Go to file
Amir Alexander Abdelbaki 268feaa1f2 feat(ansipa): add Nextcloud, and make FreeIPA the sole identity source
Adds a built-in Nextcloud to the ansipa stack and wires every service's
logins back to FreeIPA, either through Keycloak or directly.

Nextcloud:
  - nextcloud + redis services, sharing the existing postgres server via a
    second database. The initdb hook only fires on an empty data directory,
    so run.sh also creates the role/DB idempotently for stacks that predate
    Nextcloud.
  - served at the /nextcloud subpath of the gateway (OVERWRITEWEBROOT), with
    the /.well-known/* DAV redirects at the server root that sync clients and
    Nextcloud's own setup checks expect.

Identity:
  - keycloak-configure.sh now provisions confidential OIDC clients per relying
    party (nextcloud, proxmox-ve, proxmox-bs, opnsense) plus a realm-wide
    "groups" claim, writing secrets to .oidc-secrets (0600, gitignored).
  - nextcloud-configure.sh binds the IPA LDAP backend as the account source
    and user_oidc for login. The internal username is pinned to the IPA uid
    and unique-uid is disabled, otherwise every SSO login creates a second,
    empty account beside the LDAP one.
  - checkmk-ldap-configure.sh binds CheckMK straight to FreeIPA. CheckMK
    cannot go through Keycloak: SAML is commercial-edition only and no
    edition supports OIDC. The LDAP REST endpoints landed in 2.4 (werk
    #16527) but the stack pins 2.3, so it writes user_connections.mk —
    generated via Python repr() so quotes in a password cannot produce a
    SyntaxError that takes the GUI down, backed up and rolled back if the
    site fails to load it. Directory type is 389directoryserver, which is
    what gives FreeIPA the correct uid/member attribute defaults.

Monitoring:
  - OPNsense local check (gateways, pf state table vs its hard limit,
    firmware, CARP) plus an installer. POSIX sh, since OPNsense is FreeBSD
    with no bash or GNU grep. Transport is agent-over-SSH rather than inetd
    on 6556, because OPNsense regenerates inetd.conf/services/hosts.allow
    from config.xml and silently reverts those edits on reboot.

Fixes found along the way:
  - keycloak-configure.sh used KC_URL without the /auth relative path and
    probed /health/ready, which lives on management port 9000 and is not
    under that path — so it 404'd and timed out on this deployment.
  - .env.example had an unquoted `cn=Directory Manager`, which the shell
    scripts sourcing it parsed as a command named `Manager`.
  - summary heredocs printed raw escape codes; colours now use ANSI-C quoting.

docs/md/ansipa-sso.md covers the identity chain, the per-service support
matrix, Proxmox VE/PBS OpenID realm setup, and why packet captures should
not be tunnelled through the CheckMK API.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BWLuyyrydC1u2FjM7naPcz
2026-08-10 14:51:27 +02:00
alot fix(alot): stop shipping real mail identity as the tracked default 2026-07-30 16:30:02 +02:00
clamav chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
desktopenvs fix(astro-menu): stop the taskbar poll resetting the window list's scroll 2026-08-05 23:15:34 +02:00
docs feat(ansipa): add Nextcloud, and make FreeIPA the sole identity source 2026-08-10 14:51:27 +02:00
etc-greetd fix(hyprlua): match notif/audio-panel theming to eww's violet/magenta look 2026-07-30 20:03:18 +02:00
etc-lightdm feat(greeter): switch to greetd+ReGreet (Wayland), fix FIDO/scaling/wallpaper 2026-07-04 03:16:12 +02:00
etc-systemd-sleep feat(hyprlua): add orbit-menu radial power/utility menu 2026-07-17 09:51:02 +02:00
git amssh now themed 2026-05-11 13:26:02 +02:00
gtk-themes/cyberqueer feat(qt,gtk): overhaul theming — qt6ct style plugin, dark palette, GTK color-scheme 2026-05-19 13:43:13 +02:00
micro cleanup: archive deprecated configs, remove logs and merge artifacts 2026-05-08 10:13:12 +02:00
notes renamed old doc -> notes 2026-05-18 15:49:38 +02:00
nvim feat(nvim): auto-quit when only NERDTree/dadbod/Claude Code remain 2026-07-23 11:31:59 +02:00
nvim.old feat(nvim): convert config to Lua with lazy.nvim 2026-05-19 08:56:43 +02:00
qt-themes/deprecated/cyberqueer fixed theming issues 2026-05-19 14:39:29 +02:00
resources feat(plymouth): centred skull logo + boot-log tail, drop spinner 2026-07-04 03:18:44 +02:00
setup feat(ansipa): add Nextcloud, and make FreeIPA the sole identity source 2026-08-10 14:51:27 +02:00
spotify-tui added spotify tui 2024-11-20 01:12:57 +01:00
yazi yazi: remove invalid \$schema key from keymap.toml 2026-05-12 12:48:38 +02:00
.bashrc feat(archiso+branding): rebrand to m-archy, ship fastfetch logo and os-release 2026-06-26 09:50:39 +02:00
.gitignore added nohup.out to gitignore 2026-07-06 10:57:54 +02:00
.vimrc chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
.zshrc feat(archiso+branding): rebrand to m-archy, ship fastfetch logo and os-release 2026-06-26 09:50:39 +02:00
apply-theme.sh fix(greetd): give hyprlua its own plain greeter skin, separate from hyprdrive 2026-07-30 20:03:43 +02:00
colors.conf chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
create-webapp.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
decrypt.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
encrypt.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
etc-ly-config.ini we switching to ly 2026-02-12 10:35:05 +01:00
hyprdrive.md feat(hyprdrive): add hyprdrive DE with full Cosmonaut Shell suite 2026-07-17 15:28:07 +02:00
readme.md feat(ansipa): add Nextcloud, and make FreeIPA the sole identity source 2026-08-10 14:51:27 +02:00
readme.md.old docs: replace readme with cliff notes and links to full docs 2026-05-18 16:00:30 +02:00
setup-creds-missing.sh chmods 2026-06-01 15:37:40 +02:00
starship.toml reverted starship config because claude fucked it up 2026-06-25 14:11:14 +02:00
sysupdate.sh fix(greetd): give hyprlua its own plain greeter skin, separate from hyprdrive 2026-07-30 20:03:43 +02:00
update-aur-onebyone.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
update.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00
wgq-projekt.sh added school project vpn-connect script 2026-06-09 11:05:52 +02:00
zshplugins.sh chore: add inline comments across all modules and configs 2026-06-25 13:07:06 +02:00

readme.md

M-Archy Dotfiles

Arch Linux · Hyprland · Wayland · CyberQueer

Production-grade Arch Linux config for network administration, development, and gaming.


Quick Start

git clone https://git.abdelbaki.eu/The_miro/Dotfiles.git ~/Dotfiles
bash ~/Dotfiles/setup/tui-install.sh

The TUI installer covers: packages, desktop environment, optional apps, and colour palette. To add modules to an existing system: bash ~/Dotfiles/setup/install-modules.sh


Cliff Notes

  • Single source of truth for colours — edit colors.conf, run apply-theme.sh to propagate everywhere.
  • Answerfile — generate with setup/tools/generate-answerfile.sh, place at /answerfile.json for a fully automated install. Passwords are never stored in it.
  • Hostname uniqueness — the MAC address of the primary NIC is appended automatically when an answerfile hostname is set (myhostmyhost-aabbccddee11).
  • LUKS encryption — backup key is auto-generated from /dev/urandom, enrolled in a second LUKS slot, written to /_LUKS_BACKUP_KEY (root-only, inside the encrypted container). Collected by Ansible and stored on the SMB ansipa-luks-keys share (KeyAdmin-only read access).
  • Custom ISOsetup/archiso/ builds a live USB that can embed a pre-baked answerfile for zero-touch deployment. The live environment also includes a System Reset mode that reinstalls the root subvolume while preserving home data and FIDO2 auth keys.
  • FreeIPA + Keycloak + CheckMK + Nextcloud containersetup/modules/FreeipaAnsible/image/ ships a single docker compose up stack: FreeIPA for identity, Keycloak for OIDC, CheckMK for monitoring, Nextcloud for files/calendar/contacts, and Samba for LUKS-key SMB shares. FreeIPA is the single source of truth for accounts; see ansipa-sso.md. Host-group-driven policies (binary blocking, daemon enable/disable, daily scans, alert delivery) are enforced on enrolled clients every 30 minutes via Ansible-deployed timers.
  • Modular — core, shell, services, and desktop are independent components; pick only what you need.

Documentation

Full docs live in docs/md/ (Markdown) and docs/html/ (rendered).

Topic Markdown HTML
Overview & repo layout index.md index.html
Installation (TUI, answerfile, ISO) installation.md installation.html
Hyprland desktop hyprland.md hyprland.html
Theming & CyberQueer palette theming.md theming.html
Optional modules & app catalogue modules.md modules.html
Custom Archiso builder archiso.md archiso.html
FreeIPA, Ansible, Keycloak & SMB freeipa-ansible.md freeipa-ansible.html
ansipa Single Sign-On ansipa-sso.md ansipa-sso.html
Editors (Neovim, Micro, Yazi) editors.md editors.html
Utilities (encrypt, ClamAV, updates) utilities.md utilities.html

The old readme is preserved at readme.md.old.