Skip to content

Commit be659ba

Browse files
author
GovSignals Bot
committed
feat(helm): add supervisor.extraVolumes/extraVolumeMounts
Mirrors the existing webapp.extraVolumes / webapp.extraVolumeMounts pattern. Required for compliance environments that need to mount a custom CA bundle ConfigMap into the supervisor pod (e.g. Palantir Rubix or GameWarden CAs) and point NODE_EXTRA_CA_CERTS at it. Both extras render unconditionally — they no longer depend on the legacy bootstrap-disabled volume block — so any consumer can opt in.
1 parent 203c4e0 commit be659ba

2 files changed

Lines changed: 26 additions & 2 deletions

File tree

‎hosting/k8s/helm/templates/supervisor.yaml‎

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -245,24 +245,34 @@ spec:
245245
{{- with .Values.supervisor.extraEnvVars }}
246246
{{- toYaml . | nindent 12 }}
247247
{{- end }}
248-
{{- if not .Values.webapp.bootstrap.enabled }}
248+
{{- if or (not .Values.webapp.bootstrap.enabled) .Values.supervisor.extraVolumeMounts }}
249249
volumeMounts:
250+
{{- if not .Values.webapp.bootstrap.enabled }}
250251
- name: shared
251252
mountPath: /home/node/shared
253+
{{- end }}
254+
{{- with .Values.supervisor.extraVolumeMounts }}
255+
{{- toYaml . | nindent 12 }}
256+
{{- end }}
252257
{{- end }}
253258
{{- with .Values.supervisor.securityContext }}
254259
securityContext:
255260
{{- toYaml . | nindent 12 }}
256261
{{- end }}
257-
{{- if not .Values.webapp.bootstrap.enabled }}
262+
{{- if or (not .Values.webapp.bootstrap.enabled) .Values.supervisor.extraVolumes }}
258263
volumes:
264+
{{- if not .Values.webapp.bootstrap.enabled }}
259265
- name: shared
260266
{{- if .Values.persistence.shared.enabled }}
261267
persistentVolumeClaim:
262268
claimName: {{ include "trigger-v4.fullname" . }}-shared
263269
{{- else }}
264270
emptyDir: {}
265271
{{- end }}
272+
{{- end }}
273+
{{- with .Values.supervisor.extraVolumes }}
274+
{{- toYaml . | nindent 8 }}
275+
{{- end }}
266276
{{- end }}
267277
{{- with .Values.supervisor.nodeSelector }}
268278
nodeSelector:

‎hosting/k8s/helm/values.yaml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -329,6 +329,20 @@ supervisor:
329329
# - name: CUSTOM_VAR
330330
# value: "custom-value"
331331

332+
# Extra volumes added to the Supervisor pod (e.g. CA bundle ConfigMap)
333+
extraVolumes:
334+
[]
335+
# - name: ca-bundle
336+
# configMap:
337+
# name: my-ca-bundle
338+
339+
# Extra volume mounts added to the Supervisor container
340+
extraVolumeMounts:
341+
[]
342+
# - name: ca-bundle
343+
# mountPath: /etc/ssl/custom-ca
344+
# readOnly: true
345+
332346
# ServiceMonitor for Prometheus monitoring
333347
serviceMonitor:
334348
enabled: false

0 commit comments

Comments
 (0)