The edition package lists installed BOTH grub-pc and grub-efi-amd64 (+ shim-signed). Those provide the same bootloader role and conflict in apt, so every rootfs build failed with "unable to correct problems, you have held broken packages". A rootfs now carries exactly ONE bootloader, chosen by the BOOT variable (mirroring the existing --boot bios|efi deploy option): - versions.mk / common.sh: BOOT := bios (bios -> grub-pc, efi -> grub-efi-amd64 + shim-signed + mokutil), exported via the Makefile. - build-rootfs.sh validates BOOT early and injects the matching boot packages into the apt install; the static package lists no longer contain any grub package. - deploy-disk.sh / build-image.sh / install.sh default --boot from the same BOOT variable, so a rootfs and the artifact deployed from it can never disagree (BOOT=efi make image-cloud produces a UEFI image). - mokutil is now installed explicitly in the efi flavour (it was not pulled in because we install with --no-install-recommends). - docs updated (building.md knob + rationale, secureboot.md note).
62 lines
2.7 KiB
Plaintext
62 lines
2.7 KiB
Plaintext
# Arcline Cloud — package set
|
|
# Minimal footprint: cloud kernel, cloud-init, guest agents, storage tooling.
|
|
|
|
# ── base system ─────────────────────────────────────────────────────────────
|
|
systemd
|
|
systemd-sysv
|
|
dbus
|
|
libpam-systemd
|
|
ca-certificates
|
|
locales
|
|
tzdata
|
|
|
|
# ── boot ────────────────────────────────────────────────────────────────────
|
|
# The bootloader is chosen by the BOOT build variable and injected by
|
|
# build-rootfs.sh: bios → grub-pc, efi → grub-efi-amd64 + shim-signed.
|
|
# (Installing grub-pc and grub-efi-amd64 together makes apt fail with a
|
|
# "held broken packages" conflict — exactly one is ever installed.)
|
|
|
|
# ── kernel (cloud variant) ──────────────────────────────────────────────────
|
|
linux-image-cloud-amd64
|
|
|
|
# ── filesystem ──────────────────────────────────────────────────────────────
|
|
btrfs-progs
|
|
zstd
|
|
xz-utils
|
|
|
|
# ── cloud provisioning ──────────────────────────────────────────────────────
|
|
cloud-init
|
|
cloud-guest-utils
|
|
cloud-image-utils
|
|
open-vm-tools
|
|
qemu-guest-agent
|
|
|
|
# ── storage / block devices ─────────────────────────────────────────────────
|
|
nvme-cli
|
|
open-iscsi
|
|
multipath-tools
|
|
lvm2
|
|
mdadm
|
|
|
|
# ── security / hardening ────────────────────────────────────────────────────
|
|
openssh-server
|
|
nftables
|
|
apparmor
|
|
apparmor-utils
|
|
|
|
# ── observability (Debian-main components) ─────────────────────────────────
|
|
prometheus-node-exporter
|
|
|
|
# ── minimal admin tooling ───────────────────────────────────────────────────
|
|
curl
|
|
jq
|
|
git
|
|
rsync
|
|
htop
|
|
vim-tiny
|
|
|
|
# ── Arcline toolchain (built from toolchain/) ───────────────────────────────
|
|
# arcline-uptime arcline-check arcline-audit arcline-dns
|
|
# arcline-vault arcline-email arcline-migrate arcline-billing
|
|
# arcline-portal arcline-website arcline-status
|