- docs/secureboot.md: MOK workflow (generate, build, enroll). - docs/building.md: image + install quickstart, new outputs, ARCLINE_SIGN. - docs/observability.md: vendor .debs are now the primary packaging path. - docs/editions.md: cloud ships a qcow2; qemu test command. - docs/architecture.md: full pipeline table incl. deploy/install; the four follow-up items are now implemented; new "on the horizon" list. - README: updated feature list, quickstart, and status.
95 lines
4.4 KiB
Markdown
95 lines
4.4 KiB
Markdown
# Arcline OS — build system
|
|
|
|
> The Linux OS for people who run infrastructure. Hardened Debian base.
|
|
> Pre-configured monitoring, auditing, and security tooling. Zero telemetry.
|
|
|
|
This repository is the build system ("the wires") behind
|
|
[Arcline OS](https://arcline.it). It turns a Debian base and a set of plain-text
|
|
manifests into hardened, bootable operating system images for three editions:
|
|
**Server**, **Workstation**, and **Cloud**.
|
|
|
|
## What you get
|
|
|
|
- A transparent, script-based build pipeline (no magic, everything auditable)
|
|
- `debootstrap` → package install → overlay → in-chroot configure → live ISO
|
|
- **Disk images + installer**: `make image-<edition>` builds bootable qcow2/raw
|
|
images; `scripts/install.sh` installs to a real disk (both share the
|
|
`deploy-disk.sh` core: partition → btrfs layout → GRUB → real fstab)
|
|
- **Secure by default**: hardened kernel cmdline + sysctl, default-deny
|
|
nftables, key-only ssh, AppArmor, no core dumps
|
|
- **btrfs-native**: subvolume layout, scheduled read-only snapshots, and
|
|
boot-to-snapshot rollback tooling
|
|
- **Zero telemetry**: enforced by package selection, masked apt timers, and
|
|
smoke tests that fail the build if telemetry is found
|
|
- **Pre-configured observability** (server): Prometheus + node_exporter +
|
|
Grafana (auto-provisioned) + Loki + promtail, local-only — Grafana/Loki/
|
|
promtail packaged as `.debs` by `make vendor`
|
|
- **The Arcline toolchain**: a harness that packages all 11 Go tools into
|
|
`.deb`s and installs them into the image
|
|
- **Optional secure boot**: MOK-based signing of the boot chain
|
|
(`ARCLINE_SIGN=1`)
|
|
- Smoke tests, GitLab CI, and docs that explain every decision
|
|
|
|
## Quickstart
|
|
|
|
```bash
|
|
# on a Debian-family host with root/sudo
|
|
make deps # install host build dependencies
|
|
make check # validate the tree (fast, offline)
|
|
make iso-server # build a bootable server ISO
|
|
make iso # build all three editions
|
|
make image-cloud # cloud edition as a qcow2 disk image
|
|
make toolchain # build the 11 Go tools into .deb
|
|
make vendor # build grafana/loki/promtail .debs
|
|
make iso-server-minimal # server ISO WITHOUT the Arcline toolchain
|
|
make test # run smoke tests against built rootfs(es)
|
|
```
|
|
|
|
Artifacts land in `build/artifacts/` with `.sha256` checksums.
|
|
|
|
The Arcline tools are **optional** in an image (`ARCLINE_TOOLCHAIN=auto|skip|
|
|
require`; see [building](docs/building.md#building-without-the-arcline-toolchain)).
|
|
|
|
## Layout
|
|
|
|
```
|
|
os-build/
|
|
├── Makefile # thin orchestration (make iso-<edition>)
|
|
├── versions.mk # single source of truth for versions/paths
|
|
├── editions/ # per-edition manifests (packages, cmdline, fstab, metadata)
|
|
├── overlays/ # files that land in the image (base + per-edition layers)
|
|
├── scripts/ # the build pipeline (all plain bash)
|
|
├── btrfs/ # subvolume layout, snapshots, rollback
|
|
├── toolchain/ # packaging for the 11 Go tools
|
|
├── observability/ # Prometheus/Grafana/Loki configs (docs + overlays/server)
|
|
├── tests/ # tree validation + rootfs smoke tests
|
|
├── ci/ # GitLab CI pipeline
|
|
└── docs/ # architecture, hardening, building, editions, ...
|
|
```
|
|
|
|
## Documentation
|
|
|
|
| Doc | Contents |
|
|
|-----|----------|
|
|
| [architecture](docs/architecture.md) | the design and how a build flows |
|
|
| [building](docs/building.md) | prerequisites, quickstart, outputs, knobs |
|
|
| [hardening](docs/hardening.md) | every hardening decision, and how to tune it |
|
|
| [editions](docs/editions.md) | server / workstation / cloud manifests |
|
|
| [observability](docs/observability.md) | the pre-configured monitoring stack |
|
|
| [toolchain](docs/toolchain.md) | the 11 Go tools and their packaging |
|
|
| [secureboot](docs/secureboot.md) | MOK key generation + signing workflow |
|
|
| [btrfs](btrfs/README.md) | subvolume layout + snapshots + rollback |
|
|
|
|
## Status
|
|
|
|
The build pipeline, edition manifests, hardening baseline, btrfs tooling,
|
|
observability packaging, disk images + installer, tests, CI, and optional
|
|
secure boot are all in place and runnable. What's next: a Microsoft-KEK signed
|
|
boot chain (only relevant for commercial distribution), `arm64` support, and
|
|
booted-VM verification tests.
|
|
|
|
## License
|
|
|
|
GPL-3.0 — see [LICENSE](LICENSE). Sponsored by Arcline IT LLC.
|
|
No telemetry. No tracking.
|