WIP: cook: ship the fscrypt stack by default in Phyllome OS #10

Draft
lukas wants to merge 1 commits from feat/fscrypt-default into main
4 changed files with 38 additions and 0 deletions
Showing only changes of commit 71d236aa15 - Show all commits
+16
View File
@@ -0,0 +1,16 @@
# __ ____ ____ _____
# ____ / /_ __ __/ / /___ ____ ___ ___ / __ \/ ___/
# / __ \/ __ \/ / / / / / __ \/ __ `__ \/ _ \ / / / /\__ \
# / /_/ / / / / /_/ / / / /_/ / / / / / / __/ / /_/ /___/ /
# / .___/_/ /_/\__, /_/_/\____/_/ /_/ /_/\___/ \____//____/
# /_/ /____/
# fscrypt stack: CLI, PAM module and the Phyllome OS configuration package.
# phyllome-fscrypt depends on fscrypt + pam_fscrypt + authselect, so installing
# it alone pulls the whole stack.
%packages --exclude-weakdeps
phyllome-fscrypt # SELinux, PAM, repo + first-boot activation for fscrypt
%end # End of the packages section
+16
View File
@@ -0,0 +1,16 @@
# __ ____ ____ _____
# ____ / /_ __ __/ / /___ ____ ___ ___ / __ \/ ___/
# / __ \/ __ \/ / / / / / __ \/ __ `__ \/ _ \ / / / /\__ \
# / /_/ / / / / /_/ / / / /_/ / / / / / / __/ / /_/ /___/ /
# / .___/_/ /_/\__, /_/_/\____/_/ /_/ /_/\___/ \____//____/
# /_/ /____/
# Phyllome OS downstream repository: the fscrypt / phyllome-fscrypt RPMs
# published to the git.phyllo.me roots registry.
#
# gpgcheck stays at the anaconda default (enforced by the registry's TLS end-to-
# end; Gitea's RPM registry does not sign its repodata, see
# fscrypt-fedora/rpm/README.md). Noverifyssl is not set: the registry presents
# a valid TLS certificate.
repo --name=phyllome --baseurl=https://git.phyllo.me/api/packages/roots/rpm # Phyllome OS repository (fscrypt stack)
+4
View File
@@ -74,6 +74,10 @@ features:
intelgpu: hypervisor/intelgpu.ks
hardware-support: packages/hardware-support.ks
guest-agents: guest-agents/base.ks
fscrypt:
true:
- repo/phyllome.ks
- packages/fscrypt.ks
live:
true:
- live/core/base.ks
+2
View File
@@ -36,6 +36,7 @@ recipes:
initial-setup: gnome
hardware-support: true
guest-agents: true
fscrypt: true
hypervisor: desktop
hypervisor_type: any
@@ -50,6 +51,7 @@ recipes:
initial-setup: server
hardware-support: true
guest-agents: true
fscrypt: true
hypervisor: base
hypervisor_type: any