Commit fd41540
supermin: inject a bootc signature enforcement config
Tell bootc to enforce that `/etc/containers/policy.json` include a default
policy that verify our images signature.
When moving to image-builder, this config can be moved into the container itself
but as long as we are using osbuild manually we have to carry this in the buildroot.
TODO: uncomment this when bootc-dev/bootc#2116
is merged and released
See coreos/fedora-coreos-config#4093 (comment)1 parent dae44a7 commit fd41540
1 file changed
+11
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
97 | 97 | | |
98 | 98 | | |
99 | 99 | | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
0 commit comments