muse-workover
This commit is contained in:
+12
-5
@@ -72,12 +72,19 @@ RUN --mount=type=bind,from=build-ctx,source=/build/50-prepare-flatpak-for-bazaar
|
||||
# CONFIGURATION LAYER (Der "saubere" Teil)
|
||||
###############################################################################
|
||||
|
||||
# 1. Kopiere die Filesystem-Fixes (tmpfiles.d)
|
||||
COPY configs/bootc-fix.conf /etc/tmpfiles.d/
|
||||
# 1. Kopiere die Filesystem-Fixes (tmpfiles.d, Vendor-Default)
|
||||
COPY configs/bootc-fix.conf /usr/lib/tmpfiles.d/bootc-fix.conf
|
||||
|
||||
# 2. Kopiere die Systemd-Overrides (Update-Timer und -Service)
|
||||
COPY configs/bootc-timer-override.conf /etc/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf
|
||||
COPY configs/bootc-override.conf /etc/systemd/system/bootc-fetch-apply-updates.service.d/override.conf
|
||||
# 1b. Container-Policy (Default aus /usr/etc, kein Host-Override nötig)
|
||||
# sigstoreSigned-Pflicht für eigenes Image, Public-Registries explizit erlaubt
|
||||
COPY configs/containers/policy.json /usr/etc/containers/policy.json
|
||||
COPY cosign.pub /usr/etc/pki/containers/cosign.pub
|
||||
RUN chmod 0644 /usr/etc/containers/policy.json /usr/etc/pki/containers/cosign.pub && \
|
||||
python3 -m json.tool /usr/etc/containers/policy.json > /dev/null
|
||||
|
||||
# 2. Kopiere die Systemd-Overrides als Vendor-Drop-ins (kein /etc/-Override im Image)
|
||||
COPY configs/bootc-timer-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.timer.d/override.conf
|
||||
COPY configs/bootc-override.conf /usr/lib/systemd/system/bootc-fetch-apply-updates.service.d/override.conf
|
||||
|
||||
# 3. Kopiere das Benachrichtigungs-Skript
|
||||
COPY --chmod=755 scripts/notify-bootc-user.sh /usr/bin/
|
||||
|
||||
@@ -139,9 +139,10 @@ _rootful_load_image $target_image=image_name $tag=default_tag:
|
||||
# If the image is found, load it into rootful podman
|
||||
ID=$(just sudoif podman images --filter reference="${target_image}:${tag}" --format "'{{ '{{.ID}}' }}'")
|
||||
if [[ "$ID" != "$USER_IMG_ID" ]]; then
|
||||
# If the image ID is not found or different from user, copy the image from user podman to root podman
|
||||
COPYTMP=$(mktemp -p "${PWD}" -d -t _build_podman_scp.XXXXXXXXXX)
|
||||
just sudoif TMPDIR=${COPYTMP} podman image scp ${UID}@localhost::"${target_image}:${tag}" root@localhost::"${target_image}:${tag}"
|
||||
# podman image scp ist deprecated (Podman 5) -> save/load verwenden
|
||||
COPYTMP=$(mktemp -p "${PWD}" -d -t _build_podman_load.XXXXXXXXXX)
|
||||
podman save "${target_image}:${tag}" -o "${COPYTMP}/image.tar"
|
||||
just sudoif podman load -i "${COPYTMP}/image.tar"
|
||||
rm -rf "${COPYTMP}"
|
||||
fi
|
||||
else
|
||||
|
||||
@@ -1,112 +0,0 @@
|
||||
#!/usr/bin/bash
|
||||
set -eoux pipefail
|
||||
|
||||
###############################################################################
|
||||
# cleanup-function (Unverändert, da sehr effektiv für Image-Größe)
|
||||
###############################################################################
|
||||
cleanup() {
|
||||
echo "Starting final cleanup..."
|
||||
# 1. Ungenutzte Pakete entfernen
|
||||
dnf5 autoremove -y || true
|
||||
|
||||
# 2. Bereinigung Cache (Das ist das Wichtigste für die Layer-Größe)
|
||||
dnf5 clean all || true
|
||||
|
||||
# 3. Entfernen von temporären Dateien und Caches
|
||||
# Wir löschen KEINE Verzeichnisse unter /var/lib/rpm oder /var/lib/dnf,
|
||||
# sondern nur die temporären Metadaten/Caches.
|
||||
rm -rf /tmp/* /var/tmp/* /var/cache/dnf/* /var/cache/dnf5/* || true
|
||||
|
||||
# 4. Reinigung der Logs/Run-Verzeichnisse
|
||||
rm -rf /run/* || true
|
||||
|
||||
echo "Cleanup complete! Image is lean and clean."
|
||||
}
|
||||
|
||||
|
||||
###############################################################################
|
||||
# Fedora version (used for RPM Fusion)
|
||||
###############################################################################
|
||||
FEDORA_VERSION="$(rpm -E %fedora)"
|
||||
|
||||
###############################################################################
|
||||
# Enable RPM Fusion (free + nonfree)
|
||||
###############################################################################
|
||||
dnf5 install -y \
|
||||
https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-${FEDORA_VERSION}.noarch.rpm \
|
||||
https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-${FEDORA_VERSION}.noarch.rpm
|
||||
|
||||
###############################################################################
|
||||
# Transaction 1: Multimedia Stack (Mesa + Codecs + Group)
|
||||
# Zusammengefasst, um Abhängigkeiten in einem Schritt zu lösen.
|
||||
###############################################################################
|
||||
echo "Installing Multimedia stack (Mesa Freeworld, Codecs & Groups)..."
|
||||
dnf5 install -y \
|
||||
mesa-va-drivers-freeworld \
|
||||
mesa-vdpau-drivers-freeworld \
|
||||
mesa-vulkan-drivers-freeworld \
|
||||
ffmpeg \
|
||||
ffmpeg-libs \
|
||||
libavcodec-freeworld \
|
||||
gstreamer1-libav \
|
||||
gstreamer1-plugins-bad-freeworld \
|
||||
gstreamer1-plugins-ugly \
|
||||
--allowerasing
|
||||
|
||||
# Die Gruppeninstallation bleibt separat, da sie eine eigene logische Einheit ist
|
||||
dnf5 group install -y multimedia --with-optional --allowerasing
|
||||
|
||||
###############################################################################
|
||||
# Transaction 2: Virtualization, Tools & Hardware Helpers
|
||||
# Zusammengefasst für effizientere Paketauflösung.
|
||||
###############################################################################
|
||||
echo "Installing Virtualization, Plasma Setup and Hardware Helpers..."
|
||||
dnf5 install -y \
|
||||
libvirt-daemon \
|
||||
libvirt-daemon-driver-qemu \
|
||||
libvirt-daemon-config-network \
|
||||
libvirt-client \
|
||||
qemu-kvm \
|
||||
qemu-img \
|
||||
virt-manager \
|
||||
virt-viewer \
|
||||
distrobox \
|
||||
plasma-setup \
|
||||
libva-utils \
|
||||
intel-media-driver \
|
||||
--allowerasing || true
|
||||
|
||||
###############################################################################
|
||||
# Transaction 3: Steam (i686 dependencies)
|
||||
# Getrennt, da Architektur-Wechsel (i686) oft eigene Transaktionen erfordern.
|
||||
###############################################################################
|
||||
echo "Installing Steam and i686 libraries..."
|
||||
dnf5 install -y \
|
||||
steam \
|
||||
mesa-dri-drivers.i686 \
|
||||
mesa-libGL.i686 \
|
||||
mesa-libEGL.i686 \
|
||||
--allowerasing
|
||||
|
||||
###############################################################################
|
||||
# Cleanup of Unwanted Packages
|
||||
###############################################################################
|
||||
echo "Removing Firefox and langpacks..."
|
||||
dnf5 remove -y firefox firefox-langpacks* || true
|
||||
|
||||
###############################################################################
|
||||
# Services Configuration
|
||||
###############################################################################
|
||||
echo "Enabling services..."
|
||||
systemctl enable libvirtd.service
|
||||
systemctl enable virtlogd.service
|
||||
systemctl enable podman.socket
|
||||
systemctl enable bluetooth.service
|
||||
systemctl enable plasma-setup.service
|
||||
systemctl enable bootc-fetch-apply-updates.timer
|
||||
|
||||
###############################################################################
|
||||
# Final Cleanup
|
||||
###############################################################################
|
||||
cleanup
|
||||
echo "Custom build complete!"
|
||||
+3
-2
@@ -14,8 +14,9 @@ dnf5 clean all || true
|
||||
# sondern nur die temporären Metadaten/Caches.
|
||||
rm -rf /tmp/* /var/tmp/* /var/cache/dnf/* /var/cache/dnf5/* || true
|
||||
|
||||
# 4. Reinigung der Logs/Run-Verzeichnisse
|
||||
rm -rf /run/* || true
|
||||
# 4. /run ist im fertigen Image tmpfs und muss nicht bereinigt werden.
|
||||
# Keine Mounts anfassen, nur bekannte Build-Reste entfernen.
|
||||
rm -rf /run/podman/* 2>/dev/null || true
|
||||
|
||||
# 5. Journal- und Log-Dateien bereinigen (Verzeichnisse bleiben erhalten)
|
||||
rm -rf /var/log/journal/* || true
|
||||
|
||||
+4
-3
@@ -9,10 +9,11 @@ Scripts are named with a number prefix and run in ascending order during the con
|
||||
## Included Scripts
|
||||
|
||||
- **`10-repos.sh`** - RPM Fusion repositories einrichten (frei + nonfree)
|
||||
- **`20-multimedia.sh`** - Mesa Freeworld, Codecs, FFmpeg, GStreamer, Intel-Media-Treiber
|
||||
- **`30-virt.sh`** - Virtualisierung (libvirt, QEMU), Plasma-Setup, Distrobox, Micro, etc.
|
||||
- **`40-remove-packages.sh`** - Entfernt unerwuenschte Pakete (Firefox, Plasma Discover)
|
||||
- **`20-remove-packages.sh`** - Entfernt unerwuenschte Pakete (Firefox, Plasma Discover)
|
||||
- **`30-virt.sh`** - Virtualisierungstools, Distrobox, Toolbox, Micro, etc.
|
||||
- **`40-multimedia.sh`** - Mesa Freeworld, Codecs, FFmpeg, GStreamer, Intel-Media-Treiber
|
||||
- **`50-prepare-flatpak-for-bazaar.sh`** - Laedt Flathub-Repo-Definition fuer Bazaar
|
||||
- **`99-cleanup.sh`** - Finale Bereinigung (autoremove, dnf clean, tmp/log-Caches)
|
||||
|
||||
## Hilfsscript
|
||||
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"default": [
|
||||
{
|
||||
"type": "reject"
|
||||
}
|
||||
],
|
||||
"transports": {
|
||||
"docker": {
|
||||
"humocs-man.duckdns.org/humocs-man/fluffy-pancake": [
|
||||
{
|
||||
"type": "sigstoreSigned",
|
||||
"keyPath": "/etc/pki/containers/cosign.pub",
|
||||
"signedIdentity": {
|
||||
"type": "matchRepository"
|
||||
}
|
||||
}
|
||||
],
|
||||
"docker.io": [
|
||||
{
|
||||
"type": "insecureAcceptAnything"
|
||||
}
|
||||
],
|
||||
"quay.io": [
|
||||
{
|
||||
"type": "insecureAcceptAnything"
|
||||
}
|
||||
],
|
||||
"ghcr.io": [
|
||||
{
|
||||
"type": "insecureAcceptAnything"
|
||||
}
|
||||
],
|
||||
"registry.fedoraproject.org": [
|
||||
{
|
||||
"type": "insecureAcceptAnything"
|
||||
}
|
||||
]
|
||||
},
|
||||
"docker-daemon": {
|
||||
"": [{"type":"insecureAcceptAnything"}]
|
||||
}
|
||||
}
|
||||
}
|
||||
+1
-1
@@ -10,4 +10,4 @@ autopart
|
||||
|
||||
reboot
|
||||
|
||||
bootc install ghcr.io/humocs-man/fluffy-pancake:stable
|
||||
bootc install humocs-man.duckdns.org/humocs-man/fluffy-pancake:stable
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
contents = """
|
||||
%post
|
||||
# Switch to the custom bootc image after installation
|
||||
bootc switch --mutate-in-place --transport registry ghcr.io/humocs-man/fluffy-pancake:stable
|
||||
bootc switch --mutate-in-place --transport registry humocs-man.duckdns.org/humocs-man/fluffy-pancake:stable
|
||||
%end
|
||||
"""
|
||||
|
||||
|
||||
@@ -3,12 +3,6 @@
|
||||
"extends": [
|
||||
"config:recommended"
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"matchManagers": ["github-actions"],
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"customManagers": [
|
||||
{
|
||||
"customType": "regex",
|
||||
|
||||
Reference in New Issue
Block a user