The secrets are the same as for the main repo (same logic)
No strong opinion, I can switch to pi for the user without any problem.
I don’t think so and it seems normal that we can’t do that
I understand the need (make it simple ) but I have a slightly different philosophy. If we want it to be simple, we need to make sure the end user never has to connect to the OS via SSH. It’s a bit like the discussion about Google Home, there’s the simple way and the hard way.
And getting into this (controlling the host’s security aspect from Gladys) is a bit limiting and not safe.
So, what do you propose to ensure that the image’s password is not the default password and not a fixed password either? The password must be dynamically generated in the image.
However, for an advanced user, they must be aware of this password.
Creation or reuse of an existing account. But they don’t use docker , they provide a product with firmware.
What I can do is generate a pass for the pi user and write it somewhere on the system (Gladys can read and display it but there’s nothing secure in that. I have no idea)
Well, otherwise we’ll stick with the « pi » / « raspberry » option for now. It’s already amazing what you’ve done on this image compared to the existing one!