Commit Graph

3 Commits (ed8fe12855912206a1b9bc2acd15568d8d6feda2)

Author SHA1 Message Date
Amir Alexander Abdelbaki 96f15c82af feat(archiso): embed every installer script at /installer, with an offline repo snapshot
The ISO carried only the three entry scripts launch.sh dispatches to;
tui-install.sh, its modules/ and the desktopenvs/ configs it deploys existed
solely inside the repo the installer clones at run time. A live environment
without working networking therefore ran the whole install and only failed at
the very last step, on a missing /home/<user>/Dotfiles/setup/tui-install.sh.

build.sh now embeds the entire setup/ tree at /installer (so every installer
script is on the ISO), plus a full repo snapshot — .git included, so a seeded
checkout is a real repo — at /installer/dotfiles. launch.sh moves there too
and the overlay/motd/docs follow; profiledef's file_permissions list is
repointed, which matters because mkarchiso hard-errors on an entry whose path
does not exist.

Tree resolution in both installers is now: an existing checkout, else a fresh
clone (online installs still get what is newest), else the ISO snapshot. Each
candidate is accepted only if it actually contains setup/tui-install.sh — the
old check was a bare `-d .git`, which any leftover or half-finished checkout
satisfied.

Sudo can no longer stop the install to ask for a password:
  - before the chroot hands over to the TUI, the temporary NOPASSWD drop-in is
    proven with `sudo -n true` and `sudo -n -v` (both forms modules rely on).
    A rule that didn't apply now skips the TUI instead of stalling forever on a
    hidden prompt, and the drop-in is removed on that path too rather than
    being left behind as permanent passwordless sudo;
  - tui-install.sh's root sudo shim moves to the top of the file, ahead of the
    require_jq() bootstrap that shells out through sudo, so running it as root
    straight from /installer never needs a real sudo binary.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 19:16:45 +02:00
Amir Alexander Abdelbaki 9cd8eb2065 feat(setup): add UEFI/Secure Boot preflight checks, force mkfs.btrfs, bake nomodeset into ISO
Both installers now fail fast if booted non-UEFI or warn on Secure Boot,
since GRUB install/NVRAM registration silently "succeeds" in both broken
cases and the failure only surfaces on next boot. mkfs.btrfs now forces
past leftover filesystem signatures on reinstalls. build.sh patches
nomodeset into every boot entry (BIOS/UEFI/PXE) to work around early-KMS
hangs on Optimus laptops (e.g. Lenovo Legion).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-29 08:33:25 +02:00
Amir Alexander Abdelbaki a73bc7cb93 refactor(setup): consolidate build/deploy tooling under setup/tools; docs
Move the build and deployment scripts into setup/tools alongside the existing
generators (proxmox-lxc-gen.sh, freeipa-image.sh, generate-modules.sh):
  - setup/generate-answerfile.sh   -> setup/tools/generate-answerfile.sh
  - setup/archiso/build.sh         -> setup/tools/build.sh
  - setup/archiso/wds-deploy.sh    -> setup/tools/wds-deploy.sh
  - setup/archiso/write-usb.sh     -> setup/tools/write-usb.sh

The archiso overlay/ (profile data: airootfs, profiledef.sh, packages.extra)
stays in setup/archiso/; build.sh now resolves it via an OVERLAY_DIR anchored
at the repo root, and DOTFILES_DIR is corrected for the new two-levels-deep
location. Updated every reference (generate-modules.sh, readme.md,
docs/md/{archiso,installation,index}.md).

generate-answerfile.sh: add linux-hardened to the kernel menu; verified its
emitted answerfile schema still matches every field the installers consume
(drive/kernel/keymap/hostname/username/password/luks_password/encrypt/
fido2_*/run_tui/components/desktop_environment/apps/shell_rc/colors).

Docs: add a dedicated ansipa Setup Guide (docs/md/ansipa-setup.md) covering
architecture, the full port list, the nginx portal + reverse-proxy paths, the
exact upstream reverse-proxy snippets (nginx/Caddy), NAT/push-mode behaviour,
and the Arch autofs/AUR caveat; link it from the index and cross-reference the
CheckMK/nginx ports from freeipa-ansible.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUhrcFU8J1Hnf7vNqNxZNi
2026-07-02 13:09:18 +02:00