iso: per-device first-boot secrets + checksum emission/signing #75

Closed
lfg2025 wants to merge 0 commits from iso-first-boot-secrets into main
Owner
  • archipelago-first-boot-secrets.service: regenerates TLS keypair (hostname SAN) + SSH host keys on first boot, staging-first swap, marker-guarded, enabled on the installed target (§F critical)
  • builder emits .sha256 after xorriso; scripts/sign-iso-checksums.sh signs {artifact,sha256,size} with the release-root ceremony (§F)
  • tracker ticked with shas

🤖 Generated with Claude Code

- archipelago-first-boot-secrets.service: regenerates TLS keypair (hostname SAN) + SSH host keys on first boot, staging-first swap, marker-guarded, enabled on the installed target (§F critical) - builder emits <iso>.sha256 after xorriso; scripts/sign-iso-checksums.sh signs {artifact,sha256,size} with the release-root ceremony (§F) - tracker ticked with shas 🤖 Generated with [Claude Code](https://claude.com/claude-code)
chaum closed this pull request 2026-07-13 12:49:40 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.