Define the three flagship editions as plain-text manifests: - server (bastion): production server - observability stack, containers. - workstation (forge): curated KDE Plasma + dev toolchains. - cloud (nimbus): cloud kernel, cloud-init, guest agents. Each manifest carries metadata (services to enable/mask), a package list, a hardened kernel cmdline, and a btrfs fstab template.
36 lines
1.0 KiB
Plaintext
36 lines
1.0 KiB
Plaintext
# Arcline Server — kernel command line
|
|
# Hardening flags + console config. Kept explicit and auditable.
|
|
#
|
|
# Security notes:
|
|
# init_on_alloc / init_on_free — zero freshly allocated/freed memory
|
|
# slab_nomerge — disable merging of similar slab objects
|
|
# page_poison=1 — fill freed pages to catch use-after-free
|
|
# pti=on — kernel page-table isolation
|
|
# spectre_v2=on spec_store_bypass=on — mitigations on (no auto-off)
|
|
# tsx=off — disable TSX (TAA mitigations)
|
|
# lockdown=integrity — block unsigned kernel modifications
|
|
# oops=panic panic=-1 — panic (and stay down) on oops
|
|
# quiet loglevel=3 — quiet serial console boot
|
|
|
|
console=tty0
|
|
console=ttyS0,115200n8
|
|
quiet
|
|
loglevel=3
|
|
systemd.show_status=auto
|
|
|
|
# hardening
|
|
init_on_alloc=1
|
|
init_on_free=1
|
|
slab_nomerge
|
|
page_poison=1
|
|
pti=on
|
|
spectre_v2=on
|
|
spec_store_bypass=on
|
|
tsx=off
|
|
lockdown=integrity
|
|
oops=panic
|
|
panic=-1
|
|
|
|
# btrfs / storage
|
|
rootflags=subvol=@
|