Build containers / Compute changes (push) Successful in 2s
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-remote (44) (push) Successful in 10m30s
Build containers / fedora-cosmic (44) (push) Successful in 14m21s
Build containers / Prune old releases and tags (push) Successful in 26s
The minimal base (recommends off) was missing session infrastructure and one maintained service actively broke the greeter, so RDP clients saw only a white screen: - add dbus-daemon: gdm-wayland-session runs it for the greeter session bus - add systemd-pam: pam_systemd starts the per-user systemd manager - nsswitch: shadow must include systemd so pam_unix can resolve GDM 50's dynamic gdm-greeter user (Fedora 44 ships 'files systemd') - mask uresourced: its resource tuning makes user@<uid>.service fail with 'Failed to spawn executor', leaving no systemd user bus for gnome-session
112 lines
4.5 KiB
YAML
112 lines
4.5 KiB
YAML
# Customizations for the minimal headless remote host.
|
|
|
|
packages:
|
|
# Fedora integration normally provided by the upstream fedora.yaml (which we
|
|
# opt out of to avoid the Firefox RPM).
|
|
- fedora-release
|
|
- fedora-release-ostree-desktop
|
|
- fedora-flathub-remote
|
|
|
|
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
|
|
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
|
|
- gdm
|
|
- gnome-shell
|
|
- gnome-remote-desktop
|
|
- pipewire
|
|
- wireplumber
|
|
- xdg-desktop-portal-gnome
|
|
|
|
# Terminal (foot has no Flathub build) and Flatpak.
|
|
- foot
|
|
- flatpak
|
|
|
|
# Proxmox guest integration.
|
|
- qemu-guest-agent
|
|
|
|
# grd-firstboot generates the RDP TLS certificate with the openssl CLI.
|
|
- openssl
|
|
|
|
# GDM/gnome-session session infrastructure. The greeter needs the reference
|
|
# dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the
|
|
# per-user systemd manager; without them the greeter dies and RDP clients just
|
|
# get a white screen (base-atomic does not pull these in with recommends off).
|
|
- dbus-daemon
|
|
- systemd-pam
|
|
|
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
|
- kanidm-unixd-clients
|
|
|
|
# Firefox is shipped as a per-user Flatpak, not an RPM.
|
|
exclude-packages:
|
|
- firefox
|
|
|
|
add-files:
|
|
# Per-user Flatpaks on first login (Firefox).
|
|
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
|
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
|
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
|
# Kanidm client config + authselect profile sources.
|
|
- ["kanidm-config", "/etc/kanidm/config"]
|
|
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
|
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
|
|
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
|
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
|
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
|
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
|
|
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
|
# GNOME Remote Desktop first-boot configuration.
|
|
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
|
|
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
|
|
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
|
|
|
|
postprocess:
|
|
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
if ! (
|
|
set -euo pipefail
|
|
authselect create-profile kanidm -b local
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
|
|
/etc/authselect/custom/kanidm/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
|
|
/etc/authselect/custom/kanidm/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
|
|
/etc/authselect/custom/kanidm/nsswitch.conf
|
|
authselect select custom/kanidm --force --nobackup
|
|
); then
|
|
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
|
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
|
|
fi
|
|
|
|
# uresourced's resource tuning breaks the GDM greeter's systemd user manager
|
|
# here: user@<uid>.service fails with "Failed to spawn executor" (result
|
|
# 'resources'), so the greeter never registers and RDP clients get a white
|
|
# screen. It is optional, so mask it.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
ln -sf /dev/null /etc/systemd/system/uresourced.service
|
|
|
|
# Kanidm SELinux policy (same approach as fedora-cosmic).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
|
|
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
|
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
|
unconfined_service_t; do
|
|
semanage permissive -a "${domain}" || true
|
|
done
|
|
|
|
# Make helper scripts executable.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
|
|
systemctl --user --global preset-all
|