From 7e867757c4c5f4d59ecd573865dff430db11e1e3 Mon Sep 17 00:00:00 2001 From: humocs-man <1+humocs-man@noreply.localhost> Date: Sat, 5 Sep 2026 17:48:12 +0000 Subject: [PATCH] Containerfile aktualisiert --- Containerfile | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/Containerfile b/Containerfile index 3888654..f241ad6 100644 --- a/Containerfile +++ b/Containerfile @@ -75,12 +75,16 @@ RUN --mount=type=bind,from=build-ctx,source=/build/50-prepare-flatpak-for-bazaar # 1. Kopiere die Filesystem-Fixes (tmpfiles.d, Vendor-Default) COPY configs/bootc-fix.conf /usr/lib/tmpfiles.d/bootc-fix.conf -# 1b. Container-Policy (Default aus /usr/etc, kein Host-Override nötig) +# 1b. Container-Policy & Registry Auth für bootc # sigstoreSigned-Pflicht für eigenes Image, Public-Registries explizit erlaubt COPY configs/containers/policy.json /etc/containers/policy.json COPY cosign.pub /etc/pki/containers/cosign.pub +COPY configs/auth.json /etc/ostree/auth.json + RUN chmod 0644 /etc/containers/policy.json /etc/pki/containers/cosign.pub && \ - python3 -m json.tool /etc/containers/policy.json > /dev/null + chmod 0600 /etc/ostree/auth.json && \ + python3 -m json.tool /etc/containers/policy.json > /dev/null && \ + python3 -m json.tool /etc/ostree/auth.json > /dev/null # 2. Kopiere die Systemd-Overrides als Vendor-Drop-ins (kein /etc/-Override im Image) COPY configs/bootc-timer-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf