Files
bootc-images/images/fedora-remote/custom.yaml
T
Misthios 2e5a4fd707
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m9s
Build containers / Prune old releases and tags (push) Successful in 27s
fedora-remote: add openssl for grd-firstboot TLS, enable sshd
grd-firstboot aborts before enabling RDP because it shells out to openssl to
generate the TLS certificate, and the minimal image did not include the openssl
CLI. Add it. Also enable sshd so the headless host is reachable without RDP.
2026-09-30 17:26:58 +02:00

96 lines
3.8 KiB
YAML

# Customizations for the minimal headless remote host.
packages:
# Fedora integration normally provided by the upstream fedora.yaml (which we
# opt out of to avoid the Firefox RPM).
- fedora-release
- fedora-release-ostree-desktop
- fedora-flathub-remote
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
- gdm
- gnome-shell
- gnome-remote-desktop
- pipewire
- wireplumber
- xdg-desktop-portal-gnome
# Terminal (foot has no Flathub build) and Flatpak.
- foot
- flatpak
# Proxmox guest integration.
- qemu-guest-agent
# grd-firstboot generates the RDP TLS certificate with the openssl CLI.
- openssl
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
- kanidm-unixd-clients
# Firefox is shipped as a per-user Flatpak, not an RPM.
exclude-packages:
- firefox
add-files:
# Per-user Flatpaks on first login (Firefox).
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
# Kanidm client config + authselect profile sources.
- ["kanidm-config", "/etc/kanidm/config"]
- ["kanidm-unixd", "/etc/kanidm/unixd"]
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
# GNOME Remote Desktop first-boot configuration.
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
postprocess:
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
- |
#!/usr/bin/env bash
set -xeuo pipefail
if ! (
set -euo pipefail
authselect create-profile kanidm -b local
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
/etc/authselect/custom/kanidm/system-auth
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
/etc/authselect/custom/kanidm/password-auth
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
/etc/authselect/custom/kanidm/nsswitch.conf
authselect select custom/kanidm --force --nobackup
); then
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
fi
# Kanidm SELinux policy (same approach as fedora-cosmic).
- |
#!/usr/bin/env bash
set -xeuo pipefail
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
unconfined_service_t; do
semanage permissive -a "${domain}" || true
done
# Make helper scripts executable.
- |
#!/usr/bin/env bash
set -xeuo pipefail
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
systemctl --user --global preset-all