-
-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Import system credential from virtiofs with tag io.systemd.credentials
#29175
Comments
So I think we probably want two things:
|
Hmm does just set
on the cmdline and you'll have a rootfs mounted by a specified tag. For the other partitions entries in Or is it just about standardising on the tags for |
a generator is hard here because you can't know if a tag exists except for mounting it :/ At least I haven't found a way to discover what tags are available for mounting. There are no paths in So people have to be explicit in their |
it is my understanding that each virtiofs fs is exposed as separate virtio device, which are enumeratable in sysfs. but i didn't check. Need to have a look. |
so, yes of course, this logic would be entirely redundant, in the same way as systemd-gpt-auto-generator kinda is. It's mostly an excercise of pushing people towards a certain way to set up VMs. |
Another idea would be to use virtiofs to exfiltrate journal logs from the machine. |
Component
systemd
Is your feature request related to a problem? Please describe
I want to have a way to import credentials into my VM but I am not using QEMU . However my VMM does provide virtiofs and no SMBIOS. (e.g. MacOS Virtualization.Framework, or Cloud-Hypervisor, FireCracker).
Describe the solution you'd like
io.systemd.credentials
/run/credentials/@virtiofs
mount -t virtiofs io.systemd.credentials /run/credentials/@virtiofs
/run/credentials/@system
/run/credentials/@virtiofs
)Other option because it feels a bit pointless to copy these files around.
/run/credentials/@virtiofs
./run/credentials/@virtiofs
and/run/credentials/@system
Describe alternatives you've considered
None
The systemd version you checked that didn't have the feature you are asking for
254
The text was updated successfully, but these errors were encountered: