Commit Graph
9 Commits
Author SHA1 Message Date
Misthios 7693e22b08 fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
Build containers / fedora-cosmic (44) (push) Successful in 13m9s
Build containers / fedora-cosmic (rawhide) (push) Successful in 17m18s
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the
secret is set, via a generated add-files include. Without the secret the image
is built unchanged and the token must be provisioned on the host.
2026-09-21 19:24:15 +02:00
Misthios d7ca0cae6e fedora-cosmic: use authselect --nobackup in compose
Build containers / fedora-cosmic (rawhide) (push) Successful in 10m50s
Build containers / fedora-cosmic (44) (push) Successful in 13m46s
/var is read-only during compose so authselect could not create its backup
dir and fell back to writing PAM/nsswitch files directly. --nobackup keeps
authselect in charge of the symlinks.
2026-09-21 18:28:22 +02:00
Misthios 693d9a8147 fedora-cosmic: add OBS network:idm repo for Kanidm packages
Build containers / fedora-cosmic (rawhide) (push) Successful in 12m6s
Build containers / fedora-cosmic (44) (push) Successful in 13m43s
Kanidm is not in the Fedora repos; it ships from the openSUSE OBS
network:idm project. Add per-distro repo files (Fedora_44 / Fedora_Rawhide)
and teach build.sh to overlay repos/<distro>/*.repo.
2026-09-21 17:59:27 +02:00
Misthios dd2bf634f1 fedora-cosmic: add Kanidm Unix authentication
Build containers / fedora-cosmic (rawhide) (push) Failing after 45s
Build containers / fedora-cosmic (44) (push) Failing after 54s
Install kanidm-unixd-clients/kanidm-clients, point /etc/kanidm/config at
auth.plabble.org, configure unixd (TPM-backed cache, pam_allowed_login_groups),
and set up PAM/nsswitch via an authselect custom profile (with a direct-file
fallback). Enable kanidm-unixd{,-tasks} and make unconfined_service_t
permissive until Kanidm ships an SELinux policy.
2026-09-21 17:57:32 +02:00
Misthios de5b0f143a ci: generate package list during compose via finalize.d
Build containers / fedora-cosmic (rawhide) (push) Successful in 11m54s
Build containers / fedora-cosmic (44) (push) Successful in 12m56s
Avoid mounting the built image with buildah (ran out of disk); the
finalize.d hook records the rpm list next to the treefile and release.sh
consumes it directly.
2026-09-21 17:35:17 +02:00
Misthios 0a05b2a6bc fedora-cosmic: drop hardware/VM packages not needed on the target host
Build containers / fedora-cosmic (rawhide) (push) Failing after 15m15s
Build containers / fedora-cosmic (44) (push) Failing after 16m30s
Trim NVIDIA, Intel GPU/audio/platform, other wireless vendors and VM guest
packages from the cloned upstream manifests, and block linux-firmware's
recommends of them via a generated exclude list. Keeps amd-gpu-firmware,
amd-ucode-firmware, iwlwifi-mvm-firmware (AX200) and alsa-sof-firmware.
2026-09-21 17:17:14 +02:00
Misthios ddd095f201 fedora-cosmic: drop pcsc-tools (pulls perl, excluded upstream)
Build containers / fedora-cosmic (44) (push) Failing after 24m25s
Build containers / fedora-cosmic (rawhide) (push) Failing after 24m25s
2026-09-21 16:01:59 +02:00
Misthios 0433b1850e fedora-cosmic: enable token2-fido-bridge repo in treefile
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
2026-09-21 15:58:55 +02:00
Misthios bc542f14b2 refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
2026-09-21 15:11:26 +02:00