diff --git a/charts/core/README.md b/charts/core/README.md
index 9013fb054..aaafb4398 100644
--- a/charts/core/README.md
+++ b/charts/core/README.md
@@ -90,6 +90,8 @@ Parameter | Description | Default | Notes
`controller.podLabels` | Specify the pod labels. | `{}` |
`controller.podAnnotations` | Specify the pod annotations. | `{}` |
`controller.env` | User-defined environment variables for controller. | `[]` |
+`controller.volumes` | Additional pod volumes for controller | `nil` |
+`controller.volumeMounts` | Additional mounts for the controller container | `nil` |
`controller.ranchersso.enabled` | If true, enable single sign on for Rancher | `false` | Required for Rancher Authentication. |
`controller.pvc.enabled` | If true, enable persistence for controller using PVC | `false` | Require persistent volume type RWX, and storage 1Gi
`controller.pvc.accessModes` | Access modes for the created PVC. | `["ReadWriteMany"]` |
@@ -189,6 +191,8 @@ Parameter | Description | Default | Notes
`enforcer.podLabels` | Specify the pod labels. | `{}` |
`enforcer.podAnnotations` | Specify the pod annotations. | `{}` |
`enforcer.env` | User-defined environment variables for enforcers. | `[]` |
+`enforcer.volumes` | Additional pod volumes for enforcer | `nil` |
+`enforcer.volumeMounts` | Additional mounts for the enforcer container | `nil` |
`enforcer.tolerations` | List of node taints to tolerate | `- effect: NoSchedule`
`key: node-role.kubernetes.io/master` | other taints can be added after the default
`enforcer.resources` | Add resources requests and limits to enforcer deployment | `{}` | see examples in [values.yaml](values.yaml)
`enforcer.internal.certificate.secret` | Secret name to be used for custom enforcer internal certificate | `nil` |
@@ -210,6 +214,8 @@ Parameter | Description | Default | Notes
` CUSTOM_PAGE_HEADER_COLOR` | use color name (yellow) or value (#ffff00) |
` CUSTOM_PAGE_FOOTER_CONTENT` | max. 120 characters, base64 encoded. |
` CUSTOM_PAGE_FOOTER_COLOR` | use color name (yellow) or value (#ffff00) |
+`manager.volumes` | Additional pod volumes for manager | `nil` |
+`manager.volumeMounts` | Additional mounts for the manager container | `nil` |
`manager.svc.mgrServerPort` | set manager service port number | `8443` |
`manager.svc.type` | set manager service type for native Kubernetes | `NodePort`;
if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google
`manager.svc.nodePort` | set manager service NodePort number | `nil` |
@@ -251,6 +257,8 @@ Parameter | Description | Default | Notes
`cve.adapter.podLabels` | Specify the pod labels. | `{}` |
`cve.adapter.podAnnotations` | Specify the pod annotations. | `{}` |
`cve.adapter.env` | User-defined environment variables for adapter. | `[]` |
+`cve.adapter.volumes` | Additional pod volumes for registry adapter | `nil` |
+`cve.adapter.volumeMounts` | Additional mounts for the registry adapter container | `nil` |
`cve.adapter.svc.type` | set registry adapter service type for native Kubernetes | `NodePort`;
if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google
`cve.adapter.svc.loadBalancerIP` | if registry adapter service type is LoadBalancer, this is used to specify the load balancer's IP | `nil` |
`cve.adapter.svc.annotations` | Add annotations to registry adapter service | `{}` | see examples in [values.yaml](values.yaml)
@@ -308,6 +316,8 @@ Parameter | Description | Default | Notes
`cve.scanner.podLabels` | Specify the pod labels. | `{}` |
`cve.scanner.podAnnotations` | Specify the pod annotations. | `{}` |
`cve.scanner.env` | User-defined environment variables for scanner. | `[]` |
+`cve.scanner.volumes` | Additional pod volumes for scanner | `nil` |
+`cve.scanner.volumeMounts` | Additional mounts for the scanner container | `nil` |
`cve.scanner.replicas` | external scanner replicas | `3` |
`cve.scanner.dockerPath` | the remote docker socket if CI/CD integration need scan images before they are pushed to the registry | `nil` |
`cve.scanner.resources` | Add resources requests and limits to scanner deployment | `{}` | see examples in [values.yaml](values.yaml) |
diff --git a/charts/core/templates/controller-deployment.yaml b/charts/core/templates/controller-deployment.yaml
index 564c924f5..8770d75c0 100644
--- a/charts/core/templates/controller-deployment.yaml
+++ b/charts/core/templates/controller-deployment.yaml
@@ -261,6 +261,9 @@ spec:
- mountPath: /etc/neuvector/certs/internal/
name: internal-cert-dir
{{- end }}
+ {{- with .Values.controller.volumeMounts }}
+{{- toYaml . | nindent 12 }}
+ {{- end }}
terminationGracePeriodSeconds: 300
restartPolicy: Always
volumes:
@@ -332,6 +335,9 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
+ {{- with .Values.controller.volumes }}
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
{{- if gt (int .Values.controller.disruptionbudget) 0 }}
---
{{- if (semverCompare ">=1.21-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
diff --git a/charts/core/templates/enforcer-daemonset.yaml b/charts/core/templates/enforcer-daemonset.yaml
index 33db695b3..aef7077c1 100644
--- a/charts/core/templates/enforcer-daemonset.yaml
+++ b/charts/core/templates/enforcer-daemonset.yaml
@@ -166,6 +166,9 @@ spec:
- mountPath: /etc/neuvector/certs/internal/
name: internal-cert-dir
{{- end }}
+ {{- with .Values.enforcer.volumeMounts }}
+{{- toYaml . | nindent 12 }}
+ {{- end }}
terminationGracePeriodSeconds: 1200
restartPolicy: Always
volumes:
@@ -209,4 +212,7 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
+ {{- with .Values.enforcer.volumes }}
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
{{- end }}
diff --git a/charts/core/templates/manager-deployment.yaml b/charts/core/templates/manager-deployment.yaml
index 34b70cb77..6e68897d7 100644
--- a/charts/core/templates/manager-deployment.yaml
+++ b/charts/core/templates/manager-deployment.yaml
@@ -124,6 +124,9 @@ spec:
name: cert
readOnly: true
{{- end }}
+ {{- with .Values.manager.volumeMounts }}
+{{- toYaml . | nindent 12 }}
+ {{- end }}
{{- if .Values.manager.probes.enabled }}
startupProbe:
httpGet:
@@ -182,4 +185,7 @@ spec:
secret:
secretName: neuvector-manager-secret
{{- end }}
+ {{- with .Values.manager.volumes }}
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
{{- end }}
diff --git a/charts/core/templates/registry-adapter.yaml b/charts/core/templates/registry-adapter.yaml
index ea9745191..4dfcbbcf9 100644
--- a/charts/core/templates/registry-adapter.yaml
+++ b/charts/core/templates/registry-adapter.yaml
@@ -144,6 +144,9 @@ spec:
name: cert
readOnly: true
{{- end }}
+ {{- with .Values.cve.adapter.volumeMounts }}
+{{- toYaml . | nindent 12 }}
+ {{- end }}
resources:
{{- if .Values.cve.adapter.resources }}
{{ toYaml .Values.cve.adapter.resources | indent 12 }}
@@ -170,6 +173,9 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
+ {{- with .Values.cve.adapter.volumes }}
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
---
apiVersion: v1
diff --git a/charts/core/values.schema.json b/charts/core/values.schema.json
index df7ca5e1e..6fc693807 100644
--- a/charts/core/values.schema.json
+++ b/charts/core/values.schema.json
@@ -338,6 +338,14 @@
"type": "array",
"description": "User-defined environment variables for controller."
},
+ "volumes": {
+ "type": ["array", "null"],
+ "description": "Additional pod volumes for controller."
+ },
+ "volumeMounts": {
+ "type": ["array", "null"],
+ "description": "Additional volume mounts for the controller container."
+ },
"affinity": {
"type": "object",
"description": "controller affinity rules",
@@ -951,6 +959,14 @@
"type": "array",
"description": "User-defined environment variables for enforcers."
},
+ "volumes": {
+ "type": ["array", "null"],
+ "description": "Additional pod volumes for enforcer."
+ },
+ "volumeMounts": {
+ "type": ["array", "null"],
+ "description": "Additional volume mounts for the enforcer container."
+ },
"tolerations": {
"type": "array",
"description": "List of node taints to tolerate. Other taints can be added after the default",
@@ -1050,6 +1066,14 @@
"ssl"
]
},
+ "volumes": {
+ "type": ["array", "null"],
+ "description": "Additional pod volumes for manager."
+ },
+ "volumeMounts": {
+ "type": ["array", "null"],
+ "description": "Additional volume mounts for the manager container."
+ },
"svc": {
"type": "object",
"description": "set manager service type for native Kubernetes. if it is OpenShift platform or ingress is enabled, then default is `ClusterIP`. Set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google.",
@@ -1266,6 +1290,14 @@
"type": "array",
"description": "User-defined environment variables for adapter."
},
+ "volumes": {
+ "type": ["array", "null"],
+ "description": "Additional pod volumes for registry adapter."
+ },
+ "volumeMounts": {
+ "type": ["array", "null"],
+ "description": "Additional volume mounts for the registry adapter container."
+ },
"tolerations": {
"type": "array",
"description": "List of node taints to tolerate"
@@ -1626,6 +1658,14 @@
}
}
}
+ },
+ "volumes": {
+ "type": ["array", "null"],
+ "description": "Additional pod volumes for scanner."
+ },
+ "volumeMounts": {
+ "type": ["array", "null"],
+ "description": "Additional volume mounts for the scanner container."
}
},
"required": [
diff --git a/charts/core/values.yaml b/charts/core/values.yaml
index d7d6f5661..e9ab5b891 100644
--- a/charts/core/values.yaml
+++ b/charts/core/values.yaml
@@ -105,6 +105,8 @@ controller:
podAnnotations: {}
searchRegistries:
env: []
+ volumes:
+ volumeMounts:
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
@@ -350,6 +352,8 @@ enforcer:
podLabels: {}
podAnnotations: {}
env: []
+ volumes:
+ volumeMounts:
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/master
@@ -387,6 +391,8 @@ manager:
# value: "#FFFFFF"
# - name: CUSTOM_PAGE_FOOTER_COLOR
# value: "#FFFFFF"
+ volumes:
+ volumeMounts:
svc:
mgrServerPort: 8443
type: ClusterIP
@@ -480,6 +486,8 @@ cve:
podLabels: {}
podAnnotations: {}
env: []
+ volumes:
+ volumeMounts:
tolerations: []
nodeSelector: {}
# key1: value1