feat: add server, workstation, and cloud edition manifests

Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
Blake Ridgway
2026-08-21 13:15:43 -05:00
parent 14e5ea9e1e
commit 729f191950
12 changed files with 463 additions and 0 deletions

View File

@@ -0,0 +1,33 @@
# Edition manifest: Arcline Workstation
# Codename: forge
edition: workstation
codename: forge
summary: Same hardened base with a lightweight KDE Plasma desktop and pre-configured dev toolchains.
description: >
A hardened daily driver. Lightweight KDE Plasma, privacy-hardened browser
profiles, pre-configured Go / Rust / Python / Node toolchains, and the same
zero-telemetry, default-deny firewall as the server edition.
image:
type: iso
boot: bios+efi
filesystem: btrfs
compression: zstd:3
packages:
extra_repos: []
users:
- arcline
services:
enabled:
- systemd-networkd
- systemd-resolved
- nftables
- apparmor
- sddm
- arcline-snapshot.timer
masked:
- apt-daily.timer
- apt-daily-upgrade.timer