bootc-dev / bootc-dev/bootc

Add journaling for image finalization and firstboot

Open
#452 0 comments 0 reactions 0 assignees View on GitHub
area/updates enhancement
Dominant language
Rust
Stars
2.3k
Forks
230
Avg merge
3d 12h
Merged PRs (30d)
38

Description

It'd be useful for auditing purposes for us to emit journal messages on at least the first time a particular deployment is booted, including substantial metadata (basically at least all the image stuff: pull spec, digest, version, etc.).

We might as well also do this as part of `ostree-finalize-staged.service`. Today these services run C code from libostree which is unaware of the container bits, so to fix this we could either patch that code to be aware of the container refs (or call into `ostree container` commands if available, i.e. we put the logic in ostree-ext?). But this conflicts a bit with us doing the [podman pull](https://github.com/containers/bootc/pull/215) backend, so instead we could add units here (triggered by our new generator?) that "hook" `ostree-boot-complete.service` and `ostree-finalize-staged.service` via drop-ins say.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.