2026-02-17 17:27:26 +01:00
###############################################################################
# PROJECT NAME CONFIGURATION
###############################################################################
2026-05-10 19:16:03 +02:00
# Name: fluffy-pancake
2026-02-17 17:27:26 +01:00
#
# IMPORTANT: Change "finpilot" above to your desired project name.
# This name should be used consistently throughout the repository in:
# - Justfile: export image_name := env("IMAGE_NAME", "your-name-here")
# - README.md: # your-name-here (title)
# - artifacthub-repo.yml: repositoryID: your-name-here
# - custom/ujust/README.md: localhost/your-name-here:stable (in bootc switch example)
#
# The project name defined here is the single source of truth for your
# custom image's identity. When changing it, update all references above
# to maintain consistency.
###############################################################################
###############################################################################
2026-08-08 07:42:29 +00:00
# MULTI-STAGE BUILD ARCHITECTURE (Cache-Isolierung)
2026-02-17 17:27:26 +01:00
###############################################################################
2026-08-08 07:42:29 +00:00
# Isolierte Kontext-Stage NUR für die Build-Skripte.
# Änderungen an /configs oder /scripts hebeln dadurch die DNF-Layer (1-5) NICHT mehr aus!
FROM scratch AS build-ctx
2026-02-17 17:27:26 +01:00
COPY build /build
2026-05-01 13:35:20 +02:00
###############################################################################
# BASE IMAGE
###############################################################################
2026-09-27 12:28:46 +02:00
# labwc/Noctalia-Zweig: minimale fedora-bootc-Basis statt Kinoite.
# Der komplette Desktop (labwc, greetd, Noctalia) wird in den Layern unten
# aufgebaut. Der Kinoite-Stand bleibt auf Branch main / Tag :stable erhalten.
FROM quay.io/fedora/fedora-bootc:44
2026-02-17 17:27:26 +01:00
2026-05-01 13:35:20 +02:00
### /opt (Unverändert)
2026-02-17 17:27:26 +01:00
# RUN rm /opt && mkdir /opt
2026-05-01 13:35:20 +02:00
###############################################################################
2026-05-24 13:33:53 +02:00
# EXECUTION STAGE (Aufgeteilt in Cache-Layer)
2026-05-01 13:35:20 +02:00
###############################################################################
2026-05-24 13:33:53 +02:00
# LAYER 1: Repositories einrichten (Ändert sich fast nie)
2026-08-08 07:42:29 +00:00
RUN --mount= type = bind,from= build-ctx,source= /build/10-repos.sh,target= /tmp/10-repos.sh \
2026-02-17 17:27:26 +01:00
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
2026-05-24 13:33:53 +02:00
bash /tmp/10-repos.sh && dnf5 clean all
2026-09-27 12:28:46 +02:00
# LAYER 2: Unerwünschte Pakete entfernen (Guard - auf bootc-Basis meist No-Op)
2026-08-08 07:42:29 +00:00
RUN --mount= type = bind,from= build-ctx,source= /build/20-remove-packages.sh,target= /tmp/20-remove-packages.sh \
2026-05-24 13:33:53 +02:00
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
2026-08-08 07:16:59 +00:00
bash /tmp/20-remove-packages.sh
2026-05-24 13:33:53 +02:00
2026-09-27 12:28:46 +02:00
# LAYER 2b: labwc Desktop-Basis (Compositor, Portale, Audio, Docking-Tools)
RUN --mount= type = bind,from= build-ctx,source= /build/20-desktop-labwc.sh,target= /tmp/20-desktop-labwc.sh \
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
bash /tmp/20-desktop-labwc.sh
# LAYER 2c: Login-Stack (greetd + tuigreet-Fallback + Noctalia-Greeter)
RUN --mount= type = bind,from= build-ctx,source= /build/21-greetd.sh,target= /tmp/21-greetd.sh \
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
bash /tmp/21-greetd.sh
# LAYER 2d: Noctalia Shell v5 (nativ, aus Fedora-Repos)
RUN --mount= type = bind,from= build-ctx,source= /build/22-noctalia.sh,target= /tmp/22-noctalia.sh \
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
bash /tmp/22-noctalia.sh
2026-05-24 13:33:53 +02:00
# LAYER 3: Virtualisierung & Tools (Großer Download - stark gecacht)
2026-08-08 07:42:29 +00:00
RUN --mount= type = bind,from= build-ctx,source= /build/30-virt.sh,target= /tmp/30-virt.sh \
2026-07-12 15:01:23 +00:00
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
bash /tmp/30-virt.sh
2026-05-24 13:33:53 +02:00
2026-08-08 07:16:59 +00:00
# LAYER 4: Multimedia Stack (Großer Download - stark gecacht)
2026-08-08 07:42:29 +00:00
RUN --mount= type = bind,from= build-ctx,source= /build/40-multimedia.sh,target= /tmp/40-multimedia.sh \
2026-05-24 13:33:53 +02:00
--mount= type = cache,dst= /var/cache \
--mount= type = cache,dst= /var/log \
--mount= type = tmpfs,dst= /tmp \
2026-08-08 07:16:59 +00:00
bash /tmp/40-multimedia.sh
2026-05-24 13:33:53 +02:00
# LAYER 5: Flatpak Vorbereitung (Winzig, ganz unten)
2026-08-08 07:42:29 +00:00
RUN --mount= type = bind,from= build-ctx,source= /build/50-prepare-flatpak-for-bazaar.sh,target= /tmp/50-prepare-flatpak-for-bazaar.sh \
2026-05-24 13:33:53 +02:00
--mount= type = tmpfs,dst= /tmp \
bash /tmp/50-prepare-flatpak-for-bazaar.sh
2026-04-24 20:54:59 +02:00
2026-05-01 13:35:20 +02:00
###############################################################################
# CONFIGURATION LAYER (Der "saubere" Teil)
###############################################################################
2026-03-02 18:45:46 +01:00
2026-09-05 14:56:19 +02:00
# 1. Kopiere die Filesystem-Fixes (tmpfiles.d, Vendor-Default)
COPY configs/bootc-fix.conf /usr/lib/tmpfiles.d/bootc-fix.conf
2026-04-03 18:03:04 +02:00
2026-09-05 17:48:12 +00:00
# 1b. Container-Policy & Registry Auth für bootc
2026-09-05 14:56:19 +02:00
# sigstoreSigned-Pflicht für eigenes Image, Public-Registries explizit erlaubt
2026-09-05 13:26:23 +00:00
COPY configs/containers/policy.json /etc/containers/policy.json
COPY cosign.pub /etc/pki/containers/cosign.pub
2026-09-05 19:12:36 +00:00
COPY configs/auth.json /etc/containers/auth.json
2026-09-05 19:53:19 +00:00
COPY configs/humocs-man.yaml /etc/containers/registries.d/humocs-man.yaml
2026-09-05 17:48:12 +00:00
2026-09-05 13:34:57 +00:00
RUN chmod 0644 /etc/containers/policy.json /etc/pki/containers/cosign.pub && \
2026-09-05 19:12:36 +00:00
chmod 0600 /etc/containers/auth.json && \
2026-09-05 17:48:12 +00:00
python3 -m json.tool /etc/containers/policy.json > /dev/null && \
2026-09-05 19:12:36 +00:00
python3 -m json.tool /etc/containers/auth.json > /dev/null
2026-09-05 14:56:19 +02:00
# 2. Kopiere die Systemd-Overrides als Vendor-Drop-ins (kein /etc/-Override im Image)
COPY configs/bootc-timer-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf
COPY configs/bootc-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.service.d/override.conf
2026-09-27 18:48:10 +02:00
COPY configs/remount-fs-ostree-skip.conf /usr/lib/systemd/system/systemd-remount-fs.service.d/skip-on-ostree.conf
2026-05-01 13:35:20 +02:00
2026-09-27 12:28:46 +02:00
# 3. Kopiere die Session-Helfer und Desktop-Defaults
2026-05-30 15:42:14 +02:00
COPY --chmod= 755 scripts/notify-bootc-user.sh /usr/bin/
2026-09-27 12:28:46 +02:00
COPY --chmod= 755 scripts/kanshi-autoconfig /usr/bin/kanshi-autoconfig
COPY --chmod= 755 scripts/seed-labwc-skel.sh /usr/bin/seed-labwc-skel
# labwc/kanshi-Defaults fuer neue Benutzer (Bestand bleibt via seed-labwc-skel)
COPY configs/skel/ /etc/skel/
# Wayland-Session fuer Display-Manager (Greeter-Auswahl)
COPY configs/wayland-sessions/labwc.desktop /usr/share/wayland-sessions/labwc.desktop
# greetd-Konfiguration (Noctalia-Greeter + tuigreet-Fallback dokumentiert)
COPY configs/greetd/config.toml /etc/greetd/config.toml
# Noctalia-Greeter Standardwerte (de-Tastatur etc., werden per tmpfiles
# beim Erst-Boot nach /var/lib/noctalia-greeter/greeter.toml kopiert)
COPY configs/noctalia-greeter/greeter.toml.default /usr/share/noctalia-greeter/greeter.toml.default
COPY configs/tmpfiles/noctalia-greeter-seed.conf /usr/lib/tmpfiles.d/noctalia-greeter-seed.conf
2026-09-27 13:21:20 +02:00
# Fail-fast + Selbstheilung: Der Session-Wrapper-Pfad wird aus dem real
# installierten Paket aufgeloest und in die greetd-Config uebernommen.
# (Terra paketiert eigenstaendig, z.B. /usr/sbin statt /usr/bin.)
# Fehlt Wrapper, D-Bus, polkit oder Session -> Build-Abbruch statt
# defektem Login-Screen.
2026-09-27 12:28:46 +02:00
RUN set -u; \
2026-09-27 18:48:10 +02:00
id greeter >/dev/null || { echo "FEHLER: Service-User greeter fehlt (21-greetd.sh pruefen)" ; exit 1; } ; \
grep -q 'pam_gnome_keyring\.so' /etc/pam.d/greetd || { echo "FEHLER: Keyring-PAM in /etc/pam.d/greetd fehlt" ; exit 1; } ; \
2026-09-27 12:28:46 +02:00
wrapper = " $( command -v noctalia-greeter-session || true ) " ; \
2026-09-27 13:21:20 +02:00
echo "Gefundener Wrapper: ${ wrapper } " ; \
test -n " ${ wrapper } " || { echo "FEHLER: noctalia-greeter-session nicht installiert (Terra-Repo/includepkgs pruefen)" ; exit 1; } ; \
sed -i "s|^command = \".*\"|command = \" ${ wrapper } \"|" /etc/greetd/config.toml; \
grep -Eq "^command = \" ${ wrapper } \"" /etc/greetd/config.toml || { echo "FEHLER: Wrapper-Pfad konnte nicht in /etc/greetd/config.toml uebernommen werden" ; exit 1; } ; \
command -v dbus-run-session >/dev/null || { echo "FEHLER: dbus-run-session fehlt" ; exit 1; } ; \
test -x /usr/bin/pkexec || { echo "FEHLER: pkexec fehlt" ; exit 1; } ; \
test -f /usr/share/wayland-sessions/labwc.desktop || { echo "FEHLER: labwc-Session fehlt" ; exit 1; } ; \
echo "Greeter-Check OK ( ${ wrapper } )"
2026-05-01 13:35:20 +02:00
2026-05-23 11:41:07 +02:00
# =============================================================================
2026-05-31 18:11:43 +02:00
# SYSTEMD SERVICES (Modern Bootc Architecture)
2026-05-23 11:41:07 +02:00
# =============================================================================
2026-05-23 12:48:21 +02:00
# 4. Kopiere den Systemd-Service für den Erst-Boot von Flatpak
2026-05-23 11:41:07 +02:00
COPY configs/flatpak-preinstall.service /usr/lib/systemd/system/flatpak-preinstall.service
2026-05-23 12:48:21 +02:00
2026-05-31 18:11:43 +02:00
# 5. Aktiviere Services (Presets greifen nicht bei COPY-Dateien)
2026-09-27 12:28:46 +02:00
# HINWEIS: greetd wird bereits in 21-greetd.sh enabled; hier als
# Doku/Netz doppelt abgesichert (idempotent).
2026-05-31 18:11:43 +02:00
RUN systemctl enable \
2026-07-09 13:58:18 +00:00
# libvirtd.service \
# virtlogd.service \
2026-05-31 18:11:43 +02:00
podman.socket \
bootc-fetch-apply-updates.timer \
2026-09-27 12:28:46 +02:00
flatpak-preinstall.service \
greetd.service
# SELinux-Labels fuer Greeter/Skel/Sessions (Fehler tolerieren, Labels
# werden beim Deployment ggf. erneut gesetzt)
RUN restorecon -Rv /etc/greetd /etc/skel /usr/share/wayland-sessions 2>/dev/null || true
2026-05-23 11:41:07 +02:00
2026-08-16 11:33:04 +00:00
###############################################################################
# FINAL CLEANUP
###############################################################################
# autoremove + Cache-/Temp-Bereinigung (einmalig, am Ende aller Installs)
RUN --mount= type = bind,from= build-ctx,source= /build/99-cleanup.sh,target= /tmp/99-cleanup.sh \
--mount= type = tmpfs,dst= /tmp \
bash /tmp/99-cleanup.sh
2026-05-01 13:35:20 +02:00
###############################################################################
2026-05-23 12:48:21 +02:00
# LINTING
2026-05-01 13:35:20 +02:00
###############################################################################
2026-09-05 13:13:36 +00:00
# Wir validieren das System via bootc container lint
RUN bootc container lint