fedora-remote: install Flatpaks system-wide on first boot
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 8m28s
Build containers / Prune old releases and tags (push) Successful in 25s

Per-user Flatpaks are only visible to the account that logged in first (and
consumed space per user). Install them into the system installation instead, so
every user including Kanidm accounts sees Firefox.
This commit is contained in:
2026-09-30 19:37:03 +02:00
parent 172948822a
commit 137091b402
5 changed files with 47 additions and 6 deletions
+5 -5
View File
@@ -41,10 +41,10 @@ exclude-packages:
- firefox
add-files:
# Per-user Flatpaks on first login (Firefox).
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
# System-wide Flatpaks on first boot (Firefox), visible to every user.
- ["flatpak-system-firstboot", "/usr/libexec/flatpak-system-firstboot"]
- ["flatpak-system-firstboot.service", "/usr/lib/systemd/system/flatpak-system-firstboot.service"]
- ["50-flatpak-system-firstboot.preset", "/usr/lib/systemd/system-preset/50-flatpak-system-firstboot.preset"]
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
# Kanidm client config + authselect profile sources.
- ["kanidm-config", "/etc/kanidm/config"]
@@ -107,5 +107,5 @@ postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
chmod 0755 /usr/libexec/flatpak-system-firstboot /usr/libexec/grd-firstboot
systemctl --user --global preset-all
@@ -0,0 +1 @@
enable flatpak-system-firstboot.service
@@ -0,0 +1,26 @@
#!/usr/bin/env bash
# Install the Flatpaks listed in /usr/share/flatpak/flatpaks.list into the
# system-wide installation on first boot, so every user (including Kanidm
# accounts) sees them.
set -euo pipefail
LIST="/usr/share/flatpak/flatpaks.list"
MARKER="/var/lib/flatpak/.system-firstboot-done"
[[ -f "${LIST}" ]] || exit 0
[[ -f "${MARKER}" ]] && exit 0
# Make Flathub available system-wide.
flatpak remote-add --system --if-not-exists flathub \
https://flathub.org/repo/flathub.flatpakrepo
mapfile -t apps < <(
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
)
if [[ ${#apps[@]} -gt 0 ]]; then
flatpak install --system --noninteractive --assumeyes "${apps[@]}"
fi
install -d "$(dirname "${MARKER}")"
touch "${MARKER}"
@@ -0,0 +1,14 @@
[Unit]
Description=Install system-wide Flatpak applications on first boot
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
ConditionPathExists=!/var/lib/flatpak/.system-firstboot-done
After=network-online.target flatpak-add-fedora-repos.service
Wants=network-online.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/usr/libexec/flatpak-system-firstboot
[Install]
WantedBy=multi-user.target
+1 -1
View File
@@ -1,3 +1,3 @@
# Flatpaks installed into each user's per-user installation on first login.
# Flatpaks installed system-wide on first boot (visible to all users).
# foot is installed as an RPM (no Flathub build), so only Firefox here.
org.mozilla.firefox