bootc-dev / bootc-dev/bootc

install: Add `--copy-container-credentials`

Open
#428 1 comment 0 reactions 1 assignee Claimed by @bcrochet View on GitHub
area/install enhancement triaged
Dominant language
Rust
Stars
2.3k
Forks
230
Avg merge
3d 12h
Merged PRs (30d)
38

Description

We document that registry credentials are honored from `/etc/ostree/auth.json`, but it's easy to miss (and needs to highlighted much better) (there's also the general issue with embedding the pull secret in the image itself, cc https://github.com/containers/bootc/issues/22 )

Now when using `bootc install to-filesystem` with a private registry, we could add `bootc install --copy-container-credentials` where we go and slurp out `~/.config/containers/auth.json` and inject it into the final system as `/etc/ostree/auth.json`.

This way we get a flow where we

- `podman login` on the original host
- `bootc install to-filesystem --copy-container-credentials`

And the *original* podman credentials (injected into `~/.config/containers/auth.json`) could have come from e.g. cloud-init (which is arguably more secure than embedding them into the image itself).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.