Mount /boot as Read Only by default

The content of /boot is managed by rpm-ostree & bootupd on Fedora Atomic Desktops so we should mount it as Read Only to avoid mistakes from users.

A common mistake is running grub2-mkconfig -o /boot/grub2/grub.cfg or similar commands, which should never be done on Fedora Atomic Desktops.

See also: https://github.com/coreos/fedora-coreos-tracker/issues/652

Edited by Timothée Ravier