agregar TODOs para hacer root readonly (seguridad)
This commit is contained in:
parent
ec3a75acca
commit
63690627d6
2 changed files with 2 additions and 0 deletions
|
@ -91,6 +91,7 @@ class FirecrackerInstance {
|
|||
drive_id: "rootfs",
|
||||
path_on_host: "../rootfs.ext4",
|
||||
is_root_device: true,
|
||||
// TODO: readonly
|
||||
is_read_only: false,
|
||||
});
|
||||
if (opts?.drives) {
|
||||
|
|
|
@ -82,6 +82,7 @@ hostname -F /etc/hostname
|
|||
// r("/root/.ssh/authorized_keys"),
|
||||
// ]);
|
||||
|
||||
// TODO: hacer squashfs
|
||||
const ext4 = "rootfs.ext4";
|
||||
await rm(ext4);
|
||||
await execFile("fallocate", ["--length", "1G", ext4]);
|
||||
|
|
Loading…
Reference in a new issue