feat: add server, workstation, and cloud edition manifests

Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
Blake Ridgway
2026-08-21 13:15:43 -05:00
parent 14e5ea9e1e
commit 729f191950
12 changed files with 463 additions and 0 deletions

16
editions/server/fstab Normal file
View File

@@ -0,0 +1,16 @@
# Arcline Server — /etc/fstab template
#
# This is a TEMPLATE. btrfs-init.sh resolves the real root device UUID at
# install/first-boot time and writes /etc/fstab. The subvolume layout matches
# docs/btrfs.md.
#
# Device UUID is substituted by the installer.
# <file system> <mount point> <type> <options> <dump> <pass>
UUID=__ROOT_UUID__ / btrfs rw,noatime,compress=zstd:3,subvol=@ 0 0
UUID=__ROOT_UUID__ /home btrfs rw,noatime,compress=zstd:3,subvol=@home 0 0
UUID=__ROOT_UUID__ /var/log btrfs rw,noatime,compress=zstd:3,subvol=@log 0 0
UUID=__ROOT_UUID__ /.snapshots btrfs rw,noatime,compress=zstd:3,subvol=@snapshots 0 0
# swap
/swap/swapfile none swap sw 0 0

View File

@@ -0,0 +1,35 @@
# Arcline Server — kernel command line
# Hardening flags + console config. Kept explicit and auditable.
#
# Security notes:
# init_on_alloc / init_on_free — zero freshly allocated/freed memory
# slab_nomerge — disable merging of similar slab objects
# page_poison=1 — fill freed pages to catch use-after-free
# pti=on — kernel page-table isolation
# spectre_v2=on spec_store_bypass=on — mitigations on (no auto-off)
# tsx=off — disable TSX (TAA mitigations)
# lockdown=integrity — block unsigned kernel modifications
# oops=panic panic=-1 — panic (and stay down) on oops
# quiet loglevel=3 — quiet serial console boot
console=tty0
console=ttyS0,115200n8
quiet
loglevel=3
systemd.show_status=auto
# hardening
init_on_alloc=1
init_on_free=1
slab_nomerge
page_poison=1
pti=on
spectre_v2=on
spec_store_bypass=on
tsx=off
lockdown=integrity
oops=panic
panic=-1
# btrfs / storage
rootflags=subvol=@

View File

@@ -0,0 +1,37 @@
# Edition manifest: Arcline Server
# Codename: bastion
edition: server
codename: bastion
summary: Hardened, production-ready server OS with built-in observability and zero telemetry.
description: >
Runs applications on bare metal or in the cloud. Ships with a default-deny
nftables firewall, AppArmor + seccomp, btrfs root with snapshot rollback,
Docker + Podman, and a pre-configured Prometheus / Grafana / Loki stack.
image:
type: iso
boot: bios+efi
filesystem: btrfs
compression: zstd:3
packages:
# Upstream repos added before package install (name -> [url, suite, component]).
extra_repos: []
users:
# Accounts created at first boot by the installer/configure hook.
- arcline
services:
# systemd units enabled by default.
enabled:
- systemd-networkd
- systemd-resolved
- ssh
- nftables
- apparmor
- prometheus-node-exporter
- arcline-snapshot.timer
masked:
- apt-daily.timer
- apt-daily-upgrade.timer

View File

@@ -0,0 +1,74 @@
# Arcline Server — package set
# Debian bookworm packages. Lines beginning with # are notes/optional.
# The configure hook installs the Arcline toolchain and observability
# components that are not in Debian main (grafana, loki).
# ── base system ─────────────────────────────────────────────────────────────
systemd
systemd-sysv
dbus
libpam-systemd
ca-certificates
locales
tzdata
# ── boot ────────────────────────────────────────────────────────────────────
grub-pc
grub-efi-amd64
shim-signed
os-prober
# ── kernel / firmware ───────────────────────────────────────────────────────
linux-image-amd64
firmware-linux-free
# ── filesystem ──────────────────────────────────────────────────────────────
btrfs-progs
snapper
zstd
xz-utils
# ── security / hardening ────────────────────────────────────────────────────
openssh-server
nftables
apparmor
apparmor-utils
fail2ban
unattended-upgrades
libpam-pwquality
# ── containers ──────────────────────────────────────────────────────────────
docker.io
podman
runc
containernetworking-plugins
fuse-overlayfs
slirp4netns
# ── observability (Debian-main components) ─────────────────────────────────
prometheus
prometheus-node-exporter
prometheus-alertmanager
# grafana + loki are fetched from upstream repos by configure-system.sh
# ── admin tooling ───────────────────────────────────────────────────────────
curl
wget
jq
git
make
rsync
htop
tmux
vim-tiny
unzip
file
ethtool
sysstat
chrony
needrestart
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
# arcline-uptime arcline-check arcline-audit arcline-dns
# arcline-vault arcline-email arcline-migrate arcline-billing
# arcline-portal arcline-website arcline-status