Edit deployment.yaml

This commit is contained in:
inikulin 2025-07-24 10:45:03 +00:00
parent 4b9d303dca
commit 2694c0878a

View File

@ -23,26 +23,31 @@ spec:
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
# initContainers:
# - name: import-ca
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
# env:
# - name: CERT_ALIAS
# value: {{ .Values.global.cert_alias | quote }}
# volumeMounts:
# - name: ca-cert
# mountPath: /app/resources
# - name: cacerts-volume
# mountPath: /tmp/cacerts
# command:
# - sh
# - -c
# - |
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
# keytool -import -trustcacerts -storepass changeit -noprompt \
# -alias gemcert \
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
# -keystore /tmp/cacerts/cacerts
initContainers:
- name: import-ca
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
echo "Certificate with alias gemcert already exists, skipping import"
else
echo "Importing certificate with alias gemcert"
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
fi
containers:
- name: bff-vcs-app
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"