mirror of
https://github.com/xcat2/confluent.git
synced 2024-11-21 17:11:58 +00:00
329f2b4485
Provide mechanism for administrator to place a custom key for potential interactive recovery into /var/lib/confluent/private/os/<profile>/pending/luks.key If not provided, generate a unique one for each install. Either way, persist the key in /etc/confluent/luks.key, to facilitate later resealing if the user wants (clevis nor systemd prior to 256 supports unlock via TPM2, so keyfile is required for now). Migrating to otherwise escrowed passphrases and/or sealing to specific TPMs will be left to operators and/or third parties. |
||
---|---|---|
.. | ||
common | ||
coreos | ||
debian | ||
el7 | ||
el7-diskless | ||
el8 | ||
el8-diskless | ||
el9-diskless | ||
esxi7 | ||
genesis | ||
rhvh4 | ||
suse15 | ||
suse15-diskless | ||
ubuntu18.04 | ||
ubuntu20.04 | ||
ubuntu20.04-diskless | ||
ubuntu22.04 | ||
utils | ||
buildrpm | ||
buildrpm-aarch64 | ||
confluent_osdeploy-aarch64.spec.tmpl | ||
confluent_osdeploy.spec.tmpl | ||
ubuntu22.04-diskless | ||
ubuntu24.04 | ||
ubuntu24.04-diskless |