Jenkins installation failed on-premises

I am trying to install Jenkins using valyes.yaml on RKE Kubernetes cluster …
version : 2.414.2 using helm3 ,

this is the error I am getting when it tries to connect internal repository url to get update-center values…

disable Setup Wizard
download plugins
File containing list of plugins to be downloaded: /var/jenkins_home/plugins.txt
Reading in plugins from /var/jenkins_home/plugins.txt

No directory to download plugins entered. Will use default of /usr/share/jenkins/ref/plugins
Using update center https:///repository/new-jenkins-plugins/updates/update-center.json from JENKINS_UC environment variable
Using experimental update center https:///repository/new-jenkins-plugins/experimental/update-center.json from JENKINS_UC_EXPERIMENTAL environment variable
Using incrementals mirror Index of incrementals/ from JENKINS_INCREMENTALS_REPO_MIRROR environment variable
No CLI option or environment variable set for plugin info, using default of https://updates.jenkins.io/plugin-versions.json
Will use war file: /usr/share/jenkins/jenkins.war

Retrieving update center information
Update center URL: https:///repository/new-jenkins-plugins/updates/update-center.json?version=2.414.2
Cache miss for: update-center-2.414.2
Unable to retrieve JSON from https:///repository/new-jenkins-plugins/updates/update-center.json?version=2.414.2: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Unable to retrieve JSON from https:///repository/new-jenkins-plugins/updates/update-center.json?version=2.414.2: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
io.jenkins.tools.pluginmanager.impl.UpdateCenterInfoRetrievalException: Error getting update center json
at io.jenkins.tools.pluginmanager.impl.PluginManager.getJson(PluginManager.java:839)
at io.jenkins.tools.pluginmanager.impl.PluginManager.getUCJson(PluginManager.java:860)
at io.jenkins.tools.pluginmanager.impl.PluginManager.start(PluginManager.java:225)
at io.jenkins.tools.pluginmanager.impl.PluginManager.start(PluginManager.java:189)
at io.jenkins.tools.pluginmanager.cli.Main.main(Main.java:52)
Caused by: java.io.IOException: Unable to retrieve JSON from https:///repository/new-jenkins-plugins/updates/update-center.json?version=2.414.2: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at io.jenkins.tools.pluginmanager.impl.PluginManager.getViaHttpWithResponseHandler(PluginManager.java:1374)
at io.jenkins.tools.pluginmanager.impl.PluginManager.getJson(PluginManager.java:825)
… 4 more
Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:131)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:360)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:303)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:298)
at java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.checkServerCerts(CertificateMessage.java:654)
at java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.onCertificate(CertificateMessage.java:473)
at java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.consume(CertificateMessage.java:369)
at java.base/sun.security.ssl.SSLHandshake.consume(SSLHandshake.java:392)
at java.base/sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:443)
at java.base/sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:421)
at java.base/sun.security.ssl.TransportContext.dispatch(TransportContext.java:183)
at java.base/sun.security.ssl.SSLTransport.decode(SSLTransport.java:172)

the host where the installation is running , root CA certs added into java truststore …

I was trying to write this customerInitContainer …but I am getting permission denied because folder is unable to create because container is running as non-root

[####@######## jenkins] (default) $ k logs mm-new-jenkins-0 -n mm-ops-new-jenkins --all-containers
cat: /tmp/custom-ca-certs.crt: No such file or directory
Error from server (BadRequest): container “init” in pod “mm-new-jenkins-0” is waiting to start: PodInitializing

how can I add the below details only for this container —

runAsUser: 0
fsGroup: 1000

customInitContainers:
- name: init-inject
image: jenkins/jenkins:2.414.2-jdk11
imagePullPolicy: IfNotPresent
command: [‘sh’,‘-c’,‘echo The app is running!’]

  env:
  - name: CA_CERTS_BASE64
    value: "SGVsbG8gV29ybGQK"
  command:
  - "sh"
  - "-c"
  - >
    echo $CA_CERTS_BASE64 | base64 -d > /tmp/custom-ca-certs.crt
  command: ['sh','-c','cat /tmp/custom-ca-certs.crt' ]
  #  && cat /etc/ssl/certs/ca-buldle.crt /etc/ssl/certs/ca-buldle.trust.crt /tmp/custom-ca-certs.crt > /cacerts-share/ca-certificates.crt
  #  && cp ${JAVA_HOME}/lib/security/cacerts /cacerts-share/cacerts
  #  && chmod 644 /cacerts-share/cacerts
  #  && ${JAVA_HOME}/bin/keytool -import -trustcacerts -alias custom-ca-certs -keystore /cacerts-share/cacerts -file /tmp/custom-ca-certs.crt -noprompt -storepass changeit