Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m46s
Build containers / Prune old releases and tags (push) Successful in 25s
base-atomic ships mesa-dri-drivers (the virtio_gpu Gallium driver) but not mesa-libEGL, and with recommends off nothing pulls it in. mutter/gnome-shell only require libglvnd's EGL dispatcher, which then has no Mesa backend, so the session falls back to llvmpipe software rendering. Add mesa-libEGL explicitly so the host iGPU is used under Proxmox's VirGL/virtio-gpu display.
121 lines
5.1 KiB
YAML
121 lines
5.1 KiB
YAML
# Customizations for the minimal headless remote host.
|
|
|
|
packages:
|
|
# Fedora integration normally provided by the upstream fedora.yaml (which we
|
|
# opt out of to avoid the Firefox RPM).
|
|
- fedora-release
|
|
- fedora-release-ostree-desktop
|
|
- fedora-flathub-remote
|
|
|
|
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
|
|
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
|
|
- gdm
|
|
- gnome-shell
|
|
- gnome-remote-desktop
|
|
- pipewire
|
|
- wireplumber
|
|
- xdg-desktop-portal-gnome
|
|
|
|
# Terminal (foot has no Flathub build) and Flatpak.
|
|
- foot
|
|
- flatpak
|
|
|
|
# Proxmox guest integration.
|
|
- qemu-guest-agent
|
|
|
|
# Proxmox virtio-gpu display (VirGL): render on the host iGPU instead of
|
|
# software (llvmpipe). mesa-dri-drivers ships the virtio_gpu Gallium driver
|
|
# and comes from base-atomic; mesa-libEGL is the piece base-atomic lacks - it
|
|
# provides the Mesa EGL vendor, without which libglvnd's EGL dispatcher has no
|
|
# backend and mutter/gnome-shell fall back to software rendering. Listed
|
|
# explicitly (recommends are off) so the GL stack survives upstream changes.
|
|
- mesa-dri-drivers
|
|
- mesa-libEGL
|
|
|
|
# grd-firstboot generates the RDP TLS certificate with the openssl CLI.
|
|
- openssl
|
|
|
|
# GDM/gnome-session session infrastructure. The greeter needs the reference
|
|
# dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the
|
|
# per-user systemd manager; without them the greeter dies and RDP clients just
|
|
# get a white screen (base-atomic does not pull these in with recommends off).
|
|
- dbus-daemon
|
|
- systemd-pam
|
|
|
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
|
- kanidm-unixd-clients
|
|
|
|
# Firefox is shipped as a per-user Flatpak, not an RPM.
|
|
exclude-packages:
|
|
- firefox
|
|
|
|
add-files:
|
|
# System-wide Flatpaks on first boot (Firefox), visible to every user.
|
|
- ["flatpak-system-firstboot", "/usr/libexec/flatpak-system-firstboot"]
|
|
- ["flatpak-system-firstboot.service", "/usr/lib/systemd/system/flatpak-system-firstboot.service"]
|
|
- ["50-flatpak-system-firstboot.preset", "/usr/lib/systemd/system-preset/50-flatpak-system-firstboot.preset"]
|
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
|
# Kanidm client config + authselect profile sources.
|
|
- ["kanidm-config", "/etc/kanidm/config"]
|
|
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
|
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
|
|
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
|
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
|
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
|
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
|
|
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
|
# GNOME Remote Desktop first-boot configuration.
|
|
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
|
|
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
|
|
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
|
|
|
|
postprocess:
|
|
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
if ! (
|
|
set -euo pipefail
|
|
authselect create-profile kanidm -b local
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
|
|
/etc/authselect/custom/kanidm/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
|
|
/etc/authselect/custom/kanidm/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
|
|
/etc/authselect/custom/kanidm/nsswitch.conf
|
|
authselect select custom/kanidm --force --nobackup
|
|
); then
|
|
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
|
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
|
|
fi
|
|
|
|
# uresourced's resource tuning breaks the GDM greeter's systemd user manager
|
|
# here: user@<uid>.service fails with "Failed to spawn executor" (result
|
|
# 'resources'), so the greeter never registers and RDP clients get a white
|
|
# screen. It is optional, so mask it.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
ln -sf /dev/null /etc/systemd/system/uresourced.service
|
|
|
|
# Kanidm SELinux policy (same approach as fedora-cosmic).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
|
|
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
|
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
|
unconfined_service_t; do
|
|
semanage permissive -a "${domain}" || true
|
|
done
|
|
|
|
# Make helper scripts executable.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
chmod 0755 /usr/libexec/flatpak-system-firstboot /usr/libexec/grd-firstboot
|
|
systemctl --user --global preset-all
|