refactor: share common files between images; trim fedora-remote for a VM
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
||||
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
||||
# drop-in, since sshd honours the first directive it sees.
|
||||
PubkeyAuthentication yes
|
||||
UsePAM yes
|
||||
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
||||
AuthorizedKeysCommandUser nobody
|
||||
|
||||
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
|
||||
# public key to your account before relying on this, or you can lock yourself
|
||||
# out of SSH.
|
||||
PermitRootLogin no
|
||||
PasswordAuthentication no
|
||||
PermitEmptyPasswords no
|
||||
GSSAPIAuthentication no
|
||||
KerberosAuthentication no
|
||||
Reference in New Issue
Block a user