2026-02-17 17:27:26 +01:00
|
|
|
###############################################################################
|
|
|
|
|
# PROJECT NAME CONFIGURATION
|
|
|
|
|
###############################################################################
|
2026-05-10 19:16:03 +02:00
|
|
|
# Name: fluffy-pancake
|
2026-02-17 17:27:26 +01:00
|
|
|
#
|
|
|
|
|
# IMPORTANT: Change "finpilot" above to your desired project name.
|
|
|
|
|
# This name should be used consistently throughout the repository in:
|
|
|
|
|
# - Justfile: export image_name := env("IMAGE_NAME", "your-name-here")
|
|
|
|
|
# - README.md: # your-name-here (title)
|
|
|
|
|
# - artifacthub-repo.yml: repositoryID: your-name-here
|
|
|
|
|
# - custom/ujust/README.md: localhost/your-name-here:stable (in bootc switch example)
|
|
|
|
|
#
|
|
|
|
|
# The project name defined here is the single source of truth for your
|
|
|
|
|
# custom image's identity. When changing it, update all references above
|
|
|
|
|
# to maintain consistency.
|
|
|
|
|
###############################################################################
|
|
|
|
|
|
|
|
|
|
###############################################################################
|
2026-08-08 07:42:29 +00:00
|
|
|
# MULTI-STAGE BUILD ARCHITECTURE (Cache-Isolierung)
|
2026-02-17 17:27:26 +01:00
|
|
|
###############################################################################
|
2026-08-08 07:42:29 +00:00
|
|
|
# Isolierte Kontext-Stage NUR für die Build-Skripte.
|
|
|
|
|
# Änderungen an /configs oder /scripts hebeln dadurch die DNF-Layer (1-5) NICHT mehr aus!
|
|
|
|
|
FROM scratch AS build-ctx
|
2026-02-17 17:27:26 +01:00
|
|
|
COPY build /build
|
|
|
|
|
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
|
|
|
|
# BASE IMAGE
|
|
|
|
|
###############################################################################
|
2026-04-28 18:42:34 +02:00
|
|
|
FROM quay.io/fedora/fedora-kinoite:44
|
2026-02-17 17:27:26 +01:00
|
|
|
|
2026-05-01 13:35:20 +02:00
|
|
|
### /opt (Unverändert)
|
2026-02-17 17:27:26 +01:00
|
|
|
# RUN rm /opt && mkdir /opt
|
|
|
|
|
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
2026-05-24 13:33:53 +02:00
|
|
|
# EXECUTION STAGE (Aufgeteilt in Cache-Layer)
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
2026-05-24 13:33:53 +02:00
|
|
|
|
|
|
|
|
# LAYER 1: Repositories einrichten (Ändert sich fast nie)
|
2026-08-08 07:42:29 +00:00
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/10-repos.sh,target=/tmp/10-repos.sh \
|
2026-02-17 17:27:26 +01:00
|
|
|
--mount=type=cache,dst=/var/cache \
|
|
|
|
|
--mount=type=cache,dst=/var/log \
|
|
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
2026-05-24 13:33:53 +02:00
|
|
|
bash /tmp/10-repos.sh && dnf5 clean all
|
|
|
|
|
|
2026-08-08 07:42:29 +00:00
|
|
|
# LAYER 2: Unerwünschte Pakete entfernen (Bereinigungsschicht - vorgezogen)
|
|
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/20-remove-packages.sh,target=/tmp/20-remove-packages.sh \
|
2026-05-24 13:33:53 +02:00
|
|
|
--mount=type=cache,dst=/var/cache \
|
|
|
|
|
--mount=type=cache,dst=/var/log \
|
|
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
2026-08-08 07:16:59 +00:00
|
|
|
bash /tmp/20-remove-packages.sh
|
2026-05-24 13:33:53 +02:00
|
|
|
|
|
|
|
|
# LAYER 3: Virtualisierung & Tools (Großer Download - stark gecacht)
|
2026-08-08 07:42:29 +00:00
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/30-virt.sh,target=/tmp/30-virt.sh \
|
2026-07-12 15:01:23 +00:00
|
|
|
--mount=type=cache,dst=/var/cache \
|
|
|
|
|
--mount=type=cache,dst=/var/log \
|
|
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
|
|
|
|
bash /tmp/30-virt.sh
|
2026-05-24 13:33:53 +02:00
|
|
|
|
2026-08-08 07:16:59 +00:00
|
|
|
# LAYER 4: Multimedia Stack (Großer Download - stark gecacht)
|
2026-08-08 07:42:29 +00:00
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/40-multimedia.sh,target=/tmp/40-multimedia.sh \
|
2026-05-24 13:33:53 +02:00
|
|
|
--mount=type=cache,dst=/var/cache \
|
|
|
|
|
--mount=type=cache,dst=/var/log \
|
|
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
2026-08-08 07:16:59 +00:00
|
|
|
bash /tmp/40-multimedia.sh
|
2026-05-24 13:33:53 +02:00
|
|
|
|
|
|
|
|
# LAYER 5: Flatpak Vorbereitung (Winzig, ganz unten)
|
2026-08-08 07:42:29 +00:00
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/50-prepare-flatpak-for-bazaar.sh,target=/tmp/50-prepare-flatpak-for-bazaar.sh \
|
2026-05-24 13:33:53 +02:00
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
|
|
|
|
bash /tmp/50-prepare-flatpak-for-bazaar.sh
|
2026-04-24 20:54:59 +02:00
|
|
|
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
|
|
|
|
# CONFIGURATION LAYER (Der "saubere" Teil)
|
|
|
|
|
###############################################################################
|
2026-03-02 18:45:46 +01:00
|
|
|
|
2026-09-05 14:56:19 +02:00
|
|
|
# 1. Kopiere die Filesystem-Fixes (tmpfiles.d, Vendor-Default)
|
|
|
|
|
COPY configs/bootc-fix.conf /usr/lib/tmpfiles.d/bootc-fix.conf
|
2026-04-03 18:03:04 +02:00
|
|
|
|
2026-09-05 17:48:12 +00:00
|
|
|
# 1b. Container-Policy & Registry Auth für bootc
|
2026-09-05 14:56:19 +02:00
|
|
|
# sigstoreSigned-Pflicht für eigenes Image, Public-Registries explizit erlaubt
|
2026-09-05 13:26:23 +00:00
|
|
|
COPY configs/containers/policy.json /etc/containers/policy.json
|
|
|
|
|
COPY cosign.pub /etc/pki/containers/cosign.pub
|
2026-09-05 19:12:36 +00:00
|
|
|
COPY configs/auth.json /etc/containers/auth.json
|
2026-09-05 19:53:19 +00:00
|
|
|
COPY configs/humocs-man.yaml /etc/containers/registries.d/humocs-man.yaml
|
2026-09-05 17:48:12 +00:00
|
|
|
|
2026-09-05 13:34:57 +00:00
|
|
|
RUN chmod 0644 /etc/containers/policy.json /etc/pki/containers/cosign.pub && \
|
2026-09-05 19:12:36 +00:00
|
|
|
chmod 0600 /etc/containers/auth.json && \
|
2026-09-05 17:48:12 +00:00
|
|
|
python3 -m json.tool /etc/containers/policy.json > /dev/null && \
|
2026-09-05 19:12:36 +00:00
|
|
|
python3 -m json.tool /etc/containers/auth.json > /dev/null
|
2026-09-05 14:56:19 +02:00
|
|
|
|
|
|
|
|
# 2. Kopiere die Systemd-Overrides als Vendor-Drop-ins (kein /etc/-Override im Image)
|
|
|
|
|
COPY configs/bootc-timer-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf
|
|
|
|
|
COPY configs/bootc-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.service.d/override.conf
|
2026-05-01 13:35:20 +02:00
|
|
|
|
|
|
|
|
# 3. Kopiere das Benachrichtigungs-Skript
|
2026-05-30 15:42:14 +02:00
|
|
|
COPY --chmod=755 scripts/notify-bootc-user.sh /usr/bin/
|
2026-05-01 13:35:20 +02:00
|
|
|
|
2026-05-23 11:41:07 +02:00
|
|
|
# =============================================================================
|
2026-05-31 18:11:43 +02:00
|
|
|
# SYSTEMD SERVICES (Modern Bootc Architecture)
|
2026-05-23 11:41:07 +02:00
|
|
|
# =============================================================================
|
|
|
|
|
|
2026-05-23 12:48:21 +02:00
|
|
|
# 4. Kopiere den Systemd-Service für den Erst-Boot von Flatpak
|
2026-05-23 11:41:07 +02:00
|
|
|
COPY configs/flatpak-preinstall.service /usr/lib/systemd/system/flatpak-preinstall.service
|
2026-05-23 12:48:21 +02:00
|
|
|
|
2026-05-31 18:11:43 +02:00
|
|
|
# 5. Aktiviere Services (Presets greifen nicht bei COPY-Dateien)
|
|
|
|
|
RUN systemctl enable \
|
2026-07-09 13:58:18 +00:00
|
|
|
# libvirtd.service \
|
|
|
|
|
# virtlogd.service \
|
2026-05-31 18:11:43 +02:00
|
|
|
podman.socket \
|
|
|
|
|
bootc-fetch-apply-updates.timer \
|
|
|
|
|
flatpak-preinstall.service
|
2026-05-23 11:41:07 +02:00
|
|
|
|
2026-08-16 11:33:04 +00:00
|
|
|
###############################################################################
|
|
|
|
|
# FINAL CLEANUP
|
|
|
|
|
###############################################################################
|
|
|
|
|
# autoremove + Cache-/Temp-Bereinigung (einmalig, am Ende aller Installs)
|
|
|
|
|
RUN --mount=type=bind,from=build-ctx,source=/build/99-cleanup.sh,target=/tmp/99-cleanup.sh \
|
|
|
|
|
--mount=type=tmpfs,dst=/tmp \
|
|
|
|
|
bash /tmp/99-cleanup.sh
|
|
|
|
|
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
2026-05-23 12:48:21 +02:00
|
|
|
# LINTING
|
2026-05-01 13:35:20 +02:00
|
|
|
###############################################################################
|
2026-09-05 13:13:36 +00:00
|
|
|
# Wir validieren das System via bootc container lint
|
|
|
|
|
RUN bootc container lint
|