Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions charts/core/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,8 @@ Parameter | Description | Default | Notes
`controller.podLabels` | Specify the pod labels. | `{}` |
`controller.podAnnotations` | Specify the pod annotations. | `{}` |
`controller.env` | User-defined environment variables for controller. | `[]` |
`controller.volumes` | Additional pod volumes for controller | `nil` |
`controller.volumeMounts` | Additional mounts for the controller container | `nil` |
`controller.ranchersso.enabled` | If true, enable single sign on for Rancher | `false` | Required for Rancher Authentication. |
`controller.pvc.enabled` | If true, enable persistence for controller using PVC | `false` | Require persistent volume type RWX, and storage 1Gi
`controller.pvc.accessModes` | Access modes for the created PVC. | `["ReadWriteMany"]` |
Expand Down Expand Up @@ -189,6 +191,8 @@ Parameter | Description | Default | Notes
`enforcer.podLabels` | Specify the pod labels. | `{}` |
`enforcer.podAnnotations` | Specify the pod annotations. | `{}` |
`enforcer.env` | User-defined environment variables for enforcers. | `[]` |
`enforcer.volumes` | Additional pod volumes for enforcer | `nil` |
`enforcer.volumeMounts` | Additional mounts for the enforcer container | `nil` |
`enforcer.tolerations` | List of node taints to tolerate | `- effect: NoSchedule`<br>`key: node-role.kubernetes.io/master` | other taints can be added after the default
`enforcer.resources` | Add resources requests and limits to enforcer deployment | `{}` | see examples in [values.yaml](values.yaml)
`enforcer.internal.certificate.secret` | Secret name to be used for custom enforcer internal certificate | `nil` |
Expand All @@ -210,6 +214,8 @@ Parameter | Description | Default | Notes
` CUSTOM_PAGE_HEADER_COLOR` | use color name (yellow) or value (#ffff00) |
` CUSTOM_PAGE_FOOTER_CONTENT` | max. 120 characters, base64 encoded. |
` CUSTOM_PAGE_FOOTER_COLOR` | use color name (yellow) or value (#ffff00) |
`manager.volumes` | Additional pod volumes for manager | `nil` |
`manager.volumeMounts` | Additional mounts for the manager container | `nil` |
`manager.svc.mgrServerPort` | set manager service port number | `8443` |
`manager.svc.type` | set manager service type for native Kubernetes | `NodePort`;<br>if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google
`manager.svc.nodePort` | set manager service NodePort number | `nil` |
Expand Down Expand Up @@ -251,6 +257,8 @@ Parameter | Description | Default | Notes
`cve.adapter.podLabels` | Specify the pod labels. | `{}` |
`cve.adapter.podAnnotations` | Specify the pod annotations. | `{}` |
`cve.adapter.env` | User-defined environment variables for adapter. | `[]` |
`cve.adapter.volumes` | Additional pod volumes for registry adapter | `nil` |
`cve.adapter.volumeMounts` | Additional mounts for the registry adapter container | `nil` |
`cve.adapter.svc.type` | set registry adapter service type for native Kubernetes | `NodePort`;<br>if it is OpenShift platform or ingress is enabled, then default is `ClusterIP` | set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google
`cve.adapter.svc.loadBalancerIP` | if registry adapter service type is LoadBalancer, this is used to specify the load balancer's IP | `nil` |
`cve.adapter.svc.annotations` | Add annotations to registry adapter service | `{}` | see examples in [values.yaml](values.yaml)
Expand Down Expand Up @@ -308,6 +316,8 @@ Parameter | Description | Default | Notes
`cve.scanner.podLabels` | Specify the pod labels. | `{}` |
`cve.scanner.podAnnotations` | Specify the pod annotations. | `{}` |
`cve.scanner.env` | User-defined environment variables for scanner. | `[]` |
`cve.scanner.volumes` | Additional pod volumes for scanner | `nil` |
`cve.scanner.volumeMounts` | Additional mounts for the scanner container | `nil` |
`cve.scanner.replicas` | external scanner replicas | `3` |
`cve.scanner.dockerPath` | the remote docker socket if CI/CD integration need scan images before they are pushed to the registry | `nil` |
`cve.scanner.resources` | Add resources requests and limits to scanner deployment | `{}` | see examples in [values.yaml](values.yaml) |
Expand Down
6 changes: 6 additions & 0 deletions charts/core/templates/controller-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,9 @@ spec:
- mountPath: /etc/neuvector/certs/internal/
name: internal-cert-dir
{{- end }}
{{- with .Values.controller.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
terminationGracePeriodSeconds: 300
restartPolicy: Always
volumes:
Expand Down Expand Up @@ -332,6 +335,9 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
{{- with .Values.controller.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if gt (int .Values.controller.disruptionbudget) 0 }}
---
{{- if (semverCompare ">=1.21-0" (substr 1 -1 .Capabilities.KubeVersion.GitVersion)) }}
Expand Down
6 changes: 6 additions & 0 deletions charts/core/templates/enforcer-daemonset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -166,6 +166,9 @@ spec:
- mountPath: /etc/neuvector/certs/internal/
name: internal-cert-dir
{{- end }}
{{- with .Values.enforcer.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
terminationGracePeriodSeconds: 1200
restartPolicy: Always
volumes:
Expand Down Expand Up @@ -209,4 +212,7 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
{{- with .Values.enforcer.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
6 changes: 6 additions & 0 deletions charts/core/templates/manager-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -124,6 +124,9 @@ spec:
name: cert
readOnly: true
{{- end }}
{{- with .Values.manager.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if .Values.manager.probes.enabled }}
startupProbe:
httpGet:
Expand Down Expand Up @@ -182,4 +185,7 @@ spec:
secret:
secretName: neuvector-manager-secret
{{- end }}
{{- with .Values.manager.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
6 changes: 6 additions & 0 deletions charts/core/templates/registry-adapter.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -144,6 +144,9 @@ spec:
name: cert
readOnly: true
{{- end }}
{{- with .Values.cve.adapter.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
resources:
{{- if .Values.cve.adapter.resources }}
{{ toYaml .Values.cve.adapter.resources | indent 12 }}
Expand All @@ -170,6 +173,9 @@ spec:
emptyDir:
sizeLimit: 50Mi
{{- end }}
{{- with .Values.cve.adapter.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
---

apiVersion: v1
Expand Down
40 changes: 40 additions & 0 deletions charts/core/values.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -338,6 +338,14 @@
"type": "array",
"description": "User-defined environment variables for controller."
},
"volumes": {
"type": ["array", "null"],
"description": "Additional pod volumes for controller."
},
"volumeMounts": {
"type": ["array", "null"],
"description": "Additional volume mounts for the controller container."
},
"affinity": {
"type": "object",
"description": "controller affinity rules",
Expand Down Expand Up @@ -951,6 +959,14 @@
"type": "array",
"description": "User-defined environment variables for enforcers."
},
"volumes": {
"type": ["array", "null"],
"description": "Additional pod volumes for enforcer."
},
"volumeMounts": {
"type": ["array", "null"],
"description": "Additional volume mounts for the enforcer container."
},
"tolerations": {
"type": "array",
"description": "List of node taints to tolerate. Other taints can be added after the default",
Expand Down Expand Up @@ -1050,6 +1066,14 @@
"ssl"
]
},
"volumes": {
"type": ["array", "null"],
"description": "Additional pod volumes for manager."
},
"volumeMounts": {
"type": ["array", "null"],
"description": "Additional volume mounts for the manager container."
},
"svc": {
"type": "object",
"description": "set manager service type for native Kubernetes. if it is OpenShift platform or ingress is enabled, then default is `ClusterIP`. Set to LoadBalancer if using cloud providers, such as Azure, Amazon, Google.",
Expand Down Expand Up @@ -1266,6 +1290,14 @@
"type": "array",
"description": "User-defined environment variables for adapter."
},
"volumes": {
"type": ["array", "null"],
"description": "Additional pod volumes for registry adapter."
},
"volumeMounts": {
"type": ["array", "null"],
"description": "Additional volume mounts for the registry adapter container."
},
"tolerations": {
"type": "array",
"description": "List of node taints to tolerate"
Expand Down Expand Up @@ -1626,6 +1658,14 @@
}
}
}
},
"volumes": {
"type": ["array", "null"],
"description": "Additional pod volumes for scanner."
},
"volumeMounts": {
"type": ["array", "null"],
"description": "Additional volume mounts for the scanner container."
}
},
"required": [
Expand Down
8 changes: 8 additions & 0 deletions charts/core/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,8 @@ controller:
podAnnotations: {}
searchRegistries:
env: []
volumes:
volumeMounts:
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
Expand Down Expand Up @@ -350,6 +352,8 @@ enforcer:
podLabels: {}
podAnnotations: {}
env: []
volumes:
volumeMounts:
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/master
Expand Down Expand Up @@ -387,6 +391,8 @@ manager:
# value: "#FFFFFF"
# - name: CUSTOM_PAGE_FOOTER_COLOR
# value: "#FFFFFF"
volumes:
volumeMounts:
svc:
mgrServerPort: 8443
type: ClusterIP
Expand Down Expand Up @@ -480,6 +486,8 @@ cve:
podLabels: {}
podAnnotations: {}
env: []
volumes:
volumeMounts:
tolerations: []
nodeSelector: {}
# key1: value1
Expand Down