diff --git a/k8s/infrastructure/trivy-operator/release.yaml b/k8s/infrastructure/trivy-operator/release.yaml index 382de92cc..ed6ffa395 100644 --- a/k8s/infrastructure/trivy-operator/release.yaml +++ b/k8s/infrastructure/trivy-operator/release.yaml @@ -16,4 +16,49 @@ spec: kind: HelmRepository name: trivy-operator # https://github.com/aquasecurity/trivy-operator/blob/main/deploy/helm/values.yaml - values: {} + values: + nodeCollector: + volumeMounts: + - name: var-lib-etcd + mountPath: /var/lib/etcd + readOnly: true + - name: var-lib-kubelet + mountPath: /var/lib/kubelet + readOnly: true + - name: var-lib-kube-scheduler + mountPath: /var/lib/kube-scheduler + readOnly: true + - name: var-lib-kube-controller-manager + mountPath: /var/lib/kube-controller-manager + readOnly: true + - name: lib-systemd + mountPath: /lib/systemd/ + readOnly: true + - name: etc-kubernetes + mountPath: /etc/kubernetes + readOnly: true + - name: etc-cni-netd + mountPath: /etc/cni/net.d/ + readOnly: true + volumes: + - name: var-lib-etcd + hostPath: + path: /var/lib/etcd + - name: var-lib-kubelet + hostPath: + path: /var/lib/kubelet + - name: var-lib-kube-scheduler + hostPath: + path: /var/lib/kube-scheduler + - name: var-lib-kube-controller-manager + hostPath: + path: /var/lib/kube-controller-manager + - name: lib-systemd + hostPath: + path: /lib/systemd + - name: etc-kubernetes + hostPath: + path: /etc/kubernetes + - name: etc-cni-netd + hostPath: + path: /etc/cni/net.d/