fedora-remote: minimal headless GNOME Remote Desktop host with Kanidm
New image built from upstream base-atomic (no desktop), adding only gnome-shell + gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm. recommends=false to stay lean. Configures GNOME Remote Desktop headless remote login on first boot (TLS + credentials + enable). Firefox preinstalled as a per-user Flatpak. Add it to the CI matrix and prune both images.
This commit is contained in:
@@ -29,6 +29,10 @@ jobs:
|
|||||||
distro: rawhide
|
distro: rawhide
|
||||||
arch: x86_64
|
arch: x86_64
|
||||||
runner: job-v2
|
runner: job-v2
|
||||||
|
- image: fedora-remote
|
||||||
|
distro: "44"
|
||||||
|
arch: x86_64
|
||||||
|
runner: job-v2
|
||||||
|
|
||||||
container:
|
container:
|
||||||
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
|
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
|
||||||
@@ -141,7 +145,10 @@ jobs:
|
|||||||
- name: Prune old releases
|
- name: Prune old releases
|
||||||
env:
|
env:
|
||||||
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||||
run: ./prune-releases.sh fedora-cosmic
|
run: |
|
||||||
|
for image in fedora-cosmic fedora-remote; do
|
||||||
|
./prune-releases.sh "${image}"
|
||||||
|
done
|
||||||
- name: Prune old registry tags
|
- name: Prune old registry tags
|
||||||
env:
|
env:
|
||||||
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||||
@@ -151,4 +158,6 @@ jobs:
|
|||||||
authfile=/tmp/prune-auth.json
|
authfile=/tmp/prune-auth.json
|
||||||
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
||||||
--password-stdin --authfile "${authfile}" git.plabble.org
|
--password-stdin --authfile "${authfile}" git.plabble.org
|
||||||
AUTHFILE="${authfile}" ./prune-registry.sh fedora-cosmic Misthios 44 rawhide
|
for image in fedora-cosmic fedora-remote; do
|
||||||
|
AUTHFILE="${authfile}" ./prune-registry.sh "${image}" Misthios 44 rawhide
|
||||||
|
done
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
# Build configuration for images/fedora-remote. Sourced by build.sh.
|
||||||
|
|
||||||
|
BUILD_MODE=upstream
|
||||||
|
|
||||||
|
UPSTREAM_REPO="https://gitlab.com/fedora/ostree/ci-test.git"
|
||||||
|
|
||||||
|
# Stable only; this is a small remote-access host.
|
||||||
|
declare -A UPSTREAM_REFS=(
|
||||||
|
[44]=f44
|
||||||
|
)
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
# Customizations for the minimal headless remote host.
|
||||||
|
|
||||||
|
packages:
|
||||||
|
# Fedora integration normally provided by the upstream fedora.yaml (which we
|
||||||
|
# opt out of to avoid the Firefox RPM).
|
||||||
|
- fedora-release
|
||||||
|
- fedora-release-ostree-desktop
|
||||||
|
- fedora-flathub-remote
|
||||||
|
|
||||||
|
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
|
||||||
|
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
|
||||||
|
- gdm
|
||||||
|
- gnome-shell
|
||||||
|
- gnome-remote-desktop
|
||||||
|
- pipewire
|
||||||
|
- wireplumber
|
||||||
|
- xdg-desktop-portal-gnome
|
||||||
|
|
||||||
|
# Terminal (foot has no Flathub build) and Flatpak.
|
||||||
|
- foot
|
||||||
|
- flatpak
|
||||||
|
|
||||||
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
||||||
|
- kanidm-unixd-clients
|
||||||
|
|
||||||
|
# Firefox is shipped as a per-user Flatpak, not an RPM.
|
||||||
|
exclude-packages:
|
||||||
|
- firefox
|
||||||
|
|
||||||
|
add-files:
|
||||||
|
# Per-user Flatpaks on first login (Firefox).
|
||||||
|
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
||||||
|
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
||||||
|
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
||||||
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
||||||
|
# Kanidm client config + authselect profile sources.
|
||||||
|
- ["kanidm-config", "/etc/kanidm/config"]
|
||||||
|
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
||||||
|
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
|
||||||
|
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
|
||||||
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
|
||||||
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
||||||
|
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
|
||||||
|
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
||||||
|
# GNOME Remote Desktop first-boot configuration.
|
||||||
|
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
|
||||||
|
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
|
||||||
|
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
|
||||||
|
|
||||||
|
postprocess:
|
||||||
|
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
if ! (
|
||||||
|
set -euo pipefail
|
||||||
|
authselect create-profile kanidm -b local
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
|
||||||
|
/etc/authselect/custom/kanidm/system-auth
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
|
||||||
|
/etc/authselect/custom/kanidm/password-auth
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
|
||||||
|
/etc/authselect/custom/kanidm/nsswitch.conf
|
||||||
|
authselect select custom/kanidm --force --nobackup
|
||||||
|
); then
|
||||||
|
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
||||||
|
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
|
||||||
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Kanidm SELinux policy (same approach as fedora-cosmic).
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
|
||||||
|
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
||||||
|
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
||||||
|
unconfined_service_t; do
|
||||||
|
semanage permissive -a "${domain}" || true
|
||||||
|
done
|
||||||
|
|
||||||
|
# Make helper scripts executable.
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
|
||||||
|
systemctl --user --global preset-all
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
||||||
|
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
||||||
|
# drop-in, since sshd honours the first directive it sees.
|
||||||
|
PubkeyAuthentication yes
|
||||||
|
UsePAM yes
|
||||||
|
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
||||||
|
AuthorizedKeysCommandUser nobody
|
||||||
|
|
||||||
|
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
|
||||||
|
# public key to your account before relying on this, or you can lock yourself
|
||||||
|
# out of SSH.
|
||||||
|
PermitRootLogin no
|
||||||
|
PasswordAuthentication no
|
||||||
|
PermitEmptyPasswords no
|
||||||
|
GSSAPIAuthentication no
|
||||||
|
KerberosAuthentication no
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# GNOME Remote Desktop headless remote login.
|
||||||
|
enable gdm.service
|
||||||
|
enable gnome-remote-desktop.service
|
||||||
|
enable grd-firstboot.service
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# Kanidm Unix authentication daemons.
|
||||||
|
enable kanidm-unixd.service
|
||||||
|
enable kanidm-unixd-tasks.service
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
enable flatpak-user-firstboot.service
|
||||||
+24
@@ -0,0 +1,24 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
|
||||||
|
# the first login of each user. Run as a systemd --user oneshot unit.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
LIST="/usr/share/flatpak/flatpaks.list"
|
||||||
|
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
|
||||||
|
|
||||||
|
[[ -f "${LIST}" ]] || exit 0
|
||||||
|
|
||||||
|
# Make Flathub available for the current user.
|
||||||
|
flatpak remote-add --user --if-not-exists flathub \
|
||||||
|
https://flathub.org/repo/flathub.flatpakrepo
|
||||||
|
|
||||||
|
mapfile -t apps < <(
|
||||||
|
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
|
||||||
|
)
|
||||||
|
|
||||||
|
if [[ ${#apps[@]} -gt 0 ]]; then
|
||||||
|
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
install -dm0755 "$(dirname "${MARKER}")"
|
||||||
|
touch "${MARKER}"
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Install per-user Flatpak applications on first login
|
||||||
|
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
|
||||||
|
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
|
||||||
|
After=network-online.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecStart=/usr/libexec/flatpak-user-firstboot
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=default.target
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# Flatpaks installed into each user's per-user installation on first login.
|
||||||
|
# foot is installed as an RPM (no Flathub build), so only Firefox here.
|
||||||
|
org.mozilla.firefox
|
||||||
Executable
+38
@@ -0,0 +1,38 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# One-time configuration of GNOME Remote Desktop (system / headless remote
|
||||||
|
# login). Runs on first boot because grdctl talks to the running daemon.
|
||||||
|
#
|
||||||
|
# Optional /etc/gnome-remote-desktop/rdp.env:
|
||||||
|
# GRD_SYSTEM_USER=rdp
|
||||||
|
# GRD_SYSTEM_PASSWORD=...
|
||||||
|
# If unset, remote login is enabled but no greeter credential is configured
|
||||||
|
# (set one with: printf '%s\n%s\n' USER PASS | grdctl --system rdp set-credentials).
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
GRD_USER=gnome-remote-desktop
|
||||||
|
STATE="/var/lib/${GRD_USER}"
|
||||||
|
TLS_DIR="${STATE}/.local/share/gnome-remote-desktop"
|
||||||
|
MARKER="${STATE}/.configured"
|
||||||
|
|
||||||
|
[[ -f "${MARKER}" ]] && exit 0
|
||||||
|
|
||||||
|
install -d -o "${GRD_USER}" -g "${GRD_USER}" "${TLS_DIR}"
|
||||||
|
|
||||||
|
if [[ ! -f "${TLS_DIR}/tls.key" ]]; then
|
||||||
|
sudo -u "${GRD_USER}" openssl req -new -newkey rsa:4096 -days 720 -nodes -x509 \
|
||||||
|
-subj "/CN=${GRD_CERT_CN:-fedora-remote}" \
|
||||||
|
-out "${TLS_DIR}/tls.crt" -keyout "${TLS_DIR}/tls.key"
|
||||||
|
fi
|
||||||
|
|
||||||
|
grdctl --system rdp set-tls-key "${TLS_DIR}/tls.key"
|
||||||
|
grdctl --system rdp set-tls-cert "${TLS_DIR}/tls.crt"
|
||||||
|
|
||||||
|
if [[ -n "${GRD_SYSTEM_PASSWORD:-}" ]]; then
|
||||||
|
printf '%s\n%s\n' "${GRD_SYSTEM_USER:-rdp}" "${GRD_SYSTEM_PASSWORD}" \
|
||||||
|
| grdctl --system rdp set-credentials
|
||||||
|
fi
|
||||||
|
|
||||||
|
grdctl --system rdp enable
|
||||||
|
systemctl restart gnome-remote-desktop.service || true
|
||||||
|
|
||||||
|
touch "${MARKER}"
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Configure GNOME Remote Desktop on first boot
|
||||||
|
Documentation=https://github.com/GNOME/gnome-remote-desktop/blob/main/docs/configuration.md
|
||||||
|
After=network-online.target gnome-remote-desktop.service
|
||||||
|
Wants=network-online.target
|
||||||
|
ConditionPathExists=!/var/lib/gnome-remote-desktop/.configured
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
EnvironmentFile=-/etc/gnome-remote-desktop/rdp.env
|
||||||
|
ExecStart=/usr/libexec/grd-firstboot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
uri = "https://auth.plabble.org"
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
passwd: kanidm compat systemd
|
||||||
|
group: kanidm compat systemd
|
||||||
|
shadow: files
|
||||||
|
hosts: files dns myhostname
|
||||||
|
services: files
|
||||||
|
netgroup: files
|
||||||
|
automount: files
|
||||||
|
aliases: files
|
||||||
|
ethers: files
|
||||||
|
gshadow: files
|
||||||
|
networks: files dns
|
||||||
|
protocols: files
|
||||||
|
publickey: files
|
||||||
|
rpc: files
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
auth required pam_env.so
|
||||||
|
auth required pam_faildelay.so delay=2000000
|
||||||
|
auth sufficient pam_kanidm.so ignore_unknown_user
|
||||||
|
auth sufficient pam_unix.so nullok
|
||||||
|
auth required pam_deny.so
|
||||||
|
|
||||||
|
account sufficient pam_kanidm.so
|
||||||
|
account required pam_unix.so
|
||||||
|
|
||||||
|
password requisite pam_pwquality.so
|
||||||
|
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
|
||||||
|
password required pam_deny.so
|
||||||
|
|
||||||
|
session optional pam_keyinit.so revoke
|
||||||
|
session required pam_limits.so
|
||||||
|
-session optional pam_systemd.so
|
||||||
|
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
|
||||||
|
session optional pam_kanidm.so
|
||||||
|
session required pam_unix.so
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
auth required pam_env.so
|
||||||
|
auth required pam_faildelay.so delay=2000000
|
||||||
|
auth sufficient pam_fprintd.so
|
||||||
|
auth sufficient pam_kanidm.so ignore_unknown_user
|
||||||
|
auth sufficient pam_unix.so nullok
|
||||||
|
auth required pam_deny.so
|
||||||
|
|
||||||
|
account sufficient pam_kanidm.so ignore_unknown_user
|
||||||
|
account required pam_unix.so
|
||||||
|
|
||||||
|
password requisite pam_pwquality.so
|
||||||
|
password sufficient pam_unix.so yescrypt shadow nullok use_authtok
|
||||||
|
password required pam_deny.so
|
||||||
|
|
||||||
|
session optional pam_keyinit.so revoke
|
||||||
|
session required pam_limits.so
|
||||||
|
-session optional pam_systemd.so
|
||||||
|
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
|
||||||
|
session optional pam_kanidm.so
|
||||||
|
session required pam_unix.so
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
version = "2"
|
||||||
|
|
||||||
|
# Bind cached credentials to the local TPM when one is available.
|
||||||
|
hsm_type = "tpm_if_possible"
|
||||||
|
|
||||||
|
default_shell = "/bin/bash"
|
||||||
|
home_prefix = "/home/"
|
||||||
|
home_attr = "uuid"
|
||||||
|
home_alias = "name"
|
||||||
|
use_etc_skel = true
|
||||||
|
selinux = true
|
||||||
|
|
||||||
|
# Present the short login name ("misthios"), not the SPN, to NSS/PAM. With the
|
||||||
|
# default (spn) the passwd entry name is "misthios@auth.plabble.org", which
|
||||||
|
# confuses logins.
|
||||||
|
uid_attr_map = "name"
|
||||||
|
gid_attr_map = "name"
|
||||||
|
|
||||||
|
[kanidm]
|
||||||
|
# Members of this Kanidm POSIX group are allowed to log in via PAM.
|
||||||
|
pam_allowed_login_groups = ["unix_users"]
|
||||||
|
|
||||||
|
# A host almost always already has a local account at uid 1000. Kanidm ignores
|
||||||
|
# its own entry when a local account with the same name exists, so logins would
|
||||||
|
# use the local account (and the Kanidm password would fail). Let Kanidm take
|
||||||
|
# over these local accounts. Add more names as needed.
|
||||||
|
allow_local_account_override = ["misthios"]
|
||||||
|
|
||||||
|
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
|
||||||
|
# so the service account token (when seeded) is passed as a systemd credential
|
||||||
|
# via the build.sh-generated drop-in
|
||||||
|
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
|
||||||
|
# Do not set service_account_token_path here.
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
; Kanidm ships no SELinux policy. Without these allows, nss/pam consumers
|
||||||
|
; (sshd, the display manager, systemd-userdbd, ...) are denied write access to
|
||||||
|
; the kanidm-unixd sockets in /run/kanidm-unixd (labeled var_run_t), so Kanidm
|
||||||
|
; users cannot be resolved or authenticated and logins fail (sshd reports
|
||||||
|
; "invalid user"). This is the allow set produced by:
|
||||||
|
; grep avc: /var/log/audit/audit.log | audit2allow
|
||||||
|
(allow accountsd_t var_run_t (sock_file (write)))
|
||||||
|
(allow auditd_t var_run_t (sock_file (write)))
|
||||||
|
(allow chkpwd_t var_run_t (sock_file (write)))
|
||||||
|
(allow local_login_t var_run_t (sock_file (write)))
|
||||||
|
(allow policykit_t var_run_t (sock_file (write)))
|
||||||
|
(allow ssh_keygen_t var_run_t (sock_file (write)))
|
||||||
|
(allow sshd_auth_t var_run_t (sock_file (write)))
|
||||||
|
(allow sshd_keygen_t var_run_t (sock_file (write)))
|
||||||
|
(allow sshd_session_t var_run_t (sock_file (write)))
|
||||||
|
(allow sshd_t var_run_t (sock_file (write)))
|
||||||
|
(allow systemd_bootc_generator_t var_run_t (sock_file (write)))
|
||||||
|
(allow systemd_selinux_autorelabel_generator_t var_run_t (sock_file (write)))
|
||||||
|
(allow systemd_userdbd_t var_run_t (sock_file (write)))
|
||||||
|
(allow xdm_t var_run_t (sock_file (write)))
|
||||||
|
(allow init_t unconfined_service_t (unix_stream_socket (connectto)))
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Minimal headless remote host: GNOME Remote Desktop (RDP over Wayland) with
|
||||||
|
# Kanidm Unix authentication. Built on the upstream base-atomic (no desktop)
|
||||||
|
# manifest, not the full GNOME/silverblue set.
|
||||||
|
|
||||||
|
metadata:
|
||||||
|
summary: Fedora headless remote host (GNOME Remote Desktop + Kanidm)
|
||||||
|
|
||||||
|
variables:
|
||||||
|
# Opt out of the upstream fedora.yaml so we don't pull the Firefox RPM.
|
||||||
|
distro: "fedora-remote"
|
||||||
|
variant: "remote"
|
||||||
|
|
||||||
|
# Keep it small: no weak/optional dependencies.
|
||||||
|
recommends: false
|
||||||
|
|
||||||
|
default_target: graphical.target
|
||||||
|
|
||||||
|
ref: fedora-remote/${releasever_ref}/${basearch}/remote
|
||||||
|
|
||||||
|
repos:
|
||||||
|
# Kanidm packages (OBS network:idm).
|
||||||
|
- network_idm
|
||||||
|
|
||||||
|
include:
|
||||||
|
- base-atomic.yaml
|
||||||
|
- custom.yaml
|
||||||
|
# Generated by build.sh.
|
||||||
|
- hardware-exclude.yaml
|
||||||
|
- kanidm-token.yaml
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
[network_idm]
|
||||||
|
name=Identity Management related tools (Fedora 44)
|
||||||
|
baseurl=https://download.opensuse.org/repositories/network:/idm/Fedora_44/
|
||||||
|
type=rpm-md
|
||||||
|
skip_if_unavailable=False
|
||||||
|
gpgcheck=1
|
||||||
|
repo_gpgcheck=0
|
||||||
|
enabled=1
|
||||||
|
gpgkey=https://download.opensuse.org/repositories/network:/idm/Fedora_44/repodata/repomd.xml.key
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
# Packages removed from the cloned upstream manifests at build time.
|
||||||
|
#
|
||||||
|
# rpm-ostree treats excluding a package that an included manifest declares as a
|
||||||
|
# fatal error, so build.sh strips these lines from the upstream package
|
||||||
|
# manifests before composing.
|
||||||
|
#
|
||||||
|
# Target machine: GMKtec NucBox M7
|
||||||
|
# - AMD Ryzen 7 PRO 6850H (Radeon 680M iGPU) -> amd-gpu-firmware kept
|
||||||
|
# - 2x Intel I226-V Ethernet -> kernel driver, no fw pkg
|
||||||
|
# - Intel Wi-Fi 6 AX200 -> iwlwifi-mvm-firmware kept
|
||||||
|
# - AMD audio (SOF) -> alsa-sof-firmware kept
|
||||||
|
# No NVIDIA, no Intel GPU/audio, no other wireless vendors, bare metal (no VMs).
|
||||||
|
|
||||||
|
# NVIDIA
|
||||||
|
nvidia-gpu-firmware
|
||||||
|
|
||||||
|
# Intel GPU / platform / audio (Intel wireless firmware is kept below)
|
||||||
|
intel-gpu-firmware
|
||||||
|
intel-audio-firmware
|
||||||
|
intel-lpmd
|
||||||
|
intel-vsc-firmware
|
||||||
|
libva-intel-media-driver
|
||||||
|
|
||||||
|
# Intel-only CPU tooling (AMD uses amd-ucode-firmware)
|
||||||
|
microcode_ctl
|
||||||
|
thermald
|
||||||
|
|
||||||
|
# Wireless firmware for hardware that is not present
|
||||||
|
atheros-firmware
|
||||||
|
brcmfmac-firmware
|
||||||
|
libertas-firmware
|
||||||
|
mt7xxx-firmware
|
||||||
|
nxpwireless-firmware
|
||||||
|
qcom-wwan-firmware
|
||||||
|
realtek-firmware
|
||||||
|
tiwilink-firmware
|
||||||
|
iwlwifi-dvm-firmware
|
||||||
|
iwlegacy-firmware
|
||||||
|
|
||||||
|
# Audio firmware for other vendors
|
||||||
|
cirrus-audio-firmware
|
||||||
|
|
||||||
|
# Virtual machine guest agents / drivers
|
||||||
|
hyperv-daemons
|
||||||
|
open-vm-tools-desktop
|
||||||
|
qemu-guest-agent
|
||||||
|
spice-vdagent
|
||||||
|
spice-webdavd
|
||||||
|
virtualbox-guest-additions
|
||||||
Reference in New Issue
Block a user