refactor: share common files between images; trim fedora-remote for a VM
Build containers / fedora-remote (44) (push) Failing after 36s
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 12m34s
Build containers / Prune old releases (push) Failing after 28s

- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
  and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
  no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
This commit is contained in:
2026-09-27 22:44:10 +02:00
parent 6d70a1bfb9
commit 5bea16bc01
29 changed files with 44 additions and 209 deletions
-16
View File
@@ -1,16 +0,0 @@
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
# drop-in, since sshd honours the first directive it sees.
PubkeyAuthentication yes
UsePAM yes
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
AuthorizedKeysCommandUser nobody
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
# public key to your account before relying on this, or you can lock yourself
# out of SSH.
PermitRootLogin no
PasswordAuthentication no
PermitEmptyPasswords no
GSSAPIAuthentication no
KerberosAuthentication no
@@ -1,3 +0,0 @@
# Kanidm Unix authentication daemons.
enable kanidm-unixd.service
enable kanidm-unixd-tasks.service
@@ -1 +0,0 @@
enable flatpak-user-firstboot.service
@@ -1,12 +0,0 @@
#!/bin/bash
# Runs in the target root during `rpm-ostree compose image` (edition 2024
# finalize.d hook). Records the installed package list next to the treefile so
# build.sh can hand it to release.sh without having to mount the built image.
set -euo pipefail
if [[ -z "${RPMOSTREE_WORKDIR:-}" ]]; then
echo "RPMOSTREE_WORKDIR not set, skipping package list" >&2
exit 0
fi
rpm -qa --root "${PWD}" --qf '%{NAME} %{EVR}\n' | sort > "${RPMOSTREE_WORKDIR}/packages-current.txt"
@@ -1,24 +0,0 @@
#!/usr/bin/env bash
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
# the first login of each user. Run as a systemd --user oneshot unit.
set -euo pipefail
LIST="/usr/share/flatpak/flatpaks.list"
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
[[ -f "${LIST}" ]] || exit 0
# Make Flathub available for the current user.
flatpak remote-add --user --if-not-exists flathub \
https://flathub.org/repo/flathub.flatpakrepo
mapfile -t apps < <(
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
)
if [[ ${#apps[@]} -gt 0 ]]; then
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
fi
install -dm0755 "$(dirname "${MARKER}")"
touch "${MARKER}"
@@ -1,14 +0,0 @@
[Unit]
Description=Install per-user Flatpak applications on first login
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/usr/libexec/flatpak-user-firstboot
[Install]
WantedBy=default.target
-1
View File
@@ -1 +0,0 @@
uri = "https://auth.plabble.org"
@@ -1,14 +0,0 @@
passwd: kanidm compat systemd
group: kanidm compat systemd
shadow: files
hosts: files dns myhostname
services: files
netgroup: files
automount: files
aliases: files
ethers: files
gshadow: files
networks: files dns
protocols: files
publickey: files
rpc: files
@@ -1,19 +0,0 @@
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth sufficient pam_kanidm.so ignore_unknown_user
auth sufficient pam_unix.so nullok
auth required pam_deny.so
account sufficient pam_kanidm.so
account required pam_unix.so
password requisite pam_pwquality.so
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session optional pam_kanidm.so
session required pam_unix.so
@@ -1,20 +0,0 @@
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth sufficient pam_fprintd.so
auth sufficient pam_kanidm.so ignore_unknown_user
auth sufficient pam_unix.so nullok
auth required pam_deny.so
account sufficient pam_kanidm.so ignore_unknown_user
account required pam_unix.so
password requisite pam_pwquality.so
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session optional pam_kanidm.so
session required pam_unix.so
-33
View File
@@ -1,33 +0,0 @@
version = "2"
# Bind cached credentials to the local TPM when one is available.
hsm_type = "tpm_if_possible"
default_shell = "/bin/bash"
home_prefix = "/home/"
home_attr = "uuid"
home_alias = "name"
use_etc_skel = true
selinux = true
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
# confuses logins.
uid_attr_map = "name"
gid_attr_map = "name"
[kanidm]
# Members of this Kanidm POSIX group are allowed to log in via PAM.
pam_allowed_login_groups = ["unix_users"]
# A host almost always already has a local account at uid 1000. Kanidm ignores
# its own entry when a local account with the same name exists, so logins would
# use the local account (and the Kanidm password would fail). Let Kanidm take
# over these local accounts. Add more names as needed.
allow_local_account_override = ["misthios"]
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
# so the service account token (when seeded) is passed as a systemd credential
# via the build.sh-generated drop-in
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
# Do not set service_account_token_path here.
@@ -1,21 +0,0 @@
; Kanidm ships no SELinux policy. Without these allows, nss/pam consumers
; (sshd, the display manager, systemd-userdbd, ...) are denied write access to
; the kanidm-unixd sockets in /run/kanidm-unixd (labeled var_run_t), so Kanidm
; users cannot be resolved or authenticated and logins fail (sshd reports
; "invalid user"). This is the allow set produced by:
; grep avc: /var/log/audit/audit.log | audit2allow
(allow accountsd_t var_run_t (sock_file (write)))
(allow auditd_t var_run_t (sock_file (write)))
(allow chkpwd_t var_run_t (sock_file (write)))
(allow local_login_t var_run_t (sock_file (write)))
(allow policykit_t var_run_t (sock_file (write)))
(allow ssh_keygen_t var_run_t (sock_file (write)))
(allow sshd_auth_t var_run_t (sock_file (write)))
(allow sshd_keygen_t var_run_t (sock_file (write)))
(allow sshd_session_t var_run_t (sock_file (write)))
(allow sshd_t var_run_t (sock_file (write)))
(allow systemd_bootc_generator_t var_run_t (sock_file (write)))
(allow systemd_selinux_autorelabel_generator_t var_run_t (sock_file (write)))
(allow systemd_userdbd_t var_run_t (sock_file (write)))
(allow xdm_t var_run_t (sock_file (write)))
(allow init_t unconfined_service_t (unix_stream_socket (connectto)))