8 Commits
Author SHA1 Message Date
Misthios 0e4ea86f22 fedora-cosmic: enable Kanidm SSH public key auth
Build containers / fedora-cosmic (rawhide) (push) Failing after 46s
Build containers / Prune old releases (push) Canceled after 0s
Build containers / fedora-cosmic (44) (push) Canceled after 4m17s
Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via
kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
2026-09-27 22:09:56 +02:00
Misthios b9fe183da1 fedora-cosmic: mark login/nss domains permissive for Kanidm
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 11m55s
Build containers / Prune old releases (push) Successful in 25s
Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and
friends, but no AVC is emitted (even with dontaudit disabled), so the exact
allow could not be pinned. Keep the CIL allows and mark the login/nss domains
permissive so Kanidm logins work. Revisit when the denial can be isolated.
2026-09-27 21:18:05 +02:00
Misthios f00f4340b7 fedora-cosmic: ship SELinux policy for kanidm-unixd sockets
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m3s
nss/pam consumers (sshd, the display manager, systemd-userdbd, polkit, ...)
were denied write access to /run/kanidm-unixd/* (var_run_t), so Kanidm users
could not be resolved or authenticated and logins failed with 'invalid user'.
Add the audit2allow-derived CIL and load it at build time (semodule noreload).
2026-09-27 18:49:12 +02:00
Misthios 7693e22b08 fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
Build containers / fedora-cosmic (44) (push) Successful in 13m9s
Build containers / fedora-cosmic (rawhide) (push) Successful in 17m18s
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the
secret is set, via a generated add-files include. Without the secret the image
is built unchanged and the token must be provisioned on the host.
2026-09-21 19:24:15 +02:00
Misthios d7ca0cae6e fedora-cosmic: use authselect --nobackup in compose
Build containers / fedora-cosmic (rawhide) (push) Successful in 10m50s
Build containers / fedora-cosmic (44) (push) Successful in 13m46s
/var is read-only during compose so authselect could not create its backup
dir and fell back to writing PAM/nsswitch files directly. --nobackup keeps
authselect in charge of the symlinks.
2026-09-21 18:28:22 +02:00
Misthios dd2bf634f1 fedora-cosmic: add Kanidm Unix authentication
Build containers / fedora-cosmic (rawhide) (push) Failing after 45s
Build containers / fedora-cosmic (44) (push) Failing after 54s
Install kanidm-unixd-clients/kanidm-clients, point /etc/kanidm/config at
auth.plabble.org, configure unixd (TPM-backed cache, pam_allowed_login_groups),
and set up PAM/nsswitch via an authselect custom profile (with a direct-file
fallback). Enable kanidm-unixd{,-tasks} and make unconfined_service_t
permissive until Kanidm ships an SELinux policy.
2026-09-21 17:57:32 +02:00
Misthios ddd095f201 fedora-cosmic: drop pcsc-tools (pulls perl, excluded upstream)
Build containers / fedora-cosmic (44) (push) Failing after 24m25s
Build containers / fedora-cosmic (rawhide) (push) Failing after 24m25s
2026-09-21 16:01:59 +02:00
Misthios bc542f14b2 refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
2026-09-21 15:11:26 +02:00