Define the three flagship editions as plain-text manifests: - server (bastion): production server - observability stack, containers. - workstation (forge): curated KDE Plasma + dev toolchains. - cloud (nimbus): cloud kernel, cloud-init, guest agents. Each manifest carries metadata (services to enable/mask), a package list, a hardened kernel cmdline, and a btrfs fstab template.
29 lines
440 B
Plaintext
29 lines
440 B
Plaintext
# Arcline Cloud — kernel command line
|
|
# Same hardening baseline, serial console for cloud serial ports, no graphics.
|
|
|
|
console=tty0
|
|
console=ttyS0,115200n8
|
|
quiet
|
|
loglevel=3
|
|
systemd.show_status=auto
|
|
|
|
# hardening
|
|
init_on_alloc=1
|
|
init_on_free=1
|
|
slab_nomerge
|
|
page_poison=1
|
|
pti=on
|
|
spectre_v2=on
|
|
spec_store_bypass=on
|
|
tsx=off
|
|
lockdown=integrity
|
|
oops=panic
|
|
panic=-1
|
|
|
|
# cloud / disk
|
|
net.ifnames=0
|
|
biosdevname=0
|
|
|
|
# btrfs / storage
|
|
rootflags=subvol=@
|