ARG SYSBASE=quay.io/almalinuxorg/almalinux:10-kitten FROM ${SYSBASE} AS system-build RUN mkdir /mnt/sys-root; \ dnf install -y \ --installroot /mnt/sys-root \ --releasever 10 \ --setopt install_weak_deps=false \ --nodocs \ almalinux-release \ bash \ binutils \ coreutils-single \ crypto-policies-scripts \ curl-minimal \ findutils \ hostname \ iputils \ glibc-minimal-langpack \ krb5-libs \ less \ libcurl-minimal \ rootfiles \ systemd \ tar \ vim-minimal \ yum \ xz \ ; \ echo '%_install_langs en_US.UTF-8' > /etc/rpm/macros.image-language-conf ;\ dnf reinstall -y \ --installroot /mnt/sys-root \ --releasever 10 \ --setopt install_weak_deps=false \ --nodocs \ krb5-libs ; \ dnf --installroot /mnt/sys-root clean all; # Additional hacks for kickstart file and backward compatable support /mnt/sys-root/var/lib/dnf/history* RUN rm -rf /mnt/sys-root/var/log/dnf* /mnt/sys-root/var/log/yum.* /mnt/sys-root/usr/share/i18n/charmaps /mnt/sys-root/usr/share/i18n/locales ; \ rm -rf /mnt/sys-root/var/cache/dnf/* /mnt/sys-root/var/lib/dnf/repos /mnt/sys-root/boot /mnt/sys-root/dev/null ; \ rm -rf /mnt/sys-root/var/log/hawkey.log /mnt/sys-root/var/log/* ; \ mkdir -p /mnt/sys-root/run/lock; \ /bin/date +%Y%m%d_%H%M > /mnt/sys-root/etc/BUILDTIME; \ echo '%_install_langs C.utf8' > /mnt/sys-root/etc/rpm/macros.image-language-conf; \ echo 'LANG="C.utf8"' > /mnt/sys-root/etc/locale.conf; \ echo 'container' > /mnt/sys-root/etc/dnf/vars/infra; \ touch /mnt/sys-root/etc/.pwd.lock; \ chmod 600 /mnt/sys-root/etc/.pwd.lock; \ touch /mnt/sys-root/run/utmp ;\ chmod 664 /mnt/sys-root/run/utmp ;\ echo '0.0 0 0.0' > /mnt/sys-root/etc/adjtime; \ echo '0' >> /mnt/sys-root/etc/adjtime; \ echo 'UTC' >> /mnt/sys-root/etc/adjtime; \ echo '# This file has been generated by the Anaconda Installer.' > /mnt/sys-root/etc/sysconfig/sshd-permitrootlogin ;\ echo '# Allow root to log in using ssh. Remove this file to opt-out.' >> /mnt/sys-root/etc/sysconfig/sshd-permitrootlogin ;\ echo 'PERMITROOTLOGIN="-oPermitRootLogin=yes"' >> /mnt/sys-root/etc/sysconfig/sshd-permitrootlogin ;\ echo 'KEYMAP="us"' > /mnt/sys-root/etc/vconsole.conf; \ echo 'FONT="eurlatgr"' >> /mnt/sys-root/etc/vconsole.conf; \ rm -rf /mnt/sys-root/usr/share/locale/en_US@piglati* /mnt/sys-root/run/blkid /mnt/sys-root/var/cache/dnf/.gpgkeyschecked.yum ; \ rm -f /mnt/sys-root/etc/machine-id; \ touch /mnt/sys-root/etc/machine-id; \ touch /mnt/sys-root/etc/resolv.conf; \ touch /mnt/sys-root/etc/hostname # AL9 specific hacks RUN mkdir -p /mnt/sys-root/var/cache/private /mnt/sys-root/var/lib/private /mnt/sys-root/var/lib/systemd/coredump /mnt/sys-root/var/lib/tpm2-tss/system/keystore ;\ mkdir -p /mnt/sys-root/run/cryptsetup /mnt/sys-root/run/lock/subsys /mnt/sys-root/run/log /mnt/sys-root/run/user /mnt/sys-root/run/tpm2-tss/eventlog ;\ mkdir -p /mnt/sys-root/run/systemd/ask-password /mnt/sys-root/run/systemd/machines /mnt/sys-root/run/systemd/seats /mnt/sys-root/run/systemd/sessions /mnt/sys-root/run/systemd/shutdown /mnt/sys-root/run/systemd/users ;\ chmod 700 /mnt/sys-root/var/cache/private ; \ chmod 700 /mnt/sys-root/var/lib/private ; \ chmod 700 /mnt/sys-root/run/cryptsetup ; \ groupadd -R '/mnt/sys-root/' -r -p '!*' -g 996 sgx && groupadd -R '/mnt/sys-root/' -r -p '!*' -g 995 systemd-oom ; \ useradd -R '/mnt/sys-root/' -r -c 'systemd Userspace OOM Killer' -g 995 -u 995 -s '/usr/sbin/nologin' -M -d '/' systemd-oom ; \ sed -i "/sgx/d" /mnt/sys-root/etc/group- ; \ sed -i "/sgx/d" /mnt/sys-root/etc/gshadow- ; \ cd /mnt/sys-root/etc ; \ ln -s ../usr/share/zoneinfo/UTC localtime ; # Almalinux default build FROM scratch AS stage2 COPY --from=system-build /mnt/sys-root/ / RUN systemctl set-default multi-user.target; \ systemctl mask systemd-remount-fs.service \ dev-hugepages.mount \ sys-fs-fuse-connections.mount \ systemd-logind.service \ getty.target \ console-getty.service FROM scratch COPY --from=stage2 / / ENV LANG=C.utf8 CMD ["/bin/bash"]