Skip to content

✨ Add fileMounts to attach Secrets/ConfigMaps as files - #195

Open
djzager wants to merge 1 commit into
konveyor:mainfrom
djzager:feature/filemounts-secret-configmap-as-files
Open

✨ Add fileMounts to attach Secrets/ConfigMaps as files#195
djzager wants to merge 1 commit into
konveyor:mainfrom
djzager:feature/filemounts-secret-configmap-as-files

Conversation

@djzager

@djzager djzager commented Aug 27, 2026

Copy link
Copy Markdown
Member

AgentRun and AgentWorkflowRun gain a fileMounts field: the file-shaped sibling of envFrom, for config or credentials a skill or tool reads from a path (a config file, a service-account JSON) rather than from an environment variable. Each mount names exactly one Secret or ConfigMap (CEL-enforced), mounted read-only, and supports whole-object directory mounts, key selection (items), and single-file mounts (subPath).

The controller wires the mounts into the Sandbox pod's existing volume plumbing and rejects, before creating the Sandbox, any mountPath that lands on, under, or above a controller-managed mount — failing the run terminally with InvalidFileMounts. The reserved mount paths are centralized in one set (reservedMountPaths), and /workspace and /tmp are promoted from string literals to named constants so the mount sites and the collision guard cannot drift.

@djzager
djzager requested a review from dymurray August 27, 2026 18:27
@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 21a24905-9081-4cbf-9dce-0ceb539098a4


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

AgentRun and AgentWorkflowRun gain a fileMounts field: the file-shaped
sibling of envFrom, for config or credentials a skill or tool reads from
a path (a config file, a service-account JSON) rather than from an
environment variable. Each mount names exactly one Secret or ConfigMap
(CEL-enforced), mounted read-only, and supports whole-object directory
mounts, key selection (items), and single-file mounts (subPath).

The controller wires the mounts into the Sandbox pod's existing volume
plumbing and rejects, before creating the Sandbox, any mountPath that
lands on, under, or above a controller-managed mount — failing the run
terminally with InvalidFileMounts. The reserved mount paths are
centralized in one set (reservedMountPaths), and /workspace and /tmp are
promoted from string literals to named constants so the mount sites and
the collision guard cannot drift.

Signed-off-by: David Zager <david.j.zager@gmail.com>
@djzager
djzager force-pushed the feature/filemounts-secret-configmap-as-files branch from 5ea741b to d11dadf Compare August 27, 2026 19:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant