Per-user Flatpaks are only visible to the account that logged in first (and
consumed space per user). Install them into the system installation instead, so
every user including Kanidm accounts sees Firefox.
New image built from upstream base-atomic (no desktop), adding only gnome-shell
+ gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm.
recommends=false to stay lean. Configures GNOME Remote Desktop headless remote
login on first boot (TLS + credentials + enable). Firefox preinstalled as a
per-user Flatpak. Add it to the CI matrix and prune both images.