diff --git a/charts/core/README.md b/charts/core/README.md index 9013fb054..aaafb4398 100644 --- a/charts/core/README.md +++ b/charts/core/README.md @@ -90,6 +90,8 @@ Parameter | Description | Default | Notes `controller.podLabels` | Specify the pod labels. | `{}` | `controller.podAnnotations` | Specify the pod annotations. | `{}` | `controller.env` | User-defined environment variables for controller. | `[]` | +`controller.volumes` | Additional pod volumes for controller | `nil` | +`controller.volumeMounts` | Additional mounts for the controller container | `nil` | `controller.ranchersso.enabled` | If true, enable single sign on for Rancher | `false` | Required for Rancher Authentication. | `controller.pvc.enabled` | If true, enable persistence for controller using PVC | `false` | Require persistent volume type RWX, and storage 1Gi `controller.pvc.accessModes` | Access modes for the created PVC. | `["ReadWriteMany"]` | @@ -189,6 +191,8 @@ Parameter | Description | Default | Notes `enforcer.podLabels` | Specify the pod labels. | `{}` | `enforcer.podAnnotations` | Specify the pod annotations. | `{}` | `enforcer.env` | User-defined environment variables for enforcers. | `[]` | +`enforcer.volumes` | Additional pod volumes for enforcer | `nil` | +`enforcer.volumeMounts` | Additional mounts for the enforcer container | `nil` | `enforcer.tolerations` | List of node taints to tolerate | `- effect: NoSchedule`
`key: node-role.kubernetes.io/master` | other taints can be added after the default `enforcer.resources` | Add resources requests and limits to enforcer deployment | `{}` | see examples in [values.yaml](values.yaml) `enforcer.internal.certificate.secret` | Secret name to be used for custom enforcer internal certificate | `nil` | @@ -210,6 +214,8 @@ Parameter | Description | Default | Notes ` CUSTOM_PAGE_HEADER_COLOR` | use color name (yellow) or value (#ffff00) | ` CUSTOM_PAGE_FOOTER_CONTENT` | max. 120 characters, base64 encoded. | ` CUSTOM_PAGE_FOOTER_COLOR` | use color name (yellow) or value (#ffff00) | +`manager.volumes` | Additional pod volumes for manager | `nil` | +`manager.volumeMounts` | Additional mounts for the manager container | `nil` | `manager.svc.mgrServerPort` | set manager service port number | `8443` | `manager.svc.type` | set manager service type for native Kubernetes | `NodePort`;
if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google `manager.svc.nodePort` | set manager service NodePort number | `nil` | @@ -251,6 +257,8 @@ Parameter | Description | Default | Notes `cve.adapter.podLabels` | Specify the pod labels. | `{}` | `cve.adapter.podAnnotations` | Specify the pod annotations. | `{}` | `cve.adapter.env` | User-defined environment variables for adapter. | `[]` | +`cve.adapter.volumes` | Additional pod volumes for registry adapter | `nil` | +`cve.adapter.volumeMounts` | Additional mounts for the registry adapter container | `nil` | `cve.adapter.svc.type` | set registry adapter service type for native Kubernetes | `NodePort`;
if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google `cve.adapter.svc.loadBalancerIP` | if registry adapter service type is LoadBalancer, this is used to specify the load balancer's IP | `nil` | `cve.adapter.svc.annotations` | Add annotations to registry adapter service | `{}` | see examples in [values.yaml](values.yaml) @@ -308,6 +316,8 @@ Parameter | Description | Default | Notes `cve.scanner.podLabels` | Specify the pod labels. | `{}` | `cve.scanner.podAnnotations` | Specify the pod annotations. | `{}` | `cve.scanner.env` | User-defined environment variables for scanner. | `[]` | +`cve.scanner.volumes` | Additional pod volumes for scanner | `nil` | +`cve.scanner.volumeMounts` | Additional mounts for the scanner container | `nil` | `cve.scanner.replicas` | external scanner replicas | `3` | `cve.scanner.dockerPath` | the remote docker socket if CI/CD integration need scan images before they are pushed to the registry | `nil` | `cve.scanner.resources` | Add resources requests and limits to scanner deployment | `{}` | see examples in [values.yaml](values.yaml) | diff --git a/charts/core/templates/controller-deployment.yaml b/charts/core/templates/controller-deployment.yaml index 564c924f5..8770d75c0 100644 --- a/charts/core/templates/controller-deployment.yaml +++ b/charts/core/templates/controller-deployment.yaml @@ -261,6 +261,9 @@ spec: - mountPath: /etc/neuvector/certs/internal/ name: internal-cert-dir {{- end }} + {{- with .Values.controller.volumeMounts }} +{{- toYaml . | nindent 12 }} + {{- end }} terminationGracePeriodSeconds: 300 restartPolicy: Always volumes: @@ -332,6 +335,9 @@ spec: emptyDir: sizeLimit: 50Mi {{- end }} + {{- with .Values.controller.volumes }} + {{- toYaml . | nindent 8 }} + {{- end }} {{- if gt (int .Values.controller.disruptionbudget) 0 }} --- {{- if (semverCompare ">=1.21-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }} diff --git a/charts/core/templates/enforcer-daemonset.yaml b/charts/core/templates/enforcer-daemonset.yaml index 33db695b3..aef7077c1 100644 --- a/charts/core/templates/enforcer-daemonset.yaml +++ b/charts/core/templates/enforcer-daemonset.yaml @@ -166,6 +166,9 @@ spec: - mountPath: /etc/neuvector/certs/internal/ name: internal-cert-dir {{- end }} + {{- with .Values.enforcer.volumeMounts }} +{{- toYaml . | nindent 12 }} + {{- end }} terminationGracePeriodSeconds: 1200 restartPolicy: Always volumes: @@ -209,4 +212,7 @@ spec: emptyDir: sizeLimit: 50Mi {{- end }} + {{- with .Values.enforcer.volumes }} + {{- toYaml . | nindent 8 }} + {{- end }} {{- end }} diff --git a/charts/core/templates/manager-deployment.yaml b/charts/core/templates/manager-deployment.yaml index 34b70cb77..6e68897d7 100644 --- a/charts/core/templates/manager-deployment.yaml +++ b/charts/core/templates/manager-deployment.yaml @@ -124,6 +124,9 @@ spec: name: cert readOnly: true {{- end }} + {{- with .Values.manager.volumeMounts }} +{{- toYaml . | nindent 12 }} + {{- end }} {{- if .Values.manager.probes.enabled }} startupProbe: httpGet: @@ -182,4 +185,7 @@ spec: secret: secretName: neuvector-manager-secret {{- end }} + {{- with .Values.manager.volumes }} + {{- toYaml . | nindent 8 }} + {{- end }} {{- end }} diff --git a/charts/core/templates/registry-adapter.yaml b/charts/core/templates/registry-adapter.yaml index ea9745191..4dfcbbcf9 100644 --- a/charts/core/templates/registry-adapter.yaml +++ b/charts/core/templates/registry-adapter.yaml @@ -144,6 +144,9 @@ spec: name: cert readOnly: true {{- end }} + {{- with .Values.cve.adapter.volumeMounts }} +{{- toYaml . | nindent 12 }} + {{- end }} resources: {{- if .Values.cve.adapter.resources }} {{ toYaml .Values.cve.adapter.resources | indent 12 }} @@ -170,6 +173,9 @@ spec: emptyDir: sizeLimit: 50Mi {{- end }} + {{- with .Values.cve.adapter.volumes }} + {{- toYaml . | nindent 8 }} + {{- end }} --- apiVersion: v1 diff --git a/charts/core/values.schema.json b/charts/core/values.schema.json index df7ca5e1e..6fc693807 100644 --- a/charts/core/values.schema.json +++ b/charts/core/values.schema.json @@ -338,6 +338,14 @@ "type": "array", "description": "User-defined environment variables for controller." }, + "volumes": { + "type": ["array", "null"], + "description": "Additional pod volumes for controller." + }, + "volumeMounts": { + "type": ["array", "null"], + "description": "Additional volume mounts for the controller container." + }, "affinity": { "type": "object", "description": "controller affinity rules", @@ -951,6 +959,14 @@ "type": "array", "description": "User-defined environment variables for enforcers." }, + "volumes": { + "type": ["array", "null"], + "description": "Additional pod volumes for enforcer." + }, + "volumeMounts": { + "type": ["array", "null"], + "description": "Additional volume mounts for the enforcer container." + }, "tolerations": { "type": "array", "description": "List of node taints to tolerate. Other taints can be added after the default", @@ -1050,6 +1066,14 @@ "ssl" ] }, + "volumes": { + "type": ["array", "null"], + "description": "Additional pod volumes for manager." + }, + "volumeMounts": { + "type": ["array", "null"], + "description": "Additional volume mounts for the manager container." + }, "svc": { "type": "object", "description": "set manager service type for native Kubernetes. if it is OpenShift platform or ingress is enabled, then default is `ClusterIP`. Set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google.", @@ -1266,6 +1290,14 @@ "type": "array", "description": "User-defined environment variables for adapter." }, + "volumes": { + "type": ["array", "null"], + "description": "Additional pod volumes for registry adapter." + }, + "volumeMounts": { + "type": ["array", "null"], + "description": "Additional volume mounts for the registry adapter container." + }, "tolerations": { "type": "array", "description": "List of node taints to tolerate" @@ -1626,6 +1658,14 @@ } } } + }, + "volumes": { + "type": ["array", "null"], + "description": "Additional pod volumes for scanner." + }, + "volumeMounts": { + "type": ["array", "null"], + "description": "Additional volume mounts for the scanner container." } }, "required": [ diff --git a/charts/core/values.yaml b/charts/core/values.yaml index d7d6f5661..e9ab5b891 100644 --- a/charts/core/values.yaml +++ b/charts/core/values.yaml @@ -105,6 +105,8 @@ controller: podAnnotations: {} searchRegistries: env: [] + volumes: + volumeMounts: affinity: podAntiAffinity: preferredDuringSchedulingIgnoredDuringExecution: @@ -350,6 +352,8 @@ enforcer: podLabels: {} podAnnotations: {} env: [] + volumes: + volumeMounts: tolerations: - effect: NoSchedule key: node-role.kubernetes.io/master @@ -387,6 +391,8 @@ manager: # value: "#FFFFFF" # - name: CUSTOM_PAGE_FOOTER_COLOR # value: "#FFFFFF" + volumes: + volumeMounts: svc: mgrServerPort: 8443 type: ClusterIP @@ -480,6 +486,8 @@ cve: podLabels: {} podAnnotations: {} env: [] + volumes: + volumeMounts: tolerations: [] nodeSelector: {} # key1: value1