-
Notifications
You must be signed in to change notification settings - Fork 142
Open
Labels
area/selinuxRelates to SELinuxRelates to SELinuxenhancementNew feature or requestNew feature or requesttriagedThis looks like a valid issueThis looks like a valid issue
Description
We've now moved to client-side SELinux labeling. I think we should still though support server-side labeling, I guess through ostree container commit
/bootc build commit
? I think this today though conflicts with wanting to move away from /ostree
in the container image, but it could be implemented differently of course.
The main argument is simply reproducibility. Notably, coreos/fedora-coreos-tracker#2030 happened which is a great example of why doing this server-side would be better for those that want to opt in (like FCOS/RHCOS).
Metadata
Metadata
Assignees
Labels
area/selinuxRelates to SELinuxRelates to SELinuxenhancementNew feature or requestNew feature or requesttriagedThis looks like a valid issueThis looks like a valid issue