Blake Ridgway 18167fc70e feat: add grafana/loki/promtail vendor .debs
- toolchain/build-vendor.sh: packages the observability components that
  are not in Debian main — grafana (official OSS deb, vendored as-is),
  loki + promtail (static binaries from the Loki GitHub release, wrapped
  in minimal debs that install the overlays/server configs and systemd
  units from toolchain/vendor/). Version-pinned, overridable, and
  download failures skip with a warning (never break the OS build).
- configure-system.sh: auto-enables grafana-server/loki/promtail when
  their binaries land in the image.
- New `make vendor` target.
2026-08-21 13:33:17 -05:00
2026-08-21 13:15:43 -05:00

Arcline OS — build system

The Linux OS for people who run infrastructure. Hardened Debian base. Pre-configured monitoring, auditing, and security tooling. Zero telemetry.

This repository is the build system ("the wires") behind Arcline OS. It turns a Debian base and a set of plain-text manifests into hardened, bootable operating system images for three editions: Server, Workstation, and Cloud.

What you get

  • A transparent, script-based build pipeline (no magic, everything auditable)
  • debootstrap → package install → overlay → in-chroot configure → live ISO
  • Secure by default: hardened kernel cmdline + sysctl, default-deny nftables, key-only ssh, AppArmor, no core dumps
  • btrfs-native: subvolume layout, scheduled read-only snapshots, and boot-to-snapshot rollback tooling
  • Zero telemetry: enforced by package selection, masked apt timers, and smoke tests that fail the build if telemetry is found
  • Pre-configured observability (server): Prometheus + node_exporter + Grafana (auto-provisioned) + Loki + promtail, local-only
  • The Arcline toolchain: a harness that packages all 11 Go tools into .debs and installs them into the image
  • Smoke tests, GitLab CI, and docs that explain every decision

Quickstart

# on a Debian-family host with root/sudo
make deps              # install host build dependencies
make check             # validate the tree (fast, offline)
make iso-server        # build a bootable server ISO
make iso               # build all three editions
make toolchain         # build the 11 Go tools into .deb
make iso-server-minimal # server ISO WITHOUT the Arcline toolchain
make test              # run smoke tests against built rootfs(es)

Artifacts land in build/artifacts/ with .sha256 checksums.

The Arcline tools are optional in an image (ARCLINE_TOOLCHAIN=auto|skip| require; see building).

Layout

os-build/
├── Makefile            # thin orchestration (make iso-<edition>)
├── versions.mk         # single source of truth for versions/paths
├── editions/           # per-edition manifests (packages, cmdline, fstab, metadata)
├── overlays/           # files that land in the image (base + per-edition layers)
├── scripts/            # the build pipeline (all plain bash)
├── btrfs/              # subvolume layout, snapshots, rollback
├── toolchain/          # packaging for the 11 Go tools
├── observability/      # Prometheus/Grafana/Loki configs (docs + overlays/server)
├── tests/              # tree validation + rootfs smoke tests
├── ci/                 # GitLab CI pipeline
└── docs/               # architecture, hardening, building, editions, ...

Documentation

Doc Contents
architecture the design and how a build flows
building prerequisites, quickstart, outputs, knobs
hardening every hardening decision, and how to tune it
editions server / workstation / cloud manifests
observability the pre-configured monitoring stack
toolchain the 11 Go tools and their packaging
btrfs subvolume layout + snapshots + rollback

Status

This is the foundation: the build pipeline, edition manifests, hardening baseline, btrfs tooling, observability configs, tests, and CI are in place and runnable. The next milestones (installer that writes the btrfs layout to disk, cloud disk images, signed releases) are listed in docs/architecture.md.

License

GPL-3.0 — see LICENSE. Sponsored by Arcline IT LLC. No telemetry. No tracking.

Description
No description provided
Readme 232 KiB
Languages
Shell 82.8%
Python 9.6%
Makefile 7.6%