Files
os-build/docs/architecture.md
Blake Ridgway bb031ca92f chore: base Arcline OS on Debian trixie (current stable)
Bookworm became oldstable in July 2026 (standard support ended
2026-07-11). A new distro should be built on the current stable, which
is now Trixie (13.6): newer kernel (6.12 LTS vs 6.1, whose LTS ends Dec
2026), newer systemd/containers/toolchains, KDE 6 for the workstation
edition, and a year of stability behind it (full support until
2028-08-09).

- versions.mk / common.sh: DEBIAN_SUITE bookworm -> trixie, kernel 6.1 -> 6.12
- package list header comments: bookworm -> trixie
- GitLab CI: debian:bookworm -> debian:trixie build images
- docs (architecture, building): base references updated

All packages used across the three editions exist in Trixie unchanged.
2026-08-21 14:06:29 -05:00

86 lines
3.9 KiB
Markdown

# Arcline OS — architecture
This is the foundation ("the wires") for Arcline OS: a hardened, Debian-derived
operating system for people who run infrastructure. The landing page describes
the product; this repository is how it gets built.
## Design goals
1. **Secure by default** — hardened kernel, default-deny firewall, AppArmor,
locked-down ssh. You opt *in* to exposure, never out.
2. **Zero telemetry** — no phone-home, no analytics, no cloud integration.
3. **btrfs-native** — snapshots and boot-to-snapshot rollback are built in.
4. **Production-ready from first boot** — observability pre-configured, tools
pre-installed, everything documented.
5. **Auditable** — every script and config is plain text in this repo.
## How a build flows
```mermaid
flowchart LR
A[editions/* metadata] --> B[debootstrap<br/>Debian trixie]
B --> C[install edition<br/>packages.list]
C --> D[apply overlays<br/>base + edition]
D --> E[configure-system.sh<br/>in chroot]
E --> F[rootfs .tar.xz]
F --> G[grub-mkrescue + squashfs<br/>→ live ISO]
E -.toolchain .debs.-> C
```
Pipeline stages live in `scripts/`:
| Stage | Script | What it does |
|-------|--------|--------------|
| bootstrap | `build-rootfs.sh` | debootstrap minbase, apt sources, package install |
| overlay | `apply-overlays.sh` | copies `overlays/base` + `overlays/<edition>` into the rootfs |
| configure | `configure-system.sh` | runs *in the chroot*: hostname, locale, kernel cmdline, services, live-boot, toolchain |
| package | `build-iso.sh` | kernel + initramfs + squashfs → hybrid BIOS/UEFI ISO |
| image | `build-image.sh` | rootfs → bootable qcow2/raw disk image (via `deploy-disk.sh`) |
| deploy | `deploy-disk.sh` | partition → btrfs layout → copy rootfs → GRUB + fstab (shared by image + installer) |
| install | `install.sh` | scripted installer for a real disk (confirmation-gated) |
| orchestrate | `build-edition.sh` / `Makefile` | wire the above to `make iso-<edition>` |
## The source trees
| Path | Role |
|------|------|
| `editions/` | per-edition **manifests**: package lists, kernel cmdline, fstab, metadata |
| `overlays/` | **files that land in the image**, organised as layered rootfs trees |
| `scripts/` | the **build pipeline** (all plain bash, readable top to bottom) |
| `btrfs/`, `toolchain/`, `tests/`, `ci/` | supporting subsystems |
| `scripts/secureboot/` | MOK key generation + boot-chain signing (optional) |
There is no hidden magic: the Makefile is a thin wrapper, `versions.mk` /
`scripts/common.sh` hold the single source of truth for versions and paths.
## Zero telemetry, enforced
- No distro telemetry packages are installed (`ubuntu-report`,
`popularity-contest`, snapd are never in a package list).
- apt automatic-update timers are **masked** in every edition's metadata.
- The firewall's output chain never initiates calls on its own.
- cloud-init is pointed only at the configured cloud datasource.
- The smoke tests (`tests/smoke/verify-rootfs.sh`) fail the build if telemetry
artifacts are found.
## What "the wires" now covers
The four original follow-up items are implemented:
1. **Disk images**`make image-<edition>` produces bootable qcow2/raw images;
the cloud edition ships as a qcow2 by default.
2. **Installer**`scripts/install.sh <device>` installs to a real disk
(explicit confirmation, reuses the deploy module).
3. **Grafana/Loki/Promtail `.debs`**`make vendor` packages them so the full
observability stack installs without upstream repos.
4. **Secure boot** — MOK-based signing (`scripts/secureboot/`), off by
default, enabled with `ARCLINE_SIGN=1`.
## Still on the horizon
- A signed Microsoft-KEK boot chain (only relevant for commercial
distribution; the MOK path covers self-hosted use).
- ARM64 (`arm64`) as a first-class arch (one-line change in `versions.mk`).
- Boot-time verification tests for installed systems (the smoke tests cover
the image contents, not a booted VM yet).