refactor: share common files between images; trim fedora-remote for a VM
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
version = "2"
|
||||
|
||||
# Bind cached credentials to the local TPM when one is available.
|
||||
hsm_type = "tpm_if_possible"
|
||||
|
||||
default_shell = "/bin/bash"
|
||||
home_prefix = "/home/"
|
||||
home_attr = "uuid"
|
||||
home_alias = "name"
|
||||
use_etc_skel = true
|
||||
selinux = true
|
||||
|
||||
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
|
||||
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
|
||||
# confuses logins.
|
||||
uid_attr_map = "name"
|
||||
gid_attr_map = "name"
|
||||
|
||||
[kanidm]
|
||||
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
||||
pam_allowed_login_groups = ["unix_users"]
|
||||
|
||||
# A host almost always already has a local account at uid 1000. Kanidm ignores
|
||||
# its own entry when a local account with the same name exists, so logins would
|
||||
# use the local account (and the Kanidm password would fail). Let Kanidm take
|
||||
# over these local accounts. Add more names as needed.
|
||||
allow_local_account_override = ["misthios"]
|
||||
|
||||
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
|
||||
# so the service account token (when seeded) is passed as a systemd credential
|
||||
# via the build.sh-generated drop-in
|
||||
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
|
||||
# Do not set service_account_token_path here.
|
||||
Reference in New Issue
Block a user