cook: ship the fscrypt stack by default in Phyllome OS
- ingredients/repo/phyllome.ks: add the git.phyllo.me roots registry as a downstream repo (install-time only; the phyllome-fscrypt package owns /etc/yum.repos.d/phyllome.repo on the installed system) - ingredients/packages/fscrypt.ks: install phyllome-fscrypt, which pulls fscrypt + pam_fscrypt via Requires - recipe_templates: new 'fscrypt' feature mapping the two fragments - recipes_manifest: enable fscrypt for phyllomeos and phyllomeos-headless (default tier, repository 44) make lint/validate/test pass; both default dishes regenerate with the phyllome repo and phyllome-fscrypt included.
This commit is contained in:
@@ -0,0 +1,16 @@
|
|||||||
|
# __ ____ ____ _____
|
||||||
|
# ____ / /_ __ __/ / /___ ____ ___ ___ / __ \/ ___/
|
||||||
|
# / __ \/ __ \/ / / / / / __ \/ __ `__ \/ _ \ / / / /\__ \
|
||||||
|
# / /_/ / / / / /_/ / / / /_/ / / / / / / __/ / /_/ /___/ /
|
||||||
|
# / .___/_/ /_/\__, /_/_/\____/_/ /_/ /_/\___/ \____//____/
|
||||||
|
# /_/ /____/
|
||||||
|
|
||||||
|
# fscrypt stack: CLI, PAM module and the Phyllome OS configuration package.
|
||||||
|
# phyllome-fscrypt depends on fscrypt + pam_fscrypt + authselect, so installing
|
||||||
|
# it alone pulls the whole stack.
|
||||||
|
|
||||||
|
%packages --exclude-weakdeps
|
||||||
|
|
||||||
|
phyllome-fscrypt # SELinux, PAM, repo + first-boot activation for fscrypt
|
||||||
|
|
||||||
|
%end # End of the packages section
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# __ ____ ____ _____
|
||||||
|
# ____ / /_ __ __/ / /___ ____ ___ ___ / __ \/ ___/
|
||||||
|
# / __ \/ __ \/ / / / / / __ \/ __ `__ \/ _ \ / / / /\__ \
|
||||||
|
# / /_/ / / / / /_/ / / / /_/ / / / / / / __/ / /_/ /___/ /
|
||||||
|
# / .___/_/ /_/\__, /_/_/\____/_/ /_/ /_/\___/ \____//____/
|
||||||
|
# /_/ /____/
|
||||||
|
|
||||||
|
# Phyllome OS downstream repository: the fscrypt / phyllome-fscrypt RPMs
|
||||||
|
# published to the git.phyllo.me roots registry.
|
||||||
|
#
|
||||||
|
# gpgcheck stays at the anaconda default (enforced by the registry's TLS end-to-
|
||||||
|
# end; Gitea's RPM registry does not sign its repodata, see
|
||||||
|
# fscrypt-fedora/rpm/README.md). Noverifyssl is not set: the registry presents
|
||||||
|
# a valid TLS certificate.
|
||||||
|
|
||||||
|
repo --name=phyllome --baseurl=https://git.phyllo.me/api/packages/roots/rpm # Phyllome OS repository (fscrypt stack)
|
||||||
@@ -74,6 +74,10 @@ features:
|
|||||||
intelgpu: hypervisor/intelgpu.ks
|
intelgpu: hypervisor/intelgpu.ks
|
||||||
hardware-support: packages/hardware-support.ks
|
hardware-support: packages/hardware-support.ks
|
||||||
guest-agents: guest-agents/base.ks
|
guest-agents: guest-agents/base.ks
|
||||||
|
fscrypt:
|
||||||
|
true:
|
||||||
|
- repo/phyllome.ks
|
||||||
|
- packages/fscrypt.ks
|
||||||
live:
|
live:
|
||||||
true:
|
true:
|
||||||
- live/core/base.ks
|
- live/core/base.ks
|
||||||
|
|||||||
@@ -36,6 +36,7 @@ recipes:
|
|||||||
initial-setup: gnome
|
initial-setup: gnome
|
||||||
hardware-support: true
|
hardware-support: true
|
||||||
guest-agents: true
|
guest-agents: true
|
||||||
|
fscrypt: true
|
||||||
hypervisor: desktop
|
hypervisor: desktop
|
||||||
hypervisor_type: any
|
hypervisor_type: any
|
||||||
|
|
||||||
@@ -50,6 +51,7 @@ recipes:
|
|||||||
initial-setup: server
|
initial-setup: server
|
||||||
hardware-support: true
|
hardware-support: true
|
||||||
guest-agents: true
|
guest-agents: true
|
||||||
|
fscrypt: true
|
||||||
hypervisor: base
|
hypervisor: base
|
||||||
hypervisor_type: any
|
hypervisor_type: any
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user