try
This commit is contained in:
parent
16a9ba7f14
commit
6b0762045e
@ -16,35 +16,29 @@ sudo:x:16:
|
|||||||
dialout:x:18:
|
dialout:x:18:
|
||||||
floppy:x:19:
|
floppy:x:19:
|
||||||
games:x:20:
|
games:x:20:
|
||||||
tape:x:30:
|
tape:x:33:
|
||||||
video:x:39:
|
video:x:39:
|
||||||
ftp:x:50:
|
ftp:x:50:
|
||||||
lock:x:54:
|
lock:x:54:
|
||||||
audio:x:63:
|
audio:x:63:
|
||||||
nobody:x:99:
|
nobody:x:99:
|
||||||
users:x:100:
|
users:x:100:
|
||||||
utmp:x:22:
|
|
||||||
utempter:x:35:
|
|
||||||
ssh_keys:x:999:
|
ssh_keys:x:999:
|
||||||
systemd-journal:x:190:
|
systemd-journal:x:190:
|
||||||
dbus:x:81:
|
|
||||||
polkitd:x:998:
|
polkitd:x:998:
|
||||||
etcd:x:997:
|
etcd:x:997:
|
||||||
dip:x:40:
|
dip:x:40:
|
||||||
cgred:x:996:
|
cgred:x:996:
|
||||||
tss:x:59:
|
|
||||||
avahi-autoipd:x:170:
|
avahi-autoipd:x:170:
|
||||||
rpc:x:32:
|
|
||||||
sssd:x:993:
|
sssd:x:993:
|
||||||
dockerroot:x:986:
|
dockerroot:x:986:
|
||||||
rpcuser:x:29:
|
rpcuser:x:29:
|
||||||
nfsnobody:x:65534:
|
nfsnobody:x:65534:
|
||||||
kube:x:994:
|
kube:x:994:
|
||||||
sshd:x:74:
|
|
||||||
chrony:x:992:
|
chrony:x:992:
|
||||||
tcpdump:x:72:
|
tcpdump:x:72:
|
||||||
ceph:x:167:
|
ceph:x:167:
|
||||||
input:x:995:
|
input:x:104:
|
||||||
systemd-timesync:x:991:
|
systemd-timesync:x:991:
|
||||||
systemd-network:x:990:
|
systemd-network:x:990:
|
||||||
systemd-resolve:x:989:
|
systemd-resolve:x:989:
|
||||||
|
9
manifests/grub2-removals.yaml
Normal file
9
manifests/grub2-removals.yaml
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
remove-from-packages:
|
||||||
|
# The grub bits are mainly designed for desktops, and IMO haven't seen
|
||||||
|
# enough testing in concert with ostree. At some point we'll flesh out
|
||||||
|
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
|
||||||
|
- [grub2-tools, /etc/grub.d/08_fallback_counting,
|
||||||
|
/etc/grub.d/10_reset_boot_success,
|
||||||
|
/etc/grub.d/12_menu_auto_hide,
|
||||||
|
/usr/lib/systemd/.*]
|
||||||
|
|
@ -6,28 +6,35 @@ lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
|
|||||||
sync:x:5:0:sync:/sbin:/bin/sync
|
sync:x:5:0:sync:/sbin:/bin/sync
|
||||||
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
|
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
|
||||||
halt:x:7:0:halt:/sbin:/sbin/halt
|
halt:x:7:0:halt:/sbin:/sbin/halt
|
||||||
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
|
adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
|
||||||
operator:x:11:0:operator:/root:/sbin/nologin
|
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
|
||||||
games:x:12:100:games:/usr/games:/sbin/nologin
|
bin:x:1:1:bin:/bin:/usr/sbin/nologin
|
||||||
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
|
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
|
||||||
nobody:x:99:99:Nobody:/:/sbin/nologin
|
chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
|
||||||
dbus:x:81:81:System message bus:/:/sbin/nologin
|
cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
|
||||||
polkitd:x:999:998:User for polkitd:/:/sbin/nologin
|
daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
|
||||||
etcd:x:998:997:etcd user:/var/lib/etcd:/sbin/nologin
|
dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
|
||||||
tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin
|
dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
|
||||||
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/sbin/nologin
|
etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
|
||||||
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
|
ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
|
||||||
sssd:x:995:993:User for sssd:/:/sbin/nologin
|
games:x:12:100:games:/usr/games:/usr/sbin/nologin
|
||||||
dockerroot:x:997:986:Docker User:/var/lib/docker:/sbin/nologin
|
halt:x:7:0:halt:/sbin:/sbin/halt
|
||||||
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
|
kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
|
||||||
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
|
lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||||
kube:x:996:994:Kubernetes user:/:/sbin/nologin
|
mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
|
||||||
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
|
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
|
||||||
chrony:x:994:992::/var/lib/chrony:/sbin/nologin
|
nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
|
||||||
tcpdump:x:72:72::/:/sbin/nologin
|
operator:x:11:0:operator:/root:/usr/sbin/nologin
|
||||||
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/sbin/nologin
|
polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
|
||||||
systemd-timesync:x:993:991:systemd Time Synchronization:/:/sbin/nologin
|
root:x:0:0:Super User:/root:/bin/bash
|
||||||
systemd-network:x:991:990:systemd Network Management:/:/sbin/nologin
|
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
|
||||||
systemd-resolve:x:990:989:systemd Resolver:/:/sbin/nologin
|
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
|
||||||
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/sbin/nologin
|
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
|
||||||
cockpit-ws:x:988:987:User for cockpit-ws:/:/sbin/nologin
|
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
|
||||||
|
sssd:x:995:993:User for sssd:/:/usr/sbin/nologin
|
||||||
|
sync:x:5:0:sync:/sbin:/bin/sync
|
||||||
|
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
|
||||||
|
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
|
||||||
|
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
|
||||||
|
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
|
||||||
|
tcpdump:x:72:72::/:/usr/sbin/nologin
|
||||||
|
@ -8,11 +8,15 @@ ostree-layers:
|
|||||||
- overlay/08nouveau
|
- overlay/08nouveau
|
||||||
- overlay/09misc
|
- overlay/09misc
|
||||||
- overlay/20platform-chrony
|
- overlay/20platform-chrony
|
||||||
|
- overlay/15fcos
|
||||||
|
|
||||||
|
|
||||||
conditional-include:
|
conditional-include:
|
||||||
- if: releasever <= 8
|
- if: releasever <= 8
|
||||||
include: fallback-hostname.yaml
|
include: fallback-hostname.yaml
|
||||||
|
- if: basearch != "s390x"
|
||||||
|
# And remove some cruft from grub2
|
||||||
|
include: grub2-removals.yaml
|
||||||
|
|
||||||
packages:
|
packages:
|
||||||
- rpm
|
- rpm
|
||||||
@ -29,6 +33,7 @@ packages:
|
|||||||
- polkit
|
- polkit
|
||||||
- coreos-installer
|
- coreos-installer
|
||||||
|
|
||||||
|
|
||||||
ignore-removed-users:
|
ignore-removed-users:
|
||||||
- root
|
- root
|
||||||
ignore-removed-groups:
|
ignore-removed-groups:
|
||||||
@ -38,6 +43,7 @@ etc-group-members:
|
|||||||
- sudo
|
- sudo
|
||||||
- systemd-journal
|
- systemd-journal
|
||||||
- adm
|
- adm
|
||||||
|
- docker
|
||||||
|
|
||||||
|
|
||||||
check-passwd:
|
check-passwd:
|
||||||
|
Loading…
Reference in New Issue
Block a user