Add the files that land in the image, organised as layered rootfs trees (base first, then the edition layer wins on conflict). - base: hardened kernel cmdline + sysctl, default-deny nftables, key-only ssh, persistent journald, module blacklist, no core dumps, snapshot timer units, motd. - server: Prometheus + auto-provisioned Grafana + Loki + promtail. - workstation: dev profile and desktop sysctl relaxations (perf, rootless containers). - cloud: cloud-init provisioning config.
13 lines
287 B
Plaintext
13 lines
287 B
Plaintext
# Arcline OS — journald
|
|
# Persistent, bounded, compressed logs. Logs live on @log so they survive
|
|
# system rollbacks (see btrfs/README.md).
|
|
|
|
[Journal]
|
|
Storage=persistent
|
|
Compress=yes
|
|
SystemMaxUse=500M
|
|
SystemMaxFileSize=100M
|
|
MaxRetentionSec=14day
|
|
ForwardToSyslog=no
|
|
ForwardToConsole=no
|