F41: Add iot base bootc image

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
This commit is contained in:
Paul Whalen 2024-09-27 16:51:54 -04:00
commit 750a452d9d
8 changed files with 136 additions and 45 deletions

View file

@ -1,9 +0,0 @@
# Enable automatic updates by default
postprocess:
- |
#!/usr/bin/env bash
set -euo pipefail
target=/usr/lib/systemd/system/default.target.wants
mkdir -p $target
set -x
ln -s ../bootc-fetch-apply-updates.timer $target

View file

@ -1,10 +0,0 @@
# Configuration for bootc
postprocess:
# ext4 is our default filesystem in iot
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/bootc/install/
cat > /usr/lib/bootc/install/20-default-root.toml << EOF
[install]
root-fs-type = "ext4"
EOF

View file

@ -13,7 +13,7 @@ packages-s390x:
# provided by s390utils-base, but soon will be -core too.
- /usr/sbin/zipl
packages-x86_64:
- grub2 grub2-efi-x64 efibootmgr shim
- grub2-efi-x64 efibootmgr shim
- microcode_ctl
conditional-include:

View file

@ -6,13 +6,13 @@ postprocess:
cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF'
# We want a generic image; hostonly makes no sense as part of a server side build
hostonly=no
dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
EOF
cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF'
# Extra modules that we want by default that are known to exist in the kernel
dracutmodules+=" virtiofs "
add_dracutmodules+=" virtiofs "
EOF
cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF'
# We want this for systemd-cryptsetup tpm2 locking
dracutmodules+=" tpm2-tss "
add_dracutmodules+=" systemd-cryptsetup tpm2-tss "
EOF

113
fedora-bootc-base/iot.yaml Normal file
View file

@ -0,0 +1,113 @@
# Fedora IoT specific packages
packages:
- fedora-release-iot
- aardvark-dns
- atheros-firmware
- attr
- authselect
- basesystem
- bash
- bash-completion
- bootc
- brcmfmac-firmware
- chrony
- clevis
- clevis-dracut
- clevis-luks
- clevis-pin-tpm2
- container-selinux
- containernetworking-plugins
- coreutils
- cracklib-dicts
- criu
- criu-libs
- cryptsetup
- curl
- dbus-parsec
- dnf5-plugins
- dosfstools
- dracut-config-generic
- dracut-network
- e2fsprogs
- efibootmgr
- fdo-client
- firewalld
- fwupd
- fwupd-efi
- fwupd-plugin-modem-manager
- fwupd-plugin-uefi-capsule-data
- glibc
- glibc-minimal-langpack
- gnupg2
- greenboot
- greenboot-default-health-checks
- gzip
- hostname
- ignition
- ima-evm-utils
- iproute
- iputils
- iwd
- iwlwifi-mvm-firmware
- kernel-tools
- keyutils
- less
- libsss_sudo
- linux-firmware
- lvm2
- netavark
- NetworkManager
- NetworkManager-wifi
- NetworkManager-wwan
- nss-altfiles
- openssl
- openssh-clients
- openssh-server
- passt
- passt-selinux
- parsec
- pinentry
- podman
- policycoreutils
- policycoreutils-python-utils
- polkit
- procps-ng
- realtek-firmware
- rootfiles
- rpm
- screen
- selinux-policy-targeted
- setools-console
- setup
- shadow-utils
- skopeo
- slirp4netns
- sssd-client
- sudo
- systemd
- systemd-resolved
- tar
- tmux
- tpm2-pkcs11
- traceroute
- usbguard
- util-linux
- vim-minimal
- wpa_supplicant
- wireless-regdb
- xfsprogs
- xz
- zezere-ignition
- zram-generator
- zram-generator-defaults
packages-aarch64:
- arm-image-installer
- bcm283x-firmware
- grub2-efi-aa64
- optee_client
- shim-aa64
- uboot-images-armv8
packages-x86_64:
- grub2-efi-x64
- microcode_ctl
- shim-x64

View file

@ -50,13 +50,15 @@ remove-from-packages:
include:
- bootc.yaml
- bootupd.yaml
- ostree.yaml
- bootc-config.yaml
- initramfs.yaml
- autoupdates.yaml
- basic-fixes.yaml
- iot.yaml
packages:
# needed for building derived container images
- dnf5
# Even in tier-0, we have this. If you don't want SELinux today, you'll need
# to build a custom image.
- selinux-policy-targeted
@ -64,8 +66,3 @@ packages:
- container-selinux
# Needed for tpm2 bound luks
- tpm2-tools
# See https://github.com/coreos/bootupd
arch-include:
x86_64: bootupd.yaml
aarch64: bootupd.yaml

View file

@ -1,15 +0,0 @@
releasever: rawhide
variables:
distro: "fedora"
repos:
- fedora-rawhide
metadata:
name: fedora-bootc
summary: Fedora base bootc image
include:
- fedora-bootc-base/manifest.yaml
- fedora-bootc-base/kernel.yaml

15
fedora-iot-bootc.yaml Normal file
View file

@ -0,0 +1,15 @@
releasever: 41
variables:
distro: "fedora-iot"
repos:
- fedora-41
metadata:
name: fedora-iot-bootc-base
summary: Fedora IoT bootc base image
include:
- fedora-bootc-base/manifest.yaml
- fedora-bootc-base/kernel.yaml