build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
35 lines
1.2 KiB
YAML
35 lines
1.2 KiB
YAML
# Custom Fedora COSMIC Atomic image.
|
|
#
|
|
# This is a thin downstream layer on top of the upstream Fedora manifests from
|
|
# https://gitlab.com/fedora/ostree/ci-test, which are cloned into this directory
|
|
# at build time by build.sh (see build.conf for the ref mapping).
|
|
#
|
|
# The upstream leaf manifest is `cosmic-atomic.yaml`, which pulls in
|
|
# `cosmic-atomic-common.yaml` -> `common.yaml` + `packages/cosmic-atomic.yaml`.
|
|
|
|
metadata:
|
|
summary: Fedora COSMIC Atomic (custom)
|
|
|
|
variables:
|
|
# Opt out of the upstream `fedora.yaml` include so that we can ship our own
|
|
# Fedora integration package set without Firefox. This is the documented
|
|
# downstream hook (see the comment at the top of upstream's fedora.yaml).
|
|
distro: "fedora-cosmic"
|
|
|
|
ref: fedora-cosmic/${releasever_ref}/${basearch}/cosmic
|
|
|
|
repos:
|
|
# Local repo generated by build.sh from the token2-fido-bridge GitHub release.
|
|
- token2-fido-bridge
|
|
# Kanidm packages (OBS network:idm); distro-specific repo file selected by
|
|
# build.sh from repos/<distro>/.
|
|
- network_idm
|
|
|
|
include:
|
|
- cosmic-atomic.yaml
|
|
- custom.yaml
|
|
# Generated by build.sh from upstream-exclude.txt (exclude-packages list).
|
|
- hardware-exclude.yaml
|
|
# Generated by build.sh; adds the Kanidm unixd token when provided.
|
|
- kanidm-token.yaml
|