Valentin Lefebvre: Securitized the initramfs and the UKI

Опубликовано: 10 Июнь 2024
на канале: SUSE Labs
75
1

Showing how we can improve the security in the boot process of our image, building a static initrd or/and a UKI. I will explain the process to build these two entities, and show what we have done, learn, and built, in our OBS. I will also compare the effectiveness of different tools to use in our build service. As a result, I will show an image based on Aeon that includes the UKI as the boot option. For now, it misses the integration of snapshots with UKI to finalize the entire project