feat: add server, workstation, and cloud edition manifests
Define the three flagship editions as plain-text manifests: - server (bastion): production server - observability stack, containers. - workstation (forge): curated KDE Plasma + dev toolchains. - cloud (nimbus): cloud kernel, cloud-init, guest agents. Each manifest carries metadata (services to enable/mask), a package list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
16
editions/server/fstab
Normal file
16
editions/server/fstab
Normal file
@@ -0,0 +1,16 @@
|
||||
# Arcline Server — /etc/fstab template
|
||||
#
|
||||
# This is a TEMPLATE. btrfs-init.sh resolves the real root device UUID at
|
||||
# install/first-boot time and writes /etc/fstab. The subvolume layout matches
|
||||
# docs/btrfs.md.
|
||||
#
|
||||
# Device UUID is substituted by the installer.
|
||||
|
||||
# <file system> <mount point> <type> <options> <dump> <pass>
|
||||
UUID=__ROOT_UUID__ / btrfs rw,noatime,compress=zstd:3,subvol=@ 0 0
|
||||
UUID=__ROOT_UUID__ /home btrfs rw,noatime,compress=zstd:3,subvol=@home 0 0
|
||||
UUID=__ROOT_UUID__ /var/log btrfs rw,noatime,compress=zstd:3,subvol=@log 0 0
|
||||
UUID=__ROOT_UUID__ /.snapshots btrfs rw,noatime,compress=zstd:3,subvol=@snapshots 0 0
|
||||
|
||||
# swap
|
||||
/swap/swapfile none swap sw 0 0
|
||||
35
editions/server/kernel.cmdline
Normal file
35
editions/server/kernel.cmdline
Normal file
@@ -0,0 +1,35 @@
|
||||
# Arcline Server — kernel command line
|
||||
# Hardening flags + console config. Kept explicit and auditable.
|
||||
#
|
||||
# Security notes:
|
||||
# init_on_alloc / init_on_free — zero freshly allocated/freed memory
|
||||
# slab_nomerge — disable merging of similar slab objects
|
||||
# page_poison=1 — fill freed pages to catch use-after-free
|
||||
# pti=on — kernel page-table isolation
|
||||
# spectre_v2=on spec_store_bypass=on — mitigations on (no auto-off)
|
||||
# tsx=off — disable TSX (TAA mitigations)
|
||||
# lockdown=integrity — block unsigned kernel modifications
|
||||
# oops=panic panic=-1 — panic (and stay down) on oops
|
||||
# quiet loglevel=3 — quiet serial console boot
|
||||
|
||||
console=tty0
|
||||
console=ttyS0,115200n8
|
||||
quiet
|
||||
loglevel=3
|
||||
systemd.show_status=auto
|
||||
|
||||
# hardening
|
||||
init_on_alloc=1
|
||||
init_on_free=1
|
||||
slab_nomerge
|
||||
page_poison=1
|
||||
pti=on
|
||||
spectre_v2=on
|
||||
spec_store_bypass=on
|
||||
tsx=off
|
||||
lockdown=integrity
|
||||
oops=panic
|
||||
panic=-1
|
||||
|
||||
# btrfs / storage
|
||||
rootflags=subvol=@
|
||||
37
editions/server/metadata.yaml
Normal file
37
editions/server/metadata.yaml
Normal file
@@ -0,0 +1,37 @@
|
||||
# Edition manifest: Arcline Server
|
||||
# Codename: bastion
|
||||
edition: server
|
||||
codename: bastion
|
||||
summary: Hardened, production-ready server OS with built-in observability and zero telemetry.
|
||||
description: >
|
||||
Runs applications on bare metal or in the cloud. Ships with a default-deny
|
||||
nftables firewall, AppArmor + seccomp, btrfs root with snapshot rollback,
|
||||
Docker + Podman, and a pre-configured Prometheus / Grafana / Loki stack.
|
||||
|
||||
image:
|
||||
type: iso
|
||||
boot: bios+efi
|
||||
filesystem: btrfs
|
||||
compression: zstd:3
|
||||
|
||||
packages:
|
||||
# Upstream repos added before package install (name -> [url, suite, component]).
|
||||
extra_repos: []
|
||||
|
||||
users:
|
||||
# Accounts created at first boot by the installer/configure hook.
|
||||
- arcline
|
||||
|
||||
services:
|
||||
# systemd units enabled by default.
|
||||
enabled:
|
||||
- systemd-networkd
|
||||
- systemd-resolved
|
||||
- ssh
|
||||
- nftables
|
||||
- apparmor
|
||||
- prometheus-node-exporter
|
||||
- arcline-snapshot.timer
|
||||
masked:
|
||||
- apt-daily.timer
|
||||
- apt-daily-upgrade.timer
|
||||
74
editions/server/packages.list
Normal file
74
editions/server/packages.list
Normal file
@@ -0,0 +1,74 @@
|
||||
# Arcline Server — package set
|
||||
# Debian bookworm packages. Lines beginning with # are notes/optional.
|
||||
# The configure hook installs the Arcline toolchain and observability
|
||||
# components that are not in Debian main (grafana, loki).
|
||||
|
||||
# ── base system ─────────────────────────────────────────────────────────────
|
||||
systemd
|
||||
systemd-sysv
|
||||
dbus
|
||||
libpam-systemd
|
||||
ca-certificates
|
||||
locales
|
||||
tzdata
|
||||
|
||||
# ── boot ────────────────────────────────────────────────────────────────────
|
||||
grub-pc
|
||||
grub-efi-amd64
|
||||
shim-signed
|
||||
os-prober
|
||||
|
||||
# ── kernel / firmware ───────────────────────────────────────────────────────
|
||||
linux-image-amd64
|
||||
firmware-linux-free
|
||||
|
||||
# ── filesystem ──────────────────────────────────────────────────────────────
|
||||
btrfs-progs
|
||||
snapper
|
||||
zstd
|
||||
xz-utils
|
||||
|
||||
# ── security / hardening ────────────────────────────────────────────────────
|
||||
openssh-server
|
||||
nftables
|
||||
apparmor
|
||||
apparmor-utils
|
||||
fail2ban
|
||||
unattended-upgrades
|
||||
libpam-pwquality
|
||||
|
||||
# ── containers ──────────────────────────────────────────────────────────────
|
||||
docker.io
|
||||
podman
|
||||
runc
|
||||
containernetworking-plugins
|
||||
fuse-overlayfs
|
||||
slirp4netns
|
||||
|
||||
# ── observability (Debian-main components) ─────────────────────────────────
|
||||
prometheus
|
||||
prometheus-node-exporter
|
||||
prometheus-alertmanager
|
||||
# grafana + loki are fetched from upstream repos by configure-system.sh
|
||||
|
||||
# ── admin tooling ───────────────────────────────────────────────────────────
|
||||
curl
|
||||
wget
|
||||
jq
|
||||
git
|
||||
make
|
||||
rsync
|
||||
htop
|
||||
tmux
|
||||
vim-tiny
|
||||
unzip
|
||||
file
|
||||
ethtool
|
||||
sysstat
|
||||
chrony
|
||||
needrestart
|
||||
|
||||
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
|
||||
# arcline-uptime arcline-check arcline-audit arcline-dns
|
||||
# arcline-vault arcline-email arcline-migrate arcline-billing
|
||||
# arcline-portal arcline-website arcline-status
|
||||
Reference in New Issue
Block a user