[{"data":1,"prerenderedAt":1578},["ShallowReactive",2],{"navigation":3,"\u002Fpoc\u002Fsetup-server":73,"\u002Fpoc\u002Fsetup-server-surround":1563,"-poc-setup-server-description":1568},[4,9,14,63,68],{"title":5,"path":6,"stem":7,"icon":8},"Goals","\u002Fgoals","0.goals","i-lucide-goal",{"title":10,"path":11,"stem":12,"icon":13},"Specification","\u002Fspec","1.spec","i-lucide-square-pen",{"title":15,"path":16,"stem":17,"children":18,"icon":62},"Proof of Concept","\u002Fpoc","3.poc\u002F0.index",[19,22,27,32,37,42,47,52,57],{"title":20,"path":16,"stem":17,"icon":21},"Overview","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Container Image","\u002Fpoc\u002Fmanage-image","3.poc\u002F1.manage-image","i-lucide-layers",{"title":28,"path":29,"stem":30,"icon":31},"Server Setup","\u002Fpoc\u002Fsetup-server","3.poc\u002F2.setup-server","i-lucide-server",{"title":33,"path":34,"stem":35,"icon":36},"User Management","\u002Fpoc\u002Fmanage-users","3.poc\u002F3.manage-users","i-lucide-square-user",{"title":38,"path":39,"stem":40,"icon":41},"Fleet Management","\u002Fpoc\u002Fmanage-fleet","3.poc\u002F4.manage-fleet","i-lucide-circle-pile",{"title":43,"path":44,"stem":45,"icon":46},"Provisioning","\u002Fpoc\u002Fprovisioning","3.poc\u002F5.provisioning","i-lucide-image-down",{"title":48,"path":49,"stem":50,"icon":51},"User Data","\u002Fpoc\u002Fmanage-data","3.poc\u002F6.manage-data","i-lucide-folder-sync",{"title":53,"path":54,"stem":55,"icon":56},"Branding","\u002Fpoc\u002Fbranding","3.poc\u002F7.branding","i-lucide-paintbrush",{"title":58,"path":59,"stem":60,"icon":61},"Legacy Apps","\u002Fpoc\u002Flegacy-apps","3.poc\u002F7.legacy-apps","i-lucide-hourglass","i-lucide-code-xml",{"title":64,"path":65,"stem":66,"icon":67},"Use Cases","\u002Fuse-cases","4.use-cases","i-lucide-list",{"title":69,"path":70,"stem":71,"icon":72},"FAQ","\u002Ffaq","5.faq","i-lucide-message-circle-question-mark",{"id":74,"title":28,"body":75,"description":1557,"extension":1558,"meta":1559,"navigation":1560,"path":29,"seo":1561,"stem":30,"__hash__":1562},"docs\u002F3.poc\u002F2.setup-server.md",{"type":76,"value":77,"toc":1550},"minimark",[78,88,93,96,115,119,130,154,171,1404,1408,1415,1446,1450,1453,1506,1510,1513,1538,1546],[79,80,81],"p",{},[82,83],"img",{"alt":84,"className":85,"src":87},"EU OS PoC Architecture",[86],"white-chart","\u002Fassets\u002Feu-os-poc-architecture.webp",[89,90,92],"h2",{"id":91},"hardware","Hardware for a Proof of Concept",[79,94,95],{},"To make testing EU OS affordable (and due to the lack of budget for the EU OS process), the following recommendations for hardware are more or less the minimum. Better hardware is always better.",[97,98,99,103,106,109,112],"ul",{},[100,101,102],"li",{},"EU OS Server with 16GB RAM (e.g. Lenovo ThinkCentre M75q Tiny Gen 2 with AMD Ryzen 5 Pro,  256GB SSD, 16GBRAM in 2025 second-hand for 400€)",[100,104,105],{},"Laptop to test provisioning (e.g. Lenovo Thinkpad T14s Gen 2 with PXE support in UEFI mode)",[100,107,108],{},"optional: FIDO2 token to demonstrate unlocking of full disk encryption with hardware token (e.g. USB YubiKey 5A in 2025 new for 30€)",[100,110,111],{},"few network cables",[100,113,114],{},"wifi router or an EU OS Server with a 2nd ethernet port (you need one to connect the Laptop)",[89,116,118],{"id":117},"config","Configuration of the EU OS Server",[79,120,121,122,129],{},"The Foreman Server VM must use an OS that is supported by the software Foreman with Katello plugin. The ",[123,124,128],"a",{"href":125,"rel":126},"https:\u002F\u002Fdocs.theforeman.org\u002F3.16\u002FQuickstart\u002Findex-katello.html",[127],"nofollow","quickinstall manual"," proposes any Enterprise Linux 9. Hence, EU OS proposes for the PoC to use Almalinux 9.6 (most recent as of November 2025). To avoid confusion, EU OS proposes to use AlmaLinux 9.6 on all three systems: both VMs and also the EU OS Server.",[79,131,132,133,137,138,142,143,148,149,153],{},"Download the ",[134,135,136],"em",{},"Boot ISO"," for Almalinux 9 from ",[123,139,140],{"href":140,"rel":141},"https:\u002F\u002Falmalinux.org\u002Fget-almalinux\u002F",[127],". Copy it on a USB pendrive (e.g. with the ",[123,144,147],{"href":145,"rel":146},"https:\u002F\u002Fdocs.fedoraproject.org\u002Fen-US\u002Ffedora\u002Flatest\u002Fpreparing-boot-media\u002F",[127],"Fedora Media Writer",") and boot the EU OS Server from it. Then log in. Then follow the steps in the ",[150,151,152],"code",{},"setup-server.sh",". Note that the script cannot be run automatically as it requires few values been set manually.",[79,155,156,157,162,163,166,167,170],{},"AlmaLinux Generic Cloud images rely on ",[123,158,161],{"href":159,"rel":160},"https:\u002F\u002Fcloudinit.readthedocs.io\u002Fen\u002Flatest\u002Findex.html",[127],"cloud-init"," to setup default users\u002Fpasswords. So you should put into your ",[150,164,165],{},"$HOME"," a corresponding ",[150,168,169],{},"ci_user_data_ssh_auth_pass_pubkey",". For this setup, you may want to use in the VMs the dafault user \"almalinux\", because that is what is used in the documents here.",[172,173,174,1276,1365],"code-group",{},[175,176,181],"pre",{"className":177,"code":178,"filename":152,"language":179,"meta":180,"style":180},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# sudo usermod -a -G libvirt,wheel your_existing_user\n# sudo useradd -m -G libvirt,wheel your_new_user\n\nsudo hostnamectl hostname server.eu-os.internal\n\n# optional: convenience tools\nsudo dnf install -y wireguard-tools btop skopeo hwinfo fastfetch fish\n\n# for wifi on EU OS Server\nsudo dnf install -y NetworkManager-wifi\n\nsudo dnf install -y qemu-kvm libvirt virt-install bridge-utils libvirt-daemon-kvm\n\n# bring up virtualisation service\nsudo systemctl enable --now libvirtd\n\n# setup wifi, so that the ethernet interface can be disabled and mapped to the VM\nsudo nmcli device wifi connect \"\u003CWIFI-SSID>\" --ask # connect to wifi with password\n\nsudo chmod og+r \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002F\n\nsudo wget -o \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2 https:\u002F\u002Frepo.almalinux.org\u002Falmalinux\u002F9\u002Fcloud\u002Fx86_64\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2\n\n# create 2 VMS for freeipa and foreman\nsudo qemu-img create -f qcow2 -b \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2 -F qcow2 \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-freeipa.qcow2 20G\nsudo qemu-img create -f qcow2 -b \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2 -F qcow2 \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman.qcow2 40G\n\nexport LIBVIRT_DEFAULT_URI=qemu:\u002F\u002F\u002Fsystem\n# for fish: set -Ux LIBVIRT_DEFAULT_URI qemu:\u002F\u002F\u002Fsystem\n\nvirt-install \\\n    --name alma9-freeipa \\\n    --memory 2048 \\\n    --machine q35 \\\n    --vcpus 6 \\\n    --cpu host-passthrough \\\n    --import \\\n    --cloud-init user-data=\"ci_user_data_ssh_auth_pass_pubkey\",meta-data=\"ci_keyboard\" \\\n    --osinfo name=almalinux9 \\\n    --disk \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-freeipa.qcow2 \\\n    --virt-type kvm \\\n    --memorybacking=source.type=memfd,access.mode=shared \\\n    --network default,mac=52:54:00:00:00:12 \\\n    --noautoconsole\n\nvirt-install \\\n    --name alma9-foreman \\\n    --memory 10240 \\\n    --machine q35 \\\n    --vcpus 6 \\\n    --cpu host-passthrough \\\n    --import \\\n    --cloud-init user-data=\"ci_user_data_ssh_auth_pass_pubkey\",meta-data=\"ci_keyboard\" \\\n    --osinfo name=almalinux9 \\\n    --disk \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman.qcow2 \\\n    --virt-type kvm \\\n    --memorybacking=source.type=memfd,access.mode=shared \\\n    --network default,mac=52:54:00:00:00:11 \\\n    --noautoconsole\n\nvirsh list\n\n# Setup DNS entries for libvirt with MAC set by libvirt upon VM creation\nvirsh net-update default add ip-dhcp-host \\\n      \"\u003Chost mac='52:54:00:00:00:12' name='users' ip='192.168.122.112' \u002F>\" \\\n       --live --config\nvirsh net-update default add ip-dhcp-host \\\n      \"\u003Chost mac='52:54:00:00:00:11' name='fleet' ip='192.168.122.111' \u002F>\" \\\n       --live --config\n\n# later not needed when DNS is configured fully with freeipa\nvirsh net-update default add dns-host \\\n      \"\u003Chost ip='192.168.122.112'>\u003Chostname>users.eu-os.internal\u003C\u002Fhostname>\u003C\u002Fhost>\" \\\n       --live --config\nvirsh net-update default add dns-host \\\n      \"\u003Chost ip='192.168.122.111'>\u003Chostname>fleet.eu-os.internal\u003C\u002Fhostname>\u003C\u002Fhost>\" \\\n       --live --config\n\nvirsh net-dumpxml default # check config, edit with (requires restart of network): virsh net-edit default\n\n\n# setup enp2s0f1 as mactvtap for foreman VM\nsudo nmcli connection modify enp2s0f1 connection.autoconnect false\nsudo nmcli connection down enp2s0f1\nsudo virsh attach-interface --domain alma9-foreman --type direct --source enp2s0f1 --model virtio --config\n\n# optional: add swap partition to foreman\nsudo qemu-img create -f raw \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman-swap.img 20G\nvirsh attach-disk alma9-foreman --source \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman-swap.img --target vdb --live --persistent\n\n# enable autostart\nvirsh autostart alma9-freeipa\nvirsh autostart alma9-foreman\n\n# get IP address\nvirsh domifaddr --source agent alma9-freeipa\nvirsh domifaddr --source agent alma9-foreman\n\n# start VMs\nvirsh start alma9-freeipa\nvirsh start alma9-foreman\n","bash","",[150,182,183,192,198,205,222,227,233,265,270,276,290,295,321,326,332,349,354,360,393,398,412,417,434,439,445,478,505,510,527,533,538,547,558,570,581,592,603,611,638,649,659,670,678,689,695,700,707,717,727,736,745,754,761,784,793,802,811,818,828,833,838,847,852,858,877,890,899,914,926,933,938,944,960,972,979,994,1006,1013,1018,1031,1036,1041,1047,1069,1084,1119,1124,1130,1149,1175,1180,1186,1197,1207,1212,1218,1233,1246,1251,1257,1267],{"__ignoreMap":180},[184,185,188],"span",{"class":186,"line":187},"line",1,[184,189,191],{"class":190},"sHwdD","# sudo usermod -a -G libvirt,wheel your_existing_user\n",[184,193,195],{"class":186,"line":194},2,[184,196,197],{"class":190},"# sudo useradd -m -G libvirt,wheel your_new_user\n",[184,199,201],{"class":186,"line":200},3,[184,202,204],{"emptyLinePlaceholder":203},true,"\n",[184,206,208,212,216,219],{"class":186,"line":207},4,[184,209,211],{"class":210},"sBMFI","sudo",[184,213,215],{"class":214},"sfazB"," hostnamectl",[184,217,218],{"class":214}," hostname",[184,220,221],{"class":214}," server.eu-os.internal\n",[184,223,225],{"class":186,"line":224},5,[184,226,204],{"emptyLinePlaceholder":203},[184,228,230],{"class":186,"line":229},6,[184,231,232],{"class":190},"# optional: convenience tools\n",[184,234,236,238,241,244,247,250,253,256,259,262],{"class":186,"line":235},7,[184,237,211],{"class":210},[184,239,240],{"class":214}," dnf",[184,242,243],{"class":214}," install",[184,245,246],{"class":214}," -y",[184,248,249],{"class":214}," wireguard-tools",[184,251,252],{"class":214}," btop",[184,254,255],{"class":214}," skopeo",[184,257,258],{"class":214}," hwinfo",[184,260,261],{"class":214}," fastfetch",[184,263,264],{"class":214}," fish\n",[184,266,268],{"class":186,"line":267},8,[184,269,204],{"emptyLinePlaceholder":203},[184,271,273],{"class":186,"line":272},9,[184,274,275],{"class":190},"# for wifi on EU OS Server\n",[184,277,279,281,283,285,287],{"class":186,"line":278},10,[184,280,211],{"class":210},[184,282,240],{"class":214},[184,284,243],{"class":214},[184,286,246],{"class":214},[184,288,289],{"class":214}," NetworkManager-wifi\n",[184,291,293],{"class":186,"line":292},11,[184,294,204],{"emptyLinePlaceholder":203},[184,296,298,300,302,304,306,309,312,315,318],{"class":186,"line":297},12,[184,299,211],{"class":210},[184,301,240],{"class":214},[184,303,243],{"class":214},[184,305,246],{"class":214},[184,307,308],{"class":214}," qemu-kvm",[184,310,311],{"class":214}," libvirt",[184,313,314],{"class":214}," virt-install",[184,316,317],{"class":214}," bridge-utils",[184,319,320],{"class":214}," libvirt-daemon-kvm\n",[184,322,324],{"class":186,"line":323},13,[184,325,204],{"emptyLinePlaceholder":203},[184,327,329],{"class":186,"line":328},14,[184,330,331],{"class":190},"# bring up virtualisation service\n",[184,333,335,337,340,343,346],{"class":186,"line":334},15,[184,336,211],{"class":210},[184,338,339],{"class":214}," systemctl",[184,341,342],{"class":214}," enable",[184,344,345],{"class":214}," --now",[184,347,348],{"class":214}," libvirtd\n",[184,350,352],{"class":186,"line":351},16,[184,353,204],{"emptyLinePlaceholder":203},[184,355,357],{"class":186,"line":356},17,[184,358,359],{"class":190},"# setup wifi, so that the ethernet interface can be disabled and mapped to the VM\n",[184,361,363,365,368,371,374,377,381,384,387,390],{"class":186,"line":362},18,[184,364,211],{"class":210},[184,366,367],{"class":214}," nmcli",[184,369,370],{"class":214}," device",[184,372,373],{"class":214}," wifi",[184,375,376],{"class":214}," connect",[184,378,380],{"class":379},"sMK4o"," \"",[184,382,383],{"class":214},"\u003CWIFI-SSID>",[184,385,386],{"class":379},"\"",[184,388,389],{"class":214}," --ask",[184,391,392],{"class":190}," # connect to wifi with password\n",[184,394,396],{"class":186,"line":395},19,[184,397,204],{"emptyLinePlaceholder":203},[184,399,401,403,406,409],{"class":186,"line":400},20,[184,402,211],{"class":210},[184,404,405],{"class":214}," chmod",[184,407,408],{"class":214}," og+r",[184,410,411],{"class":214}," \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002F\n",[184,413,415],{"class":186,"line":414},21,[184,416,204],{"emptyLinePlaceholder":203},[184,418,420,422,425,428,431],{"class":186,"line":419},22,[184,421,211],{"class":210},[184,423,424],{"class":214}," wget",[184,426,427],{"class":214}," -o",[184,429,430],{"class":214}," \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2",[184,432,433],{"class":214}," https:\u002F\u002Frepo.almalinux.org\u002Falmalinux\u002F9\u002Fcloud\u002Fx86_64\u002Fimages\u002FAlmaLinux-9-GenericCloud-9.6-20250522.x86_64.qcow2\n",[184,435,437],{"class":186,"line":436},23,[184,438,204],{"emptyLinePlaceholder":203},[184,440,442],{"class":186,"line":441},24,[184,443,444],{"class":190},"# create 2 VMS for freeipa and foreman\n",[184,446,448,450,453,456,459,462,465,467,470,472,475],{"class":186,"line":447},25,[184,449,211],{"class":210},[184,451,452],{"class":214}," qemu-img",[184,454,455],{"class":214}," create",[184,457,458],{"class":214}," -f",[184,460,461],{"class":214}," qcow2",[184,463,464],{"class":214}," -b",[184,466,430],{"class":214},[184,468,469],{"class":214}," -F",[184,471,461],{"class":214},[184,473,474],{"class":214}," \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-freeipa.qcow2",[184,476,477],{"class":214}," 20G\n",[184,479,481,483,485,487,489,491,493,495,497,499,502],{"class":186,"line":480},26,[184,482,211],{"class":210},[184,484,452],{"class":214},[184,486,455],{"class":214},[184,488,458],{"class":214},[184,490,461],{"class":214},[184,492,464],{"class":214},[184,494,430],{"class":214},[184,496,469],{"class":214},[184,498,461],{"class":214},[184,500,501],{"class":214}," \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman.qcow2",[184,503,504],{"class":214}," 40G\n",[184,506,508],{"class":186,"line":507},27,[184,509,204],{"emptyLinePlaceholder":203},[184,511,513,517,521,524],{"class":186,"line":512},28,[184,514,516],{"class":515},"spNyl","export",[184,518,520],{"class":519},"sTEyZ"," LIBVIRT_DEFAULT_URI",[184,522,523],{"class":379},"=",[184,525,526],{"class":519},"qemu:\u002F\u002F\u002Fsystem\n",[184,528,530],{"class":186,"line":529},29,[184,531,532],{"class":190},"# for fish: set -Ux LIBVIRT_DEFAULT_URI qemu:\u002F\u002F\u002Fsystem\n",[184,534,536],{"class":186,"line":535},30,[184,537,204],{"emptyLinePlaceholder":203},[184,539,541,544],{"class":186,"line":540},31,[184,542,543],{"class":210},"virt-install",[184,545,546],{"class":519}," \\\n",[184,548,550,553,556],{"class":186,"line":549},32,[184,551,552],{"class":214},"    --name",[184,554,555],{"class":214}," alma9-freeipa",[184,557,546],{"class":519},[184,559,561,564,568],{"class":186,"line":560},33,[184,562,563],{"class":214},"    --memory",[184,565,567],{"class":566},"sbssI"," 2048",[184,569,546],{"class":519},[184,571,573,576,579],{"class":186,"line":572},34,[184,574,575],{"class":214},"    --machine",[184,577,578],{"class":214}," q35",[184,580,546],{"class":519},[184,582,584,587,590],{"class":186,"line":583},35,[184,585,586],{"class":214},"    --vcpus",[184,588,589],{"class":566}," 6",[184,591,546],{"class":519},[184,593,595,598,601],{"class":186,"line":594},36,[184,596,597],{"class":214},"    --cpu",[184,599,600],{"class":214}," host-passthrough",[184,602,546],{"class":519},[184,604,606,609],{"class":186,"line":605},37,[184,607,608],{"class":214},"    --import",[184,610,546],{"class":519},[184,612,614,617,620,622,624,626,629,631,634,636],{"class":186,"line":613},38,[184,615,616],{"class":214},"    --cloud-init",[184,618,619],{"class":214}," user-data=",[184,621,386],{"class":379},[184,623,169],{"class":214},[184,625,386],{"class":379},[184,627,628],{"class":214},",meta-data=",[184,630,386],{"class":379},[184,632,633],{"class":214},"ci_keyboard",[184,635,386],{"class":379},[184,637,546],{"class":519},[184,639,641,644,647],{"class":186,"line":640},39,[184,642,643],{"class":214},"    --osinfo",[184,645,646],{"class":214}," name=almalinux9",[184,648,546],{"class":519},[184,650,652,655,657],{"class":186,"line":651},40,[184,653,654],{"class":214},"    --disk",[184,656,474],{"class":214},[184,658,546],{"class":519},[184,660,662,665,668],{"class":186,"line":661},41,[184,663,664],{"class":214},"    --virt-type",[184,666,667],{"class":214}," kvm",[184,669,546],{"class":519},[184,671,673,676],{"class":186,"line":672},42,[184,674,675],{"class":214},"    --memorybacking=source.type=memfd,access.mode=shared",[184,677,546],{"class":519},[184,679,681,684,687],{"class":186,"line":680},43,[184,682,683],{"class":214},"    --network",[184,685,686],{"class":214}," default,mac=52:54:00:00:00:12",[184,688,546],{"class":519},[184,690,692],{"class":186,"line":691},44,[184,693,694],{"class":214},"    --noautoconsole\n",[184,696,698],{"class":186,"line":697},45,[184,699,204],{"emptyLinePlaceholder":203},[184,701,703,705],{"class":186,"line":702},46,[184,704,543],{"class":210},[184,706,546],{"class":519},[184,708,710,712,715],{"class":186,"line":709},47,[184,711,552],{"class":214},[184,713,714],{"class":214}," alma9-foreman",[184,716,546],{"class":519},[184,718,720,722,725],{"class":186,"line":719},48,[184,721,563],{"class":214},[184,723,724],{"class":566}," 10240",[184,726,546],{"class":519},[184,728,730,732,734],{"class":186,"line":729},49,[184,731,575],{"class":214},[184,733,578],{"class":214},[184,735,546],{"class":519},[184,737,739,741,743],{"class":186,"line":738},50,[184,740,586],{"class":214},[184,742,589],{"class":566},[184,744,546],{"class":519},[184,746,748,750,752],{"class":186,"line":747},51,[184,749,597],{"class":214},[184,751,600],{"class":214},[184,753,546],{"class":519},[184,755,757,759],{"class":186,"line":756},52,[184,758,608],{"class":214},[184,760,546],{"class":519},[184,762,764,766,768,770,772,774,776,778,780,782],{"class":186,"line":763},53,[184,765,616],{"class":214},[184,767,619],{"class":214},[184,769,386],{"class":379},[184,771,169],{"class":214},[184,773,386],{"class":379},[184,775,628],{"class":214},[184,777,386],{"class":379},[184,779,633],{"class":214},[184,781,386],{"class":379},[184,783,546],{"class":519},[184,785,787,789,791],{"class":186,"line":786},54,[184,788,643],{"class":214},[184,790,646],{"class":214},[184,792,546],{"class":519},[184,794,796,798,800],{"class":186,"line":795},55,[184,797,654],{"class":214},[184,799,501],{"class":214},[184,801,546],{"class":519},[184,803,805,807,809],{"class":186,"line":804},56,[184,806,664],{"class":214},[184,808,667],{"class":214},[184,810,546],{"class":519},[184,812,814,816],{"class":186,"line":813},57,[184,815,675],{"class":214},[184,817,546],{"class":519},[184,819,821,823,826],{"class":186,"line":820},58,[184,822,683],{"class":214},[184,824,825],{"class":214}," default,mac=52:54:00:00:00:11",[184,827,546],{"class":519},[184,829,831],{"class":186,"line":830},59,[184,832,694],{"class":214},[184,834,836],{"class":186,"line":835},60,[184,837,204],{"emptyLinePlaceholder":203},[184,839,841,844],{"class":186,"line":840},61,[184,842,843],{"class":210},"virsh",[184,845,846],{"class":214}," list\n",[184,848,850],{"class":186,"line":849},62,[184,851,204],{"emptyLinePlaceholder":203},[184,853,855],{"class":186,"line":854},63,[184,856,857],{"class":190},"# Setup DNS entries for libvirt with MAC set by libvirt upon VM creation\n",[184,859,861,863,866,869,872,875],{"class":186,"line":860},64,[184,862,843],{"class":210},[184,864,865],{"class":214}," net-update",[184,867,868],{"class":214}," default",[184,870,871],{"class":214}," add",[184,873,874],{"class":214}," ip-dhcp-host",[184,876,546],{"class":519},[184,878,880,883,886,888],{"class":186,"line":879},65,[184,881,882],{"class":379},"      \"",[184,884,885],{"class":214},"\u003Chost mac='52:54:00:00:00:12' name='users' ip='192.168.122.112' \u002F>",[184,887,386],{"class":379},[184,889,546],{"class":519},[184,891,893,896],{"class":186,"line":892},66,[184,894,895],{"class":214},"       --live",[184,897,898],{"class":214}," --config\n",[184,900,902,904,906,908,910,912],{"class":186,"line":901},67,[184,903,843],{"class":210},[184,905,865],{"class":214},[184,907,868],{"class":214},[184,909,871],{"class":214},[184,911,874],{"class":214},[184,913,546],{"class":519},[184,915,917,919,922,924],{"class":186,"line":916},68,[184,918,882],{"class":379},[184,920,921],{"class":214},"\u003Chost mac='52:54:00:00:00:11' name='fleet' ip='192.168.122.111' \u002F>",[184,923,386],{"class":379},[184,925,546],{"class":519},[184,927,929,931],{"class":186,"line":928},69,[184,930,895],{"class":214},[184,932,898],{"class":214},[184,934,936],{"class":186,"line":935},70,[184,937,204],{"emptyLinePlaceholder":203},[184,939,941],{"class":186,"line":940},71,[184,942,943],{"class":190},"# later not needed when DNS is configured fully with freeipa\n",[184,945,947,949,951,953,955,958],{"class":186,"line":946},72,[184,948,843],{"class":210},[184,950,865],{"class":214},[184,952,868],{"class":214},[184,954,871],{"class":214},[184,956,957],{"class":214}," dns-host",[184,959,546],{"class":519},[184,961,963,965,968,970],{"class":186,"line":962},73,[184,964,882],{"class":379},[184,966,967],{"class":214},"\u003Chost ip='192.168.122.112'>\u003Chostname>users.eu-os.internal\u003C\u002Fhostname>\u003C\u002Fhost>",[184,969,386],{"class":379},[184,971,546],{"class":519},[184,973,975,977],{"class":186,"line":974},74,[184,976,895],{"class":214},[184,978,898],{"class":214},[184,980,982,984,986,988,990,992],{"class":186,"line":981},75,[184,983,843],{"class":210},[184,985,865],{"class":214},[184,987,868],{"class":214},[184,989,871],{"class":214},[184,991,957],{"class":214},[184,993,546],{"class":519},[184,995,997,999,1002,1004],{"class":186,"line":996},76,[184,998,882],{"class":379},[184,1000,1001],{"class":214},"\u003Chost ip='192.168.122.111'>\u003Chostname>fleet.eu-os.internal\u003C\u002Fhostname>\u003C\u002Fhost>",[184,1003,386],{"class":379},[184,1005,546],{"class":519},[184,1007,1009,1011],{"class":186,"line":1008},77,[184,1010,895],{"class":214},[184,1012,898],{"class":214},[184,1014,1016],{"class":186,"line":1015},78,[184,1017,204],{"emptyLinePlaceholder":203},[184,1019,1021,1023,1026,1028],{"class":186,"line":1020},79,[184,1022,843],{"class":210},[184,1024,1025],{"class":214}," net-dumpxml",[184,1027,868],{"class":214},[184,1029,1030],{"class":190}," # check config, edit with (requires restart of network): virsh net-edit default\n",[184,1032,1034],{"class":186,"line":1033},80,[184,1035,204],{"emptyLinePlaceholder":203},[184,1037,1039],{"class":186,"line":1038},81,[184,1040,204],{"emptyLinePlaceholder":203},[184,1042,1044],{"class":186,"line":1043},82,[184,1045,1046],{"class":190},"# setup enp2s0f1 as mactvtap for foreman VM\n",[184,1048,1050,1052,1054,1057,1060,1063,1066],{"class":186,"line":1049},83,[184,1051,211],{"class":210},[184,1053,367],{"class":214},[184,1055,1056],{"class":214}," connection",[184,1058,1059],{"class":214}," modify",[184,1061,1062],{"class":214}," enp2s0f1",[184,1064,1065],{"class":214}," connection.autoconnect",[184,1067,1068],{"class":379}," false\n",[184,1070,1072,1074,1076,1078,1081],{"class":186,"line":1071},84,[184,1073,211],{"class":210},[184,1075,367],{"class":214},[184,1077,1056],{"class":214},[184,1079,1080],{"class":214}," down",[184,1082,1083],{"class":214}," enp2s0f1\n",[184,1085,1087,1089,1092,1095,1098,1100,1103,1106,1109,1111,1114,1117],{"class":186,"line":1086},85,[184,1088,211],{"class":210},[184,1090,1091],{"class":214}," virsh",[184,1093,1094],{"class":214}," attach-interface",[184,1096,1097],{"class":214}," --domain",[184,1099,714],{"class":214},[184,1101,1102],{"class":214}," --type",[184,1104,1105],{"class":214}," direct",[184,1107,1108],{"class":214}," --source",[184,1110,1062],{"class":214},[184,1112,1113],{"class":214}," --model",[184,1115,1116],{"class":214}," virtio",[184,1118,898],{"class":214},[184,1120,1122],{"class":186,"line":1121},86,[184,1123,204],{"emptyLinePlaceholder":203},[184,1125,1127],{"class":186,"line":1126},87,[184,1128,1129],{"class":190},"# optional: add swap partition to foreman\n",[184,1131,1133,1135,1137,1139,1141,1144,1147],{"class":186,"line":1132},88,[184,1134,211],{"class":210},[184,1136,452],{"class":214},[184,1138,455],{"class":214},[184,1140,458],{"class":214},[184,1142,1143],{"class":214}," raw",[184,1145,1146],{"class":214}," \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman-swap.img",[184,1148,477],{"class":214},[184,1150,1152,1154,1157,1159,1161,1163,1166,1169,1172],{"class":186,"line":1151},89,[184,1153,843],{"class":210},[184,1155,1156],{"class":214}," attach-disk",[184,1158,714],{"class":214},[184,1160,1108],{"class":214},[184,1162,1146],{"class":214},[184,1164,1165],{"class":214}," --target",[184,1167,1168],{"class":214}," vdb",[184,1170,1171],{"class":214}," --live",[184,1173,1174],{"class":214}," --persistent\n",[184,1176,1178],{"class":186,"line":1177},90,[184,1179,204],{"emptyLinePlaceholder":203},[184,1181,1183],{"class":186,"line":1182},91,[184,1184,1185],{"class":190},"# enable autostart\n",[184,1187,1189,1191,1194],{"class":186,"line":1188},92,[184,1190,843],{"class":210},[184,1192,1193],{"class":214}," autostart",[184,1195,1196],{"class":214}," alma9-freeipa\n",[184,1198,1200,1202,1204],{"class":186,"line":1199},93,[184,1201,843],{"class":210},[184,1203,1193],{"class":214},[184,1205,1206],{"class":214}," alma9-foreman\n",[184,1208,1210],{"class":186,"line":1209},94,[184,1211,204],{"emptyLinePlaceholder":203},[184,1213,1215],{"class":186,"line":1214},95,[184,1216,1217],{"class":190},"# get IP address\n",[184,1219,1221,1223,1226,1228,1231],{"class":186,"line":1220},96,[184,1222,843],{"class":210},[184,1224,1225],{"class":214}," domifaddr",[184,1227,1108],{"class":214},[184,1229,1230],{"class":214}," agent",[184,1232,1196],{"class":214},[184,1234,1236,1238,1240,1242,1244],{"class":186,"line":1235},97,[184,1237,843],{"class":210},[184,1239,1225],{"class":214},[184,1241,1108],{"class":214},[184,1243,1230],{"class":214},[184,1245,1206],{"class":214},[184,1247,1249],{"class":186,"line":1248},98,[184,1250,204],{"emptyLinePlaceholder":203},[184,1252,1254],{"class":186,"line":1253},99,[184,1255,1256],{"class":190},"# start VMs\n",[184,1258,1260,1262,1265],{"class":186,"line":1259},100,[184,1261,843],{"class":210},[184,1263,1264],{"class":214}," start",[184,1266,1196],{"class":214},[184,1268,1270,1272,1274],{"class":186,"line":1269},101,[184,1271,843],{"class":210},[184,1273,1264],{"class":214},[184,1275,1206],{"class":214},[175,1277,1281],{"className":1278,"code":1279,"filename":169,"language":1280,"meta":180,"style":180},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","#cloud-config\n# kate: hl yaml;\n\nssh_pwauth: true # sshd service will be configured to accept password authentication method\npassword: changeme # Set a password for almalinux\nchpasswd:\n  expire: false # Don't ask for password reset after the first log-in\nssh_authorized_keys: # Replace with your ssh public key\u002Fkeys for publickey authentication\n  - ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAykgY+AnIUy3wzTFtQOtvwE\u002FDQjcv5JKKu6eb0T\u002FpvRqmIedVB2RVObI5DhZQGEpLKLF2Hugr1fy03bG98dNL\u002FkFiStmH5nJ9vLGs9fGIHRUq+NpRJPB37vx19wGqd0YzAJeTanXDd8ZF2ZoBzCWaO5qqR\u002F9c41m\u002FDZ3GthxoryoEf0eJ04J4LFMhDcT5rC9c5PrcLqiwHcw80z9OZW5c5Npt7oL9G9Ymy7zCSysGcDJjDRXiAaPUSI59TztzB6W+MSungzsbQ8g3NPQJkPdMCtciJZ1dOFo+4+M+LCjvDG2lsdUxO8l4U34YxEhAhmZS0JrF0LoP9Ga+E5tf3Wcnaw== robert\n","yaml",[150,1282,1283,1288,1293,1297,1313,1326,1334,1347,1357],{"__ignoreMap":180},[184,1284,1285],{"class":186,"line":187},[184,1286,1287],{"class":190},"#cloud-config\n",[184,1289,1290],{"class":186,"line":194},[184,1291,1292],{"class":190},"# kate: hl yaml;\n",[184,1294,1295],{"class":186,"line":200},[184,1296,204],{"emptyLinePlaceholder":203},[184,1298,1299,1303,1306,1310],{"class":186,"line":207},[184,1300,1302],{"class":1301},"swJcz","ssh_pwauth",[184,1304,1305],{"class":379},":",[184,1307,1309],{"class":1308},"sfNiH"," true",[184,1311,1312],{"class":190}," # sshd service will be configured to accept password authentication method\n",[184,1314,1315,1318,1320,1323],{"class":186,"line":224},[184,1316,1317],{"class":1301},"password",[184,1319,1305],{"class":379},[184,1321,1322],{"class":214}," changeme",[184,1324,1325],{"class":190}," # Set a password for almalinux\n",[184,1327,1328,1331],{"class":186,"line":229},[184,1329,1330],{"class":1301},"chpasswd",[184,1332,1333],{"class":379},":\n",[184,1335,1336,1339,1341,1344],{"class":186,"line":235},[184,1337,1338],{"class":1301},"  expire",[184,1340,1305],{"class":379},[184,1342,1343],{"class":1308}," false",[184,1345,1346],{"class":190}," # Don't ask for password reset after the first log-in\n",[184,1348,1349,1352,1354],{"class":186,"line":267},[184,1350,1351],{"class":1301},"ssh_authorized_keys",[184,1353,1305],{"class":379},[184,1355,1356],{"class":190}," # Replace with your ssh public key\u002Fkeys for publickey authentication\n",[184,1358,1359,1362],{"class":186,"line":272},[184,1360,1361],{"class":379},"  -",[184,1363,1364],{"class":214}," ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAykgY+AnIUy3wzTFtQOtvwE\u002FDQjcv5JKKu6eb0T\u002FpvRqmIedVB2RVObI5DhZQGEpLKLF2Hugr1fy03bG98dNL\u002FkFiStmH5nJ9vLGs9fGIHRUq+NpRJPB37vx19wGqd0YzAJeTanXDd8ZF2ZoBzCWaO5qqR\u002F9c41m\u002FDZ3GthxoryoEf0eJ04J4LFMhDcT5rC9c5PrcLqiwHcw80z9OZW5c5Npt7oL9G9Ymy7zCSysGcDJjDRXiAaPUSI59TztzB6W+MSungzsbQ8g3NPQJkPdMCtciJZ1dOFo+4+M+LCjvDG2lsdUxO8l4U34YxEhAhmZS0JrF0LoP9Ga+E5tf3Wcnaw== robert\n",[175,1366,1368],{"className":1278,"code":1367,"filename":633,"language":1280,"meta":180,"style":180},"#cloud-config\n# kate: hl yaml;\n\nkeyboard:\n  layout: de\n  # variant: neo\n",[150,1369,1370,1374,1378,1382,1389,1399],{"__ignoreMap":180},[184,1371,1372],{"class":186,"line":187},[184,1373,1287],{"class":190},[184,1375,1376],{"class":186,"line":194},[184,1377,1292],{"class":190},[184,1379,1380],{"class":186,"line":200},[184,1381,204],{"emptyLinePlaceholder":203},[184,1383,1384,1387],{"class":186,"line":207},[184,1385,1386],{"class":1301},"keyboard",[184,1388,1333],{"class":379},[184,1390,1391,1394,1396],{"class":186,"line":224},[184,1392,1393],{"class":1301},"  layout",[184,1395,1305],{"class":379},[184,1397,1398],{"class":214}," de\n",[184,1400,1401],{"class":186,"line":229},[184,1402,1403],{"class":190},"  # variant: neo\n",[89,1405,1407],{"id":1406},"access-with-wireguard","Access with Wireguard",[79,1409,1410,1411,1414],{},"If the wifi does not allow to ",[150,1412,1413],{},"ssh"," into the EU OS Server, it is best to setup a VPN to reach the Server conveniently. This could be done with wireguard:",[175,1416,1420],{"className":1417,"code":1418,"language":1419,"meta":180,"style":180},"language-sh shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# copy config in place\nsudo vim \u002Fetc\u002Fwireguard\u002Fwg0.conf\n\n# launch wireguard service\nsudo systemctl enable --now wg-quick@wg0\n","sh",[150,1421,1422,1427,1432,1436,1441],{"__ignoreMap":180},[184,1423,1424],{"class":186,"line":187},[184,1425,1426],{},"# copy config in place\n",[184,1428,1429],{"class":186,"line":194},[184,1430,1431],{},"sudo vim \u002Fetc\u002Fwireguard\u002Fwg0.conf\n",[184,1433,1434],{"class":186,"line":200},[184,1435,204],{"emptyLinePlaceholder":203},[184,1437,1438],{"class":186,"line":207},[184,1439,1440],{},"# launch wireguard service\n",[184,1442,1443],{"class":186,"line":224},[184,1444,1445],{},"sudo systemctl enable --now wg-quick@wg0\n",[89,1447,1449],{"id":1448},"snapshots","Snapshots",[79,1451,1452],{},"The following commands allow for VM snapshots to be created or loaded:",[175,1454,1456],{"className":1417,"code":1455,"language":1419,"meta":180,"style":180},"# if swap is used: remove swap partitition from foreman\nvirsh detach-disk alma9-foreman vdb --live --persistent\n\n# create snapshots\nvirsh snapshot-create-as alma9-foreman alma9-foreman-before-foreman-install\n# recover snapshot\nvirsh snapshot-revert    alma9-foreman alma9-foreman-before-foreman-install\n\n# add swap again if used:\nvirsh attach-disk alma9-foreman --source \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman-swap.img --target vdb --live --persistent\n",[150,1457,1458,1463,1468,1472,1477,1482,1487,1492,1496,1501],{"__ignoreMap":180},[184,1459,1460],{"class":186,"line":187},[184,1461,1462],{},"# if swap is used: remove swap partitition from foreman\n",[184,1464,1465],{"class":186,"line":194},[184,1466,1467],{},"virsh detach-disk alma9-foreman vdb --live --persistent\n",[184,1469,1470],{"class":186,"line":200},[184,1471,204],{"emptyLinePlaceholder":203},[184,1473,1474],{"class":186,"line":207},[184,1475,1476],{},"# create snapshots\n",[184,1478,1479],{"class":186,"line":224},[184,1480,1481],{},"virsh snapshot-create-as alma9-foreman alma9-foreman-before-foreman-install\n",[184,1483,1484],{"class":186,"line":229},[184,1485,1486],{},"# recover snapshot\n",[184,1488,1489],{"class":186,"line":235},[184,1490,1491],{},"virsh snapshot-revert    alma9-foreman alma9-foreman-before-foreman-install\n",[184,1493,1494],{"class":186,"line":267},[184,1495,204],{"emptyLinePlaceholder":203},[184,1497,1498],{"class":186,"line":272},[184,1499,1500],{},"# add swap again if used:\n",[184,1502,1503],{"class":186,"line":278},[184,1504,1505],{},"virsh attach-disk alma9-foreman --source \u002Fvar\u002Flib\u002Flibvirt\u002Fimages\u002Falma9-foreman-swap.img --target vdb --live --persistent\n",[89,1507,1509],{"id":1508},"ssh-tunnel","SSH Tunnel",[79,1511,1512],{},"For convenient access to the VMs: local ssh port forwarding and installation of root CA.",[97,1514,1515,1526,1532],{},[100,1516,1517,1518],{},"add foreman and ipa to host file of the EU OS Server:",[175,1519,1524],{"className":1520,"code":1522,"language":1523},[1521],"language-text","192.168.122.111 fleet.eu-os.internal foreman fleet\n192.168.122.112 users.eu-os.internal ipa users\n","text",[150,1525,1522],{"__ignoreMap":180},[100,1527,1528,1531],{},[150,1529,1530],{},"ssh -TL 9090:foreman:9090 -L 9443:foreman:443 -L 2223:ipa:22 192.168.1.29"," with the last IP the one of the EU OS Server (could be the Wireguard IP)",[100,1533,1534,1537],{},[150,1535,1536],{},"sudo curl -kL -o \u002Fetc\u002Fpki\u002Fca-trust\u002Fsource\u002Fanchors\u002FIPA_CA.crt http:\u002F\u002Fusers.eu-os.internal\u002Fipa\u002Fconfig\u002Fca.crt && sudo update-ca-trust"," to install the certificate on the computer that you use to access the web interfaces of foreman and freeipa",[79,1539,1540,1541,1545],{},"The next step is to setup ",[123,1542,1544],{"href":1543},"\u002Fpoc\u002Fmanage-users\u002F","FreeIPA for User Management",", so that it can create certificates for needed for the Foreman setup.",[1547,1548,1549],"style",{},"html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfNiH, html code.shiki .sfNiH{--shiki-light:#FF5370;--shiki-default:#FF9CAC;--shiki-dark:#FF9CAC}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}",{"title":180,"searchDepth":194,"depth":194,"links":1551},[1552,1553,1554,1555,1556],{"id":91,"depth":194,"text":92},{"id":117,"depth":194,"text":118},{"id":1406,"depth":194,"text":1407},{"id":1448,"depth":194,"text":1449},{"id":1508,"depth":194,"text":1509},"Setup Server","md",{},{"icon":31},{"title":28,"description":1557},"5HGpMBz8QjiSVqroA9HYIsZZu74MuQQ5JUmdJ19NuSc",[1564,1566],{"title":23,"path":24,"stem":25,"description":1565,"icon":26,"children":-1},"Many use cases of Linux on the desktop in the public sector rely on an existing Linux distribution (such as Ubuntu or Debian) and develop customisations on top. System administrators build then an image that contains original (upstream) packages as well as custom packages and custom configuration.",{"title":33,"path":34,"stem":35,"description":1567,"icon":36,"children":-1},"Manage Users",{"data":1569,"body":1570},{},{"type":1571,"children":1572},"root",[1573],{"type":1574,"tag":79,"props":1575,"children":1576},"element",{},[1577],{"type":1523,"value":1557},1788729537803]