You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
install: Add block to config, disable tpm2-luks unless opted-in
This allows the container image builder more control over
`bootc install to-disk` in the installation config. Per discussion in
#421
this one definitely requires integration by the base image,
and not all of them will want it.
(Or if the do want LUKS, they may want more control over it)
The default value is `block: ["direct"]` which only enables
the simple filesystem install.
This change allows two different things:
`block: []`
With this, `bootc install to-disk` will just error out. It's
a way to effectively disable it for those that want to use
an external installer always.
Another possibility is:
`block: ["direct", "tpm2-luks"]`
To explicitly re-enable the builtin tpm2-luks flow.
Or, one could do just `block: ["tpm2-luks"]` to enforce encrypted installs.
Signed-off-by: Colin Walters <[email protected]>
0 commit comments