Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (44) (push) Skipped
Build containers / fedora-cosmic (rawhide) (push) Skipped
Build containers / fedora-remote (44) (push) Successful in 9m9s
Build containers / Prune old releases and tags (push) Successful in 27s
grd-firstboot aborts before enabling RDP because it shells out to openssl to generate the TLS certificate, and the minimal image did not include the openssl CLI. Add it. Also enable sshd so the headless host is reachable without RDP.
96 lines
3.8 KiB
YAML
96 lines
3.8 KiB
YAML
# Customizations for the minimal headless remote host.
|
|
|
|
packages:
|
|
# Fedora integration normally provided by the upstream fedora.yaml (which we
|
|
# opt out of to avoid the Firefox RPM).
|
|
- fedora-release
|
|
- fedora-release-ostree-desktop
|
|
- fedora-flathub-remote
|
|
|
|
# GNOME Remote Desktop headless remote login. gdm pulls gnome-session,
|
|
# gnome-settings-daemon, accountsservice, dconf and gnome-keyring-pam.
|
|
- gdm
|
|
- gnome-shell
|
|
- gnome-remote-desktop
|
|
- pipewire
|
|
- wireplumber
|
|
- xdg-desktop-portal-gnome
|
|
|
|
# Terminal (foot has no Flathub build) and Flatpak.
|
|
- foot
|
|
- flatpak
|
|
|
|
# Proxmox guest integration.
|
|
- qemu-guest-agent
|
|
|
|
# grd-firstboot generates the RDP TLS certificate with the openssl CLI.
|
|
- openssl
|
|
|
|
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
|
|
- kanidm-unixd-clients
|
|
|
|
# Firefox is shipped as a per-user Flatpak, not an RPM.
|
|
exclude-packages:
|
|
- firefox
|
|
|
|
add-files:
|
|
# Per-user Flatpaks on first login (Firefox).
|
|
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
|
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
|
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
|
# Kanidm client config + authselect profile sources.
|
|
- ["kanidm-config", "/etc/kanidm/config"]
|
|
- ["kanidm-unixd", "/etc/kanidm/unixd"]
|
|
- ["kanidm-system-auth", "/usr/share/fedora-remote/authselect/system-auth"]
|
|
- ["kanidm-password-auth", "/usr/share/fedora-remote/authselect/password-auth"]
|
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-remote/authselect/nsswitch.conf"]
|
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
|
- ["kanidm-unixd.cil", "/usr/share/fedora-remote/kanidm-unixd.cil"]
|
|
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
|
# GNOME Remote Desktop first-boot configuration.
|
|
- ["grd-firstboot", "/usr/libexec/grd-firstboot"]
|
|
- ["grd-firstboot.service", "/usr/lib/systemd/system/grd-firstboot.service"]
|
|
- ["50-grd.preset", "/usr/lib/systemd/system-preset/50-grd.preset"]
|
|
|
|
postprocess:
|
|
# Kanidm PAM/nsswitch via an authselect custom profile (direct-file fallback).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
if ! (
|
|
set -euo pipefail
|
|
authselect create-profile kanidm -b local
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth \
|
|
/etc/authselect/custom/kanidm/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth \
|
|
/etc/authselect/custom/kanidm/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf \
|
|
/etc/authselect/custom/kanidm/nsswitch.conf
|
|
authselect select custom/kanidm --force --nobackup
|
|
); then
|
|
echo "authselect setup failed, installing PAM/nsswitch directly" >&2
|
|
rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf
|
|
install -m 0644 /usr/share/fedora-remote/authselect/system-auth /etc/pam.d/system-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/password-auth /etc/pam.d/password-auth
|
|
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
|
|
fi
|
|
|
|
# Kanidm SELinux policy (same approach as fedora-cosmic).
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
semodule -n -i /usr/share/fedora-remote/kanidm-unixd.cil || true
|
|
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
|
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
|
unconfined_service_t; do
|
|
semanage permissive -a "${domain}" || true
|
|
done
|
|
|
|
# Make helper scripts executable.
|
|
- |
|
|
#!/usr/bin/env bash
|
|
set -xeuo pipefail
|
|
chmod 0755 /usr/libexec/flatpak-user-firstboot /usr/libexec/grd-firstboot
|
|
systemctl --user --global preset-all
|