-
Overview
-
redpesk OS releases
-
Security updates
- Security CVE / errata
- CVE quick look
-
Redpesk OS Tips and Tricks
-
Application Framework Manager
-
Application Framework Binder
-
APIs & Services
-
Security manager
-
OP-TEE within redpesk
-
Trusted Boot
-
Recovery features
-
redpak
-
Minimal image
- Reduce image size
- Optimizing boot time
-
Kernel fragments description
- Introduction to Linux Kernel Configuration
- 01 Disable IPC, Timers and Audit
- 02 Disable Kconfig, Scheduler and Initrd
- 03 Disable Perf, Profiling and Errata
- 04 Disable EFI, Power Management Debug and Energy Model
- 05 Disable Schedutil, CPUFreq Governors and Virtualization
- 06 Disable Kprobes and Jump Labels
- 07 Disable GCC Plugins and Function Alignment
- 08 Disable Partition Parsers
- 09 Enable Inline Spinlocks and Kernel Operations
- 10 Disable Swap, Memory Hotplug and KSM
- 11 Disable Networking IPv4, IPv6, Netfilter
- 12 Disable SCTP, VLAN, TIPC, BATMAN
- 13 Disable Wireless, Bluetooth, CAN and RFKILL
- 14 Disable PCI and Firmware
- 15 Disable GNSS and ProcEvents
- 16 Disable Block Storage NBD and AoE
- 17 Disable EEPROM and Misc Drivers
- 18 Disable Network Device Drivers
- 19 Disable PHY Drivers
- 20 Disable PPP, WLAN Coexistence, and Failover
- 21 Disable Input Devices
- 22 Disable Serial, TTY and TPM
- 23 Disable I2C, Power and Sensor Drivers
- 24 Disable MFD, Display and Media Drivers
- 25 Disable USB, Sound, RTC and VirtIO
- 26 Disable Filesystem Encodings and Compatibility
- 27 Enable Minimal Cryptographic Core with SHA3 and XTS
- 28 Disable Hardware Cryptography, Keep DRBG and Jitter Entropy
- 29 Disable Kernel Debugging Features
- 30 Disable Filesystem Verity and SecurityFS
-
Zephyr in Redpesk
-
PERM-CHECK extension
-
Mender redpesk (OTA)
-
Hardware support
- Download images
- Image metrics
- Trusted Boot
- Boards - ARM64
- Boards - x86_64
- Boards - Virtual
- Miscs
-
Building microservices natively within SDK container
-
Building microservices and framework from sources
Setup
Requirement
OCI-compliant container engine installed such as podman or docker.
Clone helloworld-binding
Set the work directory where the project will be cloned.
This work directory will be mounted inside the SDK container
WORKDIR=${HOME}/project
git clone git@github.com:redpesk-samples/helloworld-binding.git ${WORKDIR}/helloworld-binding
Set redpesk release version
Choose the SDK container version according to the redpesk version you want to develop in.
REDPESK_RELEASE=corn-3.0-update
Please refer to OS redpesk releases chapter to see the list of supported redpesk distributions.
SDK core
The following command allow to:
- Mount the
WORKDIRin the container - Attach a bash session for development
- Mount your
.sshdirectory &.gitconfigfor git operation
podman run \
--tty \
--init \
--interactive \
--name sdk-core \
--userns keep-id \
--workdir ${WORKDIR} \
--security-opt label=disable \
--volume ${WORKDIR}:${WORKDIR} \
--volume ${HOME}/.ssh:${WORKDIR}/.ssh:ro \
--volume ${HOME}/.gitconfig:${WORKDIR}/.gitconfig:ro \
registry.redpesk.bzh/redpesk-ci/redpesk-sdk-core:${REDPESK_RELEASE} bash
SDK openvscode-server
The following command allow to:
- openvscode-server port publish
- Mount the
WORKDIRin the container - Attach a bash session for development
- Mount your
.sshdirectory &.gitconfigfor git operation
podman run \
--init \
--detach \
--userns keep-id \
--publish 3000:3000 \
--workdir ${WORKDIR} \
--name sdk-openvscode-server \
--security-opt label=disable \
--volume ${WORKDIR}:${WORKDIR} \
--volume ${HOME}/.ssh:${WORKDIR}/.ssh:ro \
--volume ${HOME}/.gitconfig:${WORKDIR}/.gitconfig:ro \
registry.redpesk.bzh/redpesk-ci/redpesk-sdk-openvscode-server:${REDPESK_RELEASE}
Then open openvscode within your favority browser :
# using Firefox
firefox --new-instance http://0.0.0.0:3000
# using Chromium
chromium --app=http://0.0.0.0:3000
# other
xdg-open http://0.0.0.0:3000