refactor: share common files between images; trim fedora-remote for a VM
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
This commit is contained in:
@@ -179,6 +179,16 @@ case "${BUILD_MODE}" in
|
|||||||
if [[ -d "${IMAGE_DIR}/files" ]]; then
|
if [[ -d "${IMAGE_DIR}/files" ]]; then
|
||||||
cp -a "${IMAGE_DIR}/files/." "${BUILD_DIR}/upstream/"
|
cp -a "${IMAGE_DIR}/files/." "${BUILD_DIR}/upstream/"
|
||||||
fi
|
fi
|
||||||
|
# Shared overlay (files/repos used by multiple images).
|
||||||
|
if [[ -d "${REPO_ROOT}/images/shared/files" ]]; then
|
||||||
|
cp -a "${REPO_ROOT}/images/shared/files/." "${BUILD_DIR}/upstream/"
|
||||||
|
fi
|
||||||
|
if compgen -G "${REPO_ROOT}/images/shared/repos/*.repo" >/dev/null; then
|
||||||
|
cp "${REPO_ROOT}"/images/shared/repos/*.repo "${BUILD_DIR}/upstream/"
|
||||||
|
fi
|
||||||
|
if compgen -G "${REPO_ROOT}/images/shared/repos/${DISTRO}/*.repo" >/dev/null; then
|
||||||
|
cp "${REPO_ROOT}"/images/shared/repos/"${DISTRO}"/*.repo "${BUILD_DIR}/upstream/"
|
||||||
|
fi
|
||||||
|
|
||||||
if [[ "${TOKEN2}" == "1" ]]; then
|
if [[ "${TOKEN2}" == "1" ]]; then
|
||||||
setup_token2_repo "${BUILD_DIR}/upstream"
|
setup_token2_repo "${BUILD_DIR}/upstream"
|
||||||
@@ -209,6 +219,9 @@ case "${BUILD_MODE}" in
|
|||||||
if compgen -G "${local_dir}/repos/${DISTRO}/*.repo" >/dev/null; then
|
if compgen -G "${local_dir}/repos/${DISTRO}/*.repo" >/dev/null; then
|
||||||
cp "${local_dir}"/repos/"${DISTRO}"/*.repo "${local_dir}/"
|
cp "${local_dir}"/repos/"${DISTRO}"/*.repo "${local_dir}/"
|
||||||
fi
|
fi
|
||||||
|
if [[ -d "${REPO_ROOT}/images/shared/files" ]]; then
|
||||||
|
cp -a "${REPO_ROOT}/images/shared/files/." "${local_dir}/"
|
||||||
|
fi
|
||||||
|
|
||||||
if [[ "${TOKEN2}" == "1" ]]; then
|
if [[ "${TOKEN2}" == "1" ]]; then
|
||||||
setup_token2_repo "${local_dir}"
|
setup_token2_repo "${local_dir}"
|
||||||
|
|||||||
@@ -20,6 +20,9 @@ packages:
|
|||||||
- foot
|
- foot
|
||||||
- flatpak
|
- flatpak
|
||||||
|
|
||||||
|
# Proxmox guest integration.
|
||||||
|
- qemu-guest-agent
|
||||||
|
|
||||||
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
||||||
- kanidm-unixd-clients
|
- kanidm-unixd-clients
|
||||||
|
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
|
||||||
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
|
||||||
# drop-in, since sshd honours the first directive it sees.
|
|
||||||
PubkeyAuthentication yes
|
|
||||||
UsePAM yes
|
|
||||||
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
|
||||||
AuthorizedKeysCommandUser nobody
|
|
||||||
|
|
||||||
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
|
|
||||||
# public key to your account before relying on this, or you can lock yourself
|
|
||||||
# out of SSH.
|
|
||||||
PermitRootLogin no
|
|
||||||
PasswordAuthentication no
|
|
||||||
PermitEmptyPasswords no
|
|
||||||
GSSAPIAuthentication no
|
|
||||||
KerberosAuthentication no
|
|
||||||
@@ -1,4 +1,5 @@
|
|||||||
# GNOME Remote Desktop headless remote login.
|
# GNOME Remote Desktop headless remote login + Proxmox guest agent.
|
||||||
enable gdm.service
|
enable gdm.service
|
||||||
enable gnome-remote-desktop.service
|
enable gnome-remote-desktop.service
|
||||||
enable grd-firstboot.service
|
enable grd-firstboot.service
|
||||||
|
enable qemu-guest-agent.service
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
# Kanidm Unix authentication daemons.
|
|
||||||
enable kanidm-unixd.service
|
|
||||||
enable kanidm-unixd-tasks.service
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
enable flatpak-user-firstboot.service
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
|
|
||||||
# the first login of each user. Run as a systemd --user oneshot unit.
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
LIST="/usr/share/flatpak/flatpaks.list"
|
|
||||||
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
|
|
||||||
|
|
||||||
[[ -f "${LIST}" ]] || exit 0
|
|
||||||
|
|
||||||
# Make Flathub available for the current user.
|
|
||||||
flatpak remote-add --user --if-not-exists flathub \
|
|
||||||
https://flathub.org/repo/flathub.flatpakrepo
|
|
||||||
|
|
||||||
mapfile -t apps < <(
|
|
||||||
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
|
|
||||||
)
|
|
||||||
|
|
||||||
if [[ ${#apps[@]} -gt 0 ]]; then
|
|
||||||
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
install -dm0755 "$(dirname "${MARKER}")"
|
|
||||||
touch "${MARKER}"
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
[Unit]
|
|
||||||
Description=Install per-user Flatpak applications on first login
|
|
||||||
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
|
|
||||||
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
|
|
||||||
After=network-online.target
|
|
||||||
Wants=network-online.target
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=oneshot
|
|
||||||
RemainAfterExit=yes
|
|
||||||
ExecStart=/usr/libexec/flatpak-user-firstboot
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=default.target
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
uri = "https://auth.plabble.org"
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
passwd: kanidm compat systemd
|
|
||||||
group: kanidm compat systemd
|
|
||||||
shadow: files
|
|
||||||
hosts: files dns myhostname
|
|
||||||
services: files
|
|
||||||
netgroup: files
|
|
||||||
automount: files
|
|
||||||
aliases: files
|
|
||||||
ethers: files
|
|
||||||
gshadow: files
|
|
||||||
networks: files dns
|
|
||||||
protocols: files
|
|
||||||
publickey: files
|
|
||||||
rpc: files
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
auth required pam_env.so
|
|
||||||
auth required pam_faildelay.so delay=2000000
|
|
||||||
auth sufficient pam_kanidm.so ignore_unknown_user
|
|
||||||
auth sufficient pam_unix.so nullok
|
|
||||||
auth required pam_deny.so
|
|
||||||
|
|
||||||
account sufficient pam_kanidm.so
|
|
||||||
account required pam_unix.so
|
|
||||||
|
|
||||||
password requisite pam_pwquality.so
|
|
||||||
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
|
|
||||||
password required pam_deny.so
|
|
||||||
|
|
||||||
session optional pam_keyinit.so revoke
|
|
||||||
session required pam_limits.so
|
|
||||||
-session optional pam_systemd.so
|
|
||||||
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
|
|
||||||
session optional pam_kanidm.so
|
|
||||||
session required pam_unix.so
|
|
||||||
@@ -1,20 +0,0 @@
|
|||||||
auth required pam_env.so
|
|
||||||
auth required pam_faildelay.so delay=2000000
|
|
||||||
auth sufficient pam_fprintd.so
|
|
||||||
auth sufficient pam_kanidm.so ignore_unknown_user
|
|
||||||
auth sufficient pam_unix.so nullok
|
|
||||||
auth required pam_deny.so
|
|
||||||
|
|
||||||
account sufficient pam_kanidm.so ignore_unknown_user
|
|
||||||
account required pam_unix.so
|
|
||||||
|
|
||||||
password requisite pam_pwquality.so
|
|
||||||
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
|
|
||||||
password required pam_deny.so
|
|
||||||
|
|
||||||
session optional pam_keyinit.so revoke
|
|
||||||
session required pam_limits.so
|
|
||||||
-session optional pam_systemd.so
|
|
||||||
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
|
|
||||||
session optional pam_kanidm.so
|
|
||||||
session required pam_unix.so
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
version = "2"
|
|
||||||
|
|
||||||
# Bind cached credentials to the local TPM when one is available.
|
|
||||||
hsm_type = "tpm_if_possible"
|
|
||||||
|
|
||||||
default_shell = "/bin/bash"
|
|
||||||
home_prefix = "/home/"
|
|
||||||
home_attr = "uuid"
|
|
||||||
home_alias = "name"
|
|
||||||
use_etc_skel = true
|
|
||||||
selinux = true
|
|
||||||
|
|
||||||
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
|
|
||||||
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
|
|
||||||
# confuses logins.
|
|
||||||
uid_attr_map = "name"
|
|
||||||
gid_attr_map = "name"
|
|
||||||
|
|
||||||
[kanidm]
|
|
||||||
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
|
||||||
pam_allowed_login_groups = ["unix_users"]
|
|
||||||
|
|
||||||
# A host almost always already has a local account at uid 1000. Kanidm ignores
|
|
||||||
# its own entry when a local account with the same name exists, so logins would
|
|
||||||
# use the local account (and the Kanidm password would fail). Let Kanidm take
|
|
||||||
# over these local accounts. Add more names as needed.
|
|
||||||
allow_local_account_override = ["misthios"]
|
|
||||||
|
|
||||||
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
|
|
||||||
# so the service account token (when seeded) is passed as a systemd credential
|
|
||||||
# via the build.sh-generated drop-in
|
|
||||||
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
|
|
||||||
# Do not set service_account_token_path here.
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
; Kanidm ships no SELinux policy. Without these allows, nss/pam consumers
|
|
||||||
; (sshd, the display manager, systemd-userdbd, ...) are denied write access to
|
|
||||||
; the kanidm-unixd sockets in /run/kanidm-unixd (labeled var_run_t), so Kanidm
|
|
||||||
; users cannot be resolved or authenticated and logins fail (sshd reports
|
|
||||||
; "invalid user"). This is the allow set produced by:
|
|
||||||
; grep avc: /var/log/audit/audit.log | audit2allow
|
|
||||||
(allow accountsd_t var_run_t (sock_file (write)))
|
|
||||||
(allow auditd_t var_run_t (sock_file (write)))
|
|
||||||
(allow chkpwd_t var_run_t (sock_file (write)))
|
|
||||||
(allow local_login_t var_run_t (sock_file (write)))
|
|
||||||
(allow policykit_t var_run_t (sock_file (write)))
|
|
||||||
(allow ssh_keygen_t var_run_t (sock_file (write)))
|
|
||||||
(allow sshd_auth_t var_run_t (sock_file (write)))
|
|
||||||
(allow sshd_keygen_t var_run_t (sock_file (write)))
|
|
||||||
(allow sshd_session_t var_run_t (sock_file (write)))
|
|
||||||
(allow sshd_t var_run_t (sock_file (write)))
|
|
||||||
(allow systemd_bootc_generator_t var_run_t (sock_file (write)))
|
|
||||||
(allow systemd_selinux_autorelabel_generator_t var_run_t (sock_file (write)))
|
|
||||||
(allow systemd_userdbd_t var_run_t (sock_file (write)))
|
|
||||||
(allow xdm_t var_run_t (sock_file (write)))
|
|
||||||
(allow init_t unconfined_service_t (unix_stream_socket (connectto)))
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
[network_idm]
|
|
||||||
name=Identity Management related tools (Fedora 44)
|
|
||||||
baseurl=https://download.opensuse.org/repositories/network:/idm/Fedora_44/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
gpgkey=https://download.opensuse.org/repositories/network:/idm/Fedora_44/repodata/repomd.xml.key
|
|
||||||
@@ -1,49 +1,42 @@
|
|||||||
# Packages removed from the cloned upstream manifests at build time.
|
# Aggressive trim for a headless Proxmox VM: there is no physical hardware, so
|
||||||
#
|
# drop all firmware and non-virtio drivers. Keep qemu-guest-agent (Proxmox) and
|
||||||
# rpm-ostree treats excluding a package that an included manifest declares as a
|
# the virtio stack (in the kernel / kernel-modules).
|
||||||
# fatal error, so build.sh strips these lines from the upstream package
|
|
||||||
# manifests before composing.
|
|
||||||
#
|
|
||||||
# Target machine: GMKtec NucBox M7
|
|
||||||
# - AMD Ryzen 7 PRO 6850H (Radeon 680M iGPU) -> amd-gpu-firmware kept
|
|
||||||
# - 2x Intel I226-V Ethernet -> kernel driver, no fw pkg
|
|
||||||
# - Intel Wi-Fi 6 AX200 -> iwlwifi-mvm-firmware kept
|
|
||||||
# - AMD audio (SOF) -> alsa-sof-firmware kept
|
|
||||||
# No NVIDIA, no Intel GPU/audio, no other wireless vendors, bare metal (no VMs).
|
|
||||||
|
|
||||||
# NVIDIA
|
# All firmware (none is needed under virtio)
|
||||||
nvidia-gpu-firmware
|
amd-gpu-firmware
|
||||||
|
amd-ucode-firmware
|
||||||
# Intel GPU / platform / audio (Intel wireless firmware is kept below)
|
alsa-sof-firmware
|
||||||
intel-gpu-firmware
|
|
||||||
intel-audio-firmware
|
|
||||||
intel-lpmd
|
|
||||||
intel-vsc-firmware
|
|
||||||
libva-intel-media-driver
|
|
||||||
|
|
||||||
# Intel-only CPU tooling (AMD uses amd-ucode-firmware)
|
|
||||||
microcode_ctl
|
|
||||||
thermald
|
|
||||||
|
|
||||||
# Wireless firmware for hardware that is not present
|
|
||||||
atheros-firmware
|
atheros-firmware
|
||||||
brcmfmac-firmware
|
brcmfmac-firmware
|
||||||
|
cirrus-audio-firmware
|
||||||
|
intel-audio-firmware
|
||||||
|
intel-gpu-firmware
|
||||||
|
intel-lpmd
|
||||||
|
intel-vsc-firmware
|
||||||
|
iwlegacy-firmware
|
||||||
|
iwlwifi-dvm-firmware
|
||||||
|
iwlwifi-mvm-firmware
|
||||||
libertas-firmware
|
libertas-firmware
|
||||||
|
linux-firmware
|
||||||
mt7xxx-firmware
|
mt7xxx-firmware
|
||||||
|
nvidia-gpu-firmware
|
||||||
nxpwireless-firmware
|
nxpwireless-firmware
|
||||||
qcom-wwan-firmware
|
qcom-wwan-firmware
|
||||||
realtek-firmware
|
realtek-firmware
|
||||||
tiwilink-firmware
|
tiwilink-firmware
|
||||||
iwlwifi-dvm-firmware
|
libva-intel-media-driver
|
||||||
iwlegacy-firmware
|
|
||||||
|
|
||||||
# Audio firmware for other vendors
|
# Extra kernel modules are not needed in a VM
|
||||||
cirrus-audio-firmware
|
kernel-modules-extra
|
||||||
|
|
||||||
# Virtual machine guest agents / drivers
|
# x86 platform tools not needed under QEMU/KVM
|
||||||
|
mcelog
|
||||||
|
microcode_ctl
|
||||||
|
thermald
|
||||||
|
|
||||||
|
# Guest agents for hypervisors other than the one in use
|
||||||
hyperv-daemons
|
hyperv-daemons
|
||||||
open-vm-tools-desktop
|
open-vm-tools-desktop
|
||||||
qemu-guest-agent
|
|
||||||
spice-vdagent
|
spice-vdagent
|
||||||
spice-webdavd
|
spice-webdavd
|
||||||
virtualbox-guest-additions
|
virtualbox-guest-additions
|
||||||
|
|||||||
Reference in New Issue
Block a user