Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
30ignition/ignition-setup: mount /boot partition ro
We don't actually need write access to `/boot` here to pull out any baked Ignition config. Just mount it read-only. This also helps in the case where any other service is concurrently also mounting `/boot`: trying to mount a device as read-write that's already mounted read-only elsewhere will fail. I hit this when playing with FIPS mode, which does this: https://github.com/dracutdevs/dracut/blob/718aefda1374c7b6c3790b08cae27fd6bde505af/modules.d/01fips/fips.sh#L49 (backport of coreos#134)
- Loading branch information