Nils Hanke
bb7e8c078b
Fix version & vermagic, autofs4 in kernel, else back to module
2022-12-30 13:27:16 +01:00
Nils Hanke
5e996f9f73
Something is broken with modules in dracut :/
2022-12-30 13:27:16 +01:00
Nils Hanke
f1b77afed5
Include autofs & dm-crypt / dm-verity in kernel directly
2022-12-30 13:27:16 +01:00
Nils Hanke
aa3e728f13
fixup! fixup! Use fedpkg custom Azure Ubuntu 5.4 kernel with Wireguard
2022-12-30 13:27:16 +01:00
Nils Hanke
89eeb26788
fixup! Use fedpkg custom Azure Ubuntu 5.4 kernel with Wireguard
2022-12-30 13:27:16 +01:00
Nils Hanke
b63f333bfb
Use fedpkg custom Azure Ubuntu 5.4 kernel with Wireguard
2022-12-30 13:27:16 +01:00
Nils Hanke
993b4c781d
Test patched Kernel 6.1
2022-12-30 13:27:16 +01:00
Nils Hanke
e66113e583
Use upstream v6.0.0 kernel with random Microsoft patches
2022-12-30 13:27:16 +01:00
Nils Hanke
b2e8d71d20
Use custom Azure 5.4 CVM kernel with Wireguard patched in
2022-12-30 13:27:16 +01:00
Nils Hanke
cdd1729172
Downsize partitions for hopefully faster pipeline
2022-12-30 13:27:16 +01:00
Nils Hanke
d8d1e3d733
Go to Ubuntu-azure-cvm-5.4.0-1080.83+cvm1
2022-12-30 13:27:16 +01:00
Nils Hanke
f63c495396
Disable AppArmor
2022-12-30 13:27:16 +01:00
Nils Hanke
7b1fe6e7fd
Useless commit to bump git hash to avoid image collisions
2022-12-30 13:27:16 +01:00
Nils Hanke
7b26224e4e
Increase storage because we're lazy
2022-12-30 13:27:16 +01:00
Nils Hanke
96faef4906
Bump
2022-12-30 13:27:16 +01:00
Nils Hanke
e50592b394
Test: Use custom built kernel from Azure Ubuntu
2022-12-30 13:27:16 +01:00
3u13r
473e16feb2
image: add upgrade-agent ( #827 )
2022-12-29 17:50:11 +01:00
Paul Meyer
b9a1a9ae5e
image: set runtime-endpoint in crictl config ( #821 )
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-22 12:34:28 +01:00
Paul Meyer
c741ccfb4b
kubernetes: use new registry
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-13 16:08:19 +01:00
Paul Meyer
0150fcc22c
ci: fix new shellcheck v0.9.0 findings ( #795 )
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-13 13:24:03 +01:00
Malte Poll
4a8ebfd921
OS images: use "ref", "stream" and "version"
...
Switch azure default region to west us
Update find-image script to work with new API spec
Add version for every os image build
generate measurements: Use new API paths
CLI: config fetch measurements: Use image short versions to fetch measurements
CLI: allows shortnames to specify image in config
Image build pipeline: Change paths to contain "ref" and "stream"
2022-12-09 13:37:43 +01:00
Malte Poll
53576d63a0
Downgrade GCP kernel to 5.19.17-300 ( #763 )
2022-12-09 13:20:00 +01:00
Paul Meyer
1709da0085
image: fix script for PKI generation
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 18:07:54 +01:00
Paul Meyer
a0a7294546
image: set TERM environmet variable
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-30 16:26:25 +01:00
Paul Meyer
b93b24e058
debugd: add logcollector
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-30 16:26:25 +01:00
Paul Meyer
8224d4cd1f
image: install podman
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-30 16:26:25 +01:00
Daniel Weiße
ad7baa667a
CSI driver fixes ( #668 )
...
* Fix invalid key id for resize operations
* Add udev rule for unlabeled disks
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
2022-11-30 08:35:38 +01:00
Malte Poll
29ff6cb786
Move hardcoded all zero PCR[12] to PCR[8]
2022-11-22 11:37:53 +01:00
Malte Poll
efaa0622a8
Include image version in mkosi builds
2022-11-18 10:37:45 +01:00
Malte Poll
74aabe86fa
Move PCR[8] -> PCR[12]
2022-11-18 10:37:45 +01:00
Malte Poll
239b9f6c26
Upgrade images to Fedora 37
2022-11-18 10:37:45 +01:00
Malte Poll
78481b32e8
Move image artifacts "/v1/" => "/constellation/v1" ( #579 )
2022-11-17 16:14:38 +01:00
Paul Meyer
7f5a1dd901
ci: use /usr/bin/env instead of /bin/env
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-17 12:01:29 +01:00
Paul Meyer
cca02597c8
image: remove bash options from sourced scripts
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-17 11:28:49 +01:00
Paul Meyer
4847b71faa
image: use bash shebang
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-17 11:28:49 +01:00
Malte Poll
cdaf1fc476
OS Image Build pipeline: prepare lookup tables and additional artifacts ( #560 )
2022-11-16 15:45:10 +01:00
Malte Poll
74a7a80153
Do not quote azure image upload params ( #549 )
2022-11-14 15:31:50 +01:00
Malte Poll
14f0432624
Undo shell options for dracut module-setup ( #545 )
2022-11-14 14:28:47 +01:00
Paul Meyer
106b738fab
ci: format shellscripts
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-11 15:53:57 +01:00
Paul Meyer
7aa7492474
Fix shellcheck warnings
...
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-11-11 13:40:13 +01:00
Malte Poll
e9fecec0bc
Only publish release AMIs
2022-11-09 14:29:58 +01:00
Malte Poll
a96f07dbdd
shellcheck upload_aws.sh
2022-11-09 14:29:58 +01:00
Malte Poll
9e12e004bb
Set SELinux from disabled to permissive ( #474 )
2022-11-09 12:04:58 +01:00
Malte Poll
ac5ad7c378
Clarify Azure Secure Boot / VMGS settings when uploading images ( #488 )
2022-11-09 10:11:23 +01:00
Malte Poll
e07c6ada5c
Backport systemd-resolved fixes for Fedora 36
2022-11-08 00:07:04 +01:00
Malte Poll
2171b9fb31
Install CA certificates in initrd
2022-11-08 00:07:04 +01:00
Malte Poll
0d7e0b44b8
Wait for nss-lookup in initrd
2022-11-08 00:07:04 +01:00
Malte Poll
86001daf7f
Install systemd-resolved in dracut to enable DNS
2022-11-08 00:07:04 +01:00
Malte Poll
ed58fcccd3
CI: Add secure boot prod keys ( #462 )
...
* Add production secure boot keys
* Refactor OS build and upload settings
2022-11-04 16:48:52 +01:00
Malte Poll
4a7024c469
Make AMI public on creation ( #426 )
2022-11-03 15:22:51 +01:00