# Customizations for the minimal headless remote host. packages: # Fedora integration normally provided by the upstream fedora.yaml (which we # opt out of to avoid the Firefox RPM). - fedora-release - fedora-release-ostree-desktop - fedora-flathub-remote # GNOME Remote Desktop headless remote login. gdm pulls gnome-session, # gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam. - gdm - gnome-shell - gnome-remote-desktop - pipewire - wireplumber - xdg-desktop-portal-gnome # Terminal (foot has no Flathub build) and Flatpak. - foot - flatpak # Proxmox guest integration. - qemu-guest-agent # grd-firstboot generates the RDP TLS certificate with the openssl CLI. - openssl # GDM/gnome-session session infrastructure. The greeter needs the reference # dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the # per-user systemd manager; without them the greeter dies and RDP clients just # get a white screen (base-atomic does not pull these in with recommends off). - dbus-daemon - systemd-pam # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients # Firefox is shipped as a per-user Flatpak, not an RPM. exclude-packages: - firefox add-files: # Per-user Flatpaks on first login (Firefox). - ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"] - ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"] - ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"] - ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"] # Kanidm client config + authselect profile sources. - ["kanidm-config", "/etc/kanidm/config"] - ["kanidm-unixd", "/etc/kanidm/unixd"] - ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"] - ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"] - ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"] - ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"] - ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"] - ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"] # GNOME Remote Desktop first-boot configuration. - ["grd-firstboot", "/usr/libexec/grd-firstboot"] - ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"] - ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"] postprocess: # Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback). - | #!/usr/bin/env bash set -xeuo pipefail if ! ( set -euo pipefail authselect create-profile kanidm -b local install -m 0644 /usr/share/fedora-remote/authselect/system-auth \ /etc/authselect/custom/kanidm/system-auth install -m 0644 /usr/share/fedora-remote/authselect/password-auth \ /etc/authselect/custom/kanidm/password-auth install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \ /etc/authselect/custom/kanidm/nsswitch.conf authselect select custom/kanidm --force --nobackup ); then echo "authselect setup failed, installing PAM/nsswitch directly" >&2 rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf fi # uresourced's resource tuning breaks the GDM greeter's systemd user manager # here: user@.service fails with "Failed to spawn executor" (result # 'resources'), so the greeter never registers and RDP clients get a white # screen. It is optional, so mask it. - | #!/usr/bin/env bash set -xeuo pipefail ln -sf /dev/null /etc/systemd/system/uresourced.service # Kanidm SELinux policy (same approach as fedora-cosmic). - | #!/usr/bin/env bash set -xeuo pipefail semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \ systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \ unconfined_service_t; do semanage permissive -a "${domain}" || true done # Make helper scripts executable. - | #!/usr/bin/env bash set -xeuo pipefail chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot systemctl --user --global preset-all