hermes (52ad998)
Published 2026-10-01 14:54:51 -07:00 by tral
Installation
docker pull repo.rdfrn.net/tral/hermes:52ad998sha256:2586df4de16957fe013840f05f337b534e38261764a4b281d237aa805041e899About this package
AlmaLinux Bootable Container Image
Image layers
| ostree export of commit 4655ac19287b0d6607fc09441c8a9f8d8fc1e37c88e815c0d9a74b773cd31001 |
| nvidia-gpu-firmware-20260411-19.5.el10_1.noarch |
| linux-firmware-20260411-19.5.el10_1.noarch |
| podman-7:5.8.2-5.el10_2.alma.1.x86_64 |
| python3-libs-3.12.13-2.el10_2.1.x86_64 |
| kernel-modules-6.12.0-211.43.1.el10_2.x86_64 |
| atheros-firmware-20260411-19.5.el10_1.noarch |
| rpm-4.19.1.1-23.el10.alma.1.x86_64 |
| libicu-74.2-5.el10_0.x86_64 |
| kernel-modules-core-6.12.0-211.43.1.el10_2.x86_64 |
| amd-gpu-firmware-20260411-19.5.el10_1.noarch |
| skopeo-2:1.22.2-2.el10_2.x86_64 |
| kernel-core-6.12.0-211.43.1.el10_2.x86_64 |
| mt7xxx-firmware-20260411-19.5.el10_1.noarch |
| samba-client-libs-4.23.5-109.el10_2.x86_64 |
| sequoia-sq-1.3.1.1-1.el10.x86_64 |
| systemd-257-23.el10_2.2.alma.1.x86_64 |
| microcode_ctl-4:20260210-1.el10.noarch |
| glib2-2.80.4-12.el10_2.14.x86_64 |
| rpm-ostree-2026.1-5.el10_2.x86_64 |
| bootc-1.15.2-1.el10_2.alma.1.x86_64 |
| toolbox-0.3-2.el10_2.x86_64 |
| systemd-udev-257-23.el10_2.2.alma.1.x86_64 |
| coreutils-common-9.5-8.el10_2.x86_64 |
| fwupd-2.0.19-4.1.el10_2.x86_64 |
| NetworkManager-libnm-1:1.56.0-2.el10_2.x86_64 |
| file-libs-5.45-9.el10.x86_64 |
| hwdata-0.379-10.8.el10.noarch |
| brcmfmac-firmware-20260411-19.5.el10_1.noarch |
| gnupg2-2.4.5-4.el10_1.x86_64 |
| cracklib-dicts-2.9.11-8.el10.x86_64 |
| netavark-2:1.17.2-1.el10.x86_64 |
| intel-gpu-firmware-20260411-19.5.el10_1.noarch |
| grub2-tools-1:2.12-46.el10_2.alma.1.x86_64 |
| bash-5.2.26-6.el10.x86_64 |
| glibc-gconv-extra-2.39-128.el10_2.alma.1.x86_64 |
| podman-sequoia-0.4.0~pqc.3-1.el10_2.x86_64 |
| 150 components |
| glibc-2.39-128.el10_2.alma.1.x86_64 |
| glibc-common-2.39-128.el10_2.alma.1.x86_64 and kernel-modules-extra-6.12.0-211.43.1.el10_2.x86_64 |
| openssl-libs-1:3.5.5-6.el10_2.alma.1.x86_64 and grub2-common-1:2.12-46.el10_2.alma.1.noarch |
| 7 components |
| 10 components |
| 10 components |
| realtek-firmware-20260411-19.5.el10_1.noarch and sssd-common-2.12.0-3.el10_2.1.x86_64 and tiwilink-firmware-20260411-19.5.el10_1.noarch |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 10 components |
| 20 components |
| 20 components |
| 14 components |
| 20 components |
| 20 components |
| 20 components |
| nftables-1:1.1.5-5.el10_2.x86_64 |
| initramfs (kernel 6.12.0-211.43.1.el10_2.x86_64) and rpmostree-unpackaged-content |
| Reserved for new packages |
| COPY multi:dc74a071b1aaef9530d8cd18cb2d56e69ae7ce9962c814e2896cd7d066005055 in /etc/yum.repos.d/ |
| COPY file:fd7ad48161ff1c845aed5b48c26fab12bf8218dd5915766ee4c32729fd6655b2 in /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana |
| /bin/sh -c rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana |
| /bin/sh -c dnf install -y ipa-client oddjob-mkhomedir firewalld cloud-init nfs-utils rsync vim-enhanced && dnf clean all && systemctl enable firewalld oddjobd && systemctl enable cloud-init-local.service cloud-init.service cloud-config.service cloud-final.service |
| /bin/sh -c dnf install -y alloy-1.19.2-1 && dnf clean all && systemctl enable alloy.service && rm -rf /var/lib/alloy |
| COPY dir:bc6911985618ba4fb0948122e2e0660e710d4dcce277d352f07c6863b141ab45 in / |
| /bin/sh -c rmdir /opt && ln -s var/opt /opt |
| /bin/sh -c ln -sf ../usr/share/zoneinfo/America/Los_Angeles /etc/localtime |
| /bin/sh -c mkdir -p /sysroot/ostree/bootc/storage |
| /bin/sh -c chmod 0440 /etc/sudoers.d/10-rdfrn-secure-path && visudo -cf /etc/sudoers.d/10-rdfrn-secure-path |
| /bin/sh -c update-ca-trust |
| /bin/sh -c chmod 0700 /usr/local/sbin/ipa-enroll-firstboot && systemctl enable ipa-enroll-firstboot.service |
| ARG RESTIC_VERSION |
| ARG RESTIC_SHA256 RESTIC_VERSION |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c curl -fsSL -o /tmp/restic.bz2 "https://github.com/restic/restic/releases/download/v${RESTIC_VERSION}/restic_${RESTIC_VERSION}_linux_amd64.bz2" && echo "${RESTIC_SHA256} /tmp/restic.bz2" | sha256sum -c - && bzip2 -d /tmp/restic.bz2 && install -m 0755 -o root -g root /tmp/restic /usr/local/bin/restic && rm -f /tmp/restic |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c mkdir -p /etc/rdfrn-backup.d && chmod 0755 /usr/local/sbin/rdfrn-backup && systemctl enable rdfrn-backup.timer |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c chmod 0755 /usr/local/sbin/rdfrn-drift-check && systemctl enable rdfrn-drift-check.timer |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c systemctl mask bootc-fetch-apply-updates.timer bootc-fetch-apply-updates.service |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache && find /var/log -type f -exec truncate -s0 {} \; && for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/* |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/lib/certmonger /var/lib/dnf |
| |2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c bootc container lint --fatal-warnings |
| /bin/sh -c dnf install -y nginx nginx-mod-stream git-core && dnf clean all && rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache /var/lib/dnf && find /var/log -type f -exec truncate -s0 {} \; |
| COPY dir:f6534ad5793cf237f6c01bbf7b4b3ca5ebf3b556976046a15afd39d75bb999a6 in / |
| COPY dir:ce83fe0864200c06391340d0dbd64a33524fd51526c95c4ffab800adf8d8cb7b in /usr/lib/rdfrn-sandbox-tools |
| COPY dir:4e79656b769ca32ef54058fb17953eb99fd6db20dd0a008746d47b696a84d0af in /usr/rdfrn-kb/tools/kb/ |
| COPY dir:680dc2b267f9e9808e72e1258c90a96b110a60785bcbde9df7a8f1d1d3ea3d21 in /usr/rdfrn-kb/tools/lib/ |
| COPY dir:231ec9da4dafb8fb446f307b2fc2e9cf79a8891e367ccba1fd5d48f0311cdfe6 in /usr/rdfrn-kb/state/graph/ |
| COPY file:42ef988c86dc38a73e3826fa940138e61039f05fbcad200e7f9439172b0e550f in /usr/rdfrn-kb/docs/explanation/work-breakdown.md |
| /bin/sh -c python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; build.ensure_index(Path('/usr/rdfrn-kb'))" && python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; assert build._up_to_date(Path('/usr/rdfrn-kb/.kb/index.sqlite'), Path('/usr/rdfrn-kb/state/graph'))" |
| /bin/sh -c find /usr/rdfrn-kb -type d -name __pycache__ -prune -exec rm -rf {} + && find /usr/rdfrn-kb -type f -name '*.pyc' -delete |
| /bin/sh -c cd /usr/share/selinux/rdfrn && checkmodule -M -m -o rdfrn_hermes_engine.mod rdfrn_hermes_engine.te && semodule_package -o rdfrn_hermes_engine.pp -m rdfrn_hermes_engine.mod && semodule -N -i rdfrn_hermes_engine.pp && rm -f rdfrn_hermes_engine.mod rdfrn_hermes_engine.pp |
| /bin/sh -c chmod 0755 /usr/libexec/rdfrn-hermes-cert-* /usr/libexec/rdfrn-hermes-repo-sync && firewall-offline-cmd --zone=public --add-service=https && firewall-offline-cmd --zone=public --add-service=http && firewall-offline-cmd --new-policy=hermes-to-mon && firewall-offline-cmd --policy=hermes-to-mon --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-mon --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.10/32" port port="8443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.10/32" reject' && firewall-offline-cmd --new-policy=hermes-to-forgejo && firewall-offline-cmd --policy=hermes-to-forgejo --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-forgejo --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.135/32" port port="443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.135/32" reject' && setsebool -P httpd_can_network_connect on && systemctl enable nginx hermes-cert.service hermes-selinux.service rdfrn-hermes-repo-sync.timer |
| /bin/sh -c chown root:sssd /etc/sssd /etc/sssd/conf.d /etc/sssd/conf.d/50-hermes-access.conf && chmod 0750 /etc/sssd /etc/sssd/conf.d && chmod 0640 /etc/sssd/conf.d/50-hermes-access.conf && test "$(stat -c '%U:%G %a' /etc/sssd)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d/50-hermes-access.conf)" = "root:sssd 640" |
| /bin/sh -c for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/* |
| /bin/sh -c bootc container lint --fatal-warnings |
Labels
| Key | Value |
|---|---|
| build-date | 2026-08-08T03:31:30+00:00 |
| containers.bootc | 1 |
| io.buildah.version | 1.43.1 |
| org.opencontainers.image.created | 2026-08-08T03:31:30+00:00 |
| org.opencontainers.image.description | AlmaLinux Bootable Container Image |
| org.opencontainers.image.source | git://github.com/AlmaLinux/bootc-images.git |
| org.opencontainers.image.title | almalinux-bootc |
| org.opencontainers.image.url | https://github.com/AlmaLinux/bootc-images |
| org.opencontainers.image.vendor | AlmaLinux OS Foundation |
| org.opencontainers.image.version | 10.2.20260808.0 |
| ostree.bootable | 1 |
| ostree.commit | 4655ac19287b0d6607fc09441c8a9f8d8fc1e37c88e815c0d9a74b773cd31001 |
| ostree.final-diffid | sha256:12787d84fa137cd5649a9005efe98ec9d05ea46245fdc50aecb7dd007f2035b1 |
| redhat.id | almalinux |
| redhat.version-id | 10.2 |
| release | 10.2 |
| version | 10.2 |