Files
os-build/README.md
Blake Ridgway a27d3fb313 docs: document disk images, installer, vendor packaging, and secure boot
- docs/secureboot.md: MOK workflow (generate, build, enroll).
- docs/building.md: image + install quickstart, new outputs, ARCLINE_SIGN.
- docs/observability.md: vendor .debs are now the primary packaging path.
- docs/editions.md: cloud ships a qcow2; qemu test command.
- docs/architecture.md: full pipeline table incl. deploy/install; the
  four follow-up items are now implemented; new "on the horizon" list.
- README: updated feature list, quickstart, and status.
2026-08-21 13:33:17 -05:00

95 lines
4.4 KiB
Markdown

# Arcline OS — build system
> The Linux OS for people who run infrastructure. Hardened Debian base.
> Pre-configured monitoring, auditing, and security tooling. Zero telemetry.
This repository is the build system ("the wires") behind
[Arcline OS](https://arcline.it). It turns a Debian base and a set of plain-text
manifests into hardened, bootable operating system images for three editions:
**Server**, **Workstation**, and **Cloud**.
## What you get
- A transparent, script-based build pipeline (no magic, everything auditable)
- `debootstrap` → package install → overlay → in-chroot configure → live ISO
- **Disk images + installer**: `make image-<edition>` builds bootable qcow2/raw
images; `scripts/install.sh` installs to a real disk (both share the
`deploy-disk.sh` core: partition → btrfs layout → GRUB → real fstab)
- **Secure by default**: hardened kernel cmdline + sysctl, default-deny
nftables, key-only ssh, AppArmor, no core dumps
- **btrfs-native**: subvolume layout, scheduled read-only snapshots, and
boot-to-snapshot rollback tooling
- **Zero telemetry**: enforced by package selection, masked apt timers, and
smoke tests that fail the build if telemetry is found
- **Pre-configured observability** (server): Prometheus + node_exporter +
Grafana (auto-provisioned) + Loki + promtail, local-only — Grafana/Loki/
promtail packaged as `.debs` by `make vendor`
- **The Arcline toolchain**: a harness that packages all 11 Go tools into
`.deb`s and installs them into the image
- **Optional secure boot**: MOK-based signing of the boot chain
(`ARCLINE_SIGN=1`)
- Smoke tests, GitLab CI, and docs that explain every decision
## Quickstart
```bash
# on a Debian-family host with root/sudo
make deps # install host build dependencies
make check # validate the tree (fast, offline)
make iso-server # build a bootable server ISO
make iso # build all three editions
make image-cloud # cloud edition as a qcow2 disk image
make toolchain # build the 11 Go tools into .deb
make vendor # build grafana/loki/promtail .debs
make iso-server-minimal # server ISO WITHOUT the Arcline toolchain
make test # run smoke tests against built rootfs(es)
```
Artifacts land in `build/artifacts/` with `.sha256` checksums.
The Arcline tools are **optional** in an image (`ARCLINE_TOOLCHAIN=auto|skip|
require`; see [building](docs/building.md#building-without-the-arcline-toolchain)).
## Layout
```
os-build/
├── Makefile # thin orchestration (make iso-<edition>)
├── versions.mk # single source of truth for versions/paths
├── editions/ # per-edition manifests (packages, cmdline, fstab, metadata)
├── overlays/ # files that land in the image (base + per-edition layers)
├── scripts/ # the build pipeline (all plain bash)
├── btrfs/ # subvolume layout, snapshots, rollback
├── toolchain/ # packaging for the 11 Go tools
├── observability/ # Prometheus/Grafana/Loki configs (docs + overlays/server)
├── tests/ # tree validation + rootfs smoke tests
├── ci/ # GitLab CI pipeline
└── docs/ # architecture, hardening, building, editions, ...
```
## Documentation
| Doc | Contents |
|-----|----------|
| [architecture](docs/architecture.md) | the design and how a build flows |
| [building](docs/building.md) | prerequisites, quickstart, outputs, knobs |
| [hardening](docs/hardening.md) | every hardening decision, and how to tune it |
| [editions](docs/editions.md) | server / workstation / cloud manifests |
| [observability](docs/observability.md) | the pre-configured monitoring stack |
| [toolchain](docs/toolchain.md) | the 11 Go tools and their packaging |
| [secureboot](docs/secureboot.md) | MOK key generation + signing workflow |
| [btrfs](btrfs/README.md) | subvolume layout + snapshots + rollback |
## Status
The build pipeline, edition manifests, hardening baseline, btrfs tooling,
observability packaging, disk images + installer, tests, CI, and optional
secure boot are all in place and runnable. What's next: a Microsoft-KEK signed
boot chain (only relevant for commercial distribution), `arm64` support, and
booted-VM verification tests.
## License
GPL-3.0 — see [LICENSE](LICENSE). Sponsored by Arcline IT LLC.
No telemetry. No tracking.