hermes (ea8b849)

Published 2026-10-01 15:17:15 -07:00 by tral

Installation

docker pull repo.rdfrn.net/tral/hermes:ea8b849
sha256:634e875e8fe1de0c849adb133f619ff42ea501ecc1c3d72dabe892856c31c332

About this package

AlmaLinux Bootable Container Image

Image layers

ostree export of commit aa0c6e42a26e9bada5a0f238af20831ce67f1707206fc025867220d09586de92
nvidia-gpu-firmware-20260804-23.2.el10_2.noarch
linux-firmware-20260804-23.2.el10_2.noarch
podman-7:5.8.2-9.el10_2.alma.1.x86_64
atheros-firmware-20260804-23.2.el10_2.noarch
python3-libs-3.12.14-1.el10_2.x86_64
kernel-modules-6.12.0-211.56.1.el10_2.x86_64
rpm-4.19.1.1-23.el10.alma.1.x86_64
libicu-74.2-5.el10_0.x86_64
mt7xxx-firmware-20260804-23.2.el10_2.noarch
kernel-modules-core-6.12.0-211.56.1.el10_2.x86_64
amd-gpu-firmware-20260804-23.2.el10_2.noarch
skopeo-2:1.22.2-5.el10_2.x86_64
kernel-core-6.12.0-211.56.1.el10_2.x86_64
samba-client-libs-4.23.5-110.el10_2.x86_64
bootc-1.16.4-1.el10_2.alma.1.x86_64
sequoia-sq-1.3.1.1-1.el10.x86_64
microcode_ctl-4:20260812-0.el10_2.noarch
systemd-257-23.el10_2.2.alma.1.x86_64
glib2-2.80.4-12.el10_2.22.x86_64
rpm-ostree-2026.2-2.el10_2.x86_64
toolbox-0.3-2.el10_2.x86_64
systemd-udev-257-23.el10_2.2.alma.1.x86_64
coreutils-common-9.5-8.el10_2.1.x86_64
fwupd-2.0.19-4.1.el10_2.x86_64
NetworkManager-libnm-1:1.56.0-2.el10_2.x86_64
file-libs-5.45-9.el10.x86_64
hwdata-0.379-10.8.el10.noarch
brcmfmac-firmware-20260804-23.2.el10_2.noarch
gnupg2-2.4.5-4.el10_1.x86_64
cracklib-dicts-2.9.11-8.el10.x86_64
netavark-2:1.17.2-1.el10.x86_64
intel-gpu-firmware-20260804-23.2.el10_2.noarch
grub2-tools-1:2.12-46.el10_2.alma.1.x86_64
bash-5.2.26-6.el10.x86_64
glibc-gconv-extra-2.39-128.el10_2.alma.1.x86_64
podman-sequoia-0.4.0~pqc.3-1.el10_2.x86_64
152 components
glibc-2.39-128.el10_2.alma.1.x86_64
glibc-common-2.39-128.el10_2.alma.1.x86_64 and kernel-modules-extra-6.12.0-211.56.1.el10_2.x86_64
openssl-libs-1:3.5.8-1.el10_2.alma.1.x86_64 and grub2-common-1:2.12-46.el10_2.alma.1.noarch
7 components
10 components
grub2-tools-minimal-1:2.12-46.el10_2.alma.1.x86_64 and vim-minimal-2:9.1.083-9.el10_2.20.x86_64
10 components
realtek-firmware-20260804-23.2.el10_2.noarch and tiwilink-firmware-20260804-23.2.el10_2.noarch
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
10 components
20 components
20 components
13 components
20 components
20 components
20 components
9 components
initramfs (kernel 6.12.0-211.56.1.el10_2.x86_64) and rpmostree-unpackaged-content
Reserved for new packages
COPY multi:dc74a071b1aaef9530d8cd18cb2d56e69ae7ce9962c814e2896cd7d066005055 in /etc/yum.repos.d/
COPY file:fd7ad48161ff1c845aed5b48c26fab12bf8218dd5915766ee4c32729fd6655b2 in /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana
/bin/sh -c rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-grafana
/bin/sh -c dnf install -y ipa-client oddjob-mkhomedir firewalld cloud-init nfs-utils rsync vim-enhanced && dnf clean all && systemctl enable firewalld oddjobd && systemctl enable cloud-init-local.service cloud-init.service cloud-config.service cloud-final.service
/bin/sh -c dnf install -y alloy-1.19.2-1 && dnf clean all && systemctl enable alloy.service && rm -rf /var/lib/alloy
COPY dir:bc6911985618ba4fb0948122e2e0660e710d4dcce277d352f07c6863b141ab45 in /
/bin/sh -c rmdir /opt && ln -s var/opt /opt
/bin/sh -c ln -sf ../usr/share/zoneinfo/America/Los_Angeles /etc/localtime
/bin/sh -c mkdir -p /sysroot/ostree/bootc/storage
/bin/sh -c chmod 0440 /etc/sudoers.d/10-rdfrn-secure-path && visudo -cf /etc/sudoers.d/10-rdfrn-secure-path
/bin/sh -c update-ca-trust
/bin/sh -c chmod 0700 /usr/local/sbin/ipa-enroll-firstboot && systemctl enable ipa-enroll-firstboot.service
ARG RESTIC_VERSION
ARG RESTIC_SHA256 RESTIC_VERSION
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c curl -fsSL -o /tmp/restic.bz2 "https://github.com/restic/restic/releases/download/v${RESTIC_VERSION}/restic_${RESTIC_VERSION}_linux_amd64.bz2" && echo "${RESTIC_SHA256} /tmp/restic.bz2" | sha256sum -c - && bzip2 -d /tmp/restic.bz2 && install -m 0755 -o root -g root /tmp/restic /usr/local/bin/restic && rm -f /tmp/restic
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c mkdir -p /etc/rdfrn-backup.d && chmod 0755 /usr/local/sbin/rdfrn-backup && systemctl enable rdfrn-backup.timer
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c chmod 0755 /usr/local/sbin/rdfrn-drift-check && systemctl enable rdfrn-drift-check.timer
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c systemctl mask bootc-fetch-apply-updates.timer bootc-fetch-apply-updates.service
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache && find /var/log -type f -exec truncate -s0 {} \; && for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/*
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c rm -rf /var/lib/certmonger /var/lib/dnf
|2 RESTIC_SHA256=f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c RESTIC_VERSION=0.19.1 /bin/sh -c bootc container lint --fatal-warnings
/bin/sh -c dnf install -y nginx nginx-mod-stream git-core && dnf clean all && rm -rf /var/cache/dnf /var/log/dnf*.log /var/log/hawkey.log /var/lib/dnf/history.sqlite* /var/cache/ldconfig/aux-cache /var/lib/dnf && find /var/log -type f -exec truncate -s0 {} \;
COPY dir:f6534ad5793cf237f6c01bbf7b4b3ca5ebf3b556976046a15afd39d75bb999a6 in /
COPY dir:ce83fe0864200c06391340d0dbd64a33524fd51526c95c4ffab800adf8d8cb7b in /usr/lib/rdfrn-sandbox-tools
COPY dir:4e79656b769ca32ef54058fb17953eb99fd6db20dd0a008746d47b696a84d0af in /usr/rdfrn-kb/tools/kb/
COPY dir:680dc2b267f9e9808e72e1258c90a96b110a60785bcbde9df7a8f1d1d3ea3d21 in /usr/rdfrn-kb/tools/lib/
COPY dir:231ec9da4dafb8fb446f307b2fc2e9cf79a8891e367ccba1fd5d48f0311cdfe6 in /usr/rdfrn-kb/state/graph/
COPY file:42ef988c86dc38a73e3826fa940138e61039f05fbcad200e7f9439172b0e550f in /usr/rdfrn-kb/docs/explanation/work-breakdown.md
/bin/sh -c python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; build.ensure_index(Path('/usr/rdfrn-kb'))" && python3 -B -c "import sys; from pathlib import Path; sys.path.insert(0, '/usr/rdfrn-kb/tools/kb'); from index import build; assert build._up_to_date(Path('/usr/rdfrn-kb/.kb/index.sqlite'), Path('/usr/rdfrn-kb/state/graph'))"
/bin/sh -c find /usr/rdfrn-kb -type d -name __pycache__ -prune -exec rm -rf {} + && find /usr/rdfrn-kb -type f -name '*.pyc' -delete
/bin/sh -c cd /usr/share/selinux/rdfrn && checkmodule -M -m -o rdfrn_hermes_engine.mod rdfrn_hermes_engine.te && semodule_package -o rdfrn_hermes_engine.pp -m rdfrn_hermes_engine.mod && semodule -N -i rdfrn_hermes_engine.pp && rm -f rdfrn_hermes_engine.mod rdfrn_hermes_engine.pp
/bin/sh -c chmod 0755 /usr/libexec/rdfrn-hermes-cert-* /usr/libexec/rdfrn-hermes-repo-sync && firewall-offline-cmd --zone=public --add-service=https && firewall-offline-cmd --zone=public --add-service=http && firewall-offline-cmd --new-policy=hermes-to-mon && firewall-offline-cmd --policy=hermes-to-mon --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-mon --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.10/32" port port="8443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-mon --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.10/32" reject' && firewall-offline-cmd --new-policy=hermes-to-forgejo && firewall-offline-cmd --policy=hermes-to-forgejo --add-ingress-zone=HOST && firewall-offline-cmd --policy=hermes-to-forgejo --add-egress-zone=ANY && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-2" family="ipv4" destination address="192.168.1.135/32" port port="443" protocol="tcp" accept' && firewall-offline-cmd --policy=hermes-to-forgejo --add-rich-rule='rule priority="-1" family="ipv4" destination address="192.168.1.135/32" reject' && setsebool -P httpd_can_network_connect on && systemctl enable nginx hermes-cert.service hermes-selinux.service rdfrn-hermes-repo-sync.timer
/bin/sh -c chown root:sssd /etc/sssd /etc/sssd/conf.d /etc/sssd/conf.d/50-hermes-access.conf && chmod 0750 /etc/sssd /etc/sssd/conf.d && chmod 0640 /etc/sssd/conf.d/50-hermes-access.conf && test "$(stat -c '%U:%G %a' /etc/sssd)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d)" = "root:sssd 750" && test "$(stat -c '%U:%G %a' /etc/sssd/conf.d/50-hermes-access.conf)" = "root:sssd 640"
/bin/sh -c for entry in /run/* /run/.*; do case "$entry" in /run/.|/run/..) continue ;; esac; [ -e "$entry" ] || continue; mountpoint -q "$entry" && continue; rm -rf "$entry"; done && rm -rf /tmp/*
/bin/sh -c bootc container lint --fatal-warnings

Labels

Key Value
build-date 2026-10-01T03:17:02+00:00
containers.bootc 1
io.buildah.version 1.43.1
org.opencontainers.image.created 2026-10-01T03:17:02+00:00
org.opencontainers.image.description AlmaLinux Bootable Container Image
org.opencontainers.image.source git://github.com/AlmaLinux/bootc-images.git
org.opencontainers.image.title almalinux-bootc
org.opencontainers.image.url https://github.com/AlmaLinux/bootc-images
org.opencontainers.image.vendor AlmaLinux OS Foundation
org.opencontainers.image.version 10.2.20261001.0
ostree.bootable 1
ostree.commit aa0c6e42a26e9bada5a0f238af20831ce67f1707206fc025867220d09586de92
ostree.final-diffid sha256:12787d84fa137cd5649a9005efe98ec9d05ea46245fdc50aecb7dd007f2035b1
redhat.id almalinux
redhat.version-id 10.2
release 10.2
version 10.2
Details
Container
2026-10-01 15:17:15 -07:00
1
OCI / Docker
linux/amd64
1.1 GiB
Versions (106) View all
testing 2026-10-04
5488ef6 2026-10-04
f1416c5 2026-10-04
52a8086 2026-10-04
0e018ee 2026-10-03