diff --git a/internal/selfhosted/webhook/base_manifests.go b/internal/selfhosted/webhook/base_manifests.go index f6184ed..fbd2ad9 100644 --- a/internal/selfhosted/webhook/base_manifests.go +++ b/internal/selfhosted/webhook/base_manifests.go @@ -117,21 +117,18 @@ func (b *baseManifestFactory) deployment() *appsv1.Deployment { // Command: []string{}, // Command must be patched VolumeMounts: []corev1.VolumeMount{ { - Name: "webhook-certs", - MountPath: "/var/run/app/certs", - ReadOnly: false, + Name: "cert", + MountPath: "/etc/webhook/certs", + ReadOnly: true, }, }, }, }, - Volumes: []corev1.Volume{ - { - Name: "webhook-certs", - VolumeSource: corev1.VolumeSource{ - EmptyDir: &corev1.EmptyDirVolumeSource{}, - }, - }, - }, + // Volumes: []corev1.Volume{ //Volumes must be patched + // { + // Name: "cert", + // }, + // }, }, }, }, diff --git a/internal/selfhosted/webhook/testdata/deployment.yaml b/internal/selfhosted/webhook/testdata/deployment.yaml index ab80396..9154ede 100644 --- a/internal/selfhosted/webhook/testdata/deployment.yaml +++ b/internal/selfhosted/webhook/testdata/deployment.yaml @@ -28,9 +28,6 @@ spec: # - --token-audience=sts.amazonaws.com # - --logtostderr volumeMounts: - - name: webhook-certs - mountPath: /var/run/app/certs - readOnly: false - volumes: - - name: webhook-certs - emptyDir: {} + - name: cert + mountPath: /etc/webhook/certs + readOnly: true diff --git a/internal/selfhosted/webhook/webhook.go b/internal/selfhosted/webhook/webhook.go index 70d617f..8ec6e1a 100644 --- a/internal/selfhosted/webhook/webhook.go +++ b/internal/selfhosted/webhook/webhook.go @@ -4,6 +4,7 @@ import ( "fmt" "github.com/kkb0318/irsa-manager/internal/manifests" + corev1 "k8s.io/api/core/v1" "k8s.io/apimachinery/pkg/types" "sigs.k8s.io/controller-runtime/pkg/client" ) @@ -49,7 +50,7 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) { deploy := base.deployment() deploy.Spec.Template.Spec.Containers[0].Command = []string{ "/webhook", - "--in-cluster", + "--in-cluster=false", fmt.Sprintf("--namespace=%s", WEBHOOK_NAMESPACE), fmt.Sprintf("--service-name=%s", base.serviceMeta.Name), fmt.Sprintf("--tls-secret=%s", secretNamespacedName.Name), @@ -57,6 +58,16 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) { "--token-audience=sts.amazonaws.com", "--logtostderr", } + deploy.Spec.Template.Spec.Volumes = []corev1.Volume{ + { + Name: "cert", + VolumeSource: corev1.VolumeSource{ + Secret: &corev1.SecretVolumeSource{ + SecretName: secretNamespacedName.Name, + }, + }, + }, + } mutate := base.mutatingWebhookConfiguration() mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle()) resources = append(resources,