feat: add server, workstation, and cloud edition manifests
Define the three flagship editions as plain-text manifests: - server (bastion): production server - observability stack, containers. - workstation (forge): curated KDE Plasma + dev toolchains. - cloud (nimbus): cloud kernel, cloud-init, guest agents. Each manifest carries metadata (services to enable/mask), a package list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
10
editions/workstation/fstab
Normal file
10
editions/workstation/fstab
Normal file
@@ -0,0 +1,10 @@
|
||||
# Arcline Workstation — /etc/fstab template
|
||||
# See editions/server/fstab for the layout notes. btrfs-init.sh resolves the
|
||||
# root UUID at install time.
|
||||
|
||||
UUID=__ROOT_UUID__ / btrfs rw,noatime,compress=zstd:3,subvol=@ 0 0
|
||||
UUID=__ROOT_UUID__ /home btrfs rw,noatime,compress=zstd:3,subvol=@home 0 0
|
||||
UUID=__ROOT_UUID__ /var/log btrfs rw,noatime,compress=zstd:3,subvol=@log 0 0
|
||||
UUID=__ROOT_UUID__ /.snapshots btrfs rw,noatime,compress=zstd:3,subvol=@snapshots 0 0
|
||||
|
||||
/swap/swapfile none swap sw 0 0
|
||||
24
editions/workstation/kernel.cmdline
Normal file
24
editions/workstation/kernel.cmdline
Normal file
@@ -0,0 +1,24 @@
|
||||
# Arcline Workstation — kernel command line
|
||||
# Same hardening baseline as server, without the serial console and with
|
||||
# graphics-friendly settings.
|
||||
|
||||
console=tty0
|
||||
quiet
|
||||
loglevel=3
|
||||
systemd.show_status=auto
|
||||
|
||||
# hardening
|
||||
init_on_alloc=1
|
||||
init_on_free=1
|
||||
slab_nomerge
|
||||
page_poison=1
|
||||
pti=on
|
||||
spectre_v2=on
|
||||
spec_store_bypass=on
|
||||
tsx=off
|
||||
lockdown=integrity
|
||||
oops=panic
|
||||
panic=-1
|
||||
|
||||
# btrfs / storage
|
||||
rootflags=subvol=@
|
||||
33
editions/workstation/metadata.yaml
Normal file
33
editions/workstation/metadata.yaml
Normal file
@@ -0,0 +1,33 @@
|
||||
# Edition manifest: Arcline Workstation
|
||||
# Codename: forge
|
||||
edition: workstation
|
||||
codename: forge
|
||||
summary: Same hardened base with a lightweight KDE Plasma desktop and pre-configured dev toolchains.
|
||||
description: >
|
||||
A hardened daily driver. Lightweight KDE Plasma, privacy-hardened browser
|
||||
profiles, pre-configured Go / Rust / Python / Node toolchains, and the same
|
||||
zero-telemetry, default-deny firewall as the server edition.
|
||||
|
||||
image:
|
||||
type: iso
|
||||
boot: bios+efi
|
||||
filesystem: btrfs
|
||||
compression: zstd:3
|
||||
|
||||
packages:
|
||||
extra_repos: []
|
||||
|
||||
users:
|
||||
- arcline
|
||||
|
||||
services:
|
||||
enabled:
|
||||
- systemd-networkd
|
||||
- systemd-resolved
|
||||
- nftables
|
||||
- apparmor
|
||||
- sddm
|
||||
- arcline-snapshot.timer
|
||||
masked:
|
||||
- apt-daily.timer
|
||||
- apt-daily-upgrade.timer
|
||||
101
editions/workstation/packages.list
Normal file
101
editions/workstation/packages.list
Normal file
@@ -0,0 +1,101 @@
|
||||
# Arcline Workstation — package set
|
||||
# Curated KDE Plasma desktop (not the full task-* meta-package) plus a
|
||||
# complete developer toolchain.
|
||||
|
||||
# ── base system ─────────────────────────────────────────────────────────────
|
||||
systemd
|
||||
systemd-sysv
|
||||
dbus
|
||||
libpam-systemd
|
||||
ca-certificates
|
||||
locales
|
||||
tzdata
|
||||
|
||||
# ── boot ────────────────────────────────────────────────────────────────────
|
||||
grub-pc
|
||||
grub-efi-amd64
|
||||
shim-signed
|
||||
os-prober
|
||||
|
||||
# ── kernel / firmware ───────────────────────────────────────────────────────
|
||||
linux-image-amd64
|
||||
firmware-linux-free
|
||||
firmware-misc-nonfree # broadcom/intel wifi + gpu firmware
|
||||
|
||||
# ── filesystem ──────────────────────────────────────────────────────────────
|
||||
btrfs-progs
|
||||
snapper
|
||||
zstd
|
||||
xz-utils
|
||||
|
||||
# ── desktop: X + KDE Plasma ─────────────────────────────────────────────────
|
||||
xserver-xorg
|
||||
xinit
|
||||
plasma-desktop
|
||||
sddm
|
||||
konsole
|
||||
dolphin
|
||||
kate
|
||||
ark
|
||||
gwenview
|
||||
plasma-discover
|
||||
network-manager
|
||||
network-manager-gnome
|
||||
pipewire
|
||||
pipewire-pulse
|
||||
wireplumber
|
||||
pulseaudio-utils
|
||||
|
||||
# ── display / audio / input extras ──────────────────────────────────────────
|
||||
fonts-noto-core
|
||||
fonts-liberation
|
||||
firefox-esr
|
||||
|
||||
# ── security / hardening ────────────────────────────────────────────────────
|
||||
openssh-server
|
||||
nftables
|
||||
apparmor
|
||||
apparmor-utils
|
||||
fail2ban
|
||||
|
||||
# ── developer toolchain ─────────────────────────────────────────────────────
|
||||
build-essential
|
||||
gcc
|
||||
g++
|
||||
clang
|
||||
clang-format
|
||||
llvm
|
||||
lld
|
||||
gdb
|
||||
cmake
|
||||
ninja-build
|
||||
pkg-config
|
||||
golang-go
|
||||
rustc
|
||||
cargo
|
||||
python3
|
||||
python3-pip
|
||||
python3-venv
|
||||
nodejs
|
||||
npm
|
||||
git
|
||||
make
|
||||
curl
|
||||
wget
|
||||
jq
|
||||
vim
|
||||
nano
|
||||
htop
|
||||
tmux
|
||||
ripgrep
|
||||
fd-find
|
||||
bat
|
||||
docker.io
|
||||
podman
|
||||
runc
|
||||
containernetworking-plugins
|
||||
|
||||
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
|
||||
# arcline-uptime arcline-check arcline-audit arcline-dns
|
||||
# arcline-vault arcline-email arcline-migrate arcline-billing
|
||||
# arcline-portal arcline-website arcline-status
|
||||
Reference in New Issue
Block a user