From 3c3d28ae0347dd4b24914e906d5cd33b0dc3aa0a Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:29:01 -0400 Subject: [PATCH 1/9] Create authorized_keys file --- system_files/root/.ssh/authorized_keys | 1 + 1 file changed, 1 insertion(+) create mode 100644 system_files/root/.ssh/authorized_keys diff --git a/system_files/root/.ssh/authorized_keys b/system_files/root/.ssh/authorized_keys new file mode 100644 index 0000000..6fbe984 --- /dev/null +++ b/system_files/root/.ssh/authorized_keys @@ -0,0 +1 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDQHiphKW6zliwK0LfHMn2zebaNYWd0KfLh2RtZkzHcFoLISRiJ1tGxsVFHehcgU4snk/p6YW/JJ3x0m8wrOBAY4gUN+a309JPqfXGIH+/vfaP+81qSqI6xMr2LSVDf+26uirRRfcY2yCvQ5cOfEv3yE6wuiOfwue3ibSJkxDreh3wrbKjg0RuJceMNanmc7nJKfy5r8RH9/B/gTnRzsjLnUCLdJ7EYnlMm6pB8q0xdrKtFdajaI3JIV6GhlaJB9+U1SILhN/9XX4WyGrJKe4h1hkLJQspUfHXOo2WTfvSO3vqPxcangNregh4XLMRU7tV69uGBA/LP8pMQBSR5Ag9+xqkOD5XzarDvICPwvj+i3ErlIN4aSvjPrhasu8s4Y76ddtZSwiw1fAcQ1Rxc0w/TNizVMqDJVnjx0Xs5Thj+AV/Us+sUiYdyvKe84ssstwc1Cz2HIawqjuhiR1G6R3G+IrM/0ftZ7omH1l5bVvH4fzzNY2xgu3NRLPkpROvqYILOq180tHoMB3qFmgZU89mYpLEfVsiWVpq3YNcIE0xjwbDCD5AyjLJFBpzlki4DolbbJejZRJJfTaUPCmTuA+POXRQ1FYbbH4rJcZghO/GNlQgn0kxTSW0IRR6s5jP299INvctGVLiHj5Bz59aU+noTSnRiXfEggipaHIdooHsgt7TMax+0DM8Q7txOMuBZUh5B9EJsQteU/DGU4QY56ZLiBv9eaB6r8HsSZDameIJy8mXk6ysGajfv0bVq8+CFBlE/fa0RF3MW8Ph05Y2shaAW1+WNDZwI9i1VW1iPt7OvHHGZMpKbZw6GD/8COQff6I2sA/HOY97REwn+UJ9RDO4KE/lUreZ2WRlnyI1FC02OZetfS8qCKeUD/yXJOsBTSBgbEN/iC7MkdKjufIJzzG5MRxUz0q9VkDnpaSoK/QwSdWeVbih0DNLffy8J3VKcddQOKNFaVq1N3vxJkSXaDeZ3rlziJCmtlegVkL1g5FyF+/M/8Ap696tsOlMJOVYu20BLN6EJAiluDZ8M2OspnFQiEaQP7SIt0ARpVRln+P+kPFjTKvaKZ95G29xPfnOlB56VJjv6r1ELlJcq/18tMS5YvIfBIfhbHK5evmu+NQuXQAvqdYquMStR8vlPPI69CJiZc7LxO4k29EZXWWLTDVom42O7Fj3kHUTCgiWM+bTOiZpXBXxlN2WQGV4WYayhTphqR1FkH0p9kXH/58A5xwD3seQbBGd3p8nmzn1IjCKimvXErwS1JrrxY59ifch5uHDEc7IYwB6fipxx0AXu54dsBxBb1RrkRuTGi+Hl0Ovln8+ry+CKWXjcRjWHYj9MIdZpRIjs9nIUsLbse1dUoLsj From e3018a0eb950a1cc2e5b538bad859bb1390e5db2 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:31:44 -0400 Subject: [PATCH 2/9] Fix permissions on /root/.ssh in build.sh --- build_files/build.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/build_files/build.sh b/build_files/build.sh index c4777f5..3df463c 100755 --- a/build_files/build.sh +++ b/build_files/build.sh @@ -5,6 +5,10 @@ set -ouex pipefail # Copy the contents of system_files/ of the git repo to / cp -avf "/ctx/system_files"/. / +# Fix permissions on /root/.ssh +chmod 700 /root/.ssh +chmod 600 /root/.ssh/authorized_keys + ### Install packages dnf5 install -y alacritty fish greetd helix niri From e10a25836df113217df3cd9141cb3ca62e1237c7 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:37:53 -0400 Subject: [PATCH 3/9] Enable sshd --- build_files/build.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/build_files/build.sh b/build_files/build.sh index 3df463c..d42359a 100755 --- a/build_files/build.sh +++ b/build_files/build.sh @@ -26,6 +26,10 @@ dnf5 install -y alacritty fish greetd helix niri # systemctl disable ModemManager.service avahi-daemon.service avahi-daemon.socket systemctl disable avahi-daemon.service avahi-daemon.socket +### Enable SSH + +systemctl enable sshd.service + ### Configure greeter # enable if switching to fedora-silverblue base image From d5d8c1de49a9b3bcf8ebe7c55bf6d47e2e30589e Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:39:48 -0400 Subject: [PATCH 4/9] debugging --- build_files/build.sh | 2 ++ 1 file changed, 2 insertions(+) diff --git a/build_files/build.sh b/build_files/build.sh index d42359a..5615623 100755 --- a/build_files/build.sh +++ b/build_files/build.sh @@ -2,6 +2,8 @@ set -ouex pipefail +ls -al / /root + # Copy the contents of system_files/ of the git repo to / cp -avf "/ctx/system_files"/. / From 39006587ce47362ce4946c777d8053f02fcab0e7 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:47:28 -0400 Subject: [PATCH 5/9] Configure sshd --- system_files/etc/ssh/sshd_config.d/10-arcade.conf | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 system_files/etc/ssh/sshd_config.d/10-arcade.conf diff --git a/system_files/etc/ssh/sshd_config.d/10-arcade.conf b/system_files/etc/ssh/sshd_config.d/10-arcade.conf new file mode 100644 index 0000000..56e9e07 --- /dev/null +++ b/system_files/etc/ssh/sshd_config.d/10-arcade.conf @@ -0,0 +1,6 @@ +AllowUsers root +PermitRootLogin prohibit-password +PasswordAuthentication no +ChallengeResponseAuthentication no +PubkeyAuthentication yes +UsePAM no From e98a49a4e83e048b30c501abc950008d11103956 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:54:19 -0400 Subject: [PATCH 6/9] Configure sshd to look under /etc for authorized keys --- system_files/etc/ssh/sshd_config.d/10-arcade.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/system_files/etc/ssh/sshd_config.d/10-arcade.conf b/system_files/etc/ssh/sshd_config.d/10-arcade.conf index 56e9e07..e6c460d 100644 --- a/system_files/etc/ssh/sshd_config.d/10-arcade.conf +++ b/system_files/etc/ssh/sshd_config.d/10-arcade.conf @@ -4,3 +4,5 @@ PasswordAuthentication no ChallengeResponseAuthentication no PubkeyAuthentication yes UsePAM no + +AuthorizedKeysFile /etc/ssh/authorized_keys/%u From 41c955603faeeabb56240356c21a6604e898f451 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:54:59 -0400 Subject: [PATCH 7/9] Rename system_files/root/.ssh/authorized_keys to system_files/etc/ssh/authorized_keys/root --- .../{root/.ssh/authorized_keys => etc/ssh/authorized_keys/root} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename system_files/{root/.ssh/authorized_keys => etc/ssh/authorized_keys/root} (100%) diff --git a/system_files/root/.ssh/authorized_keys b/system_files/etc/ssh/authorized_keys/root similarity index 100% rename from system_files/root/.ssh/authorized_keys rename to system_files/etc/ssh/authorized_keys/root From 82a8bb36a06c416e0fd969b2b36634e0564cead8 Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:58:47 -0400 Subject: [PATCH 8/9] Fix permissions on SSH authorized keys files in build.sh --- build_files/build.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/build_files/build.sh b/build_files/build.sh index 5615623..fe5227d 100755 --- a/build_files/build.sh +++ b/build_files/build.sh @@ -7,9 +7,9 @@ ls -al / /root # Copy the contents of system_files/ of the git repo to / cp -avf "/ctx/system_files"/. / -# Fix permissions on /root/.ssh -chmod 700 /root/.ssh -chmod 600 /root/.ssh/authorized_keys +# Fix permissions on SSH authorized keys files +chmod 755 /etc/ssh/authorized_keys +chmod 644 /etc/ssh/authorized_keys/root ### Install packages From 1a4051a41990397c6e6b261f105fc52bb862643f Mon Sep 17 00:00:00 2001 From: Michael Pfaff <23013931+mpfaff@users.noreply.github.com> Date: Wed, 7 Oct 2026 23:11:41 -0400 Subject: [PATCH 9/9] done debugging --- build_files/build.sh | 2 -- 1 file changed, 2 deletions(-) diff --git a/build_files/build.sh b/build_files/build.sh index fe5227d..809463d 100755 --- a/build_files/build.sh +++ b/build_files/build.sh @@ -2,8 +2,6 @@ set -ouex pipefail -ls -al / /root - # Copy the contents of system_files/ of the git repo to / cp -avf "/ctx/system_files"/. /