First tiny working commit
This commit is contained in:
commit
9e1a7021e1
11 changed files with 165 additions and 0 deletions
9
Containerfile
Normal file
9
Containerfile
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
FROM quay.io/fedora/fedora-coreos:stable
|
||||
|
||||
COPY post-install.sh /tmp/post-install.sh
|
||||
COPY post-install/ /tmp/post-install/
|
||||
RUN chmod +x /tmp/post-install.sh \
|
||||
&& /tmp/post-install.sh \
|
||||
&& rm -rf /tmp/post-install.sh /tmp/post-install
|
||||
|
||||
RUN bootc container lint
|
||||
19
Justfile
Normal file
19
Justfile
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
image := "rosenvold-core"
|
||||
tag := "latest"
|
||||
fcos_stable := "quay.io/fedora/fedora-coreos:stable"
|
||||
|
||||
# List available recipes
|
||||
default:
|
||||
@just --list
|
||||
|
||||
# Build the bootc container image
|
||||
build:
|
||||
docker build -t {{image}}:{{tag}} -f Containerfile .
|
||||
|
||||
# Build and validate the image with bootc container lint
|
||||
test: build
|
||||
docker run --rm {{image}}:{{tag}} bootc container lint
|
||||
|
||||
# Remove the built image
|
||||
clean:
|
||||
docker rmi -f {{image}}:{{tag}}
|
||||
52
examples/rosenvold-core-autorebase.butane
Normal file
52
examples/rosenvold-core-autorebase.butane
Normal file
|
|
@ -0,0 +1,52 @@
|
|||
variant: fcos
|
||||
version: 1.4.0
|
||||
passwd:
|
||||
users:
|
||||
- name: core
|
||||
ssh_authorized_keys:
|
||||
- YOUR_SSH_PUB_KEY_HERE
|
||||
password_hash: YOUR_GOOD_PASSWORD_HASH_HERE
|
||||
groups:
|
||||
- docker
|
||||
storage:
|
||||
directories:
|
||||
- path: /etc/rosenvold-core-autorebase
|
||||
mode: 0754
|
||||
systemd:
|
||||
units:
|
||||
- name: rosenvold-core-unsigned-autorebase.service
|
||||
enabled: true
|
||||
contents: |
|
||||
[Unit]
|
||||
Description=rosenvold-core autorebase to unsigned OCI and reboot
|
||||
ConditionPathExists=!/etc/rosenvold-core-autorebase/unverified
|
||||
ConditionPathExists=!/etc/rosenvold-core-autorebase/signed
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
[Service]
|
||||
Type=oneshot
|
||||
StandardOutput=journal+console
|
||||
ExecStart=/usr/bin/rpm-ostree rebase --bypass-driver ostree-unverified-registry:ghcr.io/rosenvold-technology/rosenvold-core:stable
|
||||
ExecStart=/usr/bin/touch /etc/rosenvold-core-autorebase/unverified
|
||||
ExecStart=/usr/bin/systemctl disable rosenvold-core-unsigned-autorebase.service
|
||||
ExecStart=/usr/bin/systemctl reboot
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
- name: rosenvold-core-signed-autorebase.service
|
||||
enabled: true
|
||||
contents: |
|
||||
[Unit]
|
||||
Description=rosenvold-core autorebase to signed OCI and reboot
|
||||
ConditionPathExists=/etc/rosenvold-core-autorebase/unverified
|
||||
ConditionPathExists=!/etc/rosenvold-core-autorebase/signed
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
[Service]
|
||||
Type=oneshot
|
||||
StandardOutput=journal+console
|
||||
ExecStart=/usr/bin/rpm-ostree rebase --bypass-driver ostree-image-signed:docker://ghcr.io/rosenvold-technology/rosenvold-core:stable
|
||||
ExecStart=/usr/bin/touch /etc/rosenvold-core-autorebase/signed
|
||||
ExecStart=/usr/bin/systemctl disable rosenvold-core-signed-autorebase.service
|
||||
ExecStart=/usr/bin/systemctl reboot
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
35
post-install.sh
Executable file
35
post-install.sh
Executable file
|
|
@ -0,0 +1,35 @@
|
|||
#!/bin/sh
|
||||
set -ouex pipefail
|
||||
|
||||
## Regular post-install (adapted from ublue-os/ucore's post-install-ucore-minimal.sh
|
||||
## for a plain Fedora CoreOS base with no extra packages installed)
|
||||
##
|
||||
## Implementation: each step lives in its own function/file under
|
||||
## post-install/lib/<step>.sh; this script only sources them and runs the
|
||||
## steps in order.
|
||||
|
||||
SCRIPT_DIR="$(dirname -- "$0")"
|
||||
LIB_DIR="$SCRIPT_DIR/post-install/lib"
|
||||
|
||||
# shellcheck source=post-install/lib/mask_migration_motd_units.sh
|
||||
. "$LIB_DIR/mask_migration_motd_units.sh"
|
||||
# shellcheck source=post-install/lib/enable_docker_socket.sh
|
||||
. "$LIB_DIR/enable_docker_socket.sh"
|
||||
# shellcheck source=post-install/lib/disable_zincati.sh
|
||||
. "$LIB_DIR/disable_zincati.sh"
|
||||
# shellcheck source=post-install/lib/configure_automatic_updates.sh
|
||||
. "$LIB_DIR/configure_automatic_updates.sh"
|
||||
# shellcheck source=post-install/lib/set_default_timezone.sh
|
||||
. "$LIB_DIR/set_default_timezone.sh"
|
||||
# shellcheck source=post-install/lib/set_rosenvold_branding.sh
|
||||
. "$LIB_DIR/set_rosenvold_branding.sh"
|
||||
# shellcheck source=post-install/lib/install_welcome_motd.sh
|
||||
. "$LIB_DIR/install_welcome_motd.sh"
|
||||
|
||||
mask_migration_motd_units
|
||||
enable_docker_socket
|
||||
disable_zincati
|
||||
configure_automatic_updates
|
||||
set_default_timezone
|
||||
set_rosenvold_branding
|
||||
install_welcome_motd
|
||||
5
post-install/lib/configure_automatic_updates.sh
Normal file
5
post-install/lib/configure_automatic_updates.sh
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
# Stage rpm-ostree updates automatically instead of only checking for them.
|
||||
configure_automatic_updates() {
|
||||
systemctl enable rpm-ostreed-automatic.timer
|
||||
sed -i 's/#AutomaticUpdatePolicy.*/AutomaticUpdatePolicy=stage/' /etc/rpm-ostreed.conf
|
||||
}
|
||||
4
post-install/lib/disable_zincati.sh
Normal file
4
post-install/lib/disable_zincati.sh
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
# Disable zincati; bootc image updates replace FCOS's default auto-updater.
|
||||
disable_zincati() {
|
||||
systemctl disable zincati.service
|
||||
}
|
||||
4
post-install/lib/enable_docker_socket.sh
Normal file
4
post-install/lib/enable_docker_socket.sh
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
# Enable Docker's socket-activated daemon.
|
||||
enable_docker_socket() {
|
||||
systemctl enable docker.socket
|
||||
}
|
||||
16
post-install/lib/install_welcome_motd.sh
Normal file
16
post-install/lib/install_welcome_motd.sh
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
# Drop the upstream FCOS tracker/discuss motd (no longer accurate once
|
||||
# rebranded) and replace it with our own welcome banner.
|
||||
install_welcome_motd() {
|
||||
rm -f /usr/lib/motd.d/tracker.motd
|
||||
cat >/usr/lib/motd.d/10-rosenvold-welcome.motd <<'EOF'
|
||||
[1;36mRosenvold CoreOS[0m
|
||||
[2m────────────────[0m
|
||||
|
||||
A personal Fedora CoreOS derivative, managed via bootc.
|
||||
|
||||
[1mbootc status[0m show the current deployment
|
||||
[1mbootc upgrade[0m check for and stage updates
|
||||
[1mjournalctl -xe[0m view recent logs
|
||||
|
||||
EOF
|
||||
}
|
||||
6
post-install/lib/mask_migration_motd_units.sh
Normal file
6
post-install/lib/mask_migration_motd_units.sh
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# Mask the FCOS -> ostree-container migration motd units up front so a
|
||||
# future FCOS release doesn't surprise us with them mid-boot.
|
||||
mask_migration_motd_units() {
|
||||
systemctl mask coreos-container-signing-migration-motd.service
|
||||
systemctl mask coreos-oci-migration-motd.service
|
||||
}
|
||||
4
post-install/lib/set_default_timezone.sh
Normal file
4
post-install/lib/set_default_timezone.sh
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
# FCOS container images ship without /etc/localtime; default to UTC.
|
||||
set_default_timezone() {
|
||||
ln -sf ../usr/share/zoneinfo/UTC /etc/localtime
|
||||
}
|
||||
11
post-install/lib/set_rosenvold_branding.sh
Normal file
11
post-install/lib/set_rosenvold_branding.sh
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
# Branding: rosenvold-core is a personal Fedora CoreOS derivative, so
|
||||
# identify as such rather than as upstream Fedora CoreOS. ID/VARIANT_ID are
|
||||
# left alone so tooling that keys off "fedora" family detection still works.
|
||||
set_rosenvold_branding() {
|
||||
sed -i \
|
||||
-e 's/^NAME=.*/NAME="Rosenvold CoreOS"/' \
|
||||
-e 's/Fedora CoreOS/Rosenvold CoreOS/' \
|
||||
-e 's/^VARIANT=.*/VARIANT="Rosenvold CoreOS"/' \
|
||||
-e 's/^VARIANT_ID=.*/VARIANT_ID=rosenvold-core/' \
|
||||
/usr/lib/os-release
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue