert-manager components, including the controller, webhook, cainjector, and startupapicheck.
  • Conformance Compliance: Addressed conformance warnings regarding missing CPU and memory limits by providing explicit resource constraints in the values.yaml file.
New Features

🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment Gemini (@gemini-code-assist) Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added the area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review label May 12, 2026
@coderabbitai

coderabbitai Bot commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 8ec8b204-8fcb-4dc1-a6b5-889e10829d60

📥 Commits

Reviewing files that changed from the base of the PR and between 86f5267 and afab347.

📒 Files selected for processing (1)
  • packages/system/cert-manager/values.yaml

📝 Walkthrough

Walkthrough

A new Helm values configuration file for cert-manager is introduced, specifying Kubernetes resource limits and requests (CPU and memory) for the main application and its component subcharts: webhook, cainjector, and startupapicheck.

Changes

Cert-Manager Resource Configuration

Layer / File(s) Summary
Cert-manager Helm values with resource limits and requests
packages/system/cert-manager/values.yaml
Helm values file specifying CPU and memory resource limits and requests for cert-manager and its webhook, cainjector, and startupapicheck components.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

A values file hops into the fold, 🐰
Resource limits, shiny and bold,
Webhook, cainjector in tow,
Helm charts ready to grow! 🌱

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title '[cert-manager] Set resources requests/limits on cert-manager pods' clearly and concisely describes the main change in the PR: adding CPU and memory resource requests and limits to cert-manager pod configurations.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added the size/M This PR changes 30-99 lines, ignoring generated files label May 12, 2026
@dosubot dosubot Bot added the quality-of-life QoL improvements label May 12, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces resource requests and limits for the cert-manager, webhook, cainjector, and startupapicheck components. The reviewer noted that the commit messages and PR title must follow the Conventional Commits format and include a Signed-off-by trailer as required by the style guide. Furthermore, it is suggested to increase the memory request for the startupapicheck component from 16Mi to 32Mi to prevent potential OOM issues and align with upstream standards.

@@ -0,0 +1,32 @@
cert-manager:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

low

The pull request title and commit messages do not follow the Conventional Commits format required by the repository style guide. It should follow the pattern type(scope): description (e.g., feat(cert-manager): set resource requests and limits). Additionally, ensure that each commit includes a Signed-off-by: trailer.

References
  1. Commits must follow the Conventional Commits format (type(scope): description) and include a Signed-off-by trailer. (link)

memory: 64Mi
requests:
cpu: 10m
memory: 16Mi

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

low

The memory request for startupapicheck is set to 16Mi, which is lower than the 32Mi suggested in the upstream cert-manager examples and used for other helper components like the webhook and cainjector in this PR. Increasing this to 32Mi provides a safer margin for the Go runtime and avoids potential OOM kills during the initial API checks.

        memory: 32Mi
References
  1. Ensure appropriate resource requests and limits are set for all workloads to maintain stability and avoid conformance warnings.

@lexfrei Aleksei Sviridkin (lexfrei) added kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt area/platform Issues or PRs related to platform infrastructure (bundle, flux, talos, installer) and removed area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review labels May 25, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The four value paths map correctly onto the vendored cert-manager subchart — controller at top-level resources, plus webhook.resources, cainjector.resources, and startupapicheck.resources (which is enabled by default, so the block takes effect). Sizing is sane for each role and the requests stay modest. Nit: the title isn't in Conventional Commits form; and the earlier bot note about a missing Signed-off-by is stale — the head commit is signed off.

Non-blocking: startupapicheck memory request 16Mi is fine for a one-shot check job, but 32Mi would give more margin if the API bundle grows.

The upstream cert-manager chart ships with resources: {} for all four
workloads (controller, webhook, cainjector, startupapicheck), which
triggers 'no CPU limit' conformance warnings on every pod. Override the
package values.yaml to set sane requests and limits sized to each
component's role: controller is the most loaded, webhook and cainjector
handle short-lived admission/injection work, and startupapicheck is a
one-shot Job.

Signed-off-by: Matthieu <[email protected]>
@lexfrei
Aleksei Sviridkin (lexfrei) force-pushed the fix/cert-manager-cainjector-cpu-limit branch from afab347 to cd95040 Compare July 3, 2026 16:14
@github-actions github-actions Bot added the area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review label Jul 3, 2026
@lexfrei
Aleksei Sviridkin (lexfrei) merged commit 1aa6436 into cozystack:main Jul 3, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/platform Issues or PRs related to platform infrastructure (bundle, flux, talos, installer) area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt quality-of-life QoL improvements size/M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants