edge.24-12-10

Changes TLS certificate provisioning architecture to avoid rate limits on large clusters, adds backwards compatibility for EKS cluster creator privileges, and improves Authentik stability during PostgreSQL failovers.

Upgrade Modules in Order

This release changes the way that public ingress TLS certificates are provisioned in order to avoid hitting rate limits on large clusters. This architectural update requires that the modules be upgraded in the following order:

  1. kube_cert_issuers

  2. kube_ingress_nginx. To avoid service disruptions, you MUST wait until all the old NGINX pods have been fully terminated before proceeding.

  3. The remainder of the modules may be updated in any order.


There are many clouds. This one is yours.

Copyright © 2026 Panfactum Group, Inc.