feat: add server, workstation, and cloud edition manifests

Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
Blake Ridgway
2026-08-21 13:15:43 -05:00
parent 14e5ea9e1e
commit 729f191950
12 changed files with 463 additions and 0 deletions

View File

@@ -0,0 +1,60 @@
# Arcline Cloud — package set
# Minimal footprint: cloud kernel, cloud-init, guest agents, storage tooling.
# ── base system ─────────────────────────────────────────────────────────────
systemd
systemd-sysv
dbus
libpam-systemd
ca-certificates
locales
tzdata
# ── boot ────────────────────────────────────────────────────────────────────
grub-pc
grub-efi-amd64
shim-signed
# ── kernel (cloud variant) ──────────────────────────────────────────────────
linux-image-cloud-amd64
# ── filesystem ──────────────────────────────────────────────────────────────
btrfs-progs
zstd
xz-utils
# ── cloud provisioning ──────────────────────────────────────────────────────
cloud-init
cloud-guest-utils
cloud-image-utils
open-vm-tools
qemu-guest-agent
# ── storage / block devices ─────────────────────────────────────────────────
nvme-cli
open-iscsi
multipath-tools
lvm2
mdadm
# ── security / hardening ────────────────────────────────────────────────────
openssh-server
nftables
apparmor
apparmor-utils
# ── observability (Debian-main components) ─────────────────────────────────
prometheus-node-exporter
# ── minimal admin tooling ───────────────────────────────────────────────────
curl
jq
git
rsync
htop
vim-tiny
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
# arcline-uptime arcline-check arcline-audit arcline-dns
# arcline-vault arcline-email arcline-migrate arcline-billing
# arcline-portal arcline-website arcline-status