Skip to content

Conversation

@gerblesh
Copy link

By default this builds without the sealed image and requires two secrets (DB_KEY) and (DB_CRT) which can be generated with the provided just recipe. The reason it by default builds without the UKI is because when extending the image the user is going to need to rebuild the UKI, etc themselves which means that all of the effort to sign the base image would be moot (nobody is going to be daily driving raw arch bootc from a tty)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant