Skip to content
Snippets Groups Projects
Verified Commit 6d94e7b9 authored by Kristian Klausen's avatar Kristian Klausen :tada:
Browse files

Merge branch 'vm_runner-lockdown' into 'master'

gitlab_runner: try to protect the VM runner kernel from the root user

See merge request !617
parents 4d8dfb6a ab612463
No related branches found
No related tags found
1 merge request!617gitlab_runner: try to protect the VM runner kernel from the root user
Pipeline #28964 passed
......@@ -37,6 +37,8 @@ arch-chroot mnt pacman -Sy --noconfirm --needed archlinux-keyring
arch-chroot mnt pacman -Syu --noconfirm --needed git git-lfs gitlab-runner
sed -E 's/^#(IgnorePkg *=)/\1 linux/' -i mnt/etc/pacman.conf
arch-chroot mnt userdel -r arch
sed 's/^\(GRUB_CMDLINE_LINUX=".*\)"$/\1 lockdown=confidentiality"/' -i mnt/etc/default/grub
arch-chroot mnt /usr/bin/grub-mkconfig -o /boot/grub/grub.cfg
install -d -m0700 mnt/root/.ssh
install -m0600 /etc/libvirt-executor/id_ed25519.pub mnt/root/.ssh/authorized_keys
rm -f mnt/etc/machine-id
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment