Skip to content

feat: allow custom volumes and mounts for main workloads - #663

Open
rodneyxr wants to merge 1 commit into
neuvector:masterfrom
rodneyxr:feat/add-extra-volumes
Open

rodneyxr wants to merge 1 commit into
neuvector:masterfrom
rodneyxr:feat/add-extra-volumes

Conversation

@rodneyxr

Copy link
Copy Markdown

Description

Allow custom pod volumes and main-container volume mounts for the controller, enforcer, manager, and registry adapter. The new values follow scanner’s existing volumes and volumeMounts convention; existing env settings are unchanged.

Fix #2905

I've updated the README.md and values.schema.json to reflect the changes.

Test

helm lint charts/core

Render the chart with volumes and volumeMounts overrides for each of the five workloads (controller, enforcer, manager, cve.adapter, and cve.scanner). Set cve.adapter.enabled=true to include the adapter. Confirm the custom entries appear alongside built-in entries, mounts appear only on main containers, and controller init-container mounts are unchanged.

Additional Information

Tradeoff

Custom entries are appended without chart-side collision checks. Users must avoid conflicting volume names and mount paths; Kubernetes rejects invalid pod configurations. This issue already existed for the existing env values anyway.

Potential improvement

Possibly rename the the values to extraVolumes, extraVolumeMounts and extraEnv to be consistent with the common helm pattern but since env was already used this way, I decided to keep the existing pattern.

@rodneyxr
rodneyxr requested a review from a team as a code owner September 25, 2026 20:51
@rodneyxr
rodneyxr requested review from esther-suse and removed request for a team September 25, 2026 20:51
@rodneyxr

rodneyxr commented Sep 25, 2026 •

Copy link
Copy Markdown
Author

This likely also fixes #193 and maybe should be considered over #513

@rodneyxr

Copy link
Copy Markdown
Author

@williamlin-suse pinging you since I've seen you active in #542 which is somewhat related to that issue. Hoping to get this merged in quickly so we can avoid manually patching workloads to mount our CA certs.

@rodneyxr

rodneyxr commented Oct 2, 2026

Copy link
Copy Markdown
Author

👀

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support custom volumes and mounts in Helm chart for NeuVector core workloads

1 participant