• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

wrouesnel / netboot / 37394099508
45%
main: 45%

Build:
Build:
LAST BUILD BRANCH: wrouesnel/secure-boot-features
DEFAULT BRANCH: main
Ran 06 Oct 2026 12:28AM UTC
Jobs 1
Files 51
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

06 Oct 2026 12:27AM UTC coverage: 44.67% (+2.8%) from 41.902%
37394099508

push

github

wrouesnel
pixiecore: delegate Secure Boot signing to a remote signing service

With --secureboot-delegate-url, Pixiecore doesn't hold a signing key.
It POSTs each UEFI image to an HTTPS signing service, with
X-Pixiecore-Mac and X-Pixiecore-Image-Type (ipxe or kernel), and serves
the signed image the service returns. So the service decides, per
machine, whether and how to sign.

- iPXE is signed for the machine when it's fetched over TFTP, and
  signing starts when Pixiecore offers the machine a boot, so it's
  usually ready by the time the machine asks. Kernels are signed for
  the machine when they're served.
- The kernel URL token (ksig) now also covers the MAC address, so a
  machine can't get a kernel signed for another machine.
- Responses must be the image that was sent (same Authenticode digest)
  with a new signature, checked by the new uefisign.CheckSigned.
  Failures are logged, with the service's error message, and the image
  is served unsigned.
- Concurrent and recent requests for the same image and machine share
  one signing request. Failures aren't cached.
- TLS: --secureboot-delegate-ca-cert trusts a CA for the service. mTLS:
  --secureboot-delegate-client-cert/-client-key, or
  --secureboot-delegate-client-tpm for the TPM client certificate that
  --api-client-tpm uses. --secureboot-delegate-timeout limits requests.
- It can't be used with --secureboot-key or --secureboot-tpm.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

211 of 237 new or added lines in 9 files covered. (89.03%)

6 existing lines in 1 file now uncovered.

2108 of 4719 relevant lines covered (44.67%)

6.12 hits per line

Uncovered Changes

Lines Coverage ∆ File
11
59.02
14.19% pixiecore/cli/secureboot.go
8
88.41
pixiecore/securebootdelegate.go
4
83.16
3.16% pixiecore/uefisign/uefisign.go
2
70.61
1.31% pixiecore/cli/apiclient.go
1
0.0
0.0% pixiecore/dhcp.go

Coverage Regressions

Lines Coverage ∆ File
6
9.21
0.0% pixiecore/cli/tpmcertcmd.go
Jobs
ID Job ID Ran Files Coverage
1 37394099508.1 06 Oct 2026 12:28AM UTC 51
44.67
GitHub Action Run
Source Files on build 37394099508
  • Tree
  • List 51
  • Changed 10
  • Source Changed 0
  • Coverage Changed 10
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • f173b342 on github
  • Prev Build on wrouesnel/secure-boot-features (#37203770096)
  • Next Build on wrouesnel/secure-boot-features (#37400995822)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc