Skip to content

Commit

Permalink
refactor: Use --extra-ca and not env var, mount secret key
Browse files Browse the repository at this point in the history
Signed-off-by: Víctor Cuadrado Juan <[email protected]>
  • Loading branch information
viccuad committed Jul 28, 2023
1 parent 5f72879 commit 56e2338
Showing 1 changed file with 5 additions and 3 deletions.
8 changes: 5 additions & 3 deletions charts/kubewarden-controller/templates/audit-scanner.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,16 +32,18 @@ spec:
secret:
defaultMode: 420
secretName: policy-server-root-ca
items:
- key: policy-server-root-ca-pem
path: "policy-server-root-ca-pem"
containers:
- name: audit-scanner
image: '{{ template "system_default_registry" . }}{{ .Values.auditScanner.image.repository }}:{{ .Values.auditScanner.image.tag }}'
imagePullPolicy: {{ .Values.auditScanner.image.pullPolicy }}
command:
{{- include "audit-scanner.command" . | nindent 14 -}}
- --extra-ca
- "/pki/policy-server-root-ca-pem"
{{- with .Values.containerSecurityContext }}
env:
- name: KUBEWARDEN_CACERT_PEM_POLICYSERVERS
value: "/pki/policy-server-root-ca-pem"
volumeMounts:
- mountPath: "/pki"
name: policyservers-ca-cert
Expand Down

0 comments on commit 56e2338

Please sign in to comment.