Skip to content

Continue supporting server-side SELinux labeling #1637

@jlebon

Description

@jlebon

We've now moved to client-side SELinux labeling. I think we should still though support server-side labeling, I guess through ostree container commit/bootc build commit? I think this today though conflicts with wanting to move away from /ostree in the container image, but it could be implemented differently of course.

The main argument is simply reproducibility. Notably, coreos/fedora-coreos-tracker#2030 happened which is a great example of why doing this server-side would be better for those that want to opt in (like FCOS/RHCOS).

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/selinuxRelates to SELinuxenhancementNew feature or requesttriagedThis looks like a valid issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions