diff --git a/autoinstall/openSUSE/15/autoinst.xml b/autoinstall/openSUSE/15/autoinst.xml new file mode 100644 index 000000000..0c41e171f --- /dev/null +++ b/autoinstall/openSUSE/15/autoinst.xml @@ -0,0 +1,1419 @@ + + + + + + + repo-backports-update + cd:/?devices=/dev/sr0 + Update repository of openSUSE Backports + 99 + / + + + repo-non-oss + cd:/?devices=/dev/sr0 + Non-OSS Repository + 99 + + + + repo-sle-update + cd:/?devices=/dev/sr0 + Update repository with updates from SUSE Linux Enterprise 15 + 99 + / + + + repo-update-non-oss + cd:/?devices=/dev/sr0 + Update Repository (Non-Oss) + 99 + + + + + + + splash=silent preempt=full mitigations=auto quiet security=apparmor + auto + auto + false + true + true + gfxterm + 8 + true + vga=gfx-1024x768x16 + + {% if firmware is defined and firmware | lower == 'efi' %} + grub2-efi + {% else %} + grub2 + {% endif %} + + + public + false + off + false + + + Unsolicited incoming network packets are rejected. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed. + + false + block + + + + Block + %%REJECT%% + + + For computers in your demilitarized zone that are publicly-accessible with limited access to your internal network. Only selected incoming connections are accepted. + + false + dmz + + + + ssh + + DMZ + default + + + All network connections are accepted. + + docker0 + + false + docker + + + + docker + ACCEPT + + + Unsolicited incoming network packets are dropped. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed. + + false + drop + + + + Drop + DROP + + + For use on external networks. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + true + external + + + + ssh + + External + default + + + For use in home areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + false + home + + + + dhcpv6-client + mdns + samba-client + ssh + + Home + default + + + For use on internal networks. You mostly trust the other computers on the networks to not harm your computer. Only selected incoming connections are accepted. + + false + internal + + + + dhcpv6-client + mdns + samba-client + ssh + + Internal + default + + + + + false + nm-shared + + + icmp + ipv6-icmp + + + dhcp + dns + ssh + + NetworkManager Shared + ACCEPT + + + For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + false + public + + + + dhcpv6-client + + Public + default + + + All network connections are accepted. + + false + trusted + + + + Trusted + ACCEPT + + + For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted. + + false + work + + + + dhcpv6-client + ssh + + Work + default + + + + + + false + + + + + 100 + users + + + + 493 + utmp + + + + 494 + kmem + + + + 463 + nm-openvpn + + + + 469 + rtkit + + + + 495 + systemd-timesync + + + + 482 + mail + postfix + + + 492 + audio + pulse,brltty + + + 475 + wheel + + + + 466 + sshd + + + + 496 + systemd-network + + + + 59 + maildrop + postfix + + + 461 + gdm + + + + 472 + polkitd + + + + 487 + lp + + + + 477 + pulse + + + + 484 + tape + + + + 62 + man + + + + 486 + render + + + + 468 + scard + + + + 462 + vnc + + + + 490 + dialout + brltty + + + 5 + tty + brltty + + + 464 + nm-openconnect + + + + 476 + flatpak + + + + 489 + disk + + + + 0 + root + brltty + + + 491 + cdrom + + + + 467 + brlapi + brltty + + + 485 + sgx + + + + 65534 + nobody + + + + 481 + chrony + + + + 478 + pulse-access + brltty + + + 460 + brltty + + + + 36 + kvm + + + + 499 + lock + + + + 51 + postfix + + + + 471 + avahi + + + + 474 + audit + + + + 1 + bin + daemon + + + 483 + video + gdm + + + 479 + srvGeoClue + + + + 71 + ntadmin + + + + 480 + tftp + dnsmasq + + + 470 + dnsmasq + + + + 15 + shadow + vnc + + + 2 + daemon + + + + 465 + colord + + + + 488 + input + brltty + + + 473 + nscd + + + + 498 + messagebus + + + + 65533 + nogroup + + + + 42 + trusted + + + + 497 + systemd-journal + + + {% if new_user is defined and new_user != 'root' %} + + true + 1000 + x + {{ new_user }} + {{ new_user }} + + {% endif %} + + + + + 127.0.0.1 + + localhost + + + + ::1 + + localhost ipv6-localhost ipv6-loopback + + + + fe00::0 + + ipv6-localnet + + + + ff00::0 + + ipv6-mcastprefix + + + + ff02::1 + + ipv6-allnodes + + + + ff02::2 + + ipv6-allrouters + + + + ff02::3 + + ipv6-allhosts + + + + + {% if new_user is defined and new_user != 'root' %} + + {{ new_user }} + + {% endif %} + + true + true + + true + localhost + auto + + true + true + true + + + dhcp + eth0 + auto + + + + + auto + + manual + + + + /dev/{{ boot_disk_name }} + gpt + false + + + true + vfat + true + {% if firmware is defined and firmware | lower == 'efi' %} + utf8 + /boot/efi + uuid + {% endif %} + 259 + 1 + false + 536870912 + + + true + true + btrfs + true + / + uuid + 131 + 2 + false + false + 42411736576 + + + false + var + + + true + usr/local + + + true + tmp + + + true + srv + + + true + root + + + true + opt + + + true + home + + + true + boot/grub2/x86_64-efi + + + true + boot/grub2/i386-pc + + + @ + + + CT_DISK + all + + + + false + + + graphical + + + ModemManager + NetworkManager + NetworkManager-dispatcher + NetworkManager-wait-online + YaST2-Firstboot + YaST2-Second-Stage + apparmor + appstream-sync-cache + auditd + avahi-daemon + bluetooth + klog + chronyd + cron + cups + display-manager + haveged + irqbalance + issue-generator + kbdsettings + lvm2-monitor + mcelog + nscd + postfix + purge-kernels + rsyslog + smartd + sshd + systemd-remount-fs + vgauthd + vmblock-fuse + vmtoolsd + + + pcscd + + + + + true + + + shim + os-prober + openssh + openSUSE-release + numactl + mokutil + kexec-tools + irqbalance + grub2 + glibc + e2fsprogs + dosfstools + chrony + btrfsprogs + autoyast2 + NetworkManager + + + apparmor + base + basesystem + documentation + enhanced_base + fonts + fonts_opt + gnome + gnome_basic + gnome_basis + gnome_basis_opt + gnome_games + gnome_imaging + gnome_internet + gnome_multimedia + gnome_office + gnome_utilities + gnome_x11 + gnome_yast + imaging + minimal_base + multimedia + office + sw_management + sw_management_gnome + x11 + x11_enhanced + x11_yast + yast2_basis + yast2_desktop + + + Leap + + + + false + false + + + America/New_York + + + + 100 + /home + -1 + /bin/bash + 022 + + + {% if new_user is defined and new_user != 'root' %} + + + {{ ssh_public_key }} + + true + + 1000 + /home/{{ new_user }} + false + + + + + 99999 + 0 + 7 + + /bin/bash + 1001 + {{ vm_password_hash }} + {{ new_user }} + + {% endif %} + + true + NetworkManager user for OpenConnect + 464 + /var/lib/nm-openconnect + false + + + + + + + + + /usr/sbin/nologin + 475 + ! + nm-openconnect + + + true + user for rpcbind + 65534 + /var/lib/empty + false + + + + + + + + + /sbin/nologin + 487 + ! + rpc + + + true + Flatpak system helper + 476 + / + false + + + + + + + + + /usr/sbin/nologin + 488 + ! + flatpak + + + + {{ ssh_public_key }} + + true + root + 0 + /root + false + + + + + + + + + /bin/bash + 0 + {{ vm_password_hash }} + root + + + true + Smart Card Reader + 468 + /run/pcscd + false + + + + + + + + + /usr/sbin/nologin + 479 + ! + scard + + + true + user for VNC + 462 + /var/lib/empty + false + + + + + + + + + /sbin/nologin + 473 + ! + vnc + + + true + Manual pages viewer + 62 + /var/lib/empty + false + + + + + + + + + /usr/sbin/nologin + 13 + ! + man + + + true + Gnome Display Manager daemon + 461 + /var/lib/gdm + false + + + + + + + + + /usr/sbin/nologin + 472 + ! + gdm + + + true + User for polkitd + 472 + /var/lib/polkit + false + + + + + + + + + /sbin/nologin + 484 + ! + polkitd + + + true + Printing daemon + 487 + /var/spool/lpd + false + + + + + + + + + /usr/sbin/nologin + 489 + ! + lp + + + true + PulseAudio daemon + 477 + /var/lib/pulseaudio + false + + + + + + + + + /usr/sbin/nologin + 490 + ! + pulse + + + true + SSH daemon + 466 + /var/lib/sshd + false + + + + + + + + + /usr/sbin/nologin + 477 + ! + sshd + + + true + systemd Network Management + 496 + / + false + + + + + + + + + /usr/sbin/nologin + 496 + !* + systemd-network + + + true + systemd Time Synchronization + 495 + / + false + + + + + + + + + /usr/sbin/nologin + 495 + !* + systemd-timesync + + + true + Mailer daemon + 482 + /var/spool/clientmqueue + false + + + + + + + + + /usr/sbin/nologin + 494 + ! + mail + + + true + RealtimeKit + 469 + /proc + false + + + + + + + + + /bin/false + 480 + ! + rtkit + + + true + NetworkManager user for OpenVPN + 463 + /var/lib/openvpn + false + + + + + + + + + /usr/sbin/nologin + 474 + ! + nm-openvpn + + + true + User for D-Bus + 498 + /run/dbus + false + + + + + + + + + /usr/bin/false + 499 + ! + messagebus + + + true + usbmuxd daemon + 65533 + /var/lib/usbmuxd + false + + + + + + + + + /sbin/nologin + 485 + ! + usbmux + + + true + Daemon + 2 + /sbin + false + + + + + + + + + /usr/sbin/nologin + 2 + ! + daemon + + + true + user for colord + 465 + /var/lib/colord + false + + + + + + + + + /usr/sbin/nologin + 476 + ! + colord + + + true + User for nscd + 473 + /run/nscd + false + + + + + + + + + /sbin/nologin + 486 + ! + nscd + + + true + User for GeoClue D-Bus service + 479 + /var/lib/srvGeoClue + false + + + + + + + + + /usr/sbin/nologin + 491 + ! + srvGeoClue + + + true + dnsmasq + 470 + /var/lib/empty + false + + + + + + + + + /usr/sbin/nologin + 482 + ! + dnsmasq + + + true + TFTP Account + 480 + /srv/tftpboot + false + + + + + + + + + /usr/sbin/nologin + 492 + ! + tftp + + + true + User for Avahi + 471 + /run/avahi-daemon + false + + + + + + + + + /usr/sbin/nologin + 483 + ! + avahi + + + true + bin + 1 + /bin + false + + + + + + + + + /usr/sbin/nologin + 1 + ! + bin + + + true + NFS statd daemon + 65533 + /var/lib/nfs + false + + + + + + + + + /sbin/nologin + 481 + ! + statd + + + true + Postfix Daemon + 51 + /var/spool/postfix + false + + + + + + + + + /usr/sbin/nologin + 51 + ! + postfix + + + true + Chrony Daemon + 481 + /var/lib/chrony + false + + + + + + + + + /usr/sbin/nologin + 493 + ! + chrony + + + true + user account for the brltty daemon + 100 + /var/lib/brltty + false + + + + + + + + + /bin/false + 478 + ! + brltty + + + true + nobody + 65534 + /var/lib/nobody + false + + + + + + + + + /bin/bash + 65534 + ! + nobody + + + + + + + + \ No newline at end of file