If you have a certificate file in the node file system, you can update the NCP pod specification to mount the file in the NCP pod.

For example,

  spec:
    ...
    containers:
    - name: nsx-ncp
      ...
      volumeMounts:
      ...
      - name: nsx-cert
        # Mount path must match nsx_v3 option "nsx_api_cert_file"
        mountPath: /etc/nsx-ujo/nsx_cert
        - name: nsx-priv-key
        # Mount path must match nsx_v3 option "nsx_api_private_key_file"
        mountPath: /etc/nsx-ujo/nsx_priv_key
    volumes:
    ...
    - name: nsx-cert
      hostPath:
        path: <host-filesystem-cert-path>
    - name: nsx-priv-key
      hostPath:
        path: <host-filesystem-priv-key-path>