Commit Graph
3 Commits
Author SHA1 Message Date
Misthios dd2bf634f1 fedora-cosmic: add Kanidm Unix authentication
Build containers / fedora-cosmic (rawhide) (push) Failing after 45s
Build containers / fedora-cosmic (44) (push) Failing after 54s
Install kanidm-unixd-clients/kanidm-clients, point /etc/kanidm/config at
auth.plabble.org, configure unixd (TPM-backed cache, pam_allowed_login_groups),
and set up PAM/nsswitch via an authselect custom profile (with a direct-file
fallback). Enable kanidm-unixd{,-tasks} and make unconfined_service_t
permissive until Kanidm ships an SELinux policy.
2026-09-21 17:57:32 +02:00
Misthios ddd095f201 fedora-cosmic: drop pcsc-tools (pulls perl, excluded upstream)
Build containers / fedora-cosmic (44) (push) Failing after 24m25s
Build containers / fedora-cosmic (rawhide) (push) Failing after 24m25s
2026-09-21 16:01:59 +02:00
Misthios bc542f14b2 refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
2026-09-21 15:11:26 +02:00