Commit Graph
26 Commits
Author SHA1 Message Date
Misthios c1bf97c9c2 fedora-remote: open the RDP port in firewalld
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 8m56s
Build containers / Prune old releases and tags (push) Successful in 27s
firewalld only allows ssh by default, so GRD was listening on 3389 but the port
was still blocked. Allow the firewalld 'rdp' service in grd-firstboot.
2026-09-30 18:26:25 +02:00
Misthios 2e5a4fd707 fedora-remote: add openssl for grd-firstboot TLS, enable sshd
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m9s
Build containers / Prune old releases and tags (push) Successful in 27s
grd-firstboot aborts before enabling RDP because it shells out to openssl to
generate the TLS certificate, and the minimal image did not include the openssl
CLI. Add it. Also enable sshd so the headless host is reachable without RDP.
2026-09-30 17:26:58 +02:00
Misthios 5bea16bc01 refactor: share common files between images; trim fedora-remote for a VM
Build containers / fedora-remote (44) (push) Failing after 36s
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 12m34s
Build containers / Prune old releases (push) Failing after 28s
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
  and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
  no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
2026-09-27 22:44:10 +02:00
Misthios 6d70a1bfb9 fedora-remote: minimal headless GNOME Remote Desktop host with Kanidm
Build containers / fedora-cosmic (rawhide) (push) Failing after 54s
Build containers / fedora-cosmic (44) (push) Successful in 14m8s
Build containers / fedora-remote (44) (push) Failing after 15m36s
Build containers / Prune old releases (push) Failing after 26s
New image built from upstream base-atomic (no desktop), adding only gnome-shell
+ gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm.
recommends=false to stay lean. Configures GNOME Remote Desktop headless remote
login on first boot (TLS + credentials + enable). Firefox preinstalled as a
per-user Flatpak. Add it to the CI matrix and prune both images.
2026-09-27 22:26:48 +02:00
Misthios 6822bc3061 fedora-cosmic: harden sshd for Kanidm key-only auth
Build containers / fedora-cosmic (rawhide) (push) Failing after 54s
Build containers / fedora-cosmic (44) (push) Successful in 12m1s
Build containers / Prune old releases (push) Successful in 22s
Disable password/root/GSSAPI/Kerberos SSH auth now that public keys are
served by Kanidm.
2026-09-27 22:11:55 +02:00
Misthios 0e4ea86f22 fedora-cosmic: enable Kanidm SSH public key auth
Build containers / fedora-cosmic (rawhide) (push) Failing after 46s
Build containers / Prune old releases (push) Canceled after 0s
Build containers / fedora-cosmic (44) (push) Canceled after 4m17s
Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via
kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
2026-09-27 22:09:56 +02:00
Misthios b9fe183da1 fedora-cosmic: mark login/nss domains permissive for Kanidm
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 11m55s
Build containers / Prune old releases (push) Successful in 25s
Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and
friends, but no AVC is emitted (even with dontaudit disabled), so the exact
allow could not be pinned. Keep the CIL allows and mark the login/nss domains
permissive so Kanidm logins work. Revisit when the denial can be isolated.
2026-09-27 21:18:05 +02:00
Misthios 380d550351 fedora-cosmic: make Kanidm logins work despite a local uid-1000 account
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m0s
Build containers / Prune old releases (push) Successful in 20s
- uid_attr_map/gid_attr_map = name so NSS/PAM see 'misthios', not the SPN
- allow_local_account_override = [misthios] so Kanidm takes over an existing
  local account of the same name (Kanidm otherwise ignores its own entry,
  leaving logins to fall back to the local account and fail)
2026-09-27 19:46:36 +02:00
Misthios f00f4340b7 fedora-cosmic: ship SELinux policy for kanidm-unixd sockets
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m3s
nss/pam consumers (sshd, the display manager, systemd-userdbd, polkit, ...)
were denied write access to /run/kanidm-unixd/* (var_run_t), so Kanidm users
could not be resolved or authenticated and logins failed with 'invalid user'.
Add the audit2allow-derived CIL and load it at build time (semodule noreload).
2026-09-27 18:49:12 +02:00
Misthios a5c6170ac0 fedora-cosmic: pass Kanidm token via systemd credential
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-cosmic (44) (push) Successful in 10m50s
kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only
/etc/kanidm/unixd_token. With service_account_token_path set in
/etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user
resolved. Drop that setting and inject the token with LoadCredential +
KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in.

Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online,
'getent passwd job' resolves.
2026-09-27 17:59:36 +02:00
Misthios 7693e22b08 fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
Build containers / fedora-cosmic (44) (push) Successful in 13m9s
Build containers / fedora-cosmic (rawhide) (push) Successful in 17m18s
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the
secret is set, via a generated add-files include. Without the secret the image
is built unchanged and the token must be provisioned on the host.
2026-09-21 19:24:15 +02:00
Misthios d7ca0cae6e fedora-cosmic: use authselect --nobackup in compose
Build containers / fedora-cosmic (rawhide) (push) Successful in 10m50s
Build containers / fedora-cosmic (44) (push) Successful in 13m46s
/var is read-only during compose so authselect could not create its backup
dir and fell back to writing PAM/nsswitch files directly. --nobackup keeps
authselect in charge of the symlinks.
2026-09-21 18:28:22 +02:00
Misthios 693d9a8147 fedora-cosmic: add OBS network:idm repo for Kanidm packages
Build containers / fedora-cosmic (rawhide) (push) Successful in 12m6s
Build containers / fedora-cosmic (44) (push) Successful in 13m43s
Kanidm is not in the Fedora repos; it ships from the openSUSE OBS
network:idm project. Add per-distro repo files (Fedora_44 / Fedora_Rawhide)
and teach build.sh to overlay repos/<distro>/*.repo.
2026-09-21 17:59:27 +02:00
Misthios dd2bf634f1 fedora-cosmic: add Kanidm Unix authentication
Build containers / fedora-cosmic (rawhide) (push) Failing after 45s
Build containers / fedora-cosmic (44) (push) Failing after 54s
Install kanidm-unixd-clients/kanidm-clients, point /etc/kanidm/config at
auth.plabble.org, configure unixd (TPM-backed cache, pam_allowed_login_groups),
and set up PAM/nsswitch via an authselect custom profile (with a direct-file
fallback). Enable kanidm-unixd{,-tasks} and make unconfined_service_t
permissive until Kanidm ships an SELinux policy.
2026-09-21 17:57:32 +02:00
Misthios de5b0f143a ci: generate package list during compose via finalize.d
Build containers / fedora-cosmic (rawhide) (push) Successful in 11m54s
Build containers / fedora-cosmic (44) (push) Successful in 12m56s
Avoid mounting the built image with buildah (ran out of disk); the
finalize.d hook records the rpm list next to the treefile and release.sh
consumes it directly.
2026-09-21 17:35:17 +02:00
Misthios 0a05b2a6bc fedora-cosmic: drop hardware/VM packages not needed on the target host
Build containers / fedora-cosmic (rawhide) (push) Failing after 15m15s
Build containers / fedora-cosmic (44) (push) Failing after 16m30s
Trim NVIDIA, Intel GPU/audio/platform, other wireless vendors and VM guest
packages from the cloned upstream manifests, and block linux-firmware's
recommends of them via a generated exclude list. Keeps amd-gpu-firmware,
amd-ucode-firmware, iwlwifi-mvm-firmware (AX200) and alsa-sof-firmware.
2026-09-21 17:17:14 +02:00
Misthios ddd095f201 fedora-cosmic: drop pcsc-tools (pulls perl, excluded upstream)
Build containers / fedora-cosmic (44) (push) Failing after 24m25s
Build containers / fedora-cosmic (rawhide) (push) Failing after 24m25s
2026-09-21 16:01:59 +02:00
Misthios 0433b1850e fedora-cosmic: enable token2-fido-bridge repo in treefile
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
2026-09-21 15:58:55 +02:00
Misthios bc542f14b2 refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
2026-09-21 15:11:26 +02:00
Misthios 67fe861b56 asahi-cosmic: add gvfs-mtp package
Build containers / Build and push image (push) Successful in 9m6s
2026-03-01 20:15:09 +01:00
Misthios eb47b29286 asahi-cosmic: add upower
Build containers / Build and push image (asahi-cosmic, 43) (push) Successful in 11m18s
2026-03-01 15:25:52 +01:00
Misthios 857b3429b1 ci: rework build
Build containers / Build and push image (asahi-cosmic, 43) (push) Failing after 3h12m30s
2026-02-27 15:10:52 +00:00
Misthios ac08df1901 initial asahi-cosmic setup
Build containers / Build and push image (base, 43) (push) Failing after 36s
Build containers / Build and push image (base, 44) (push) Failing after 49s
2026-02-21 23:38:38 +01:00
Misthios e903787ba0 base/manifest add oci tag
Build containers / Build and push image (base, 43) (push) Failing after 37s
Build containers / Build and push image (base, 44) (push) Failing after 35s
2026-02-21 20:54:37 +01:00
Misthios 5c1a7ad9a5 CI: initial hardcoded ci
Build containers / Build and push image (base, 43) (push) Successful in 7m46s
2026-02-21 18:49:36 +01:00
Misthios 08fc14eab5 initial commit 2026-02-21 15:57:20 +01:00