Conversation
Author
Author
|
@williamlin-suse pinging you since I've seen you active in #542 which is somewhat related to that issue. Hoping to get this merged in quickly so we can avoid manually patching workloads to mount our CA certs. |
Author
|
👀 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Allow custom pod volumes and main-container volume mounts for the controller, enforcer, manager, and registry adapter. The new values follow scanner’s existing volumes and volumeMounts convention; existing env settings are unchanged.
Fix #2905
I've updated the
README.mdandvalues.schema.jsonto reflect the changes.Test
Render the chart with
volumesandvolumeMountsoverrides for each of the five workloads (controller, enforcer, manager, cve.adapter, and cve.scanner). Setcve.adapter.enabled=trueto include the adapter. Confirm the custom entries appear alongside built-in entries, mounts appear only on main containers, and controller init-container mounts are unchanged.Additional Information
Tradeoff
Custom entries are appended without chart-side collision checks. Users must avoid conflicting volume names and mount paths; Kubernetes rejects invalid pod configurations. This issue already existed for the existing env values anyway.
Potential improvement
Possibly rename the the values to extraVolumes, extraVolumeMounts and extraEnv to be consistent with the common helm pattern but since
envwas already used this way, I decided to keep the existing pattern.