From 7c0e66e9eaff6d369c00fae0a2c7558ec63099e8 Mon Sep 17 00:00:00 2001 From: Jason Spadaro Date: Sun, 24 Aug 2025 12:02:09 -0400 Subject: [PATCH] Add default from clone of K1. Update readme. --- default.xml | 1019 +++++++++++++++++++++++++++++++++++++++++++++++++++ readme.md | 4 + 2 files changed, 1023 insertions(+) diff --git a/default.xml b/default.xml index e69de29..f641601 100644 --- a/default.xml +++ b/default.xml @@ -0,0 +1,1019 @@ + + + + + + + repo-backports-update + http://download.opensuse.org/update/leap/15.6/backports/ + Update repository of openSUSE Backports + 99 + / + + + repo-non-oss + http://download.opensuse.org/distribution/leap/15.6/repo/non-oss/ + Non-OSS Repository + 99 + / + + + repo-openh264 + http://codecs.opensuse.org/openh264/openSUSE_Leap/ + Open H.264 Codec (openSUSE Leap) + 99 + + + + repo-sle-update + http://download.opensuse.org/update/leap/15.6/sle/ + Update repository with updates from SUSE Linux Enterprise 15 + 99 + / + + + repo-update + http://download.opensuse.org/update/leap/15.6/oss + Main Update Repository + 99 + / + + + repo-update-non-oss + http://download.opensuse.org/update/leap/15.6/non-oss/ + Update Repository (Non-Oss) + 99 + / + + + + + + splash=silent preempt=full mitigations=auto quiet security=apparmor + auto + auto + false + true + true + gfxterm + 8 + true + vga=gfx-1024x768x16 + + grub2-efi + + + public + true + off + true + + + Unsolicited incoming network packets are rejected. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed. + + false + block + + + + Block + %%REJECT%% + + + For computers in your demilitarized zone that are publicly-accessible with limited access to your internal network. Only selected incoming connections are accepted. + + false + dmz + + + + ssh + + DMZ + default + + + All network connections are accepted. + + docker0 + + false + docker + + + + docker + ACCEPT + + + Unsolicited incoming network packets are dropped. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed. + + false + drop + + + + Drop + DROP + + + For use on external networks. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + true + external + + + + ssh + + External + default + + + For use in home areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + false + home + + + + dhcpv6-client + mdns + samba-client + ssh + + Home + default + + + For use on internal networks. You mostly trust the other computers on the networks to not harm your computer. Only selected incoming connections are accepted. + + false + internal + + + + dhcpv6-client + mdns + samba-client + ssh + + Internal + default + + + For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + eth0 + + false + public + + + + dhcpv6-client + ssh + + Public + default + + + All network connections are accepted. + + false + trusted + + + + Trusted + ACCEPT + + + For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + false + work + + + + dhcpv6-client + ssh + + Work + default + + + + + + false + + + + + 100 + users + + + + 2 + daemon + + + + 71 + ntadmin + + + + 5 + tty + + + + 490 + dialout + + + + 492 + audio + + + + 487 + render + + + + 480 + systemd-timesync + + + + 496 + wheel + + + + 42 + trusted + + + + 65534 + nobody + + + + 485 + tape + + + + 481 + systemd-journal + + + + 1 + bin + daemon + + + 495 + kmem + + + + 51 + postfix + + + + 36 + kvm + + + + 486 + sgx + + + + 484 + video + + + + 493 + utmp + + + + 491 + cdrom + + + + 15 + shadow + + + + 475 + sshd + + + + 494 + lock + + + + 482 + chrony + + + + 477 + cockpit-wsinstance + + + + 478 + polkitd + + + + 62 + man + + + + 489 + disk + + + + 499 + messagebus + + + + 59 + maildrop + postfix + + + 65533 + nogroup + + + + 498 + mail + postfix + + + 488 + input + + + + 0 + root + + + + 497 + lp + + + + 479 + nscd + + + + 483 + audit + + + + + + + 127.0.0.1 + + localhost + + + + ::1 + + localhost ipv6-localhost ipv6-loopback + + + + fe00::0 + + ipv6-localnet + + + + ff00::0 + + ipv6-mcastprefix + + + + ff02::1 + + ipv6-allnodes + + + + ff02::2 + + ipv6-allrouters + + + + ff02::3 + + ipv6-allhosts + + + + + + + + AUTO + + + + dhcp + eth0 + auto + public + + + true + true + false + + + eth0 + ATTR{address} + 00:a0:98:68:fd:46 + + + + false + false + + + + auto + + systemd + + + + /dev/sda + gpt + false + + + true + vfat + true + utf8 + /boot/efi + uuid + 259 + 1 + false + 536870912 + + + true + true + btrfs + true + / + uuid + 131 + 2 + false + false + 15568190976 + + + false + var + + + true + usr/local + + + true + tmp + + + true + srv + + + true + root + + + true + opt + + + true + home + + + true + boot/grub2/x86_64-efi + + + true + boot/grub2/i386-pc + + + @ + + + CT_DISK + all + + + + false + + + multi-user + + + YaST2-Firstboot + YaST2-Second-Stage + apparmor + auditd + klog + chronyd + cron + cups + firewalld + wickedd-auto4 + wickedd-dhcp4 + wickedd-dhcp6 + wickedd-nanny + irqbalance + issue-generator + kbdsettings + mcelog + wicked + nscd + postfix + purge-kernels + rke2-agent + rsyslog + smartd + sshd + systemd-pstore + systemd-remount-fs + + + + + true + + + wicked + tmux + shim + os-prober + openssh + openSUSE-release + numactl + neovim + mokutil + kexec-tools + irqbalance + grub2-x86_64-efi + glibc + git + firewalld + e2fsprogs + dosfstools + cockpit + chrony + btrfsprogs + btop + autoyast2 + + + apparmor + base + documentation + enhanced_base + minimal_base + sw_management + yast2_basis + + + Leap + + + + false + false + + + America/New_York + + + + 100 + /home + -1 + /bin/bash + 022 + + + + + true + jason + 100 + /home/jason + false + + + + + 99999 + 0 + 7 + + /bin/bash + 1000 + $6$iQDzIpGol7jbq6xX$nQMj7iXSYCdNpeQZCMeblY15Z8YMRMTSlO2Q3YdP4ukaQjiYq..MVCURqQRjqBRzropHJS.JWTWvfMZVPCFhi. + jason + + + true + Manual pages viewer + 62 + /var/lib/empty + false + + + + + + + + + /usr/sbin/nologin + 13 + ! + man + + + true + User for polkitd + 478 + /var/lib/polkit + false + + + + + + + + + /usr/sbin/nologin + 478 + ! + polkitd + + + true + User for D-Bus + 499 + /run/dbus + false + + + + + + + + + /usr/bin/false + 499 + ! + messagebus + + + true + Daemon + 2 + /sbin + false + + + + + + + + + /usr/sbin/nologin + 2 + ! + daemon + + + true + User for cockpit-ws instances + 477 + /nonexisting + false + + + + + + + + + /sbin/nologin + 474 + ! + cockpit-wsinstance + + + true + Chrony Daemon + 482 + /var/lib/chrony + false + + + + + + + + + /usr/sbin/nologin + 496 + ! + chrony + + + true + user for rpcbind + 65534 + /var/lib/empty + false + + + + + + + + + /sbin/nologin + 477 + ! + rpc + + + true + SSH daemon + 475 + /var/lib/sshd + false + + + + + + + + + /usr/sbin/nologin + 475 + ! + sshd + + + true + NFS statd daemon + 65533 + /var/lib/nfs + false + + + + + + + + + /sbin/nologin + 476 + ! + statd + + + true + nobody + 65534 + /var/lib/nobody + false + + + + + + + + + /bin/bash + 65534 + ! + nobody + + + true + User for nscd + 479 + /run/nscd + false + + + + + + + + + /usr/sbin/nologin + 479 + ! + nscd + + + true + Printing daemon + 497 + /var/spool/lpd + false + + + + + + + + + /usr/sbin/nologin + 497 + ! + lp + + + true + Postfix Daemon + 51 + /var/spool/postfix + false + + + + + + + + + /usr/sbin/nologin + 51 + ! + postfix + + + + ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC6l8GjJBf9zhpeLGCLVxGULA6fic/7I76tdqI5FDkxZ5ktb+BIg/fTm3ZJivmKnNQwoWiFdJTKvD8Xa+YXKlm9WAAsD8U4zqkOJIHxX4UarHuIHCxRDwO3Mh1nqevZY+8NEm4VI1zGpRnkXrP7pThRHD90mhvy4tYeGl5Xe1NbklS0Dgo3qQvipHXGuqiRMpG7yFqNDyE4b1NTEkxQYohT/aVOfNaunJmNAMkNCe5yqUIhnXqsyiHtc4Fg6L2ueEEVgKD/E2dyjLdKlnnEGHOp77u3FxYUhBuC7GV/1m7EjuvcLZEVAnaKa+zV1LJtxWFef+I+hwZ28kHEkNqMnGEy5V9F9A3NOIWIpfCiytgny01QAD/H8v0allnY+fzbUhfqJVNqXWo+AnCNJBz6KmK8EDKw3JRoY42Wfxa0FPBGH3X97INufWlCitLGrwuaK/G9++Vnmeh8/+9VlNlL7nb0Ab/tE+dfVuUNfN2qzLtfJljaYFRv8T4GNO3l9GhwYns= jason@localhost.localdomain + + true + root + 0 + /root + false + + + + + + + + + /bin/bash + 0 + $6$RwbjWFS7ugjlGV29$6bjo7FVO6l6arSA8ApaxUH3aYanB8//mQzFdmHGWUmVd/WbB5Q9migM4tpi44cJTmsQkqhxccm5Tpuf1ywoPD0 + root + + + true + bin + 1 + /bin + false + + + + + + + + + /usr/sbin/nologin + 1 + ! + bin + + + true + Mailer daemon + 498 + /var/spool/clientmqueue + false + + + + + + + + + /usr/sbin/nologin + 498 + ! + mail + + + true + systemd Time Synchronization + 480 + / + false + + + + + + + + + /usr/sbin/nologin + 480 + !* + systemd-timesync + + + diff --git a/readme.md b/readme.md index e69de29..983ade3 100644 --- a/readme.md +++ b/readme.md @@ -0,0 +1,4 @@ +# Base Autoyast Scripts for Testing + +- `default.xml` Template for building other scripts. +-