Files
os-build/editions/workstation/kernel.cmdline
Blake Ridgway 729f191950 feat: add server, workstation, and cloud edition manifests
Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
2026-08-21 13:15:43 -05:00

25 lines
403 B
Plaintext

# Arcline Workstation — kernel command line
# Same hardening baseline as server, without the serial console and with
# graphics-friendly settings.
console=tty0
quiet
loglevel=3
systemd.show_status=auto
# hardening
init_on_alloc=1
init_on_free=1
slab_nomerge
page_poison=1
pti=on
spectre_v2=on
spec_store_bypass=on
tsx=off
lockdown=integrity
oops=panic
panic=-1
# btrfs / storage
rootflags=subvol=@