{{- define "template.scan-pulumi-crossguard" -}} - name: scan-pulumi-crossguard inputs: parameters: - name: working-dir container: image: {{ .Values.images.pulumiCrossguard }} env: - name: PULUMI_ACCESS_TOKEN valueFrom: secretKeyRef: name: amp-security-pipeline-secrets key: PULUMI_ACCESS_TOKEN command: - sh - -c args: - | set -eu mkdir -p /workspace/reports cd "/workspace/{{ `{{inputs.parameters.working-dir}}` }}" pulumi preview --policy-pack {{ .Values.pulumi.policyPackPath | quote }} > /workspace/reports/pulumi-crossguard.json 2>&1 || true volumeMounts: - name: workspace mountPath: /workspace {{- end }}