On Mon, Jan 20, 2020, at 7:57 PM, Matthew Garrett wrote: > I've been thinking about ways to solve this for a while, and I'm coming > to the conclusion that the best plan is probably to just ship pre-built > initramfs images. rpm-ostree[1] (used for Fedora CoreOS and Silverblue and IoT among others) already works this way by default. (You can also enable client-side initramfs regeneration, which is used e.g. when overlaying a custom kernel - part of being a hybrid image/package system) For FCOS, signing the initramfs is already part of the plans; see: https://github.com/projectatomic/rpm-ostree/issues/1883 and https://github.com/ostreedev/ostree/pull/1959 [1] https://github.com/coreos/rpm-ostree/ _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx