Merge branch '2025-05-updates' into 'main'

2025 05 updates

See merge request greg/vms!20
This commit is contained in:
Greg Hellings
2025-07-14 04:48:14 +00:00
36 changed files with 577 additions and 11 deletions
+2 -2
View File
@@ -1,8 +1,8 @@
distro = "almalinux"
version = "9"
iso = {
url = "https://mirrors.kernel.org/almalinux/9.5/isos/x86_64/AlmaLinux-9.5-x86_64-boot.iso"
checksum = "3038fb71a29d33c3c93117bd8f4c3f612cb152dce057c666b6b11dfa793fb65c"
url = "https://mirrors.kernel.org/almalinux/9.6/isos/x86_64/AlmaLinux-9.6-x86_64-boot.iso"
checksum = "113521ec7f28aa4ab71ba4e5896719da69a0cc46cf341c4ebbd215877214f661"
}
boot_command = [
"<up>e<wait>",
+2 -2
View File
@@ -1,8 +1,8 @@
distro = "archlinux"
version = "rolling"
iso = {
url = "https://mirror.rackspace.com/archlinux/iso/2025.03.01/archlinux-2025.03.01-x86_64.iso"
checksum = "8150e3c1a479de9134baa13cea4ff78856cca5ebeb9bdfa87ecfce2e47ac9b5b"
url = "https://mirror.rackspace.com/archlinux/iso/2025.05.01/archlinux-2025.05.01-x86_64.iso"
checksum = "2008e6becc86d207272625c94a388d2ee3b14d6a24b401552d8105c4e82c96db"
}
boot_command = [
"e<down><down><down><end> net.ifnames=0 biosdevnames=0 <enter>",
+2 -2
View File
@@ -1,8 +1,8 @@
distro = "debian"
version = "12"
iso = {
url = "https://cdimage.debian.org/cdimage/release/12.10.0/amd64/iso-cd/debian-12.10.0-amd64-netinst.iso"
checksum = "ee8d8579128977d7dc39d48f43aec5ab06b7f09e1f40a9d98f2a9d149221704a"
url = "https://cdimage.debian.org/cdimage/release/12.11.0/arm64/iso-cd/debian-12.11.0-arm64-netinst.iso"
checksum = "5c050c495770ee9b076261cb8025a99a4866a15a4e3cdab2f59c49e8f69fb0ee"
}
boot_command = [
"<down>e<wait><down><down><down><end><bs><bs><bs><bs><bs><bs><bs><bs><bs><bs>",
+181
View File
@@ -0,0 +1,181 @@
user --name=vagrant --password=vagrant
rootpw --plaintext vagrant
text # don't use cmdline -- https://github.com/rhinstaller/anaconda/issues/931
lang en_US.UTF-8
keyboard us
timezone --utc Etc/UTC
selinux --enforcing
firewall --disabled
# We pass net.ifnames=0 because we always want to use eth0 here on all the cloud images.
bootloader --timeout=1 --location=mbr --append="no_timer_check net.ifnames=0 console=tty1 console=ttyS0,115200n8 biosdevnames=0"
services --enabled=sshd
# Configure for gpt with bios+uefi
clearpart --all --initlabel --disklabel=gpt
part prepboot --size=4 --fstype=prepboot
part biosboot --size=1 --fstype=biosboot
part /boot/efi --size=100 --fstype=efi
part /boot --size=1000 --fstype=ext4 --label=boot
part btrfs.007 --size=2000 --fstype=btrfs --grow
btrfs none --label=fedora btrfs.007
btrfs /home --subvol --name=home LABEL=fedora
btrfs / --subvol --name=root LABEL=fedora
repo --name=fedora --mirrorlist=https://mirrors.fedoraproject.org/mirrorlist?repo=fedora-$releasever&arch=$basearch
repo --name=updates --mirrorlist=https://mirrors.fedoraproject.org/mirrorlist?repo=updates-released-f$releasever&arch=$basearch
url --mirrorlist=https://mirrors.fedoraproject.org/mirrorlist?repo=fedora-$releasever&arch=$basearch
reboot
##### begin package list #############################################
%packages --instLangs=en
# Include packages for the cloud-server-environment group
@^cloud-server-environment
# Install the tracer dnf plugin to enable automatic reboots
# IF the user requests package updates
# AND requests a reboot
# AND the packages updated require a reboot.
# https://fedoraproject.org/wiki/Changes/Automatic_Cloud_Reboot_On_Updates
python3-dnf-plugin-tracer
# Don't include the kernel toplevel package since it pulls in
# kernel-modules. We're happy for now with kernel-core.
-kernel
kernel-core
# Don't include dracut-config-rescue. It will have dracut generate a
# "rescue" entry in the grub menu, but that also means there is a
# rescue kernel and initramfs that get created, which (currently) add
# about another 40MiB to the /boot/ partition. Also the "rescue" mode
# is generally not useful in the cloud.
-dracut-config-rescue
# Plymouth provides a graphical boot animation. In the cloud we don't
# need a graphical boot animation. This also means anaconda won't put
# rhgb/quiet on kernel command line
-plymouth
# Install qemu-guest-agent https://pagure.io/cloud-sig/issue/319 To
# improve the integration with OpenStack and other VM management
# systems (oVirt, KubeVirt).
qemu-guest-agent
# No need for firewalld for now. We don't have a firewall on by default.
-firewalld
# Don't include the geolite2 databases, which end up with 66MiB
# in /usr/share/GeoIP
-geolite2-country
-geolite2-city
# Specific to vagrant
rsync
fuse-sshfs
%end
##### end package list ###############################################
##### begin kickstart post ###########################################
%post --erroronfail
#!/bin/bash
set -x
if [ -e /dev/vda ]; then
device="/dev/vda"
elif [ -e /dev/sda ]; then
device="/dev/sda"
else
echo "No device found"
exit 1
fi
virt="$(systemd-detect-virt)"
if [ "${virt}" == "microsoft" ]; then
dnf install -y hyperv-daemons
systemctl enable hpervfcopyd
systemctl enable hypervkvpd
systemctl enable hypervvssd
fi
if [ "$(arch)" = "x86_64" ]; then
# Set up legacy BIOS boot if we booted from UEFI
grub2-install --target=i386-pc "${device}"
fi
# Blivet sets pmbr_boot flag erroneously and we need to purge it
# otherwise it'll fail to boot
parted "${device}" disk_set pmbr_boot off
# linux-firmware is installed by default and is quite large. As of mid 2020:
# Total download size: 97 M
# Installed size: 268 M
# So far we've been fine shipping without it so let's continue.
# More discussion about this in #1234504.
echo "Removing linux-firmware package."
rpm -e linux-firmware
# See the systemd-random-seed.service man page that says:
# " It is recommended to remove the random seed from OS images intended
# for replication on multiple systems"
echo "Removing random-seed so it's not the same in every image."
rm -f /var/lib/systemd/random-seed
echo "Import RPM GPG key"
releasever=$(rpm --eval '%{fedora}')
basearch=$(uname -i)
rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
echo "Zeroing out empty space."
# Create zeros file with nodatacow and no compression
touch /var/tmp/zeros
chattr +C /var/tmp/zeros
# This forces the filesystem to reclaim space from deleted files
dd bs=1M if=/dev/zero of=/var/tmp/zeros || :
echo "(Don't worry -- that out-of-space error was expected.)"
# Force sync to disk (Cf. https://pagure.io/cloud-sig/issue/340#comment-743430)
btrfs filesystem sync /
rm -f /var/tmp/zeros
btrfs filesystem sync /
# When we build the image a networking config file gets left behind.
# Let's clean it up.
echo "Cleanup leftover networking configuration"
rm -f /etc/NetworkManager/system-connections/*.nmconnection
#*/
# Truncate the /etc/resolv.conf left over from NetworkManager during the
# kickstart. This causes delays in boot with cloud-init because the
# 192.168.122.1 DNS server cannot be reached.
truncate -s 0 /etc/resolv.conf
# Clear machine-id on pre generated images
truncate -s 0 /etc/machine-id
# Vagrant setup
sed -i 's,Defaults\\s*requiretty,Defaults !requiretty,' /etc/sudoers
echo 'vagrant ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/vagrant-nopasswd
sed -i 's/.*UseDNS.*/UseDNS no/' /etc/ssh/sshd_config
cat > /etc/ssh/sshd_config.d/10-vagrant-insecure-rsa-key.conf <<EOF
# For now the vagrant insecure key is an rsa key
# htfedoratps://github.com/hashicorp/vagrant/issues/11783
PubkeyAcceptedKeyTypes=+ssh-rsa
EOF
ssh-keygen -A
mkdir -m 0700 -p /home/vagrant/.ssh/
curl -L -o /home/vagrant/.ssh/authorized_keys "https://raw.githubusercontent.com/hashicorp/vagrant/main/keys/vagrant.pub"
chown -R vagrant:vagrant /home/vagrant/.ssh
chmod 600 /home/vagrant/.ssh/authorized_keys
chcon -R unconfined_u:object_r:user_home_t:s0 /home/vagrant/.ssh
%end
##### end kickstart post ############################################
+14
View File
@@ -0,0 +1,14 @@
distro = "fedora"
version = "42"
iso = {
url = "https://ohioix.mm.fcix.net/fedora/linux/releases/42/Server/x86_64/iso/Fedora-Server-netinst-x86_64-42-1.1.iso"
checksum = "231f3e0d1dc8f565c01a9f641b3d16c49cae44530074bc2047fe2373a721c82f"
}
boot_command = [
"<up>e<down><down><end> ",
"net.ifnames=0 biosdevnames=0 inst.ks=cdrom:/amd64-ks.cfg inst.notmux <f10>"
]
cd_files = [
"distros/fedora/42/*.cfg"
]
vbox_os_type = "Fedora_64"
+6
View File
@@ -0,0 +1,6 @@
#!/usr/bin/env bash
set -ex
dnf -y update
dnf clean all
+6
View File
@@ -0,0 +1,6 @@
#!/usr/bin/env bash
set -ex
dnf install -y qemu-guest-agent
systemctl start qemu-guest-agent
systemctl enable qemu-guest-agent
+6
View File
@@ -0,0 +1,6 @@
#!/usr/bin/env bash
set -ex
dnf install -y virtualbox-guest-additions
systemctl start vboxservice
systemctl enable vboxservice
+4
View File
@@ -0,0 +1,4 @@
#!/usr/bin/env bash
set -ex
dnf install -y open-vm-tools
+6 -1
View File
@@ -17,13 +17,18 @@
{
version = "40";
arch = "amd64";
eol = false;
eol = true;
}
{
version = "41";
arch = "amd64";
eol = false;
}
{
version = "42";
arch = "amd64";
eol = false;
}
{
version = "rawhide";
arch = "amd64";
+41
View File
@@ -0,0 +1,41 @@
#!env bash
set -exo pipefail
# Name of the file to write out
name="${0%.sh}"
version="25.05"
# Base URL
base="https://channels.nixos.org/nixos-${version}/latest-nixos-minimal-x86_64-linux.iso"
# Working directory
tmp="$(mktemp -d)"
checksums="${tmp}/checksums"
# Read the SHA256 sum value
curl -L -o "${checksums}" "${base}.sha256"
until curl -f -L -o "${checksums}" "${base}.sha256"; do
sleep 1
done
sha="$(grep -e minimal "${checksums}" | cut -d' ' -f 1)"
# Write out HCL file
cat << EOF > "${name}"
distro = "nixos"
version = "${version}"
iso = {
url = "${base}"
checksum = "${sha}"
}
boot_command = [
"curl -o /tmp/install.sh http://{{ .HTTPIP }}:{{ .HTTPPort }}/install.sh<enter>",
"<wait>",
"sudo bash /tmp/install.sh {{ .HTTPPort }} {{ .HTTPIP }}<enter>"
]
http_directory = "distros/nixos/${version}/http/"
boot_wait = "90s"
EOF
rm -r "${tmp}"
rm -f "cache/latest-nixos-minimal-x86_64-linux.iso"
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env bash
set -ex
@@ -0,0 +1,73 @@
{
pkgs,
lib,
...
}:
{
imports = [
./hardware-configuration.nix
./guest-agent.nix
];
system.stateVersion = "24.11";
# Packages installed on the whole system
environment.systemPackages = with pkgs; [
curl
nano
python3
];
# Services that are running
services = {
openssh.enable = true;
#xserver.enable = true;
};
# User setup
users.groups.vagrant = { };
users.users.vagrant = {
isNormalUser = true;
group = "vagrant";
extraGroups = [ "wheel" ];
password = "vagrant";
};
security.sudo.extraRules = [
{
users = [ "vagrant" ];
groups = [ "vagrant" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
boot.loader = {
systemd-boot = {
enable = true;
};
efi.canTouchEfiVariables = true;
};
networking = {
hostName = "vagrant";
networkmanager.enable = true;
#proxy.default = "http://user:password@proxy:port/";
#proxy.noProxy = "127.0.0.1,localhost,internal.domain";
};
time.timeZone = "UTC";
i18n.defaultLocale = "en_US.UTF-8";
console = {
font = "Lat2-Terminux16";
keyMap = lib.mkForce "us";
useXkbConfig = true;
};
nix = {
settings = {
experimental-features = "nix-command flakes";
};
};
}
+16
View File
@@ -0,0 +1,16 @@
{
description = "A basic NixOS Vagrant install";
inputs = {
nixstable.url = "github:nixos/nixpkgs/nixos-25.05";
};
outputs =
{ nixstable, ... }:
{
nixosConfigurations.vagrant = nixstable.lib.nixosSystem {
system = "x86_64-linux";
modules = [ ./configuration.nix ];
};
};
}
+4
View File
@@ -0,0 +1,4 @@
{ ... }:
{
services.qemuGuest.enable = true;
}
@@ -0,0 +1,4 @@
{ ... }:
{
virtualisation.hypervGuest.enable = true;
}
+6
View File
@@ -0,0 +1,6 @@
{ ... }:
{
virtualisation.virtualbox.guest = {
enable = true;
};
}
+4
View File
@@ -0,0 +1,4 @@
{ ... }:
{
services.qemuGuest.enable = true;
}
+7
View File
@@ -0,0 +1,7 @@
{ ... }:
{
virtualisation.vmware.guest = {
enable = true;
headless = false;
};
}
+10
View File
@@ -0,0 +1,10 @@
#!/usr/bin/env bash
set -ex
# Set passwords
echo "vagrant:vagrant" | chpasswd
echo "root:vagrant" | chpasswd
# Set ownership of things vagrant should own
chown -R vagrant:vagrant ~vagrant/
chown -R vagrant:wheel /etc/nixos
+64
View File
@@ -0,0 +1,64 @@
#!/usr/bin/env bash
#vim: set ft=bash:
set -ex
port="${1}" # HTTP port that packer is running on
host="${2}"
if [ -e /dev/vda ]; then
disk="/dev/vda"
elif [ -e /dev/sda ]; then
disk="/dev/sda"
else
exit 1 # Need to teach the script which device to use in this case
fi
# The sed bit is just to strip out the extra fluff, like comments
sed -e 's/\s*\([\+0-9a-zA-Z]*\).*/\1/' << EOF | fdisk ${disk}
g # create new GPT partition table
n # new
# default partition number
# default start
+512M # size
t # set type
1 # EFI system partition
n # second partition
# default partition number
# start at first free sector
# default to full disk
p # print, for debugging
w # write the partition table and exit
EOF
sleep 10 # Let me at least read it!
#t # set partition type
#1 # on partition 1
#4 # BIOS boot
# Format and mount partitions
mkfs.vfat "${disk}1"
mkfs.ext4 "${disk}2"
mount "${disk}2" /mnt
mkdir -p /mnt/boot
mount "${disk}1" /mnt/boot
# Bootstrap system
virt="$(systemd-detect-virt)"
nixos-generate-config --root /mnt
curl -o /mnt/etc/nixos/configuration.nix "http://${host}:${port}/configuration.nix"
curl -o /mnt/etc/nixos/flake.nix "http://${host}:${port}/flake.nix"
curl -o /mnt/etc/nixos/guest-agent.nix "http://${host}:${port}/ga-${virt}.nix"
sed -i -E -e "s,@BOOT_DEVICE@,${disk}," /mnt/etc/nixos/configuration.nix
nixos-install --no-root-password --flake "/mnt/etc/nixos/#vagrant"
# Run stuff in the chroot
curl -o /mnt/root/in-chroot.sh "http://${host}:${port}/in-chroot.sh"
nixos-enter --root /mnt -c 'bash /root/in-chroot.sh'
rm /mnt/root/in-chroot.sh
umount /mnt/boot
umount /mnt
efibootmgr --bootnext "$(efibootmgr | grep Linux | awk '{print $1}' | sed -E 's/[^0-9]//g')"
reboot
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env bash
set -ex
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env bash
set -ex
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env bash
set -ex
+6 -1
View File
@@ -12,11 +12,16 @@
{
version = "24.05";
arch = "amd64";
eol = false;
eol = true;
}
{
version = "24.11";
arch = "amd64";
eol = true;
}
{
version = "25.05";
arch = "amd64";
eol = false;
}
]
+2 -2
View File
@@ -1,8 +1,8 @@
distro = "opensuse"
version = "16.0"
iso = {
url = "https://download.opensuse.org/distribution/leap/16.0/installer/iso/agama-installer-Leap.x86_64-16.0.0-Leap-Build105.1.iso"
checksum = "63784c9b201704cfc146065b24bbc7df082f2891f6ab6a5457753aa2fc1dbe26"
url = "https://download.opensuse.org/distribution/leap/16.0/installer/iso/agama-installer-Leap.x86_64-16.0.0-Leap-Build120.5.iso"
checksum = "9da557e454a5cfb9aad8e1385de0003efd9bd4531e08459385f1169b3c0bfd25"
}
boot_command = [
"e<wait>",
+1 -1
View File
@@ -12,7 +12,7 @@
{
version = "16.0";
arch = "amd64";
eol = false; # Not yet released, and bugged at the moment
eol = false;
}
{
version = "tumbleweed";
+19
View File
@@ -0,0 +1,19 @@
distro = "ubuntu"
version = "25.04"
iso = {
url = "https://releases.ubuntu.com/25.04/ubuntu-25.04-live-server-amd64.iso"
checksum = "8b44046211118639c673335a80359f4b3f0d9e52c33fe61c59072b1b61bdecc5"
}
boot_command = [
"e<down><down><down><end><bs><bs><bs>",
"fsck.mode=skip ",
"locale=en_US ",
"auto=true ",
"priority=critical ",
"autoinstall",
"<F10>",
]
cd_files = [
"distros/ubuntu/25.04/disc/*"
]
vbox_os_type = "Ubuntu_64"
View File
+47
View File
@@ -0,0 +1,47 @@
#cloud-config
# vim: set ft=yaml:
autoinstall:
version: 1
network: # Should disable networking, workaround for unattended-updates failing in install
version: 2
ethernets:
eth0:
match:
name: e*
dhcp4: yes
dhcp6: no
refresh-installer:
update: no
keyboard:
layout: us
toggle: null
variant: ''
locale: en_US.UTF-8
identity:
hostname: vagrant
username: vagrant
password: $6$rounds=4096$mJTRlY/vwPMquLe0$s4Ld3ZnvF.pM86xzbAgQD7Xpi/NMVgyQNb5CEfabFgL6nLRsP56WtwA.o.Jg/xC6HaJmM2p5fCGIo37jmKVRI0
ssh:
install-server: yes
authorized_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTkyrtvp9eWW6A8YVr+kz4TjGYe7gHzIw+niNltGEFHzD8+v1I2YJ6oXevct1YeS0o9HZyN1Q9qgCgzUFtdOKLv6IedplqoPkcmF0aYet2PkEDo3MlTBckFXPITAMzF8dJSIFo9D8HfdOV0IAdx4O7PtixWKn5y2hMNG0zQPyUecp4pzC6kivAIhyfHilFR61RGL+GPXQ2MWZWFYbAGjyiYJnAmCP3NOTd0jMZEnDkbUvxhMmBYSdETk1rRgm+R4LOzFUGaHqHDLKLX+FIPKcF96hrucXzcWyLbIbEgE98OHlnVYCzRdK8jlqm8tehUc9c9WhQ== vagrant insecure public key
allow-pw: yes
user-data:
disable_root: false
package_update: false
package_upgrade: false
late-commands:
- echo 'Defaults:vagrant !requiretty' > /target/etc/sudoers.d/vagrant
- echo 'vagrant ALL=(ALL) NOPASSWD:ALL' >> /target/etc/sudoers.d/vagrant
- chmod 440 /target/etc/sudoers.d/vagrant
- >-
curtin in-target --target=/target --
bash -c 'if [ "$(systemd-detect-virt)" == "microsoft" ]; then
apt-get update;
apt-get install -y linux-azure;
fi'
- curtin in-target --target=/target -- logger "finished late-commands"
packages:
- ca-certificates
- curl
- sudo
+16
View File
@@ -0,0 +1,16 @@
#!/usr/bin/env bash
set -ex
apt remove cloud-init -y
apt update
apt upgrade -y
# Make sshd faster
cat << EOF > /etc/ssh/sshd_config.d/00-vagrant_accept_pubkey.conf
UseDNS no
PubkeyAcceptedKeyTypes +ssh-rsa
EOF
# Clean up after ourselves
apt-get clean
+6
View File
@@ -0,0 +1,6 @@
#!/usr/bin/env bash
set -ex
apt install -y qemu-guest-agent
systemctl start qemu-guest-agent
systemctl enable qemu-guest-agent
+4
View File
@@ -0,0 +1,4 @@
#!/usr/bin/env bash
set -ex
apt install -y virtualbox-guest-utils
+4
View File
@@ -0,0 +1,4 @@
#!/usr/bin/env bash
set -ex
apt install -y open-vm-tools
+5
View File
@@ -27,6 +27,11 @@
{
version = "24.10";
arch = "amd64";
eol = true;
}
{
version = "25.04";
arch = "amd64";
eol = false;
}
]
+1
View File
@@ -63,6 +63,7 @@
packages =
(with pkgs; [
packer
vagrant
])
++ (with self'.packages; [