98 lines
2.5 KiB
Bash
98 lines
2.5 KiB
Bash
# vim: set ft=sh :
|
|
text
|
|
url --url http://fedora.mirror.constant.com/fedora/linux/releases/32/Everything/x86_64/os/
|
|
repo --name=updates --baseurl=http://fedora.mirror.constant.com/fedora/linux/updates/32/Everything/x86_64/
|
|
lang en_US.UTF-8
|
|
keyboard us
|
|
timezone --utc UTC
|
|
rootpw --lock
|
|
reboot
|
|
|
|
ignoredisk --only-use=nvme0n1
|
|
bootloader --location mbr --append "console=ttyS0,115200 quiet systemd.show_status=1"
|
|
clearpart --all --initlabel
|
|
reqpart
|
|
part /boot --fstype xfs --mkfsoptions "-m crc=0" --size=200
|
|
part pv.01 --fstype lvmpv --size=46180 --grow
|
|
volgroup vmhost0 pv.01
|
|
logvol / --fstype xfs --name=root --vgname=vmhost0 --size=3072
|
|
logvol /home --fstype xfs --name=home --vgname=vmhost0 --size=100
|
|
logvol /var --fstype xfs --name=var --vgname=vmhost0 --size=8192
|
|
logvol /var/log --fstype xfs --name=var_log --vgname=vmhost0 --size=2048
|
|
logvol swap --fstype swap --name=swap --vgname=vmhost0 --size=32768 --grow
|
|
|
|
%packages --exclude-weakdeps --excludedocs
|
|
-NetworkManager
|
|
-authconfig
|
|
-authselect
|
|
-dhcp-client
|
|
-dnf-plugins-core
|
|
-dnf-yum
|
|
-dracut-config-rescue
|
|
-e2fsprogs
|
|
-iputils
|
|
-man-db
|
|
-openssh-clients
|
|
-parted
|
|
-plymouth
|
|
-sssd-common
|
|
-sssd-kcm
|
|
-vim-minimal
|
|
-yum
|
|
audit
|
|
chrony
|
|
cracklib-dicts
|
|
dnf
|
|
dnf-command(system-upgrade)
|
|
openssh-server
|
|
selinux-policy-targeted
|
|
%end
|
|
|
|
services --enabled systemd-networkd,systemd-resolved
|
|
|
|
%addon com_redhat_kdump --disable
|
|
%end
|
|
|
|
%post --erroronfail
|
|
echo vmhost0.pyrocufflink.blue > /etc/hostname
|
|
|
|
echo 'install_weak_deps=0' >> /etc/dnf/dnf.conf
|
|
echo 'deltarpm=0' >> /etc/dnf/dnf.conf
|
|
echo '%_excludedocs 1' >> /etc/rpm/macros
|
|
|
|
systemctl mask systemd-journald-audit.socket
|
|
|
|
install -m700 -d /root/.ssh
|
|
cat >> /root/.ssh/authorized_keys <<EOF
|
|
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJsL5fSylmiJmBtW0DH/viAAmtU2E/2M17GPvysiyRs+ dustin@rosalina
|
|
EOF
|
|
|
|
# Configure GRUB2 to display the menu on the serial console
|
|
cat >> /etc/default/grub <<EOF
|
|
GRUB_TERMINAL="serial"
|
|
GRUB_SERIAL_COMMAND="serial --speed=115200"
|
|
EOF
|
|
grub2-mkconfig -o /boot/efi/EFI/fedora/grub.cfg
|
|
|
|
rm -rf /etc/sysconfig/network-scripts /etc/sysconfig/network
|
|
|
|
# Generate SSH host keys before first boot, since / will be read-only then
|
|
/usr/libexec/openssh/sshd-keygen ecdsa
|
|
/usr/libexec/openssh/sshd-keygen ed25519
|
|
/usr/libexec/openssh/sshd-keygen rsa
|
|
|
|
cat > /etc/systemd/network/30-enp5s0.network <<EOF
|
|
[Match]
|
|
Name=enp5s0
|
|
|
|
[Network]
|
|
Address=172.30.0.18/26
|
|
Gateway=172.30.0.1
|
|
DNS=172.30.0.4
|
|
EOF
|
|
|
|
# Enable read-only rootfs. This cannot be done with part/logvol, as that would
|
|
# make Anaconda mount it read-only befor the installation starts.
|
|
sed -i -r '/\S+\s+\/\s+/s/defaults/ro/' /etc/fstab
|
|
%end
|