fedora-remote: minimal headless GNOME Remote Desktop host with Kanidm
New image built from upstream base-atomic (no desktop), adding only gnome-shell + gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm. recommends=false to stay lean. Configures GNOME Remote Desktop headless remote login on first boot (TLS + credentials + enable). Firefox preinstalled as a per-user Flatpak. Add it to the CI matrix and prune both images.
This commit is contained in:
@@ -0,0 +1,89 @@
|
||||
# Customizations for the minimal headless remote host.
|
||||
|
||||
packages:
|
||||
# Fedora integration normally provided by the upstream fedora.yaml (which we
|
||||
# opt out of to avoid the Firefox RPM).
|
||||
- fedora-release
|
||||
- fedora-release-ostree-desktop
|
||||
- fedora-flathub-remote
|
||||
|
||||
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
|
||||
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
|
||||
- gdm
|
||||
- gnome-shell
|
||||
- gnome-remote-desktop
|
||||
- pipewire
|
||||
- wireplumber
|
||||
- xdg-desktop-portal-gnome
|
||||
|
||||
# Terminal (foot has no Flathub build) and Flatpak.
|
||||
- foot
|
||||
- flatpak
|
||||
|
||||
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
||||
- kanidm-unixd-clients
|
||||
|
||||
# Firefox is shipped as a per-user Flatpak, not an RPM.
|
||||
exclude-packages:
|
||||
- firefox
|
||||
|
||||
add-files:
|
||||
# Per-user Flatpaks on first login (Firefox).
|
||||
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
||||
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
||||
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
||||
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
||||
# Kanidm client config + authselect profile sources.
|
||||
- ["kanidm-config", "/etc/kanidm/config"]
|
||||
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
||||
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
|
||||
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
|
||||
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
|
||||
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
||||
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
|
||||
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
||||
# GNOME Remote Desktop first-boot configuration.
|
||||
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
|
||||
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
|
||||
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
|
||||
|
||||
postprocess:
|
||||
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
if ! (
|
||||
set -euo pipefail
|
||||
authselect create-profile kanidm -b local
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
|
||||
/etc/authselect/custom/kanidm/system-auth
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
|
||||
/etc/authselect/custom/kanidm/password-auth
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
|
||||
/etc/authselect/custom/kanidm/nsswitch.conf
|
||||
authselect select custom/kanidm --force --nobackup
|
||||
); then
|
||||
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
||||
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
|
||||
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
|
||||
fi
|
||||
|
||||
# Kanidm SELinux policy (same approach as fedora-cosmic).
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
|
||||
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
||||
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
||||
unconfined_service_t; do
|
||||
semanage permissive -a "${domain}" || true
|
||||
done
|
||||
|
||||
# Make helper scripts executable.
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
|
||||
systemctl --user --global preset-all
|
||||
Reference in New Issue
Block a user