NAME
bootc-install-config.toml
DESCRIPTION
The bootc install process supports customization through TOML drop-in files
in /usr/lib/bootc/install, /usr/local/lib/bootc/install, /etc/bootc/install,
and /run/bootc/install. If the same filename occurs in multiple directories,
the file in the later directory in this list takes precedence. The selected
files are then processed in alphanumerical filename order.
Fragments whose match_architectures includes the current architecture, or
which omit that field, are merged. Values such as the root filesystem type
are overridden when specified in a later fragment. The kargs and
karg-deletes lists are appended instead of replaced.
The individual files are merged into a single final installation config, so it is supported for e.g. a container base image to provide a default root filesystem type, that can be overridden in a derived container image.
install
This is the only defined toplevel table.
The install section supports these subfields:
block: An array of supportedto-diskbackends enabled by this base container image; if not specified, this will just bedirect. The only other supported value istpm2-luks. The first value specified will be the default. To enable both, useblock = ["direct", "tpm2-luks"].filesystem: See below.kargs: An array of strings; this will be appended to the set of kernel arguments.match_architectures: An array of strings; this filters the install config.ostree: See below.stateroot: The stateroot name to use. Defaults todefault.root-mount-spec: A string specifying the root filesystem mount specification. For example,UUID=2e9f4241-229b-4202-8429-62d2302382e1orLABEL=rootfs. If not provided, the UUID of the target filesystem will be used. An empty string signals to omit boot mount kargs entirely.boot-mount-spec: A string specifying the /boot filesystem mount specification. If not provided and /boot is a separate mount, its UUID will be used. An empty string signals to omit boot mount kargs entirely.discoverable-partitions: Boolean. Whentrue, root discovery uses the Discoverable Partitions Specification viasystemd-gpt-auto-generatorand theroot=kernel argument is omitted. This requires the bootloader to implement the Boot Loader Interface (BLI); systemd-boot always does, GRUB needs theblimodule (available in newer builds). Defaults totruewhen using systemd-boot,falseotherwise.enforce-container-sigpolicy: A boolean that controls whether to enforce thatcontainers-policy.json(seeman containers-policy.jsonfor the full search path) includes a default policy which requires signatures. Whentrue, image pulls will be rejected if the policy file specifiesinsecureAcceptAnythingas the default. Defaults tofalse. This is equivalent to the--enforce-container-sigpolicyCLI flag.
filesystem
There is one valid field:
root: An instance of "filesystem-root"; see below
filesystem-root
There is one valid field:
type: This can be any basic Linux filesystem with a mkfs.$fstype. For example, ext4, xfs, etc.
ostree
Configuration options for the ostree repository. There is one valid field:
bls-append-except-default: A string of kernel arguments that will be appended to Boot Loader Spec entries, except for the default entry. This is useful for configuring arguments that should only apply to non-default deployments.
bootupd
Configuration options for bootupd, responsible of setting up the bootloader. There is only one valid field:
skip-boot-uuid: A boolean that controls whether to skip writing partition UUIDs to the bootloader configuration. Whentrue, bootupd is invoked with--with-static-configsinstead of--write-uuid. Defaults tofalse(UUIDs are written by default).
Examples
[install.filesystem.root]
type = "xfs"
[install]
kargs = ["nosmt", "console=tty0"]
stateroot = "myos"
root-mount-spec = "LABEL=rootfs"
boot-mount-spec = "UUID=abcd-1234"
enforce-container-sigpolicy = true
[install.ostree]
bls-append-except-default = 'grub_users=""'
Enable DPS auto-discovery for root (requires a BLI-capable bootloader):
[install]
discoverable-partitions = true
SEE ALSO
bootc(1)
VERSION
The Linux Foundation® (TLF) has registered trademarks and uses trademarks. For a list of TLF trademarks, see Trademark Usage.