Commit Graph

164 Commits

Author SHA1 Message Date
Tommy
e579cf0cf1 Disable mdns and dhcpv6-client for x86 QEMU
Signed-off-by: Tommy <contact@tommytran.io>
2024-04-05 15:53:36 -07:00
Tommy
c6a758d8a0 Switch to using systemd timer for container update
Signed-off-by: Tommy <contact@tommytran.io>
2024-04-05 14:21:39 -07:00
Tommy
4b109fa93b Disable msr
Signed-off-by: Tommy <contact@tommytran.io>
2024-04-05 13:43:06 -07:00
Tommy
2f67145fd1 Update ptrace settings
Signed-off-by: Tommy <contact@tommytran.io>
2024-03-24 14:38:07 -07:00
Tommy
c3481cbcc8 Disable coreos-cni-networking-check.service
Signed-off-by: Tommy <contact@tommytran.io>
2024-03-24 14:00:46 -07:00
Tommy
2ecb5662fc Enable module sig enforce and lockdown=confidentiality
Signed-off-by: Tommy <contact@tommytran.io>
2024-03-05 14:52:54 -07:00
Tommy
f5411aab36 Add ARM hardened malloc
Signed-off-by: Tommy <contact@tommytran.io>
2024-03-05 14:24:45 -07:00
Tommy
9ee6949e84 Fix rpm-ostree kargs --editor
Signed-off-by: Tommy <contact@tommytran.io>
2024-03-05 14:06:08 -07:00
Tommy
652b549e71 FCOS has already fixed SELinux handling
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-29 11:39:21 -07:00
Tommy
0721f0d393 Fix /var labels
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-29 10:48:58 -07:00
Tommy
0e29af560f ld_preload fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-28 10:47:05 -07:00
Tommy
469358b8ed Add serial port support for Proxmox
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-28 09:40:01 -07:00
Tommy
3f8465e696 Use systemd units section to disable kdump and debug-shell
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-27 21:56:58 -07:00
Tommy
0adadc1932 Add missing stamp for postinst2
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-27 18:48:17 -07:00
Tommy
bf92773f86 Fix GPG signature
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-27 18:41:02 -07:00
Tommy
46285b769e Single quote echo
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-27 02:19:44 -07:00
Tommy
e754f3a5eb ld.preload path does not needed to be hardcoded
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-27 00:19:46 -07:00
Tommy
3ec705b520 Remove extra_latent_entropy from karg file
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-26 23:38:22 -07:00
Tommy
6f0bf8d8a7 Implement hardened_malloc, rename to x86_64-v3
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-26 23:36:13 -07:00
Tommy
3cb35c79d5 Remove extra_latent_entropy
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-26 21:00:56 -07:00
Tommy
e5f1e9d988 Move coredump.conf to Linux-Setup-Scripts
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 17:02:21 -07:00
Tommy
0ed3ff3b7f Better regex for nullok
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 16:56:59 -07:00
Tommy
a6f5adde00 Space before nullok
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 16:50:28 -07:00
Tommy
3f9d70c9f1 Update on Friday instead
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 16:33:31 -07:00
Tommy
bb9719eff6 Implement /etc/issue
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 16:01:42 -07:00
Tommy
472dd72cc6 Rename VM to QEMU
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 15:09:49 -07:00
Tommy
baf5ca9334 Remove more packages
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-13 14:18:04 -07:00
Tommy
c8611cf3dd Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-11 04:27:32 -07:00
Tommy
6e0729b203 Remove more unneeded packages
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-11 04:21:48 -07:00
Tommy
e0c04ff5b6 Update gvisor-downloader.service description
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 19:52:02 -07:00
Tommy
2155a601e1 Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:54:33 -07:00
Tommy
96e6a41ec6 Update kargs
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:41:30 -07:00
Tommy
30896a69c8 Cleaup .gitignore
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:39:48 -07:00
Tommy
a939832941 Remove workspace config
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:39:14 -07:00
Tommy
8c627c88d9 docker-compose-updater requires docker.service
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:38:17 -07:00
Tommy
d61e21c966 Reimplement Docker Compose Plugin in Generic.yml
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:32:49 -07:00
Tommy
e06a0066f7 Update README.md
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:22:37 -07:00
Tommy
f7a8f005b6 Let zincati use "localtime" because TZ is alr MST
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:22:24 -07:00
Tommy
9ddc479705 Update copyright year
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:13:26 -07:00
Tommy
34712aa7bf Reconfigure Zincati
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 12:03:47 -07:00
Tommy
d48591d194 Fix gVisor downloader
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 11:33:33 -07:00
Tommy
dc0a155c30 More typo fixes
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 11:20:52 -07:00
Tommy
dca71564e7 Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 10:54:09 -07:00
Tommy
461e4bca05 Fix gVisor Updater
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 10:37:36 -07:00
Tommy
4bad3e63a0 Split out configs
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 10:02:45 -07:00
Tommy
89b9395dfe Code cleanup
Signed-off-by: Tommy <contact@tommytran.io>
2024-02-07 07:27:18 -07:00
Tommy
8b6b26ad75 Fix unbound config typo
Signed-off-by: Tommy <contact@tommytran.io>
2024-01-26 06:36:59 -07:00
Tommy
ef4d004c52 Add No-Config
Signed-off-by: Tommy <contact@tommytran.io>
2024-01-16 14:21:28 -07:00
Tommy
9e687de707 Fix chrony.conf
Signed-off-by: Tommy <contact@tommytran.io>
2024-01-16 02:29:26 -07:00
Tommy
57f6171df3 Bug fixes
Signed-off-by: Tommy <contact@tommytran.io>
2024-01-15 08:49:56 -07:00