>> You can then bake those files into an image that you present as a disk >> device to rumprun.
I had runtime configuration in mind rather than pre-baked. Consider certificates and keys - I can give you a rumpkernel and if the certs can be copied onto the disk before launch then the kernel build process never need access to your certs. I’ll try to find a way around it. as
