-
-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy pathlf-debian.cfg
More file actions
177 lines (137 loc) · 7.84 KB
/
Copy pathlf-debian.cfg
File metadata and controls
177 lines (137 loc) · 7.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
# Debian Preseed Configuration
# Author: Linuxfabrik GmbH, Zurich, Switzerland
# Contact: info (at) linuxfabrik (dot) ch
# https://www.linuxfabrik.ch/
# License: The Unlicense, see LICENSE file.
# This preseed file is the Debian equivalent of lf-rhel.cfg.
# It provides a minimal Debian installation with LVM partitioning.
#
# Note: Preseed only works with the Debian Installer (d-i).
# It does NOT work with Ubuntu 20.04+ (which uses autoinstall/subiquity).
#
# Usage:
# Boot from a Debian netinst/DVD ISO, press ESC at the boot menu, then:
# boot: auto url=http://<server>/<path>/lf-debian.cfg
# Or press 'e' on the "Install" entry and append:
# auto url=http://<server>/<path>/lf-debian.cfg
#
# Version stamp (YYYYMMDDNN): LF_KICKSTART_VERSION=2026042401
# See CONTRIBUTING "Versioning the Kickstart File" for the bump rules. The
# same literal must appear in the early_command and late_command blocks
# below; it is logged via logger(1) at install time (lands in /var/log/syslog
# and later /var/log/installer/syslog) and written to /root/lf-install-version
# on the installed system so any host can be traced back to a specific
# lf-debian.cfg build.
### Version stamp
d-i preseed/early_command string \
logger -t linuxfabrik-preseed 'Linuxfabrik Kickstart version: 2026042401'
### Localization
d-i debian-installer/locale string en_US.UTF-8
d-i keyboard-configuration/xkb-keymap select us
### Network
# DHCP is the default. Do not set explicit network options to allow
# kernel cmdline settings to take effect.
d-i netcfg/choose_interface select auto
d-i netcfg/get_hostname string localhost
d-i netcfg/get_domain string localdomain
### Mirror
d-i mirror/country string manual
d-i mirror/http/hostname string deb.debian.org
d-i mirror/http/directory string /debian
d-i mirror/http/proxy string
### Clock and timezone
d-i clock-setup/utc boolean true
d-i time/zone string Europe/Zurich
d-i clock-setup/ntp boolean true
### Users
# Do not create a root account (locks root, similar to lf-rhel.cfg)
d-i passwd/root-login boolean false
# Create linuxfabrik user with password 'password' (change after first login)
# SHA-512 hash of 'password'
d-i passwd/user-fullname string Linuxfabrik
d-i passwd/username string linuxfabrik
d-i passwd/user-password-crypted password $6$jUQz3dmHOgqKZ8By$mDSQTJ.DQiHnCvT2WUekXi/z6/mf8/lGrP2pHY0hgopg6QW6XULPebzYAhDbJ0PQ18IGpCuhTNbOHp2ZVJOxs1
### Partitioning: LVM with /boot, /, /backup and swap
d-i partman-auto/method string lvm
d-i partman-auto/disk string /dev/vda /dev/sda /dev/nvme0n1
d-i partman-lvm/device_remove_lvm boolean true
d-i partman-lvm/confirm boolean true
d-i partman-lvm/confirm_nooverwrite boolean true
d-i partman-md/device_remove_md boolean true
d-i partman-md/confirm boolean true
# Use GPT
d-i partman-partitioning/choose_label select gpt
d-i partman-partitioning/default_label string gpt
d-i partman-efi/non_efi_system boolean true
# Volume group name
d-i partman-auto-lvm/new_vg_name string rl
d-i partman-auto-lvm/guided_size string max
d-i partman-auto/choose_recipe select custom
d-i partman-auto/expert_recipe string \
custom :: \
512 512 512 fat32 \
$iflabel{ gpt } \
$reusemethod{ } \
method{ efi } format{ } \
. \
1024 1024 1024 ext4 \
$primary{ } $bootable{ } \
method{ format } format{ } \
use_filesystem{ } filesystem{ ext4 } \
mountpoint{ /boot } \
. \
1024 1024 -1 ext4 \
method{ lvm } \
vg_name{ rl } \
. \
1024 1024 1024 ext4 \
$lvmok{ } \
lv_name{ backup } \
in_vg{ rl } \
method{ format } format{ } \
use_filesystem{ } filesystem{ ext4 } \
mountpoint{ /backup } \
options/nodev{ nodev } \
options/noexec{ noexec } \
options/nosuid{ nosuid } \
. \
2048 2048 2048 linux-swap \
$lvmok{ } \
lv_name{ swap } \
in_vg{ rl } \
method{ swap } format{ } \
. \
4096 4096 -1 ext4 \
$lvmok{ } \
lv_name{ root } \
in_vg{ rl } \
method{ format } format{ } \
use_filesystem{ } filesystem{ ext4 } \
mountpoint{ / } \
.
d-i partman-partitioning/confirm_write_new_label boolean true
d-i partman/choose_partition select finish
d-i partman/confirm boolean true
d-i partman/confirm_nooverwrite boolean true
### Packages
tasksel tasksel/first multiselect standard, ssh-server
d-i pkgsel/include string sudo qemu-guest-agent
d-i pkgsel/upgrade select full-upgrade
popularity-contest popularity-contest/participate boolean false
### Boot loader
d-i grub-installer/only_debian boolean true
d-i grub-installer/bootdev string default
### Post-installation
d-i preseed/late_command string \
echo '2026042401' > /target/root/lf-install-version; \
echo 'linuxfabrik ALL=(ALL) NOPASSWD: ALL' > /target/etc/sudoers.d/linuxfabrik; \
chmod 0440 /target/etc/sudoers.d/linuxfabrik; \
mkdir -p -m0700 /target/home/linuxfabrik/.ssh; \
echo 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFnYvkLotqpRKOWyT06IC73nqfvUWxtPTPvFZOnWmUVH danyal.berchtold@linuxfabrik.ch' >> /target/home/linuxfabrik/.ssh/authorized_keys; \
echo 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDaWaDOEGqhZy1XD3a0IJKPvuB0wz2Yzc7Y8b2E91PPDSfi2wczUjZ9T2f8J7fw46i6O8dUFdsle8HePlVt1f6P+SPr84KIvte4sCXPGjHO7UlP+0biPl1FJbe+LU6akGVgAhc37CTn7h10COim5TpIdmPfn8A1y0Y8G3GNTVELSC4GG6rJLgme++OTkNlenH+L7KSobQE1v+MS4mRjrg+qitgPzBv1VgTWJff4d3vdEtb9zwVdzZzyXcdP5/nWH54iDaZawLsyvPXG2VDQq9bUn4CbZ+/ldrVg+yi8Y5RlSLFlbaX2XKnqf8mC3fpszXrmZ93d/idvCLDQ2ijV1FQzYLNg9nstV6VHCek1+g0u3oQ17CyRRCuxSRf3kDagO/+FMGwIliQTSX8rTx0epYzj4vUKA0nYIHXhwklUTG2PFNgJ1Nfxllqblij/PbFfoJCCp+st7/ewYYiclV6jrAg01/bqAvrdS8PW6JQpTIeuJRZhkrvCxgzDsuYE+EqTHxyBs7Uxu9D8QvgZEYiwuClRE92xPNmuEk/BDpX9s8mcXtamp57AUESRFWPFUZoDFuHRjHz56lXJ0UIfDR7XDZHumdQRt6jh7Sj0YGVN3Es9UIqka9dZRiXLdZ9q/C0IReZKtcKDSIn/xB1Kt2qAIRLpSG3IX8JmONOa1h/Gns1NKw== markus.frei@linuxfabrik.ch' >> /target/home/linuxfabrik/.ssh/authorized_keys; \
echo 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM5DxWzuUlSfdHHE1c4oQ2cbC0TyjXkVCuNKBJvn7TvX navid.sassan@linuxfabrik.ch' >> /target/home/linuxfabrik/.ssh/authorized_keys; \
chmod 600 /target/home/linuxfabrik/.ssh/authorized_keys; \
in-target chown -R linuxfabrik:linuxfabrik /home/linuxfabrik/.ssh
### Shutdown after installation
d-i debian-installer/exit/poweroff boolean true
d-i finish-install/reboot_in_progress note