hermes (12dad13)

Published 2026-10-03 19:58:16 -07:00 by tral

Installation

docker pull repo.rdfrn.net/tral/hermes:12dad13
sha256:d9e98bd4e98ecde7515d0e63be9b547673fb3018f2e4c3fbbbe99d32609fc42d

About this package

AlmaLinux Bootable Container Image

Image layers

ostree export of commit 9d2262803c258bd88d54716bb0197329523f4383e041f215deff68a9de21e981
nvidia-gpu-firmware-20260804-23.2.el10_2.noarch
linux-firmware-20260804-23.2.el10_2.noarch
podman-7:5.8.2-9.el10_2.alma.1.x86_64
atheros-firmware-20260804-23.2.el10_2.noarch
python3-libs-3.12.14-1.el10_2.x86_64
kernel-modules-6.12.0-211.56.1.el10_2.x86_64
rpm-4.19.1.1-23.el10.alma.1.x86_64
libicu-74.2-5.el10_0.x86_64
mt7xxx-firmware-20260804-23.2.el10_2.noarch
kernel-modules-core-6.12.0-211.56.1.el10_2.x86_64
amd-gpu-firmware-20260804-23.2.el10_2.noarch
skopeo-2:1.22.2-5.el10_2.x86_64
kernel-core-6.12.0-211.56.1.el10_2.x86_64
samba-client-libs-4.23.5-110.el10_2.x86_64
bootc-1.16.4-2.el10_2.alma.1.x86_64
sequoia-sq-1.3.1.1-1.el10.x86_64
microcode_ctl-4:20260812-0.el10_2.noarch
systemd-257-23.el10_2.2.alma.1.x86_64
glib2-2.80.4-12.el10_2.22.x86_64
rpm-ostree-2026.2-2.el10_2.x86_64
toolbox-0.3-2.el10_2.x86_64
systemd-udev-257-23.el10_2.2.alma.1.x86_64
coreutils-common-9.5-8.el10_2.1.x86_64
fwupd-2.0.19-4.1.el10_2.x86_64
NetworkManager-libnm-1:1.56.0-2.el10_2.x86_64
file-libs-5.45-9.el10.x86_64
hwdata-0.379-10.8.el10.noarch
brcmfmac-firmware-20260804-23.2.el10_2.noarch
gnupg2-2.4.5-4.el10_1.x86_64
cracklib-dicts-2.9.11-8.el10.x86_64
netavark-2:1.17.2-1.el10.x86_64
intel-gpu-firmware-20260804-23.2.el10_2.noarch
grub2-tools-1:2.12-46.el10_2.alma.1.x86_64
bash-5.2.26-6.el10.x86_64
glibc-gconv-extra-2.39-128.el10_2.alma.1.x86_64
podman-sequoia-0.4.0~pqc.3-1.el10_2.x86_64
152 components
glibc-2.39-128.el10_2.alma.1.x86_64
glibc-common-2.39-128.el10_2.alma.1.x86_64 and kernel-modules-extra-6.12.0-211.56.1.el10_2.x86_64
openssl-libs-1:3.5.8-1.el10_2.alma.1.x86_64 and grub2-common-1:2.12-46.el10_2.alma.1.noarch
7 components
10 components
grub2-tools-minimal-1:2.12-46.el10_2.alma.1.x86_64 and vim-minimal-2:9.1.083-9.el10_2.20.x86_64
10 components
realtek-firmware-20260804-23.2.el10_2.noarch and tiwilink-firmware-20260804-23.2.el10_2.noarch
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
20 components
20 components
13 components
20 components
20 components
20 components
9 components
initramfs (kernel 6.12.0-211.56.1.el10_2.x86_64) and rpmostree-unpackaged-content
Reserved for new packages
COPY multi:dc74a071b1aaef9530d8cd18cb2d56e69ae7ce9962c814e2896cd7d066005055 in /etc/yum.repos.d/
COPY file:fd7ad48161ff1c845aed5b48c26fab12bf8218dd5915766ee4c32729fd6655b2 in /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana
/bin/sh -c rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana
/bin/sh -c dnf install -y ipa-client oddjob-mkhomedir firewalld cloud-init nfs-utils rsync vim-enhanced && dnf clean all && systemctl enable firewalld oddjobd && systemctl enable cloud-init-local.service cloud-init.service cloud-config.service cloud-final.service
/bin/sh -c dnf install -y alloy-1.20.1-1 && dnf clean all && systemctl enable alloy.service && rm -rf /var/lib/alloy
COPY dir:03075414ad5fb40a14031751f0d35ac2f2a61a77aba15243e0827b228c788058 in /
/bin/sh -c rmdir /opt && ln -s var/opt /opt
/bin/sh -c ln -sf ../usr/share/zoneinfo/America/Los_Angeles /etc/localtime
/bin/sh -c mkdir -p /sysroot/ostree/bootc/storage
/bin/sh -c chmod 0440 /etc/sudoers.d/10-rdfrn-secure-path && visudo -cf /etc/sudoers.d/10-rdfrn-secure-path
/bin/sh -c update-ca-trust
/bin/sh -c chmod 0700 /usr/local/sbin/ipa-enroll-firstboot && systemctl enable ipa-enroll-firstboot.service
ARG RESTIC_VERSION
ARG RESTIC_SHA256 RESTIC_VERSION
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c curl -fsSL -o /tmp/restic.bz2 "https://github.com/restic/restic/releases/download/v${RESTIC_VERSION}/restic_${RESTIC_VERSION}_linux_amd64.bz2" && echo "${RESTIC_SHA256} /tmp/restic.bz2" | sha256sum -c - && bzip2 -d /tmp/restic.bz2 && install -m 0755 -o root -g root /tmp/restic /usr/local/bin/restic && rm -f /tmp/restic
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c mkdir -p /etc/rdfrn-backup.d && chmod 0755 /usr/local/sbin/rdfrn-backup && systemctl enable rdfrn-backup.timer
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c chmod 0755 /usr/local/sbin/rdfrn-drift-check && systemctl enable rdfrn-drift-check.timer
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c systemctl mask bootc-fetch-apply-updates.timer bootc-fetch-apply-updates.service
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache && find /var/log -type f -exec truncate -s0 {} \; && for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/*
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/lib/certmonger /var/lib/dnf
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c bootc container lint --fatal-warnings
/bin/sh -c dnf install -y nginx nginx-mod-stream git-core && dnf clean all && rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache /var/lib/dnf && find /var/log -type f -exec truncate -s0 {} \;
COPY dir:1ca252f6d74b80e0c0aad677446cd9e7139e068ae7d07511426cadb0f2362f14 in /
COPY dir:84a86237b0aee182e93ce0883a1d7d20a6575bb866bc61fc1d67fb861a7deac9 in /usr/lib/rdfrn-sandbox-tools
COPY dir:cb1407bb6fdc14d7ea3830a7c9ac2dbf23a7c746b2b2f4e4b5b1c6442bb23da5 in /usr/rdfrn-kb/tools/kb/
COPY dir:680dc2b267f9e9808e72e1258c90a96b110a60785bcbde9df7a8f1d1d3ea3d21 in /usr/rdfrn-kb/tools/lib/
COPY dir:b823104fe4058b19b0b7fad0def5a9883cdd432855b872136abd20e7a0d7b10d in /usr/rdfrn-kb/state/graph/
COPY file:ccde9b6d9b573159305e1019fb8f029cbf299b422910e82a0ba4004c03e52bd3 in /usr/rdfrn-kb/docs/explanation/work-breakdown.md
/bin/sh -c python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; build.ensure_index(Path('/usr/rdfrn-kb'))" && python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; assert build._up_to_date(Path('/usr/rdfrn-kb/.kb/index.sqlite'), Path('/usr/rdfrn-kb/state/graph'))"
/bin/sh -c find /usr/rdfrn-kb -type d -name __pycache__ -prune -exec rm -rf {} + && find /usr/rdfrn-kb -type f -name '*.pyc' -delete
/bin/sh -c cd /usr/share/selinux/rdfrn && checkmodule -M -m -o rdfrn_hermes_engine.mod rdfrn_hermes_engine.te && semodule_package -o rdfrn_hermes_engine.pp -m rdfrn_hermes_engine.mod && semodule -N -i rdfrn_hermes_engine.pp && rm -f rdfrn_hermes_engine.mod rdfrn_hermes_engine.pp
/bin/sh -c chmod 0755 /usr/libexec/rdfrn-hermes-cert-* /usr/libexec/rdfrn-hermes-repo-sync && firewall-offline-cmd --zone=public --add-service=https && firewall-offline-cmd --zone=public --add-service=http && firewall-offline-cmd --new-policy=hermes-to-mon && firewall-offline-cmd --policy=hermes-to-mon --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-mon --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.10/32" port port="8443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.10/32" reject' && firewall-offline-cmd --new-policy=hermes-to-forgejo && firewall-offline-cmd --policy=hermes-to-forgejo --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-forgejo --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.135/32" port port="443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.135/32" reject' && setsebool -P httpd_can_network_connect on && systemctl enable nginx hermes-cert.service hermes-selinux.service rdfrn-hermes-repo-sync.timer
/bin/sh -c chown root:sssd /etc/sssd /etc/sssd/conf.d /etc/sssd/conf.d/50-hermes-access.conf && chmod 0750 /etc/sssd /etc/sssd/conf.d && chmod 0640 /etc/sssd/conf.d/50-hermes-access.conf && test "$(stat -c '%U:%G %a' /etc/sssd)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d/50-hermes-access.conf)" = "root:sssd 640"
/bin/sh -c for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/*
/bin/sh -c bootc container lint --fatal-warnings

Labels

Key Value
build-date 2026-10-02T03:12:41+00:00
containers.bootc 1
io.buildah.version 1.43.1
org.opencontainers.image.created 2026-10-02T03:12:41+00:00
org.opencontainers.image.description AlmaLinux Bootable Container Image
org.opencontainers.image.source git://github.com/AlmaLinux/bootc-images.git
org.opencontainers.image.title almalinux-bootc
org.opencontainers.image.url https://github.com/AlmaLinux/bootc-images
org.opencontainers.image.vendor AlmaLinux OS Foundation
org.opencontainers.image.version 10.2.20261002.0
ostree.bootable 1
ostree.commit 9d2262803c258bd88d54716bb0197329523f4383e041f215deff68a9de21e981
ostree.final-diffid sha256:12787d84fa137cd5649a9005efe98ec9d05ea46245fdc50aecb7dd007f2035b1
redhat.id almalinux
redhat.version-id 10.2
release 10.2
version 10.2
Details
Container
2026-10-03 19:58:16 -07:00
1
OCI / Docker
linux/amd64
1.1 GiB
Versions (106) View all
testing 2026-10-04
5488ef6 2026-10-04
f1416c5 2026-10-04
52a8086 2026-10-04
0e018ee 2026-10-03