werf
Three release channels at once as werf 3 takes shape beside a still-shipping 2.75.
A side-by-side editorial comparison of cert-manager and Argo Rollouts — release velocity, themes, recent moves, and the top alternatives to consider.
cert-manager's 1.21 line is about failure handling: backoff caps, renewal policies and clearer auth errors
cert-manager is running the 1.21 pre-release train through alpha.0, alpha.1 and now beta.0. The changes cluster around what happens when certificate issuance goes wrong: a configurable cap on CertificateRequest retry backoff, a new AuthFailed issuer condition that separates bad Venafi credentials from transient infrastructure failures, and certificate renewal policies.
An RC-only feed where 1.9's headline change was reverted before it shipped.
Every entry in this window is a release candidate; no GA tag appears at all. The 1.9 line spent three RCs largely on pipeline problems — rc3 explicitly ships no changes from rc2 — and its one architectural change was withdrawn. That change would have narrowed .status.selector to report only the stable ReplicaSet for traffic-routed canaries so HPA stopped counting canary pods in its desired-replica math. The 1.10.0-rc1 notes are dominated by build and dependency work.
cert-manager is running the 1.21 pre-release train through alpha.0, alpha.1 and now beta.0. The changes cluster around what happens when certificate issuance goes wrong: a configurable cap on CertificateRequest retry backoff, a new AuthFailed issuer condition that separates bad Venafi credentials from transient infrastructure failures, and certificate renewal policies.
This is a reliability and observability cycle rather than a feature cycle. The recurring theme is making cert-manager's failure states legible — distinguishing permanent from transient errors, bounding retry storms, and letting Helm's common labels propagate into the ACME solver resources it creates on the fly. CAInjectorMerging reaching GA and deprecated API removal point to a line that is consolidating.
Expect a 1.21.0 release candidate next, with the renewal policy work being the piece most likely to change shape before it stabilises.
Every entry in this window is a release candidate; no GA tag appears at all. The 1.9 line spent three RCs largely on pipeline problems — rc3 explicitly ships no changes from rc2 — and its one architectural change was withdrawn. That change would have narrowed .status.selector to report only the stable ReplicaSet for traffic-routed canaries so HPA stopped counting canary pods in its desired-replica math. The 1.10.0-rc1 notes are dominated by build and dependency work.
The visible direction is operational rather than behavioural: notifications broadened to Teams workflows and NATS.io, a build system parameterized for company forks, CI skipped for docs-only changes, a move to pnpm. The selector revert says the project would rather live with awkward HPA math than break autoscaling for existing users, so progressive-delivery mechanics stay where they are.
1.10.0 looks likely to land close to rc1 — dependency, CVE and notification work with no controller-semantics change — and the HPA selector question stays open unless it returns behind an opt-in flag.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either cert-manager or Argo Rollouts.
Three release channels at once as werf 3 takes shape beside a still-shipping 2.75.
Volatility 3 caught up with Volatility 2, then started reorganising itself.
A small LDAP server that grew OpenTelemetry tracing, embedded plugins and RISC-V builds.
OctoPrint 2.0 turns serial into one connector among several, and breaks plugins doing it.
Patch tags land monthly with release notes that itemize nothing.
A self-hosted PaaS spending its releases on secrets, injection fixes and plan limits.
See all cert-manager alternatives → · See all Argo Rollouts alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — kubernetes — within Infra & APIs. cert-manager and Argo Rollouts are shipping at a similar cadence (velocity 0.0 vs 0.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. cert-manager and Argo Rollouts are shipping at a similar cadence (velocity 0.0 vs 0.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top cert-manager alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "cert-manager alternatives" section above for the current picks, or visit /alternatives/cert-manager for the full list with editorial commentary on each.
Top Argo Rollouts alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Argo Rollouts alternatives" section above for the current picks, or visit /alternatives/argo-rollouts for the full list with editorial commentary on each.