• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

wrouesnel / netboot / 37203770096

30 Sep 2026 06:36AM UTC coverage: 41.902% (+7.3%) from 34.596%
37203770096

push

github

wrouesnel
pixiecore: Secure Boot signing, HTTP proxy, DNS forwarder, API headers

Secure Boot:
- Sign the UEFI iPXE binaries at startup, and kernels as they're
  served, for UEFI Secure Boot (--secureboot-key/--secureboot-cert, or
  a TPM-held RSA key with --tpm-enabled --secureboot-tpm). Existing
  signatures are kept. Kernel URLs carry an HMAC token so only boot
  spec kernels are signed. Adds the uefisign package, using go-uefi.
- Add "pixiecore secureboot-cert" to create the TPM key and a
  self-signed certificate or CSR.
- Separate --api-client-tpm from --tpm-enabled, so the TPM can hold the
  Secure Boot key without being used for the API client certificate.

API mode:
- Send X-Pixiecore-Http-Port and X-Pixiecore-Https-Port for the ports
  Pixiecore listens on.
- Replace --api-proxy with --http-proxy/--http-proxy-port (default
  3128): a forward HTTP proxy that tunnels CONNECT without intercepting
  TLS, sending X-Pixiecore-Proxy-Port to the API.
- Add --dns: a DNS forwarder on --dns-port (default 53) with
  --dns-upstream servers (plain or DNS-over-HTTPS) and --dns-override
  names that resolve to Pixiecore or a given address, sending
  X-Pixiecore-Dns (ip:port) to the API. Adds the dnsforward package,
  using miekg/dns.
- Add --api-header "Name: value" for extra headers to the API server,
  e.g. bearer tokens.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

480 of 731 new or added lines in 14 files covered. (65.66%)

173 existing lines in 7 files now uncovered.

1886 of 4501 relevant lines covered (41.9%)

3.76 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

5.52
/pixiecore/pixiecore.go


Source Not Available

STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc