meson: unlock imds network by default

Enabling locking by default would constitute a major footgun and
compatibility break on upgrades. This functionality is useful, but it
requires the rest of the system to be "ported" to use systemd-imds
first. The user or distro should opt in to "locked" mode only after
doing the integration work.
This commit is contained in:
Zbigniew Jędrzejewski-Szmek
2026-03-26 17:32:43 +01:00
parent c3e4e8a527
commit 6240d420d6
2 changed files with 8 additions and 8 deletions

14
NEWS
View File

@@ -13,13 +13,13 @@ CHANGES WITH 261 in spe:
attestation environments which use hardware CC registers and not the
TPM quote.
* By default networking to cloud IMDS services is now locked down, for
recognized clouds. This is recommended for secure installations, but
typically conflicts with traditional IMDS clients such as cloud-init,
which require direct IMDS access currently. The new meson option
"imds-network" can be used to change the default networking mode to
"unlocked" at build-time, for compatibility. This is probably what
general purpose distributions should set for now.
New features:
* Networking to cloud IMDS services may be locked down for recognized
clouds. This is recommended for secure installations, but typically
conflicts with traditional IMDS clients such as cloud-init, which
require direct IMDS access. The new meson option "-Dimds-network="
can be used to change the default mode to "locked" at build-time.
CHANGES WITH 260:

View File

@@ -144,7 +144,7 @@ option('timesyncd', type : 'boolean',
description : 'install the systemd-timesyncd daemon')
option('imds', type : 'feature',
description : 'install the systemd-imds stack')
option('imds-network', type : 'combo', choices : [ 'locked', 'unlocked' ],
option('imds-network', type : 'combo', choices : ['unlocked', 'locked'],
description : 'whether to default to locked/unlocked IMDS network mode')
option('journal-storage-default', type : 'combo', choices : ['persistent', 'auto', 'volatile', 'none'],
description : 'default storage mode for journald (main namespace)')