Commit Graph

  • 5e7b96e582 Remove unnecessary config main Tommy 2025-06-12 09:16:14 -07:00
  • e93575a87f Add docker-auto-update Tommy 2025-06-12 02:55:44 -07:00
  • bffb50dd7a Make Notes smaller Tommy 2025-06-12 02:38:28 -07:00
  • 48b5df3957 Switch back to Docker Tommy 2025-06-12 02:37:49 -07:00
  • 90b5b42aa9 Download gvisor at first boot Tommy 2025-06-10 14:39:31 -07:00
  • c193aecd1e Fix /etc/ld.so.preload handling Tommy 2025-06-08 03:31:06 -07:00
  • 494371382f Reorganize postinst.service Tommy 2025-06-08 03:11:52 -07:00
  • 7b3f274d3a Reschedule gvisor and podman update schedule Tommy 2025-06-07 23:07:27 -07:00
  • 768715d076 Cleanup & enable podman-auto-update Tommy 2025-06-06 02:19:12 -07:00
  • f79017fd3e Fix chrony.conf Tommy 2025-06-05 04:10:22 -07:00
  • 0c69141cac Add containers.conf and reallow systemd-resolved Tommy 2025-06-05 03:57:34 -07:00
  • 65f05d7e76 Update README.md Tommy 2025-06-05 03:11:21 -07:00
  • 6b592afe0f Repo cleanup Tommy 2025-06-05 03:06:25 -07:00
  • fa060e74d8 Full removal of systemd-resolved Tommy 2025-06-04 17:04:52 -07:00
  • 8f064a9c08 Hard code DNS resolver IP for Metropolis Nexus Tommy 2025-06-02 13:56:07 -07:00
  • 94be1579c6 Syntax fix Tommy 2025-06-02 13:11:49 -07:00
  • 2da19bf47e Make stamp before editting ld.so.preload Tommy 2025-06-02 06:04:40 -07:00
  • a9871c9452 Daily updates Tommy 2025-06-02 05:57:57 -07:00
  • cc7b76262e Simplify removal Tommy 2025-06-02 05:27:59 -07:00
  • 5369e16d8c Update module blacklist URL Tommy 2025-06-02 04:44:14 -07:00
  • 1bab888069 Update butane spec Tommy 2025-06-02 04:37:48 -07:00
  • 931620b545 Repo cleanup Tommy 2025-06-02 04:18:35 -07:00
  • 44f68f326e Daily Updates Tommy 2025-06-02 03:19:52 -07:00
  • c25323a8b6 coreos-cni-networking-check no longer exists Tommy 2025-06-02 03:05:10 -07:00
  • 9471469cca Remove FCOS 40 -> 41 notes Tommy 2025-05-28 18:19:28 -07:00
  • 34046ac8f9 Update kargs Tommy 2025-05-28 18:19:01 -07:00
  • 776c3ef8d3 Update sshd override location Tommy 2025-04-20 23:20:12 -07:00
  • 3b649130a9 Update chrony config location Tommy 2025-04-18 14:12:03 -07:00
  • 7278fd8753 Update blacklist file name Tommy 2025-01-10 15:22:47 -07:00
  • b609589ea1 Remove unnecessary comment Tommy 2025-01-10 15:20:14 -07:00
  • 32a770c5a0 Reduce overrides Tommy 2025-01-10 15:18:20 -07:00
  • 8ec5731965 Repo clean up Tommy 2025-01-10 15:14:10 -07:00
  • 144bf15b74 Update conflict resolution instruction Tommy 2025-01-10 15:06:38 -07:00
  • b08e7b7aad Remove exytra firmware packages Tommy 2024-12-19 20:29:38 -07:00
  • a50917bf04 Update to FCOS 41 Tommy 2024-12-19 20:20:40 -07:00
  • 4ef166f60f Fix systemd ssh override Tommy 2024-10-15 14:39:46 -07:00
  • 89d390ca5b Update Ignition file Tommy 2024-10-08 14:33:04 -07:00
  • cac37c848b Cleaner gvisor-updater ExecStart Tommy 2024-10-08 14:05:51 -07:00
  • 7a207ba742 Fix docker-compose-updater dependency Tommy 2024-09-27 16:31:58 -07:00
  • 46f5a8070d Fix scheduling for docker-compose-updater@.service Tommy 2024-09-26 19:20:35 -07:00
  • 74acd37ef2 Update gvisor updater service Tommy 2024-09-26 19:00:34 -07:00
  • 18593b03fd Update package removal list Tommy 2024-09-24 15:37:01 -07:00
  • ec61164648 Update modprobe URL Tommy 2024-07-26 05:10:01 -07:00
  • c04b7a84f9 Update after Blue-OCI rebuilds Tommy 2024-07-21 20:03:39 -07:00
  • 18d5d4b591 Update on Tuesday and Friday Tommy 2024-07-05 06:00:17 -07:00
  • b2df161d15 Update gvisor updater Tommy 2024-06-28 22:45:25 -07:00
  • bb8041a73a New gvisor-updater.service Tommy 2024-06-28 16:13:33 -07:00
  • b674e55d42 Unbound systemd hardening moved to Linux-Setup-Scripts Tommy 2024-06-25 22:32:16 -07:00
  • 7f470747b9 Unbound listen on ::1 Tommy 2024-06-24 02:34:55 -07:00
  • 540f5f1774 Do not remove resolved Tommy 2024-06-21 15:09:58 -07:00
  • 14446d8c6b No Unbound on UTM Tommy 2024-06-21 15:07:58 -07:00
  • 0d634e5051 Unbound for container Tommy 2024-06-21 15:06:09 -07:00
  • d88311198c Switch to UTC Tommy 2024-06-20 05:21:05 -07:00
  • 7fad7ab23b Panic on oops Tommy 2024-06-17 01:19:59 -07:00
  • 4eef6410bb Remove Divested PGP key Tommy 2024-06-09 05:35:45 -07:00
  • 551814f15c Remove divested repo Tommy 2024-06-09 05:35:13 -07:00
  • e49c2c5ca4 Rename server-blacklist to vps-blacklist Tommy 2024-06-07 04:51:45 -07:00
  • d9bd0f9563 Use secureblue hardenedmalloc Tommy 2024-06-06 22:54:40 -07:00
  • 37ab9797c7 Disable coredump in systemd as well Tommy 2024-06-04 14:09:50 -07:00
  • 71d681ff8b Use custom config and SecureBlue whenever possible Tommy 2024-06-04 13:58:01 -07:00
  • 1a38e16151 Remove bind overrides Tommy 2024-05-31 14:24:56 -07:00
  • 13a4d89a69 Better regex for kernel module blacklist Tommy 2024-05-31 13:49:45 -07:00
  • 64efef581c Add escapes for regex Tommy 2024-05-31 13:37:30 -07:00
  • d06e7489e9 Beter regex Tommy 2024-05-31 13:16:38 -07:00
  • f9823a43e4 Better regex Tommy 2024-05-31 02:36:47 -07:00
  • 0eda27d343 Update overrides for F40 Tommy 2024-05-28 16:21:59 -07:00
  • d3e0ea0f35 Add notes to fix FCOS 39 -> 40 upgrade Tommy 2024-05-28 14:22:23 -07:00
  • 4295b7e075 Update gvisor-downloader Tommy 2024-05-28 13:48:13 -07:00
  • 3cb75ee460 Remove 5 seconds wait Tommy 2024-05-27 15:15:41 -07:00
  • 4906ea33d8 Update kargs Tommy 2024-05-27 13:23:30 -07:00
  • e5f5980e0c Use After=network-online.target Tommy 2024-05-22 12:17:24 -07:00
  • 8d6447c67b /etc/issue moved to Linux-Setup-Scripts Tommy 2024-05-16 23:18:07 -07:00
  • c320659852 zram-generator config moved to Linux-Setup-Scripts Tommy 2024-05-16 22:27:06 -07:00
  • f6751a1597 Workaround for unbound-keygen Tommy 2024-05-06 23:47:45 -07:00
  • 2e0f0719cd Update docker-compose-updater Tommy 2024-05-03 14:55:36 -07:00
  • 147945e752 Rearrange kargs Tommy 2024-04-19 14:50:41 -07:00
  • 02ae78dfec Add trailing white space Tommy 2024-04-12 16:45:15 -07:00
  • 7b62e6d24f Update docker-compose-updater.service Tommy 2024-04-09 15:15:34 -07:00
  • e579cf0cf1 Disable mdns and dhcpv6-client for x86 QEMU Tommy 2024-04-05 15:53:36 -07:00
  • c6a758d8a0 Switch to using systemd timer for container update Tommy 2024-04-05 14:21:39 -07:00
  • 4b109fa93b Disable msr Tommy 2024-04-05 13:43:06 -07:00
  • 2f67145fd1 Update ptrace settings Tommy 2024-03-24 14:38:07 -07:00
  • c3481cbcc8 Disable coreos-cni-networking-check.service Tommy 2024-03-24 14:00:46 -07:00
  • 2ecb5662fc Enable module sig enforce and lockdown=confidentiality Tommy 2024-03-05 14:52:54 -07:00
  • f5411aab36 Add ARM hardened malloc Tommy 2024-03-05 14:24:45 -07:00
  • 9ee6949e84 Fix rpm-ostree kargs --editor Tommy 2024-03-05 14:06:08 -07:00
  • 652b549e71 FCOS has already fixed SELinux handling Tommy 2024-02-29 11:39:21 -07:00
  • 0721f0d393 Fix /var labels Tommy 2024-02-29 10:48:58 -07:00
  • 0e29af560f ld_preload fix Tommy 2024-02-28 10:47:05 -07:00
  • 469358b8ed Add serial port support for Proxmox Tommy 2024-02-28 09:40:01 -07:00
  • 3f8465e696 Use systemd units section to disable kdump and debug-shell Tommy 2024-02-27 21:56:58 -07:00
  • 0adadc1932 Add missing stamp for postinst2 Tommy 2024-02-27 18:48:17 -07:00
  • bf92773f86 Fix GPG signature Tommy 2024-02-27 18:41:02 -07:00
  • 46285b769e Single quote echo Tommy 2024-02-27 02:19:44 -07:00
  • e754f3a5eb ld.preload path does not needed to be hardcoded Tommy 2024-02-27 00:19:46 -07:00
  • 3ec705b520 Remove extra_latent_entropy from karg file Tommy 2024-02-26 23:38:22 -07:00
  • 6f0bf8d8a7 Implement hardened_malloc, rename to x86_64-v3 Tommy 2024-02-26 23:36:13 -07:00
  • 3cb35c79d5 Remove extra_latent_entropy Tommy 2024-02-26 21:00:56 -07:00
  • e5f1e9d988 Move coredump.conf to Linux-Setup-Scripts Tommy 2024-02-13 17:02:21 -07:00
  • 0ed3ff3b7f Better regex for nullok Tommy 2024-02-13 16:56:59 -07:00