No description
|
|
||
|---|---|---|
| .github | ||
| files | ||
| modules | ||
| recipes | ||
| .gitignore | ||
| cosign.pub | ||
| LICENSE | ||
| README.md | ||
Deinonyxus 
Deinonyxus is a personal spin of the UBlue Bluefin DX image with experimental Nix package manager baked in (borrowed from the great Daemonix image) and a first-login bootstrap for home-manager packages.
What’s inside
- Base:
ghcr.io/ublue-os/bluefin-dx:latestwithout Cockpit, Docker, Firefox, VS Code - Nix: multi-user install baked in;
nix-overlay.serviceandnix-daemon.serviceenabled. - First-login bootstrap: installs nix packages
uv micro vscodium mcviahome-manager. - System packages added:
syncthing,waydroid; - System flatpaks added: Telegram Desktop, Waterfox
First login behavior
- Triggers for each non-root user on their first session.
- Writes state to
~/.local/state/deinonyxus/nixpkgs-init.done; delete it to rerun. - Bootstraps
~/.config/home-manager/home.nixand runshome-manager switchwith the package set above.
Install / Rebase
Warning
Uses the Fedora Atomic native container workflow.
# First pull unsigned to get signing policy
rpm-ostree rebase ostree-unverified-registry:ghcr.io/randogoth/deinonyxus:latest
systemctl reboot
# Then move to the signed image
rpm-ostree rebase ostree-image-signed:docker://ghcr.io/randogoth/deinonyxus:latest
systemctl reboot
The latest tag always tracks the latest build for the Fedora base set in recipes/recipe.yml.
Building locally
bluebuild build --recipe recipes/recipe.yml
Signature verification
Images are signed with Sigstore/cosign. Verify with the repo's cosign.pub:
cosign verify --key cosign.pub ghcr.io/randogoth/deinonyxus