cluster/admitomatic: allow whitelist-source-range

Without this, cert-manager get stuck.

Deployed to prod.

Change-Id: I356cd44f455b6f4aecea9ae396f6a05e1a727859
diff --git a/cluster/admitomatic/ingress.go b/cluster/admitomatic/ingress.go
index a1d57a5..6b8a365 100644
--- a/cluster/admitomatic/ingress.go
+++ b/cluster/admitomatic/ingress.go
@@ -210,6 +210,8 @@
 		"proxy-body-size":  true,
 		"ssl-redirect":     true,
 		"backend-protocol": true,
+		// Used by cert-manager
+		"whitelist-source-range": true,
 	}
 	prefix := "nginx.ingress.kubernetes.io/"
 	for k, _ := range ingress.Annotations {
diff --git a/cluster/kube/lib/admitomatic.libsonnet b/cluster/kube/lib/admitomatic.libsonnet
index ab44bfb..d8e0440 100644
--- a/cluster/kube/lib/admitomatic.libsonnet
+++ b/cluster/kube/lib/admitomatic.libsonnet
@@ -32,7 +32,7 @@
 
         cfg:: {
             namespace: "admitomatic",
-            image: "registry.k0.hswaw.net/q3k/admitomatic:1612618063-0b68e233116f733fb3ec9016c9d3b7decb86f192",
+            image: "registry.k0.hswaw.net/q3k/admitomatic:315532800-6cc2f867951e123909b23955cd7bcbcc3ec24f8a",
 
             proto: {},
         },