Index | Thread | Search

From:
Chris Narkiewicz <hello@ezaquarii.com>
Subject:
Re: [patch] Autoinstall with disk encryption
To:
tech@openbsd.org
Date:
Thu, 8 Feb 2024 23:06:20 +0000

Download raw body.

Thread
On Thu, Feb 08, 2024 at 01:29:46PM +0000, Stuart Henderson wrote:
> But, do enough people really want autoinstall with FDE from a password
> fetched from a webserver to be worth doing this? It doesn't seem very
> sensible to me.

I re-install with FDE quite often, either when I do some destructive
experiment or simply b0rk my current system. I have full ansible
automation to handle it, but can't autoinstall.

I also do it for VPS. I re-install all my hosts in local network and
ship bunch of qcow2 images over SFTP to re-provision VPS instances.

Again, FDE password being the only thing not allowed in autoinstall is
the only thing preventing full automation, like a nail house on a
motorway.  This inconsistency forces me to go over the whole process
manually for each machine.

Best regards,
Chris Narkiewicz