Compare commits

...
Sign in to create a new pull request.

45 commits

Author SHA1 Message Date
Flux
ed55583fb2
Merge pull request #6 from randogoth/nix-bind-mount
Nix bind mount
2026-01-14 20:34:17 +02:00
randogoth
e2ccc907c4 Merge branch 'main' into nix-bind-mount 2026-01-14 20:33:49 +02:00
randogoth
f6b7be239d removed curator 2026-01-14 20:28:01 +02:00
randogoth
f65c6846f7 selinux fix 2026-01-14 19:45:46 +02:00
randogoth
8e33e4fa3f fixed missing system profile 2026-01-14 18:46:55 +02:00
randogoth
c2eb4e0bf6 bind-mount attempt 2026-01-14 18:19:46 +02:00
randogoth
29beb6408f kmod 2026-01-07 18:56:06 +02:00
randogoth
1e7553948e polychromatic 2026-01-07 18:29:37 +02:00
randogoth
febe1ed1c0 openrazer 2026-01-07 18:23:52 +02:00
randogoth
e216813d56 added os release info 2026-01-03 18:11:14 +02:00
randogoth
f194d54d2d script fix 2026-01-03 17:57:27 +02:00
randogoth
fb7a13908d nix daemon fix 2026-01-03 16:50:35 +02:00
randogoth
ccb558b597 nix daemon fix 2026-01-03 16:47:49 +02:00
randogoth
7a9e31f66d removed razer 2026-01-01 17:47:03 +02:00
randogoth
ddac14ae8a Revert "removed razer for now"
This reverts commit 963b5e7415.
2026-01-01 17:45:35 +02:00
randogoth
963b5e7415 removed razer for now 2026-01-01 17:42:46 +02:00
randogoth
550ee4e2dc stub 2026-01-01 17:41:57 +02:00
randogoth
2d6f6e3691 missing kernel deps 2026-01-01 17:23:43 +02:00
randogoth
c40c60e820 added openrazer 2026-01-01 15:28:20 +02:00
Flux
4918d3297e
Update README with overlay mount mention 2025-12-30 17:32:08 +02:00
Flux
ea4ed7a25c
Merge pull request #5 from randogoth/lix-rpm
Replaced Nix with Lix
2025-12-30 16:34:25 +02:00
randogoth
67a413bce8 finalized Lix setup 2025-12-30 16:19:24 +02:00
randogoth
4274d2db55 lix key fix 2025-12-30 12:56:58 +02:00
randogoth
5afecd67c5 lix rpm from nix-community 2025-12-30 11:08:13 +02:00
randogoth
c8830fc50a dnf module fix, readme 2025-12-28 19:16:42 +02:00
randogoth
6d7cb97cc0 codium from dnf 2025-12-28 18:28:06 +02:00
randogoth
03d376d931 added devbox 2025-12-26 20:44:47 +02:00
randogoth
f9a4599c9f uvx 2025-12-25 14:30:36 +02:00
randogoth
fa529b0b9a curator in readme 2025-12-24 13:15:43 +02:00
randogoth
bfd48449c7 swapped home-manager with curator 2025-12-24 13:13:07 +02:00
randogoth
ea79ed24f4 filename fixes 2025-12-23 23:34:09 +02:00
Flux
c171b01829
Merge pull request #4 from randogoth/nix
Nix support
2025-12-23 21:12:19 +02:00
randogoth
4695571654 renamed 2025-12-23 21:11:11 +02:00
randogoth
83e657e74b bootstrap home manager and nix packages on login 2025-12-23 20:35:57 +02:00
randogoth
9d5b4ddecd nix package installer 2025-12-23 19:34:21 +02:00
randogoth
9e859af388 ignore gpg 2025-12-22 21:56:28 +02:00
randogoth
4de510d1f9 script fix 2025-12-22 21:21:02 +02:00
randogoth
d4e84b0e41 daemonix approach 2025-12-22 21:13:22 +02:00
randogoth
8d362d13b2 distrobox nix 2025-12-22 20:53:36 +02:00
randogoth
7a9bf4eb0d merge 2025-12-22 20:45:56 +02:00
randogoth
57c18ac902 Merge branch 'main' of github.com:randogoth/randofin-os 2025-12-22 20:45:53 +02:00
randogoth
2ac7aebcb0 added nix toolbox 2025-12-22 20:43:26 +02:00
randogoth
df6bc8c3b4 removed docker and code, added flatpaks 2025-11-22 14:31:02 +02:00
randogoth
3a66d036dc removed grub stuff 2025-11-22 14:04:49 +02:00
randogoth
f48f0615b6 added grub2 theme, removed docker and code 2025-11-22 10:49:43 +02:00
11 changed files with 204 additions and 47 deletions

1
.gitignore vendored
View file

@ -1,3 +1,4 @@
cosign.key cosign.key
cosign.private cosign.private
/Containerfile /Containerfile
/.bluebuild-scripts_*

View file

@ -1,43 +1,37 @@
# randofin-os   [![bluebuild build badge](https://github.com/randogoth/randofin-os/actions/workflows/build.yml/badge.svg)](https://github.com/randogoth/randofin-os/actions/workflows/build.yml) # Deinonyxus   [![bluebuild build badge](https://github.com/randogoth/deinonyxus/actions/workflows/build.yml/badge.svg)](https://github.com/randogoth/deinonyxus/actions/workflows/build.yml)
See the [BlueBuild docs](https://blue-build.org/how-to/setup/) for quick setup instructions for setting up your own repository based on this template. *Deinonyxus* is a personal spin of the UBlue Bluefin DX image with the 🍦[Lix](https://lix.systems/) flavored Nix package manager baked in.
After setup, it is recommended you update this README to describe your custom image. ## Whats inside
- Base: `ghcr.io/ublue-os/bluefin-dx:latest` without Cockpit, Docker, Firefox, VS Code
- System packages added: `syncthing`, `uv`, `vscodium`, `waydroid`;
- System flatpaks added: Telegram Desktop, Waterfox browser
## Installation ## Just Recipes
- `upgrade-nix`: upgrades to the latest version of Lix via the user profile. Replaces `nix upgrade-nix` which does not work with an immutable lowerdir `/nix/store` folder
- `install-nix-software-center`: installs a graphical app store for Nix packages
> [!WARNING] ## Install / Rebase
> [This is an experimental feature](https://www.fedoraproject.org/wiki/Changes/OstreeNativeContainerStable), try at your own discretion.
To rebase an existing atomic Fedora installation to the latest build:
- First rebase to the unsigned image, to get the proper signing keys and policies installed:
```
rpm-ostree rebase ostree-unverified-registry:ghcr.io/randogoth/randofin-os:latest
```
- Reboot to complete the rebase:
```
systemctl reboot
```
- Then rebase to the signed image, like so:
```
rpm-ostree rebase ostree-image-signed:docker://ghcr.io/randogoth/randofin-os:latest
```
- Reboot again to complete the installation
```
systemctl reboot
```
The `latest` tag will automatically point to the latest build. That build will still always use the Fedora version specified in `recipe.yml`, so you won't get accidentally updated to the next major version.
## ISO
If build on Fedora Atomic, you can generate an offline ISO with the instructions available [here](https://blue-build.org/learn/universal-blue/#fresh-install-from-an-iso). These ISOs cannot unfortunately be distributed on GitHub for free due to large sizes, so for public projects something else has to be used for hosting.
## Verification
These images are signed with [Sigstore](https://www.sigstore.dev/)'s [cosign](https://github.com/sigstore/cosign). You can verify the signature by downloading the `cosign.pub` file from this repo and running the following command:
```bash ```bash
cosign verify --key cosign.pub ghcr.io/randogoth/randofin-os # First pull unsigned to get signing policy
rpm-ostree rebase ostree-unverified-registry:ghcr.io/randogoth/deinonyxus:latest
systemctl reboot
# Then move to the signed image
rpm-ostree rebase ostree-image-signed:docker://ghcr.io/randogoth/deinonyxus:latest
systemctl reboot
```
The `latest` tag always tracks the latest build for the Fedora base set in `recipes/recipe.yml`.
## Building locally
```bash
bluebuild build
```
## Signature verification
Images are signed with Sigstore/cosign. Verify with the repo's `cosign.pub`:
```bash
cosign verify --key cosign.pub ghcr.io/randogoth/deinonyxus
``` ```

View file

@ -0,0 +1,7 @@
upgrade-nix:
echo 'Installing latest Lix package'
nix profile install nixpkgs#lix && nix upgrade-nix
install-nix-software-center:
echo 'Installing Nix Software Center'
nix profile install github:snowfallorg/nix-software-center

View file

@ -1,6 +0,0 @@
#!/usr/bin/env bash
# Tell this script to exit if there are any errors.
# You should have this in every custom script, to ensure that your completed
# builds actually ran successfully without any errors!
set -oue pipefail

48
files/scripts/install-lix.sh Executable file
View file

@ -0,0 +1,48 @@
#!/usr/bin/env bash
set -euo pipefail
# === INSTALL LIX FROM RPM ===
rpm_url="https://nix-community.github.io/nix-installers/lix/x86_64/lix-multi-user-2.91.1.rpm"
install -d /usr/share/nix-store /var/lib/nix-store /nix /etc/nix
# Avoid systemd calls during RPM %post in the image build environment.
export SYSTEMD_OFFLINE=1
# Install the RPM; allow missing GPG key since we fetch directly by URL.
dnf install -y --nogpgcheck "$rpm_url"
# === ADD MISSING LIX CACHE ACCESS PUBKEY ===
nix_conf=/etc/nix/nix.conf
lix_cache_url="https://cache.lix.systems/"
lix_cache_key="cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o="
ensure_list_value() {
local key="$1" value="$2" escaped_value
escaped_value=$(printf '%s' "$value" | sed 's/[\\&]/\\&/g')
touch "$nix_conf"
if grep -Eq "^${key}[[:space:]]*=.*${escaped_value}" "$nix_conf"; then
return
fi
if grep -Eq "^${key}[[:space:]]*=" "$nix_conf"; then
sed -i "s|^${key}[[:space:]]*= *\\(.*\\)|${key} = \\1 ${escaped_value}|" "$nix_conf"
else
echo "${key} = ${value}" >>"$nix_conf"
fi
}
ensure_list_value "substituters" "$lix_cache_url"
ensure_list_value "trusted-public-keys" "$lix_cache_key"
# === SEED STORE FOR FIRST BOOT (copied into /var on boot) ===
if compgen -G "/nix/*" >/dev/null; then
rsync -aH --delete /nix/ /usr/share/nix-store/
rm -rf /nix/*
fi

View file

@ -0,0 +1,2 @@
/nix(/.*)? system_u:object_r:bin_t:s0
/var/lib/nix-store(/.*)? system_u:object_r:bin_t:s0

View file

@ -0,0 +1,5 @@
[Service]
# Run the daemon unconfined to avoid SELinux denials on the Nix store binaries.
SELinuxContext=system_u:system_r:unconfined_service_t:s0
ExecStart=
ExecStart=/usr/bin/nix-daemon-wrapper.sh --daemon

View file

@ -0,0 +1,58 @@
#!/usr/bin/env bash
set -euo pipefail
# Bind-mount /var/lib/nix-store to /nix.
# If /var/lib/nix-store is empty, seed it from the baked store in /usr/share/nix-store.
mkdir -p /usr/share/nix-store /var/lib/nix-store /nix
copy_seed_store() {
if command -v rsync >/dev/null 2>&1; then
rsync -aH --delete /usr/share/nix-store/ /var/lib/nix-store/
else
cp -a /usr/share/nix-store/. /var/lib/nix-store/
fi
}
sync_missing_store() {
# Ensure any baked store paths exist in /var without clobbering user additions.
if command -v rsync >/dev/null 2>&1; then
rsync -aH --ignore-existing /usr/share/nix-store/store/ /var/lib/nix-store/store/
fi
}
ensure_system_profile() {
local seed_profile="/usr/share/nix-store/var/nix/profiles/system"
local target_profile="/var/lib/nix-store/var/nix/profiles/system"
mkdir -p /var/lib/nix-store/var/nix/profiles
if { [ ! -e "$target_profile" ] || [ -L "$target_profile" ] && [ ! -e "$(readlink -f "$target_profile")" ]; } \
&& { [ -e "$seed_profile" ] || [ -L "$seed_profile" ]; }; then
cp -a "$seed_profile" "$target_profile"
fi
}
if ! mountpoint -q /nix; then
if [ -z "$(ls -A /var/lib/nix-store 2>/dev/null)" ] && compgen -G "/usr/share/nix-store/*" >/dev/null; then
copy_seed_store
fi
ensure_system_profile
sync_missing_store
mount --bind /var/lib/nix-store /nix
# Force an executable SELinux context on the bind mount so systemd can exec nix-daemon.
# Use a permissive fallback if the label option is rejected.
if ! mount -o remount,bind,exec,context=system_u:object_r:bin_t:s0 /nix 2>/dev/null; then
mount -o remount,bind,exec /nix
fi
# Ensure daemon paths exist and labels are sane.
if command -v systemd-tmpfiles >/dev/null 2>&1; then
systemd-tmpfiles --create /usr/lib/tmpfiles.d/nix-daemon.conf
fi
if command -v restorecon >/dev/null 2>&1; then
restorecon -RF /var/lib/nix-store /nix || true
fi
fi

View file

@ -0,0 +1,2 @@
#!/usr/bin/env bash
exec /nix/var/nix/profiles/system/bin/nix-daemon "$@"

View file

@ -0,0 +1,15 @@
[Unit]
Description=Bind-mount /var/lib/nix-store to /nix
DefaultDependencies=no
After=local-fs.target
RequiresMountsFor=/var /var/lib/nix-store
Before=nix-daemon.service nix-daemon.socket
ConditionPathExists=/usr/bin/mount-nix.sh
[Service]
Type=oneshot
ExecStart=/usr/bin/mount-nix.sh
RemainAfterExit=yes
[Install]
WantedBy=sysinit.target

View file

@ -1,9 +1,9 @@
--- ---
# yaml-language-server: $schema=https://schema.blue-build.org/recipe-v1.json # yaml-language-server: $schema=https://schema.blue-build.org/recipe-v1.json
# image will be published to ghcr.io/<user>/<name> # image will be published to ghcr.io/<user>/<name>
name: randofin-os name: deinonyxus
# description will be included in the image's metadata # description will be included in the image's metadata
description: This is my personal spin based on the latest bluefin image. description: Bluefin DX with Nix and sprinkles.
# the base image to build on top of (FROM) and the version tag to use # the base image to build on top of (FROM) and the version tag to use
base-image: ghcr.io/ublue-os/bluefin-dx base-image: ghcr.io/ublue-os/bluefin-dx
@ -12,15 +12,45 @@ image-version: latest # latest is also supported if you want new updates ASAP
# module configuration, executed in order # module configuration, executed in order
# you can include multiple instances of the same module # you can include multiple instances of the same module
modules: modules:
- type: os-release
properties:
ID: deinonyxus
NAME: Deinonyxus
PRETTY_NAME: Deinonyxus (Bluefin DX)
DEFAULT_HOSTNAME: deinonyxus
HOME_URL: https://codeberg.org/randogoth/deinonyxus
SUPPORT_URL: https://codeberg.org/randogoth/deinonyxus/issues
BUG_REPORT_URL: https://codeberg.org/randogoth/deinonyxus/issues
- type: files - type: files
files: files:
- source: system - source: system
destination: / # copies files/system/* (* means everything inside it) into your image's root folder / destination: / # copies files/system/* (* means everything inside it) into your image's root folder /
- type: script
scripts:
- install-lix.sh
- type: systemd
system:
enabled:
- nix-overlay.service
- nix-daemon.service
- nix-daemon.socket
- type: dnf - type: dnf
repos:
files:
add:
- https://repo.vscodium.dev/vscodium.repo
install: install:
packages: packages:
- repo: vscodium
packages:
- codium
- syncthing - syncthing
- uv
- waydroid - waydroid
remove: remove:
packages: packages:
@ -39,8 +69,10 @@ modules:
- docker-ce-rootless-extras - docker-ce-rootless-extras
- docker-compose-plugin - docker-compose-plugin
- docker-model-plugin - docker-model-plugin
- containerd
- moby-engine - type: justfiles
include:
- nixpkgs.just
- type: default-flatpaks - type: default-flatpaks
configurations: configurations:
@ -49,7 +81,6 @@ modules:
# If no repo information is specified, Flathub will be used by default # If no repo information is specified, Flathub will be used by default
install: # system flatpaks we want all users to have and not remove install: # system flatpaks we want all users to have and not remove
- net.waterfox.waterfox - net.waterfox.waterfox
- com.vscodium.codium
- org.telegram.desktop - org.telegram.desktop
remove: # replace default Firefox with Waterfox remove: # replace default Firefox with Waterfox
- org.mozilla.firefox - org.mozilla.firefox