If you really want to harden an OS with a good SElinux implementation you should try enabling user roles.
Last time I tried that was maybe Fedora 20 something and it broke a lot.
If you really want to harden an OS with a good SElinux implementation you should try enabling user roles.
Last time I tried that was maybe Fedora 20 something and it broke a lot.
All of this can be done in several ways. Ansible, manually, a script, etc. Building it into an image just makes it more convenient.
So why should I download images from a 3rd party outside of the Fedora project?
All of the CICD is completely open and transparent. You can read through the github actions logs and build config to verify everything for yourself if you want.
If you really want to harden an OS with a good SElinux implementation you should try enabling user roles.
Agreed, that would be a massive improvement. There's a SIG upstream working on it.
Any other project ontop of Fedora increases the attack vector with its own maintainers.
If I can choose between legible Ansible yaml, and an ISO, I find the yaml much easier to grasp and understand.
Bundling things you could easily do with yaml into an ISO is almost obfuscation. Because most people are not going to read or understand your build config and logs. While Ansible yaml is clearly labeled and tagged for each action.
Totally understandable.
an ISO
Small point of correction: we're not publishing ISOs.
I don't understand these spins/release patterns
Most of these several gig ISOs amount to two dozen lines of scripting in the kickstarts
I can't edit now but thought this deserved mention