Fixes found during a complete archiso → FreeIPA DC → client enrollment → ansipa policy deployment test cycle (Rocky 9 client VM, FreeIPA in Docker): arch-autoinstall.sh: - Add openssh to pacstrap — was missing, breaking headless/automated installs - Enable sshd at boot and set PermitRootLogin yes for post-install access ansipa-install-packages.sh: - Fix broken uninstall logic: three always-true conditions caused every package removal to be silently skipped; replace with a state-file-based approach that tracks packages installed by ansipa and removes only those when the IPA group disappears ansipa-enforce-policies.sh: - Add usr_admin policy: creates /etc/sudoers.d/ansipa-usr-admin granting full sudo to the FreeIPA usr_admin user group on every enrolled host; reverted when the IPA group is deleted - Add usr_prt_<printer> policy: auto-adds CUPS printers for FreeIPA user group members at login; printer URI stored in IPA group description; per-user ACL; reverted when group is deleted or membership ends deploy-ansipa-policies.yml: - Document usr_admin and usr_prt_* policies in header comment - Install cups package on clients (required for printer policy) FreeIPA container (image/): - Add docker-env.service: extracts IPA_*/SMB_*/LUKS_*/KEYCLOAK_* env vars from /proc/1/environ into /etc/container.env on container start; services read from there rather than relying on PassEnvironment (which is lost on container restart) - Add run.sh: wrapper that starts FreeIPA with --cgroupns host, required on cgroup v2 hosts (WSL2, recent Linux) because Docker Compose schema does not expose cgroupns_mode; also wires LUKS_KEY_UPLOAD_PASSWORD which the SMB service needs - Dockerfile: copy + enable docker-env.service; add glibc-langpack-en for locale - ansipa-smb.service: use EnvironmentFile=/etc/container.env (via docker-env.service) instead of PassEnvironment; add docker-env.service dependency - ipa-first-boot.service: add docker-env.service dependency + EnvironmentFile - ipa-first-boot.sh: add --skip-mem-check (container has limited cgroup memory visibility); remove --no-reverse from non-DNS path (was invalid without DNS) - docker-compose.yml: add prominent cgroupns note explaining when to use run.sh Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DHops6PU4c2Mv5UyhUj8Ms |
||
|---|---|---|
| alot | ||
| clamav | ||
| desktopenvs | ||
| docs | ||
| git | ||
| gtk-themes/cyberqueer | ||
| micro | ||
| notes | ||
| nvim | ||
| nvim.old | ||
| qt-themes/deprecated/cyberqueer | ||
| resources | ||
| setup | ||
| spotify-tui | ||
| yazi | ||
| .bashrc | ||
| .gitignore | ||
| .vimrc | ||
| .zshrc | ||
| apply-theme.sh | ||
| colors.conf | ||
| create-webapp.sh | ||
| decrypt.sh | ||
| encrypt.sh | ||
| etc-ly-config.ini | ||
| readme.md | ||
| readme.md.old | ||
| setup-creds-missing.sh | ||
| starship.toml | ||
| sysupdate.sh | ||
| update-aur-onebyone.sh | ||
| update.sh | ||
| wgq-projekt.sh | ||
| zshplugins.sh | ||
readme.md
M-Archy Dotfiles
Arch Linux · Hyprland · Wayland · CyberQueer
Production-grade Arch Linux config for network administration, development, and gaming.
Quick Start
git clone https://git.abdelbaki.eu/The_miro/Dotfiles.git ~/Dotfiles
bash ~/Dotfiles/setup/tui-install.sh
The TUI installer covers: packages, desktop environment, optional apps, and colour palette.
To add modules to an existing system: bash ~/Dotfiles/setup/install-modules.sh
Cliff Notes
- Single source of truth for colours — edit
colors.conf, runapply-theme.shto propagate everywhere. - Answerfile — generate with
setup/generate-answerfile.sh, place at/answerfile.jsonfor a fully automated install. Passwords are never stored in it. - Hostname uniqueness — the MAC address of the primary NIC is appended automatically when an answerfile hostname is set (
myhost→myhost-aabbccddee11). - LUKS encryption — backup key is auto-generated from
/dev/urandom, enrolled in a second LUKS slot, written to/_LUKS_BACKUP_KEY(root-only, inside the encrypted container). Collected by Ansible and stored on the SMBansipa-luks-keysshare (KeyAdmin-only read access). - Custom ISO —
setup/archiso/builds a live USB that can embed a pre-baked answerfile for zero-touch deployment. The live environment also includes a System Reset mode that reinstalls the root subvolume while preserving home data and FIDO2 auth keys. - FreeIPA + Keycloak + Samba container —
setup/modules/FreeipaAnsible/image/ships a singledocker compose upstack: FreeIPA for identity, Keycloak for OIDC, and Samba for scan-result and LUKS-key SMB shares. Host-group-driven policies (binary blocking, daemon enable/disable, daily scans, alert delivery) are enforced on enrolled clients every 30 minutes via Ansible-deployed timers. - Modular — core, shell, services, and desktop are independent components; pick only what you need.
Documentation
Full docs live in docs/md/ (Markdown) and docs/html/ (rendered).
| Topic | Markdown | HTML |
|---|---|---|
| Overview & repo layout | index.md | index.html |
| Installation (TUI, answerfile, ISO) | installation.md | installation.html |
| Hyprland desktop | hyprland.md | hyprland.html |
| Theming & CyberQueer palette | theming.md | theming.html |
| Optional modules & app catalogue | modules.md | modules.html |
| Custom Archiso builder | archiso.md | archiso.html |
| FreeIPA, Ansible, Keycloak & SMB | freeipa-ansible.md | freeipa-ansible.html |
| Editors (Neovim, Micro, Yazi) | editors.md | editors.html |
| Utilities (encrypt, ClamAV, updates) | utilities.md | utilities.html |
The old readme is preserved at
readme.md.old.