-
Notifications
You must be signed in to change notification settings - Fork 60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Encryption: All disks are belong to us #287
Comments
What do we mean by "blessed"? |
To be explicitly clear: the purpose of this tracker item is not to propose any change of behavior to FCOS. That can be considered if there is interest. The reason I created it here is that since FCOS is upstream to RHCOS, and some of the dependent features will benefit FCOS:
The other reason why I create it here is so that the changes to CoreOS Assembler, Fedora Core Config, Ignition (and Ignition Dracut), etc, can be reference this tracker item; there didn't seem to be a good place for such a document. |
Summarizing a lot from the IRC meeting:
The overall flow would look like:
|
It's good to see you are considering supporting encryption a priority. 😃 |
Initial LUKS support for Ignition has landed in coreos/ignition#960 & coreos/ignition-dracut#192 Outstanding work for getting said work into FCOS is coreos/fedora-coreos-config#503 & cutting a new Ignition release and making it into coreos/fedora-coreos-config |
IMO, we can close this out when all the bits land in Fedora. We sort of ignored the game plan...but we got a much better path. Well done @arithx ! |
Bits have landed in FCOS. I'm going to close this out as work well done. |
All disks are belong to us
With Openshift Enhancement Request for Policy-Based Encryption RHCOS will be extended to support root disk encryption. It is the strong preference that both RHCOS and FCOS align with respect to disk handling.
This is a tracking issue to ensure alignment with the idea.
Phase 0 (OpenShift 4.3)
Phase 1 (OpenShift 4.4)
Phase 2 (OpenShift 4.4 or 4.5)
Action Iteams:
The text was updated successfully, but these errors were encountered: