Skip to content

Support (a subset of) customizations for sealed bootable container (HMS-11222) #2560

Description

@supakeen

Currently we basically accept no customizations for bootable containers to ensure we don't accidentally break things with the fs-verity hash in the native composefs.

It should however be possible to enable any customizations that only touch /etc or /var.

Disk customizations are likely to be kept disabled for now as there is tight coupling to the kernel arguments in the signed UKI versus the disk layout.

Metadata

Metadata

Assignees

No one assigned

    Labels

    admin/has-jiraTracked in JIRA as well.area/bootcRelated to bootable containers.enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions