diff --git a/README.md b/README.md index 49aac3a9f..725ffdf0a 100644 --- a/README.md +++ b/README.md @@ -301,7 +301,7 @@ echo -e 'FROM alpine \nRUN echo "created from standard input"' > Dockerfile | ta "volumeMounts": [ { "name": "cabundle", - "mountPath": "/kaniko/ssl/certs/" + "mountPath": "/etc/ssl/certs/" }, { "name": "docker-config", diff --git a/deploy/Dockerfile b/deploy/Dockerfile index 335d83841..0ec7e3ff6 100644 --- a/deploy/Dockerfile +++ b/deploy/Dockerfile @@ -66,12 +66,12 @@ FROM scratch AS kaniko-base-slim # Create kaniko directory with world write permission to allow non root run RUN --mount=from=busybox,dst=/usr/ ["busybox", "sh", "-c", "mkdir -p /kaniko && chmod 777 /kaniko"] -COPY --from=certs /etc/ssl/certs/ca-certificates.crt /kaniko/ssl/certs/ +COPY --from=certs /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ COPY files/nsswitch.conf /etc/nsswitch.conf ENV HOME /root ENV USER root ENV PATH /usr/local/bin:/kaniko -ENV SSL_CERT_DIR=/kaniko/ssl/certs +ENV SSL_CERT_DIR=/etc/ssl/certs/ FROM kaniko-base-slim AS kaniko-base diff --git a/integration/testdata/files.yaml b/integration/testdata/files.yaml index 8f19b259d..114b6b366 100644 --- a/integration/testdata/files.yaml +++ b/integration/testdata/files.yaml @@ -5,7 +5,7 @@ fileExistenceTests: path: '/' shouldExist: true - name: certs - path: '/kaniko/ssl/certs/ca-certificates.crt' + path: '/etc/ssl/certs/ca-certificates.crt' shouldExist: true - name: certs path: '/etc/nsswitch.conf'