Sí: mejor generarlo por partes.
Este artículo tiene demasiadas capas para escribirlo entero de una vez sin que se vuelva una sopa. Lo ideal sería tratarlo como una serie o como un artículo largo con “spinoffs”. El resumen ya marca el hilo: empezamos en Docker/Chisel/licencias, pasamos por read-only real, y terminamos en bootable appliances con EROFS/UKI/LinuxBoot .
Yo lo plantearía así:
Artículo principal
Title: Turning a Docker Image into a Bootable Immutable Linux Appliance
Opening thesis:
Containers gave us reproducible application filesystems. Kubernetes allowed us to deploy them at scale on the cloud. But for edge appliances, IoT devices, satellites, media gateways, and even unattended devices, the next step is making that filesystem bootable, immutable, verifiable, and explicitly persistent only where intended.
Este sería el signature piece.
Lo escribiría por partes:
-
The motivation Contenedores, edge, appliances, SAT Companion, media gateways, anti-drones, dispositivos no atendidos.
-
Part I — Building the minimal container rootfs Chisel,
scratch,nonroot,/sbin/nologin, licencias exportadas,docker-bake.hcl. -
Part II — Why Docker read-only is not enough
--read-only, límites OCI, fail-fast sin shell conrocheck. -
Part III — Turning the rootfs into a real immutable filesystem EROFS vs SquashFS vs ISO9660/ROMFS.
-
Part IV — Booting it GRUB vs UKI vs U-Boot vs LinuxBoot/Coreboot.
-
Part V — Runtime model init mínimo en C/Rust, tini,
/datacomo volumen, EXT4/XFS. -
Part VI — Updates and verification A/B, ESP no montada, Secure Boot, dm-verity, SBOM, futuras métricas.
-
Conclusion No es “reemplazar Docker”, es llevar su modelo mental a bare metal.
Artículos secundarios que salen de aquí
-
“Docker images cannot require
--read-only— but they can refuse to run” Solo sobrerocheck. -
“Chisel, copyrights, and minimal Ubuntu containers” Licencias,
--output,bake, compliance. -
“EROFS vs SquashFS for immutable Linux appliances” Comparativa técnica.
-
“UKI vs GRUB vs LinuxBoot for bootable containers” Boot chain.
-
“PID 1 without shell: designing a minimal appliance init” C/Rust init, tini, reboot limpio.
Mi recomendación: no lo escribas entero en una pasada. Primero hacemos el outline detallado del artículo principal, luego redactamos sección por sección. Así queda más afilado y además podemos extraer artículos secundarios sin duplicar esfuerzo.