diff --git a/charts/kubewarden-controller/templates/audit-scanner.yaml b/charts/kubewarden-controller/templates/audit-scanner.yaml index 127a510f..7ae0dcaf 100644 --- a/charts/kubewarden-controller/templates/audit-scanner.yaml +++ b/charts/kubewarden-controller/templates/audit-scanner.yaml @@ -27,6 +27,11 @@ spec: {{- toYaml .Values.imagePullSecrets | nindent 12 }} {{- end }} restartPolicy: {{ .Values.auditScanner.containerRestartPolicy }} + volumes: + - name: policyservers-ca-cert + secret: + defaultMode: 420 + secretName: policy-server-root-ca containers: - name: audit-scanner image: '{{ template "system_default_registry" . }}{{ .Values.auditScanner.image.repository }}:{{ .Values.auditScanner.image.tag }}' @@ -34,6 +39,13 @@ spec: command: {{- include "audit-scanner.command" . | nindent 14 -}} {{- with .Values.containerSecurityContext }} + env: + - name: KUBEWARDEN_CACERT_PEM_POLICYSERVERS + value: "/pki/policy-server-root-ca-pem" + volumeMounts: + - mountPath: "/pki" + name: policyservers-ca-cert + readOnly: true securityContext: {{- toYaml . | nindent 14 }} {{- end }}