Qodana Docker Scanner: Custom CA Trust Store Reload Limitation
0 reputation · 03 Sept 2022, 16:01 UTC
Qodana Docker Scanner: Custom CA Trust Store Reload Limitation
When running Qodana in a Docker container, users often mount a private CA certificate into the image to allow Maven or NPM repositories to be accessed over HTTPS. The scanner will trust the certificate only after the image’s trust store has been updated and the container restarted.
This behavior limits CI pipelines that rotate internal certificates, as each rotation requires a new image build or container recreation. The container’s Java runtime does not expose a mechanism to reload the updated trust store while the scanner is running.
Given that the container uses the host’s /etc/resolv.conf by default, custom DNS settings can also be applied via Docker’s --dns flag, but this does not affect the trust store reload issue.
What are the options to enable automatic reload of updated trust stores without restarting the scanner? Does Qodana support configuring the Java trust store via an environment variable or a dedicated flag? Could a shared volume be used to trigger a trust store refresh on certificate changes?