Add the files that land in the image, organised as layered rootfs trees (base first, then the edition layer wins on conflict). - base: hardened kernel cmdline + sysctl, default-deny nftables, key-only ssh, persistent journald, module blacklist, no core dumps, snapshot timer units, motd. - server: Prometheus + auto-provisioned Grafana + Loki + promtail. - workstation: dev profile and desktop sysctl relaxations (perf, rootless containers). - cloud: cloud-init provisioning config.
13 lines
262 B
Desktop File
13 lines
262 B
Desktop File
[Unit]
|
|
Description=Arcline btrfs snapshot
|
|
Documentation=file:///usr/local/sbin/arcline-snapshot
|
|
RequiresMountsFor=/.snapshots
|
|
After=local-fs.target
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStart=/usr/local/sbin/arcline-snapshot snapshot
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|