Skip to content

feat: switch to bluebuild secret mounts#1202

Merged
RoyalOughtness merged 17 commits intosecureblue:livefrom
RoyalOughtness:secretmounts
Aug 1, 2025
Merged

feat: switch to bluebuild secret mounts#1202
RoyalOughtness merged 17 commits intosecureblue:livefrom
RoyalOughtness:secretmounts

Conversation

@RoyalOughtness
Copy link
Copy Markdown
Collaborator

@RoyalOughtness RoyalOughtness commented Jul 24, 2025

Utilizes the new secret mount feature in bluebuild as opposed to pulling from a file:

blue-build/cli#487

This has security benefits like scoping the secure boot signing key to only the scripts that need it, built in shredding functionality, and keeping the privkey out of the image fileystem during the build

@RoyalOughtness RoyalOughtness marked this pull request as ready for review July 30, 2025 02:02
@RoyalOughtness RoyalOughtness merged commit f41b9a0 into secureblue:live Aug 1, 2025
18 of 19 checks passed
RoyalOughtness added a commit to RoyalOughtness/secureblue-dev that referenced this pull request Aug 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants