feat: add server, workstation, and cloud edition manifests

Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
Blake Ridgway
2026-08-21 13:15:43 -05:00
parent 14e5ea9e1e
commit 729f191950
12 changed files with 463 additions and 0 deletions

View File

@@ -0,0 +1,74 @@
# Arcline Server — package set
# Debian bookworm packages. Lines beginning with # are notes/optional.
# The configure hook installs the Arcline toolchain and observability
# components that are not in Debian main (grafana, loki).
# ── base system ─────────────────────────────────────────────────────────────
systemd
systemd-sysv
dbus
libpam-systemd
ca-certificates
locales
tzdata
# ── boot ────────────────────────────────────────────────────────────────────
grub-pc
grub-efi-amd64
shim-signed
os-prober
# ── kernel / firmware ───────────────────────────────────────────────────────
linux-image-amd64
firmware-linux-free
# ── filesystem ──────────────────────────────────────────────────────────────
btrfs-progs
snapper
zstd
xz-utils
# ── security / hardening ────────────────────────────────────────────────────
openssh-server
nftables
apparmor
apparmor-utils
fail2ban
unattended-upgrades
libpam-pwquality
# ── containers ──────────────────────────────────────────────────────────────
docker.io
podman
runc
containernetworking-plugins
fuse-overlayfs
slirp4netns
# ── observability (Debian-main components) ─────────────────────────────────
prometheus
prometheus-node-exporter
prometheus-alertmanager
# grafana + loki are fetched from upstream repos by configure-system.sh
# ── admin tooling ───────────────────────────────────────────────────────────
curl
wget
jq
git
make
rsync
htop
tmux
vim-tiny
unzip
file
ethtool
sysstat
chrony
needrestart
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
# arcline-uptime arcline-check arcline-audit arcline-dns
# arcline-vault arcline-email arcline-migrate arcline-billing
# arcline-portal arcline-website arcline-status