diff --git a/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml b/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml index d8e7853..ca804b9 100755 --- a/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml +++ b/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml @@ -14,9 +14,47 @@ spec: labels: {{- include "bff-admin-app.selectorLabels" . | nindent 8 }} spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi containers: - name: bff-admin-app image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}" imagePullPolicy: {{ .Values.image.pullPolicy }} env: - {{- include "global.env.general" . | nindent 12 }} \ No newline at end of file + {{- include "global.env.general" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts \ No newline at end of file