From b2d89ccd77a653c00e95a14dd80d1e5e10279162 Mon Sep 17 00:00:00 2001 From: johnlanni Date: Mon, 23 Sep 2024 17:16:05 +0800 Subject: [PATCH] add istio workload sds --- helm/core/templates/_pod.tpl | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/helm/core/templates/_pod.tpl b/helm/core/templates/_pod.tpl index 657a4f29d4..432f9d3d4e 100644 --- a/helm/core/templates/_pod.tpl +++ b/helm/core/templates/_pod.tpl @@ -167,6 +167,12 @@ template: {{- toYaml .Values.gateway.resources | nindent 10 }} {{- end }} volumeMounts: + - mountPath: /var/run/secrets/workload-spiffe-uds + name: workload-socket + - mountPath: /var/run/secrets/credential-uds + name: credential-socket + - mountPath: /var/run/secrets/workload-spiffe-credentials + name: workload-certs {{- if eq (include "controller.jwtPolicy" .) "third-party-jwt" }} - name: istio-token mountPath: /var/run/secrets/tokens @@ -245,6 +251,12 @@ template: {{- toYaml . | nindent 6 }} {{- end }} volumes: + - emptyDir: {} + name: workload-socket + - emptyDir: {} + name: credential-socket + - emptyDir: {} + name: workload-certs {{- if eq (include "controller.jwtPolicy" .) "third-party-jwt" }} - name: istio-token projected: