Files
bootc-images/images/fedora-remote/files/grd-firstboot
T
Misthios 6d70a1bfb9
Build containers / fedora-cosmic (rawhide) (push) Failing after 54s
Build containers / fedora-cosmic (44) (push) Successful in 14m8s
Build containers / fedora-remote (44) (push) Failing after 15m36s
Build containers / Prune old releases (push) Failing after 26s
fedora-remote: minimal headless GNOME Remote Desktop host with Kanidm
New image built from upstream base-atomic (no desktop), adding only gnome-shell
+ gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm.
recommends=false to stay lean. Configures GNOME Remote Desktop headless remote
login on first boot (TLS + credentials + enable). Firefox preinstalled as a
per-user Flatpak. Add it to the CI matrix and prune both images.
2026-09-27 22:26:48 +02:00

39 lines
1.3 KiB
Bash
Executable File

#!/usr/bin/env bash
# One-time configuration of GNOME Remote Desktop (system / headless remote
# login). Runs on first boot because grdctl talks to the running daemon.
#
# Optional /etc/gnome-remote-desktop/rdp.env:
# GRD_SYSTEM_USER=rdp
# GRD_SYSTEM_PASSWORD=...
# If unset, remote login is enabled but no greeter credential is configured
# (set one with: printf '%s\n%s\n' USER PASS | grdctl --system rdp set-credentials).
set -euo pipefail
GRD_USER=gnome-remote-desktop
STATE="/var/lib/${GRD_USER}"
TLS_DIR="${STATE}/.local/share/gnome-remote-desktop"
MARKER="${STATE}/.configured"
[[ -f "${MARKER}" ]] && exit 0
install -d -o "${GRD_USER}" -g "${GRD_USER}" "${TLS_DIR}"
if [[ ! -f "${TLS_DIR}/tls.key" ]]; then
sudo -u "${GRD_USER}" openssl req -new -newkey rsa:4096 -days 720 -nodes -x509 \
-subj "/CN=${GRD_CERT_CN:-fedora-remote}" \
-out "${TLS_DIR}/tls.crt" -keyout "${TLS_DIR}/tls.key"
fi
grdctl --system rdp set-tls-key "${TLS_DIR}/tls.key"
grdctl --system rdp set-tls-cert "${TLS_DIR}/tls.crt"
if [[ -n "${GRD_SYSTEM_PASSWORD:-}" ]]; then
printf '%s\n%s\n' "${GRD_SYSTEM_USER:-rdp}" "${GRD_SYSTEM_PASSWORD}" \
| grdctl --system rdp set-credentials
fi
grdctl --system rdp enable
systemctl restart gnome-remote-desktop.service || true
touch "${MARKER}"