diff --git a/Containerfile b/Containerfile index 96e82b7..54ed06e 100644 --- a/Containerfile +++ b/Containerfile @@ -72,12 +72,19 @@ RUN --mount=type=bind,from=build-ctx,source=/build/50-prepare-flatpak-for-bazaar # CONFIGURATION LAYER (Der "saubere" Teil) ############################################################################### -# 1. Kopiere die Filesystem-Fixes (tmpfiles.d) -COPY configs/bootc-fix.conf /etc/tmpfiles.d/ +# 1. Kopiere die Filesystem-Fixes (tmpfiles.d, Vendor-Default) +COPY configs/bootc-fix.conf /usr/lib/tmpfiles.d/bootc-fix.conf -# 2. Kopiere die Systemd-Overrides (Update-Timer und -Service) -COPY configs/bootc-timer-override.conf /etc/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf -COPY configs/bootc-override.conf /etc/systemd/system/bootc-fetch-apply-updates.service.d/override.conf +# 1b. Container-Policy (Default aus /usr/etc, kein Host-Override nötig) +# sigstoreSigned-Pflicht für eigenes Image, Public-Registries explizit erlaubt +COPY configs/containers/policy.json /usr/etc/containers/policy.json +COPY cosign.pub /usr/etc/pki/containers/cosign.pub +RUN chmod 0644 /usr/etc/containers/policy.json /usr/etc/pki/containers/cosign.pub && \ + python3 -m json.tool /usr/etc/containers/policy.json > /dev/null + +# 2. Kopiere die Systemd-Overrides als Vendor-Drop-ins (kein /etc/-Override im Image) +COPY configs/bootc-timer-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf +COPY configs/bootc-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.service.d/override.conf # 3. Kopiere das Benachrichtigungs-Skript COPY --chmod=755 scripts/notify-bootc-user.sh /usr/bin/ diff --git a/Justfile b/Justfile index 86f087c..5d79157 100644 --- a/Justfile +++ b/Justfile @@ -139,9 +139,10 @@ _rootful_load_image $target_image=image_name $tag=default_tag: # If the image is found, load it into rootful podman ID=$(just sudoif podman images --filter reference="${target_image}:${tag}" --format "'{{ '{{.ID}}' }}'") if [[ "$ID" != "$USER_IMG_ID" ]]; then - # If the image ID is not found or different from user, copy the image from user podman to root podman - COPYTMP=$(mktemp -p "${PWD}" -d -t _build_podman_scp.XXXXXXXXXX) - just sudoif TMPDIR=${COPYTMP} podman image scp ${UID}@localhost::"${target_image}:${tag}" root@localhost::"${target_image}:${tag}" + # podman image scp ist deprecated (Podman 5) -> save/load verwenden + COPYTMP=$(mktemp -p "${PWD}" -d -t _build_podman_load.XXXXXXXXXX) + podman save "${target_image}:${tag}" -o "${COPYTMP}/image.tar" + just sudoif podman load -i "${COPYTMP}/image.tar" rm -rf "${COPYTMP}" fi else diff --git a/build/90-build.sh.bak b/build/90-build.sh.bak deleted file mode 100755 index 8f059f4..0000000 --- a/build/90-build.sh.bak +++ /dev/null @@ -1,112 +0,0 @@ -#!/usr/bin/bash -set -eoux pipefail - -############################################################################### -# cleanup-function (Unverändert, da sehr effektiv für Image-Größe) -############################################################################### -cleanup() { - echo "Starting final cleanup..." - # 1. Ungenutzte Pakete entfernen - dnf5 autoremove -y || true - - # 2. Bereinigung Cache (Das ist das Wichtigste für die Layer-Größe) - dnf5 clean all || true - - # 3. Entfernen von temporären Dateien und Caches - # Wir löschen KEINE Verzeichnisse unter /var/lib/rpm oder /var/lib/dnf, - # sondern nur die temporären Metadaten/Caches. - rm -rf /tmp/* /var/tmp/* /var/cache/dnf/* /var/cache/dnf5/* || true - - # 4. Reinigung der Logs/Run-Verzeichnisse - rm -rf /run/* || true - - echo "Cleanup complete! Image is lean and clean." -} - - -############################################################################### -# Fedora version (used for RPM Fusion) -############################################################################### -FEDORA_VERSION="$(rpm -E %fedora)" - -############################################################################### -# Enable RPM Fusion (free + nonfree) -############################################################################### -dnf5 install -y \ - https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-${FEDORA_VERSION}.noarch.rpm \ - https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-${FEDORA_VERSION}.noarch.rpm - -############################################################################### -# Transaction 1: Multimedia Stack (Mesa + Codecs + Group) -# Zusammengefasst, um Abhängigkeiten in einem Schritt zu lösen. -############################################################################### -echo "Installing Multimedia stack (Mesa Freeworld, Codecs & Groups)..." -dnf5 install -y \ - mesa-va-drivers-freeworld \ - mesa-vdpau-drivers-freeworld \ - mesa-vulkan-drivers-freeworld \ - ffmpeg \ - ffmpeg-libs \ - libavcodec-freeworld \ - gstreamer1-libav \ - gstreamer1-plugins-bad-freeworld \ - gstreamer1-plugins-ugly \ - --allowerasing - -# Die Gruppeninstallation bleibt separat, da sie eine eigene logische Einheit ist -dnf5 group install -y multimedia --with-optional --allowerasing - -############################################################################### -# Transaction 2: Virtualization, Tools & Hardware Helpers -# Zusammengefasst für effizientere Paketauflösung. -############################################################################### -echo "Installing Virtualization, Plasma Setup and Hardware Helpers..." -dnf5 install -y \ - libvirt-daemon \ - libvirt-daemon-driver-qemu \ - libvirt-daemon-config-network \ - libvirt-client \ - qemu-kvm \ - qemu-img \ - virt-manager \ - virt-viewer \ - distrobox \ - plasma-setup \ - libva-utils \ - intel-media-driver \ - --allowerasing || true - -############################################################################### -# Transaction 3: Steam (i686 dependencies) -# Getrennt, da Architektur-Wechsel (i686) oft eigene Transaktionen erfordern. -############################################################################### -echo "Installing Steam and i686 libraries..." -dnf5 install -y \ - steam \ - mesa-dri-drivers.i686 \ - mesa-libGL.i686 \ - mesa-libEGL.i686 \ - --allowerasing - -############################################################################### -# Cleanup of Unwanted Packages -############################################################################### -echo "Removing Firefox and langpacks..." -dnf5 remove -y firefox firefox-langpacks* || true - -############################################################################### -# Services Configuration -############################################################################### -echo "Enabling services..." -systemctl enable libvirtd.service -systemctl enable virtlogd.service -systemctl enable podman.socket -systemctl enable bluetooth.service -systemctl enable plasma-setup.service -systemctl enable bootc-fetch-apply-updates.timer - -############################################################################### -# Final Cleanup -############################################################################### -cleanup -echo "Custom build complete!" diff --git a/build/99-cleanup.sh b/build/99-cleanup.sh index b233d02..8fc697e 100644 --- a/build/99-cleanup.sh +++ b/build/99-cleanup.sh @@ -14,8 +14,9 @@ dnf5 clean all || true # sondern nur die temporären Metadaten/Caches. rm -rf /tmp/* /var/tmp/* /var/cache/dnf/* /var/cache/dnf5/* || true -# 4. Reinigung der Logs/Run-Verzeichnisse -rm -rf /run/* || true +# 4. /run ist im fertigen Image tmpfs und muss nicht bereinigt werden. +# Keine Mounts anfassen, nur bekannte Build-Reste entfernen. +rm -rf /run/podman/* 2>/dev/null || true # 5. Journal- und Log-Dateien bereinigen (Verzeichnisse bleiben erhalten) rm -rf /var/log/journal/* || true diff --git a/build/README.md b/build/README.md index 335c986..eeb2fec 100644 --- a/build/README.md +++ b/build/README.md @@ -9,10 +9,11 @@ Scripts are named with a number prefix and run in ascending order during the con ## Included Scripts - **`10-repos.sh`** - RPM Fusion repositories einrichten (frei + nonfree) -- **`20-multimedia.sh`** - Mesa Freeworld, Codecs, FFmpeg, GStreamer, Intel-Media-Treiber -- **`30-virt.sh`** - Virtualisierung (libvirt, QEMU), Plasma-Setup, Distrobox, Micro, etc. -- **`40-remove-packages.sh`** - Entfernt unerwuenschte Pakete (Firefox, Plasma Discover) +- **`20-remove-packages.sh`** - Entfernt unerwuenschte Pakete (Firefox, Plasma Discover) +- **`30-virt.sh`** - Virtualisierungstools, Distrobox, Toolbox, Micro, etc. +- **`40-multimedia.sh`** - Mesa Freeworld, Codecs, FFmpeg, GStreamer, Intel-Media-Treiber - **`50-prepare-flatpak-for-bazaar.sh`** - Laedt Flathub-Repo-Definition fuer Bazaar +- **`99-cleanup.sh`** - Finale Bereinigung (autoremove, dnf clean, tmp/log-Caches) ## Hilfsscript diff --git a/configs/containers/policy.json b/configs/containers/policy.json new file mode 100644 index 0000000..b4ebf25 --- /dev/null +++ b/configs/containers/policy.json @@ -0,0 +1,43 @@ +{ + "default": [ + { + "type": "reject" + } + ], + "transports": { + "docker": { + "humocs-man.duckdns.org/humocs-man/fluffy-pancake": [ + { + "type": "sigstoreSigned", + "keyPath": "/etc/pki/containers/cosign.pub", + "signedIdentity": { + "type": "matchRepository" + } + } + ], + "docker.io": [ + { + "type": "insecureAcceptAnything" + } + ], + "quay.io": [ + { + "type": "insecureAcceptAnything" + } + ], + "ghcr.io": [ + { + "type": "insecureAcceptAnything" + } + ], + "registry.fedoraproject.org": [ + { + "type": "insecureAcceptAnything" + } + ] + }, + "docker-daemon": { + "": [{"type":"insecureAcceptAnything"}] + } + } +} diff --git a/iso/bootc.ks b/iso/bootc.ks index 576c6fa..b6c04a0 100644 --- a/iso/bootc.ks +++ b/iso/bootc.ks @@ -10,4 +10,4 @@ autopart reboot -bootc install ghcr.io/humocs-man/fluffy-pancake:stable +bootc install humocs-man.duckdns.org/humocs-man/fluffy-pancake:stable diff --git a/iso/iso.toml b/iso/iso.toml index c01fe0f..05f3153 100644 --- a/iso/iso.toml +++ b/iso/iso.toml @@ -5,7 +5,7 @@ contents = """ %post # Switch to the custom bootc image after installation -bootc switch --mutate-in-place --transport registry ghcr.io/humocs-man/fluffy-pancake:stable +bootc switch --mutate-in-place --transport registry humocs-man.duckdns.org/humocs-man/fluffy-pancake:stable %end """ diff --git a/renovate.json b/renovate.json index 72237d3..4c8cfe9 100644 --- a/renovate.json +++ b/renovate.json @@ -3,12 +3,6 @@ "extends": [ "config:recommended" ], - "packageRules": [ - { - "matchManagers": ["github-actions"], - "enabled": false - } - ], "customManagers": [ { "customType": "regex",