[Feat] Volume mount service secrets on workloads#72
[Feat] Volume mount service secrets on workloads#72anirudhprasad-sap wants to merge 19 commits intomainfrom
Conversation
|
An evaluation was done to store service secrets as volume mounts to support credential rotation. But we have the following issues-
Because of these drawbacks, it doesn't make sense to support volume mounts for secrets right now. We will revisit the topic once the above points are resolved. |
enhanced volume & volume mount propogation
pass volume mount to initcontainers added unit tests
Even though the above issue still exists, we decided to merge it. This feature can be enabled by setting annotation |
volume mount annotation changed
I updated the annotation to |
|
|



Volume mount service secrets on workloads instead of using VCAP. Enabled by setting annotation
sme.sap.com/use-credential-volume-mount: "true"on the CAPApplicationVersion resource.Test controller image -
ghcr.io/anirudhprasad-sap/cap-operator/controller:vol-mnt-3ghcr.io/anirudhprasad-sap/cap-operator/controller:vol-mnt-4