misuto has quit [Remote host closed the connection]
misuto has joined #fedora-coreos
Betal has quit [Quit: WeeChat 3.8]
bgilbert has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
paragan has quit [Quit: Leaving]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 260 seconds]
jpn has joined #fedora-coreos
anthr76[m] has quit [Quit: You have been kicked for being idle]
<bluecmd>
Hi! I am playing with CoreOS layering. I have uploaded my own CoreOS derrivation on quay.io/bluecmd/bluecmd-coreos and I am trying to figure out how I can restrict my CoreOS instance to only accept it as a rebase target. I am playing around with sudo rpm-ostree rebase ostree-image-signed:docker://quay.io/bluecmd/bluecmd-coreos:test and /etc/containers/policy.json but I cannot seem to get the rebase to fail - it always succeeds even
<bluecmd>
though I am asking it to require signatures from /dev/null.
<bluecmd>
Or am I thinking about this the wrong way -- should my derivation somehow sign the OSTree and I should auth the OSTree instead?
<apollo13[m]>
bluecmd[m]: as far as I understood it /etc/containers/policy.jon is not yet consulted by the ostree tooling
<apollo13[m]>
(but take that with a grain of salt)
<bluecmd>
From what I have observed, it complains about the default setting in that file if it is set to insecureAlwaysAccept - so I assumed it cared about the contents of the policy
<apollo13[m]>
mhm then I am probably wrong 🙂
mei has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
ravanell_ has joined #fedora-coreos
ravanelli has quit [Ping timeout: 248 seconds]
mei has left #fedora-coreos [#fedora-coreos]
jpn has joined #fedora-coreos
jawaharlal has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
plarsen has joined #fedora-coreos
plarsen has quit [Remote host closed the connection]
gursewak has joined #fedora-coreos
ravanell_ has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
Betal has joined #fedora-coreos
jpn has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
jpn has quit [Ping timeout: 268 seconds]
jpn has joined #fedora-coreos
ravanelli has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
ravanelli has quit [Ping timeout: 260 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 268 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
daMaestro has joined #fedora-coreos
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 260 seconds]
jpn has joined #fedora-coreos
klaas has quit [Read error: Connection reset by peer]