3 ms·
Most of this can be done with Ansible. All of this can be done in several ways. Ansible, manually, a script, etc. Building it into an image just makes it more
by secureblue 3y ago
Most of this can be done with Ansible.
All of this can be done in several ways. Ansible, manually, a script, etc. Building it into an image just makes it more convenient.
So why should I download images from a 3rd party outside of the Fedora project?
All of the CICD is completely open and transparent. You can read through the github actions logs and build config to verify everything for yourself if you want.
If you really want to harden an OS with a good SElinux implementation you should try enabling user roles.
Agreed, that would be a massive improvement. There's a SIG upstream working on it.
- INTPenis 3y agoThe ublue images are useful to people, so I'm sure your images will be useful to someone. I'm just making a judgement call for myself. Any other project ontop of Fedora increases the attack vector with its own maintainers. If I can choose between legible Ansible yaml, and an ISO, I find the yaml much easier to grasp and understand. Bundling things you could easily do with yaml into an ISO is almost obfuscation. Because most people are not going to read or understand your build config and logs. While Ansible yaml is clearly labeled and tagged for each action.
- secureblue 3y agoI'm just making a judgement call for myself. Any other project ontop of Fedora increases the attack vector with its own maintainers. Totally understandable. an ISO Small point of correction: we're not publishing ISOs.