bootc-dev / bootc-dev/bootc

install: Add `--copy-container-credentials`

Aperta
#428 1 commento 0 reazioni 1 assegnatario Rivendicata da @bcrochet Vedi su GitHub
area/install enhancement triaged
Lingua principale
Rust
Stelle
2.3k
Fork
230
Merge medio
3g 12h
PR unite (30g)
38

Descrizione

We document that registry credentials are honored from `/etc/ostree/auth.json`, but it's easy to miss (and needs to highlighted much better) (there's also the general issue with embedding the pull secret in the image itself, cc https://github.com/containers/bootc/issues/22 )

Now when using `bootc install to-filesystem` with a private registry, we could add `bootc install --copy-container-credentials` where we go and slurp out `~/.config/containers/auth.json` and inject it into the final system as `/etc/ostree/auth.json`.

This way we get a flow where we

- `podman login` on the original host
- `bootc install to-filesystem --copy-container-credentials`

And the *original* podman credentials (injected into `~/.config/containers/auth.json`) could have come from e.g. cloud-init (which is arguably more secure than embedding them into the image itself).

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.