Files
bootc-images/images/fedora-remote/custom.yaml
T
Misthios 5bea16bc01
Build containers / fedora-remote (44) (push) Failing after 36s
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 12m34s
Build containers / Prune old releases (push) Failing after 28s
refactor: share common files between images; trim fedora-remote for a VM
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
  and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
  no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
2026-09-27 22:44:10 +02:00

93 lines
3.7 KiB
YAML

# Customizations for the minimal headless remote host.
packages:
# Fedora integration normally provided by the upstream fedora.yaml (which we
# opt out of to avoid the Firefox RPM).
- fedora-release
- fedora-release-ostree-desktop
- fedora-flathub-remote
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
- gdm
- gnome-shell
- gnome-remote-desktop
- pipewire
- wireplumber
- xdg-desktop-portal-gnome
# Terminal (foot has no Flathub build) and Flatpak.
- foot
- flatpak
# Proxmox guest integration.
- qemu-guest-agent
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
- kanidm-unixd-clients
# Firefox is shipped as a per-user Flatpak, not an RPM.
exclude-packages:
- firefox
add-files:
# Per-user Flatpaks on first login (Firefox).
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
# Kanidm client config + authselect profile sources.
- ["kanidm-config", "/etc/kanidm/config"]
- ["kanidm-unixd", "/etc/kanidm/unixd"]
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
# GNOME Remote Desktop first-boot configuration.
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
postprocess:
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
- |
#!/usr/bin/env bash
set -xeuo pipefail
if ! (
set -euo pipefail
authselect create-profile kanidm -b local
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
/etc/authselect/custom/kanidm/system-auth
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
/etc/authselect/custom/kanidm/password-auth
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
/etc/authselect/custom/kanidm/nsswitch.conf
authselect select custom/kanidm --force --nobackup
); then
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
fi
# Kanidm SELinux policy (same approach as fedora-cosmic).
- |
#!/usr/bin/env bash
set -xeuo pipefail
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
unconfined_service_t; do
semanage permissive -a "${domain}" || true
done
# Make helper scripts executable.
- |
#!/usr/bin/env bash
set -xeuo pipefail
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
systemctl --user --global preset-all