build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
105 lines
4.3 KiB
YAML
105 lines
4.3 KiB
YAML
# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests.
|
|
|
|
packages:
|
|
# Fedora integration packages normally provided by the upstream fedora.yaml,
|
|
# re-added here without Firefox (which is shipped as a Flatpak instead).
|
|
- fedora-bookmarks
|
|
- fedora-chromium-config
|
|
- fedora-flathub-remote
|
|
- fedora-workstation-backgrounds
|
|
- fedora-workstation-repositories
|
|
- fedora-release-cosmic-atomic
|
|
- toolbox
|
|
|
|
# Smartcard / FIDO2 support for token2-fido-bridge.
|
|
# token2-fido-bridge itself is installed from a local repo that build.sh
|
|
# generates from the upstream GitHub release (it is not packaged in Fedora).
|
|
- pcsc-lite
|
|
- pcsc-lite-ccid
|
|
- opensc
|
|
- libfido2
|
|
- fido2-tools
|
|
- p11-kit
|
|
- pam-u2f
|
|
- token2-fido-bridge
|
|
|
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
|
- kanidm-unixd-clients
|
|
- kanidm-clients
|
|
|
|
# Firefox is intentionally not part of the base system. It is preinstalled as a
|
|
# per-user Flatpak on first login instead (see flatpaks.list).
|
|
exclude-packages:
|
|
- firefox
|
|
|
|
add-files:
|
|
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
|
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
|
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
|
- ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"]
|
|
- ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"]
|
|
# Kanidm client config and authselect profile sources.
|
|
- ["kanidm-config", "/etc/kanidm/config"]
|
|
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
|
- ["kanidm-system-auth", "/usr/share/fedora-cosmic/authselect/system-auth"]
|
|
- ["kanidm-password-auth", "/usr/share/fedora-cosmic/authselect/password-auth"]
|
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
|
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
|
|
|
postprocess:
|
|
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
|
# Third Party repo list. We opt out of that manifest, so replicate it here.
|
|
# Workaround for https://github.com/coreos/rpm-ostree/issues/5494
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true
|
|
|
|
# Ensure the first-login script is executable and make sure the
|
|
# globally-enabled per-user Flatpak unit is picked up.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
chmod 0755 /usr/libexec/flatpak-user-firstboot
|
|
systemctl --user --global preset-all
|
|
|
|
# Kanidm PAM/nsswitch integration. Prefer an authselect profile; fall back to
|
|
# installing the files directly (and dropping the authselect symlinks) if
|
|
# authselect is unavailable in the compose environment.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
if ! (
|
|
set -euo pipefail
|
|
authselect create-profile kanidm -b local
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/system-auth \
|
|
/etc/authselect/custom/kanidm/system-auth
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/password-auth \
|
|
/etc/authselect/custom/kanidm/password-auth
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf \
|
|
/etc/authselect/custom/kanidm/nsswitch.conf
|
|
authselect select custom/kanidm --force --nobackup
|
|
); then
|
|
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
|
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/system-auth /etc/pam.d/system-auth
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/password-auth /etc/pam.d/password-auth
|
|
install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf /etc/nsswitch.conf
|
|
fi
|
|
|
|
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
semanage permissive -a unconfined_service_t || true
|
|
|
|
# Lock down the Kanidm service account token if it was seeded at build time.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
if [[ -f /etc/kanidm/unixd_token ]]; then
|
|
chown root:root /etc/kanidm/unixd_token
|
|
chmod 0600 /etc/kanidm/unixd_token
|
|
fi
|