Skip to main content

Feature Matrix

Legend:

  • ✅: Fully supported.
  • ☑️: In preview or partially supported.
  • 🔜: Planned feature. Not implemented yet.
  • ⚠️: Refer to relevant notes for details.
  • ❌: Not supported.

Servicing Features

CategoryFeatureInstallVM-InitUpdate
🚀 RuntimeNative binary
🚀 RuntimeContainerized
⚙️ BootloaderUEFI [1]
⚙️ BootloaderGPT partitioning
⚙️ BootloaderGrub2
⚙️ BootloaderSystemd-boot☑️☑️☑️
🔄 LifecycleOnboard system for updates
🔄 LifecycleRollback (grub)
🔄 LifecycleRollback (systemd-boot/UKI)🔜🔜🔜
🔏 IntegritySecure boot
🔏 IntegrityUKI☑️☑️☑️
🔏 IntegrityRoot verity (grub)⚠️[2]⚠️[2]⚠️[2]
🔏 IntegrityRoot verity (UKI)☑️☑️☑️
🔏 IntegrityUser verity (UKI)☑️☑️☑️
💽 StorageBlock device creation🔜
💽 StorageImage streaming (local)🔜
💽 StorageImage streaming (HTTPS)🔜
💽 StorageMultiboot☑️✅[3]
💽 StoragePartition adoption☑️✅[3]
💽 StorageSoftware RAID✅[3]
💽 StorageESP redundancy✅[3]
💽 StorageEncryption with secure boot PCR sealing🔜✅[3]
💽 StorageEncryption with OS PCR sealing🔜[4]🔜✅[3]
📝 OS ConfigNetwork configuration
📝 OS ConfigHostname configuration✅[5]✅[5]
📝 OS ConfigUser configuration✅[5]✅[5]
📝 OS ConfigSSH configuration✅[5]✅[5]
📝 OS ConfigInitrd regeneration (grub)
📝 OS ConfigInitrd regeneration (UKI)
🛡️ SecuritySELinux Configuration
🪛 CustomizationUser provided-scripts
🛠️ DevelopmentOffline validation🔜🔜
🛠️ DevelopmentDebugging log

Notes:

  • [1] Trident exclusively supports UEFI booting. BIOS booting is not supported.
  • [2] Root verity is supported with grub, but support for this feature will be deprecated soon.
  • [3] A system installed with these features can be updated, but the features themselves cannot be activated during an update.
  • [4] Currently, only PCR 7 is supported. Sealing against other PCRs is planned for a future release.
  • [5] This feature cannot be used in conjunction with root verity.

Out-of-Band Features

These are features that exist outside of the normal servicing flows in Trident.

CategoryFeatureStatusNotes
💽 StorageRAID RebuildRebuild a software RAID array after a physical drive replacement.