From 5bea16bc0173ed17d911a158ece1db3f02174b34 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Sun, 27 Sep 2026 22:44:10 +0200 Subject: [PATCH] refactor: share common files between images; trim fedora-remote for a VM - Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos} and have build.sh overlay them for every image. - fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra, no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox). - Fixes the missing package-list (release step) for fedora-remote. --- build.sh | 13 ++++ images/fedora-remote/custom.yaml | 3 + images/fedora-remote/files/10-kanidm.conf | 16 ----- images/fedora-remote/files/50-grd.preset | 3 +- images/fedora-remote/files/50-kanidm.preset | 3 - .../files/60-flatpak-user-firstboot.preset | 1 - .../files/flatpak-user-firstboot | 24 -------- .../files/flatpak-user-firstboot.service | 14 ----- images/fedora-remote/files/kanidm-config | 1 - .../fedora-remote/files/kanidm-nsswitch.conf | 14 ----- .../fedora-remote/files/kanidm-password-auth | 19 ------ images/fedora-remote/files/kanidm-system-auth | 20 ------- images/fedora-remote/files/kanidm-unixd | 33 ----------- images/fedora-remote/files/kanidm-unixd.cil | 21 ------- .../fedora-remote/repos/44/network-idm.repo | 9 --- images/fedora-remote/upstream-exclude.txt | 59 ++++++++----------- .../files/10-kanidm.conf | 0 .../files/50-kanidm.preset | 0 .../files/60-flatpak-user-firstboot.preset | 0 .../files/finalize.d/50-packages | 0 .../files/flatpak-user-firstboot | 0 .../files/flatpak-user-firstboot.service | 0 .../files/kanidm-config | 0 .../files/kanidm-nsswitch.conf | 0 .../files/kanidm-password-auth | 0 .../files/kanidm-system-auth | 0 .../files/kanidm-unixd | 0 .../files/kanidm-unixd.cil | 0 .../repos/44/network-idm.repo | 0 29 files changed, 44 insertions(+), 209 deletions(-) delete mode 100644 images/fedora-remote/files/10-kanidm.conf delete mode 100644 images/fedora-remote/files/50-kanidm.preset delete mode 100644 images/fedora-remote/files/60-flatpak-user-firstboot.preset delete mode 100755 images/fedora-remote/files/flatpak-user-firstboot delete mode 100644 images/fedora-remote/files/flatpak-user-firstboot.service delete mode 100644 images/fedora-remote/files/kanidm-config delete mode 100644 images/fedora-remote/files/kanidm-nsswitch.conf delete mode 100644 images/fedora-remote/files/kanidm-password-auth delete mode 100644 images/fedora-remote/files/kanidm-system-auth delete mode 100644 images/fedora-remote/files/kanidm-unixd delete mode 100644 images/fedora-remote/files/kanidm-unixd.cil delete mode 100644 images/fedora-remote/repos/44/network-idm.repo rename images/{fedora-cosmic => shared}/files/10-kanidm.conf (100%) rename images/{fedora-cosmic => shared}/files/50-kanidm.preset (100%) rename images/{fedora-cosmic => shared}/files/60-flatpak-user-firstboot.preset (100%) rename images/{fedora-cosmic => shared}/files/finalize.d/50-packages (100%) rename images/{fedora-cosmic => shared}/files/flatpak-user-firstboot (100%) rename images/{fedora-cosmic => shared}/files/flatpak-user-firstboot.service (100%) rename images/{fedora-cosmic => shared}/files/kanidm-config (100%) rename images/{fedora-cosmic => shared}/files/kanidm-nsswitch.conf (100%) rename images/{fedora-cosmic => shared}/files/kanidm-password-auth (100%) rename images/{fedora-cosmic => shared}/files/kanidm-system-auth (100%) rename images/{fedora-cosmic => shared}/files/kanidm-unixd (100%) rename images/{fedora-cosmic => shared}/files/kanidm-unixd.cil (100%) rename images/{fedora-cosmic => shared}/repos/44/network-idm.repo (100%) diff --git a/build.sh b/build.sh index 50393c8..f126bec 100755 --- a/build.sh +++ b/build.sh @@ -179,6 +179,16 @@ case "${BUILD_MODE}" in if [[ -d "${IMAGE_DIR}/files" ]]; then cp -a "${IMAGE_DIR}/files/." "${BUILD_DIR}/upstream/" fi + # Shared overlay (files/repos used by multiple images). + if [[ -d "${REPO_ROOT}/images/shared/files" ]]; then + cp -a "${REPO_ROOT}/images/shared/files/." "${BUILD_DIR}/upstream/" + fi + if compgen -G "${REPO_ROOT}/images/shared/repos/*.repo" >/dev/null; then + cp "${REPO_ROOT}"/images/shared/repos/*.repo "${BUILD_DIR}/upstream/" + fi + if compgen -G "${REPO_ROOT}/images/shared/repos/${DISTRO}/*.repo" >/dev/null; then + cp "${REPO_ROOT}"/images/shared/repos/"${DISTRO}"/*.repo "${BUILD_DIR}/upstream/" + fi if [[ "${TOKEN2}" == "1" ]]; then setup_token2_repo "${BUILD_DIR}/upstream" @@ -209,6 +219,9 @@ case "${BUILD_MODE}" in if compgen -G "${local_dir}/repos/${DISTRO}/*.repo" >/dev/null; then cp "${local_dir}"/repos/"${DISTRO}"/*.repo "${local_dir}/" fi + if [[ -d "${REPO_ROOT}/images/shared/files" ]]; then + cp -a "${REPO_ROOT}/images/shared/files/." "${local_dir}/" + fi if [[ "${TOKEN2}" == "1" ]]; then setup_token2_repo "${local_dir}" diff --git a/images/fedora-remote/custom.yaml b/images/fedora-remote/custom.yaml index 8a82a6b..a84450a 100644 --- a/images/fedora-remote/custom.yaml +++ b/images/fedora-remote/custom.yaml @@ -20,6 +20,9 @@ packages: - foot - flatpak + # Proxmox guest integration. + - qemu-guest-agent + # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients diff --git a/images/fedora-remote/files/10-kanidm.conf b/images/fedora-remote/files/10-kanidm.conf deleted file mode 100644 index 77f85b1..0000000 --- a/images/fedora-remote/files/10-kanidm.conf +++ /dev/null @@ -1,16 +0,0 @@ -# Fetch authorized SSH public keys from Kanidm (uploaded to the account). -# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand -# drop-in, since sshd honours the first directive it sees. -PubkeyAuthentication yes -UsePAM yes -AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u -AuthorizedKeysCommandUser nobody - -# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH -# public key to your account before relying on this, or you can lock yourself -# out of SSH. -PermitRootLogin no -PasswordAuthentication no -PermitEmptyPasswords no -GSSAPIAuthentication no -KerberosAuthentication no diff --git a/images/fedora-remote/files/50-grd.preset b/images/fedora-remote/files/50-grd.preset index ce40af8..98187bc 100644 --- a/images/fedora-remote/files/50-grd.preset +++ b/images/fedora-remote/files/50-grd.preset @@ -1,4 +1,5 @@ -# GNOME Remote Desktop headless remote login. +# GNOME Remote Desktop headless remote login + Proxmox guest agent. enable gdm.service enable gnome-remote-desktop.service enable grd-firstboot.service +enable qemu-guest-agent.service diff --git a/images/fedora-remote/files/50-kanidm.preset b/images/fedora-remote/files/50-kanidm.preset deleted file mode 100644 index aaa3fb5..0000000 --- a/images/fedora-remote/files/50-kanidm.preset +++ /dev/null @@ -1,3 +0,0 @@ -# Kanidm Unix authentication daemons. -enable kanidm-unixd.service -enable kanidm-unixd-tasks.service diff --git a/images/fedora-remote/files/60-flatpak-user-firstboot.preset b/images/fedora-remote/files/60-flatpak-user-firstboot.preset deleted file mode 100644 index 0ce2a82..0000000 --- a/images/fedora-remote/files/60-flatpak-user-firstboot.preset +++ /dev/null @@ -1 +0,0 @@ -enable flatpak-user-firstboot.service diff --git a/images/fedora-remote/files/flatpak-user-firstboot b/images/fedora-remote/files/flatpak-user-firstboot deleted file mode 100755 index 1b39a00..0000000 --- a/images/fedora-remote/files/flatpak-user-firstboot +++ /dev/null @@ -1,24 +0,0 @@ -#!/usr/bin/env bash -# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on -# the first login of each user. Run as a systemd --user oneshot unit. -set -euo pipefail - -LIST="/usr/share/flatpak/flatpaks.list" -MARKER="${HOME}/.config/flatpak-user-firstboot.done" - -[[ -f "${LIST}" ]] || exit 0 - -# Make Flathub available for the current user. -flatpak remote-add --user --if-not-exists flathub \ - https://flathub.org/repo/flathub.flatpakrepo - -mapfile -t apps < <( - sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true -) - -if [[ ${#apps[@]} -gt 0 ]]; then - flatpak install --user --noninteractive --assumeyes "${apps[@]}" -fi - -install -dm0755 "$(dirname "${MARKER}")" -touch "${MARKER}" diff --git a/images/fedora-remote/files/flatpak-user-firstboot.service b/images/fedora-remote/files/flatpak-user-firstboot.service deleted file mode 100644 index 180157c..0000000 --- a/images/fedora-remote/files/flatpak-user-firstboot.service +++ /dev/null @@ -1,14 +0,0 @@ -[Unit] -Description=Install per-user Flatpak applications on first login -Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html -ConditionPathExists=!%h/.config/flatpak-user-firstboot.done -After=network-online.target -Wants=network-online.target - -[Service] -Type=oneshot -RemainAfterExit=yes -ExecStart=/usr/libexec/flatpak-user-firstboot - -[Install] -WantedBy=default.target diff --git a/images/fedora-remote/files/kanidm-config b/images/fedora-remote/files/kanidm-config deleted file mode 100644 index 78e1c17..0000000 --- a/images/fedora-remote/files/kanidm-config +++ /dev/null @@ -1 +0,0 @@ -uri = "https://auth.plabble.org" diff --git a/images/fedora-remote/files/kanidm-nsswitch.conf b/images/fedora-remote/files/kanidm-nsswitch.conf deleted file mode 100644 index c3857f5..0000000 --- a/images/fedora-remote/files/kanidm-nsswitch.conf +++ /dev/null @@ -1,14 +0,0 @@ -passwd: kanidm compat systemd -group: kanidm compat systemd -shadow: files -hosts: files dns myhostname -services: files -netgroup: files -automount: files -aliases: files -ethers: files -gshadow: files -networks: files dns -protocols: files -publickey: files -rpc: files diff --git a/images/fedora-remote/files/kanidm-password-auth b/images/fedora-remote/files/kanidm-password-auth deleted file mode 100644 index ea9d379..0000000 --- a/images/fedora-remote/files/kanidm-password-auth +++ /dev/null @@ -1,19 +0,0 @@ -auth required pam_env.so -auth required pam_faildelay.so delay=2000000 -auth sufficient pam_kanidm.so ignore_unknown_user -auth sufficient pam_unix.so nullok -auth required pam_deny.so - -account sufficient pam_kanidm.so -account required pam_unix.so - -password requisite pam_pwquality.so -password sufficient pam_unix.so yescrypt shadow nullok use_authtok -password required pam_deny.so - -session optional pam_keyinit.so revoke -session required pam_limits.so --session optional pam_systemd.so -session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid -session optional pam_kanidm.so -session required pam_unix.so diff --git a/images/fedora-remote/files/kanidm-system-auth b/images/fedora-remote/files/kanidm-system-auth deleted file mode 100644 index 41019d3..0000000 --- a/images/fedora-remote/files/kanidm-system-auth +++ /dev/null @@ -1,20 +0,0 @@ -auth required pam_env.so -auth required pam_faildelay.so delay=2000000 -auth sufficient pam_fprintd.so -auth sufficient pam_kanidm.so ignore_unknown_user -auth sufficient pam_unix.so nullok -auth required pam_deny.so - -account sufficient pam_kanidm.so ignore_unknown_user -account required pam_unix.so - -password requisite pam_pwquality.so -password sufficient pam_unix.so yescrypt shadow nullok use_authtok -password required pam_deny.so - -session optional pam_keyinit.so revoke -session required pam_limits.so --session optional pam_systemd.so -session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid -session optional pam_kanidm.so -session required pam_unix.so diff --git a/images/fedora-remote/files/kanidm-unixd b/images/fedora-remote/files/kanidm-unixd deleted file mode 100644 index fd72ba2..0000000 --- a/images/fedora-remote/files/kanidm-unixd +++ /dev/null @@ -1,33 +0,0 @@ -version = "2" - -# Bind cached credentials to the local TPM when one is available. -hsm_type = "tpm_if_possible" - -default_shell = "/bin/bash" -home_prefix = "/home/" -home_attr = "uuid" -home_alias = "name" -use_etc_skel = true -selinux = true - -# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the -# default (spn) the passwd entry name is "misthios@auth.plabble.org", which -# confuses logins. -uid_attr_map = "name" -gid_attr_map = "name" - -[kanidm] -# Members of this Kanidm POSIX group are allowed to log in via PAM. -pam_allowed_login_groups = ["unix_users"] - -# A host almost always already has a local account at uid 1000. Kanidm ignores -# its own entry when a local account with the same name exists, so logins would -# use the local account (and the Kanidm password would fail). Let Kanidm take -# over these local accounts. Add more names as needed. -allow_local_account_override = ["misthios"] - -# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, -# so the service account token (when seeded) is passed as a systemd credential -# via the build.sh-generated drop-in -# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf. -# Do not set service_account_token_path here. diff --git a/images/fedora-remote/files/kanidm-unixd.cil b/images/fedora-remote/files/kanidm-unixd.cil deleted file mode 100644 index 93b5cf1..0000000 --- a/images/fedora-remote/files/kanidm-unixd.cil +++ /dev/null @@ -1,21 +0,0 @@ -; Kanidm ships no SELinux policy. Without these allows, nss/pam consumers -; (sshd, the display manager, systemd-userdbd, ...) are denied write access to -; the kanidm-unixd sockets in /run/kanidm-unixd (labeled var_run_t), so Kanidm -; users cannot be resolved or authenticated and logins fail (sshd reports -; "invalid user"). This is the allow set produced by: -; grep avc: /var/log/audit/audit.log | audit2allow -(allow accountsd_t var_run_t (sock_file (write))) -(allow auditd_t var_run_t (sock_file (write))) -(allow chkpwd_t var_run_t (sock_file (write))) -(allow local_login_t var_run_t (sock_file (write))) -(allow policykit_t var_run_t (sock_file (write))) -(allow ssh_keygen_t var_run_t (sock_file (write))) -(allow sshd_auth_t var_run_t (sock_file (write))) -(allow sshd_keygen_t var_run_t (sock_file (write))) -(allow sshd_session_t var_run_t (sock_file (write))) -(allow sshd_t var_run_t (sock_file (write))) -(allow systemd_bootc_generator_t var_run_t (sock_file (write))) -(allow systemd_selinux_autorelabel_generator_t var_run_t (sock_file (write))) -(allow systemd_userdbd_t var_run_t (sock_file (write))) -(allow xdm_t var_run_t (sock_file (write))) -(allow init_t unconfined_service_t (unix_stream_socket (connectto))) diff --git a/images/fedora-remote/repos/44/network-idm.repo b/images/fedora-remote/repos/44/network-idm.repo deleted file mode 100644 index d252ccb..0000000 --- a/images/fedora-remote/repos/44/network-idm.repo +++ /dev/null @@ -1,9 +0,0 @@ -[network_idm] -name=Identity Management related tools (Fedora 44) -baseurl=https://download.opensuse.org/repositories/network:/idm/Fedora_44/ -type=rpm-md -skip_if_unavailable=False -gpgcheck=1 -repo_gpgcheck=0 -enabled=1 -gpgkey=https://download.opensuse.org/repositories/network:/idm/Fedora_44/repodata/repomd.xml.key diff --git a/images/fedora-remote/upstream-exclude.txt b/images/fedora-remote/upstream-exclude.txt index a1a877d..4ad3f08 100644 --- a/images/fedora-remote/upstream-exclude.txt +++ b/images/fedora-remote/upstream-exclude.txt @@ -1,49 +1,42 @@ -# Packages removed from the cloned upstream manifests at build time. -# -# rpm-ostree treats excluding a package that an included manifest declares as a -# fatal error, so build.sh strips these lines from the upstream package -# manifests before composing. -# -# Target machine: GMKtec NucBox M7 -# - AMD Ryzen 7 PRO 6850H (Radeon 680M iGPU) -> amd-gpu-firmware kept -# - 2x Intel I226-V Ethernet -> kernel driver, no fw pkg -# - Intel Wi-Fi 6 AX200 -> iwlwifi-mvm-firmware kept -# - AMD audio (SOF) -> alsa-sof-firmware kept -# No NVIDIA, no Intel GPU/audio, no other wireless vendors, bare metal (no VMs). +# Aggressive trim for a headless Proxmox VM: there is no physical hardware, so +# drop all firmware and non-virtio drivers. Keep qemu-guest-agent (Proxmox) and +# the virtio stack (in the kernel / kernel-modules). -# NVIDIA -nvidia-gpu-firmware - -# Intel GPU / platform / audio (Intel wireless firmware is kept below) -intel-gpu-firmware -intel-audio-firmware -intel-lpmd -intel-vsc-firmware -libva-intel-media-driver - -# Intel-only CPU tooling (AMD uses amd-ucode-firmware) -microcode_ctl -thermald - -# Wireless firmware for hardware that is not present +# All firmware (none is needed under virtio) +amd-gpu-firmware +amd-ucode-firmware +alsa-sof-firmware atheros-firmware brcmfmac-firmware +cirrus-audio-firmware +intel-audio-firmware +intel-gpu-firmware +intel-lpmd +intel-vsc-firmware +iwlegacy-firmware +iwlwifi-dvm-firmware +iwlwifi-mvm-firmware libertas-firmware +linux-firmware mt7xxx-firmware +nvidia-gpu-firmware nxpwireless-firmware qcom-wwan-firmware realtek-firmware tiwilink-firmware -iwlwifi-dvm-firmware -iwlegacy-firmware +libva-intel-media-driver -# Audio firmware for other vendors -cirrus-audio-firmware +# Extra kernel modules are not needed in a VM +kernel-modules-extra -# Virtual machine guest agents / drivers +# x86 platform tools not needed under QEMU/KVM +mcelog +microcode_ctl +thermald + +# Guest agents for hypervisors other than the one in use hyperv-daemons open-vm-tools-desktop -qemu-guest-agent spice-vdagent spice-webdavd virtualbox-guest-additions diff --git a/images/fedora-cosmic/files/10-kanidm.conf b/images/shared/files/10-kanidm.conf similarity index 100% rename from images/fedora-cosmic/files/10-kanidm.conf rename to images/shared/files/10-kanidm.conf diff --git a/images/fedora-cosmic/files/50-kanidm.preset b/images/shared/files/50-kanidm.preset similarity index 100% rename from images/fedora-cosmic/files/50-kanidm.preset rename to images/shared/files/50-kanidm.preset diff --git a/images/fedora-cosmic/files/60-flatpak-user-firstboot.preset b/images/shared/files/60-flatpak-user-firstboot.preset similarity index 100% rename from images/fedora-cosmic/files/60-flatpak-user-firstboot.preset rename to images/shared/files/60-flatpak-user-firstboot.preset diff --git a/images/fedora-cosmic/files/finalize.d/50-packages b/images/shared/files/finalize.d/50-packages similarity index 100% rename from images/fedora-cosmic/files/finalize.d/50-packages rename to images/shared/files/finalize.d/50-packages diff --git a/images/fedora-cosmic/files/flatpak-user-firstboot b/images/shared/files/flatpak-user-firstboot similarity index 100% rename from images/fedora-cosmic/files/flatpak-user-firstboot rename to images/shared/files/flatpak-user-firstboot diff --git a/images/fedora-cosmic/files/flatpak-user-firstboot.service b/images/shared/files/flatpak-user-firstboot.service similarity index 100% rename from images/fedora-cosmic/files/flatpak-user-firstboot.service rename to images/shared/files/flatpak-user-firstboot.service diff --git a/images/fedora-cosmic/files/kanidm-config b/images/shared/files/kanidm-config similarity index 100% rename from images/fedora-cosmic/files/kanidm-config rename to images/shared/files/kanidm-config diff --git a/images/fedora-cosmic/files/kanidm-nsswitch.conf b/images/shared/files/kanidm-nsswitch.conf similarity index 100% rename from images/fedora-cosmic/files/kanidm-nsswitch.conf rename to images/shared/files/kanidm-nsswitch.conf diff --git a/images/fedora-cosmic/files/kanidm-password-auth b/images/shared/files/kanidm-password-auth similarity index 100% rename from images/fedora-cosmic/files/kanidm-password-auth rename to images/shared/files/kanidm-password-auth diff --git a/images/fedora-cosmic/files/kanidm-system-auth b/images/shared/files/kanidm-system-auth similarity index 100% rename from images/fedora-cosmic/files/kanidm-system-auth rename to images/shared/files/kanidm-system-auth diff --git a/images/fedora-cosmic/files/kanidm-unixd b/images/shared/files/kanidm-unixd similarity index 100% rename from images/fedora-cosmic/files/kanidm-unixd rename to images/shared/files/kanidm-unixd diff --git a/images/fedora-cosmic/files/kanidm-unixd.cil b/images/shared/files/kanidm-unixd.cil similarity index 100% rename from images/fedora-cosmic/files/kanidm-unixd.cil rename to images/shared/files/kanidm-unixd.cil diff --git a/images/fedora-cosmic/repos/44/network-idm.repo b/images/shared/repos/44/network-idm.repo similarity index 100% rename from images/fedora-cosmic/repos/44/network-idm.repo rename to images/shared/repos/44/network-idm.repo