9 Commits
Author SHA1 Message Date
Misthios 6a643c658d fedora-remote: keep Intel GPU firmware/VA-API for iGPU passthrough
Build containers / Compute changes (push) Successful in 2s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m26s
Build containers / Prune old releases and tags (push) Successful in 26s
The iGPU on the Proxmox host (UHD 630, 8086:3e91) is bound to vfio-pci and
will be passed through to this VM, so the guest's i915 needs the GuC/HuC
blobs (intel-gpu-firmware) and iHD VA-API decode (libva-intel-media-driver).
Both are upstream common.yaml entries that the trim list was dropping; iris
(mesa-dri-drivers) and i915 (kernel-modules) are already present.
2026-10-04 20:14:03 +02:00
Misthios 3a1d80ad65 fedora-remote: add Mesa EGL for Proxmox virtio-gpu acceleration
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m46s
Build containers / Prune old releases and tags (push) Successful in 25s
base-atomic ships mesa-dri-drivers (the virtio_gpu Gallium driver) but not
mesa-libEGL, and with recommends off nothing pulls it in. mutter/gnome-shell
only require libglvnd's EGL dispatcher, which then has no Mesa backend, so the
session falls back to llvmpipe software rendering. Add mesa-libEGL explicitly
so the host iGPU is used under Proxmox's VirGL/virtio-gpu display.
2026-10-04 18:55:10 +02:00
Misthios 137091b402 fedora-remote: install Flatpaks system-wide on first boot
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 8m28s
Build containers / Prune old releases and tags (push) Successful in 25s
Per-user Flatpaks are only visible to the account that logged in first (and
consumed space per user). Install them into the system installation instead, so
every user including Kanidm accounts sees Firefox.
2026-09-30 19:37:03 +02:00
Misthios 172948822a fedora-remote: fix GDM greeter so headless RDP renders
Build containers / Compute changes (push) Successful in 2s
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-remote (44) (push) Successful in 10m30s
Build containers / fedora-cosmic (44) (push) Successful in 14m21s
Build containers / Prune old releases and tags (push) Successful in 26s
The minimal base (recommends off) was missing session infrastructure and one
maintained service actively broke the greeter, so RDP clients saw only a white
screen:

- add dbus-daemon: gdm-wayland-session runs it for the greeter session bus
- add systemd-pam: pam_systemd starts the per-user systemd manager
- nsswitch: shadow must include systemd so pam_unix can resolve GDM 50's
  dynamic gdm-greeter user (Fedora 44 ships 'files systemd')
- mask uresourced: its resource tuning makes user@<uid>.service fail with
  'Failed to spawn executor', leaving no systemd user bus for gnome-session
2026-09-30 19:00:29 +02:00
Misthios f2d7ad24ec fedora-remote: set GRD credentials with explicit arguments
Build containers / Compute changes (push) Successful in 2s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 8m48s
Build containers / Prune old releases and tags (push) Successful in 25s
grdctl's interactive set-credentials reads from a controlling terminal, which a
systemd service does not have, so piping the username/password in set nothing
and GRD denied every client with 'Credentials are not set'. Pass them as
arguments instead.
2026-09-30 18:39:02 +02:00
Misthios c1bf97c9c2 fedora-remote: open the RDP port in firewalld
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 8m56s
Build containers / Prune old releases and tags (push) Successful in 27s
firewalld only allows ssh by default, so GRD was listening on 3389 but the port
was still blocked. Allow the firewalld 'rdp' service in grd-firstboot.
2026-09-30 18:26:25 +02:00
Misthios 2e5a4fd707 fedora-remote: add openssl for grd-firstboot TLS, enable sshd
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m9s
Build containers / Prune old releases and tags (push) Successful in 27s
grd-firstboot aborts before enabling RDP because it shells out to openssl to
generate the TLS certificate, and the minimal image did not include the openssl
CLI. Add it. Also enable sshd so the headless host is reachable without RDP.
2026-09-30 17:26:58 +02:00
Misthios 5bea16bc01 refactor: share common files between images; trim fedora-remote for a VM
Build containers / fedora-remote (44) (push) Failing after 36s
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 12m34s
Build containers / Prune old releases (push) Failing after 28s
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
  and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
  no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
2026-09-27 22:44:10 +02:00
Misthios 6d70a1bfb9 fedora-remote: minimal headless GNOME Remote Desktop host with Kanidm
Build containers / fedora-cosmic (rawhide) (push) Failing after 54s
Build containers / fedora-cosmic (44) (push) Successful in 14m8s
Build containers / fedora-remote (44) (push) Failing after 15m36s
Build containers / Prune old releases (push) Failing after 26s
New image built from upstream base-atomic (no desktop), adding only gnome-shell
+ gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm.
recommends=false to stay lean. Configures GNOME Remote Desktop headless remote
login on first boot (TLS + credentials + enable). Firefox preinstalled as a
per-user Flatpak. Add it to the CI matrix and prune both images.
2026-09-27 22:26:48 +02:00