Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Secure Boot Support for Metal Automation

Abierto
#33 2 comentarios 0 reacciones 1 asignado Ver en GitHub

@hardikdr ya está trabajando en esto.

Desde el 28/3/2025.

Evaluación

Este issue todavía no se ha evaluado.

Descripción

area/metal-automation area/operatingsystem

Summary

This initiative aims to introduce Secure Boot support in the Ironcore ecosystem, enabling users to launch machines (metal) with Secure Boot enabled—assuming the OS and BIOS settings permit it. Secure Boot ensures that only trusted, signed software can be executed during the boot process, and Ironcore should provide all the necessary APIs, primitives, and mechanisms to support this flow in a user-friendly and cloud-native way.

The goal is to enable secure OS bootstrapping via Ironcore, with support verified using Gardenlinux, which already supports Secure Boot.


Scope

✅ In Scope
  • Provide IroncoreAPI extensions or primitives to express Secure Boot requirements.
  • Support Secure Boot on Metal Machines, by enabling BIOS settings and passing signing keys via ServerClaim.
  • Validate and test with at least Gardenlinux as the reference OS.
  • Document how users can configure and launch Secure Boot-enabled machines.
  • Ensure workflows are seamlessly integrated into Ironcore’s provisioning flow.
❌ Out of Scope
  • Building or managing custom key infrastructure (user responsibility).
  • Broad multi-OS testing (initial focus is Gardenlinux).
  • Enforcement of Secure Boot policies at runtime.

Responsible Areas

  • Metal Automation
  • Operating System

Contributors

  • @5kt
  • @afritzler
  • @hardikdr

Acceptance Criteria

  • Metal Automation
    • BIOS settings related to Secure Boot can be toggled via ServerClaim or equivalent mechanism.
    • Keys (PK/KEK/DB) can be passed or referenced securely.
    • Contract and method of enabling Secure Boot are documented and implemented.
  • Operating System
    • Machines with Gardenlinux can be booted successfully with Secure Boot enabled.
  • Common
    • Complete documentation provided for users to configure and verify Secure Boot.

Action Items

  • Assign labels (e.g., area/security, area/virtualization, kind/epic)
  • Set milestone (H2/2025)
  • Assign dependent sub-issues in each required area
  • Assign an owner to the issue using the GitHub "Assignee" field
  • List all contributors in the "Contributors" section above
  • Add this issue to the ironcore-dev/roadmap project
Lenguaje dominante
Shell
Estrellas
1
Forks
1
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de ironcore-dev/roadmap

Todos los issues de ironcore-dev/roadmap

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.