Skip to content

support policy drop-ins for rottweiler #739

@bcressey

Description

@bcressey

What I'd like:
I'd like the ability to override some of the hard-coded behavior in rottweiler via drop-ins:

  1. PCRs for sealing keys
  2. Settings to exclude

Any alternatives you've considered:
Keep the hard-coded paths. These are inflexible and won't easily extend to downstream builds. For example, we know that aws-k8s-* builds will set settings.kubernetes.hostname-override to a host-specific value, which then makes the PCR 8 measurement unique.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions