2026-07-21 00:26:05 -07:00
|
|
|
# Base Nucleic layer baked into the naros-vm rootfs so nash is the forced shell and the
|
2026-07-21 19:14:46 -07:00
|
|
|
# hosted apt repo is trusted from the very first boot — plus the vsock control-plane agent.
|
|
|
|
|
#
|
|
|
|
|
# The agent is baked (from this same local pool, i.e. the same deb published to the hosted
|
|
|
|
|
# repo) because it is the host's ONLY way to reach the guest: it used to be overlaid by the
|
|
|
|
|
# Mac-host bootstrap from a separate GHCR artifact, but that second source could drift from
|
|
|
|
|
# the deb and silently win. With the overlay collapsed, apt is the single source of truth —
|
|
|
|
|
# and a soft-failing firstboot `apt install` is too weak a guarantee for the control plane.
|
|
|
|
|
# The REST of the tier (sudo, dbus, the tier meta) still arrives at firstboot via
|
|
|
|
|
# `apt install naros-tier-vm` (NAROS.md §7.4), which finds this dependency already satisfied.
|
2026-07-21 00:26:05 -07:00
|
|
|
nash
|
|
|
|
|
naros-init
|
|
|
|
|
naros
|
2026-07-21 04:23:04 -07:00
|
|
|
naros-identity
|
2026-07-21 00:26:05 -07:00
|
|
|
naros-keyring
|
2026-07-21 19:14:46 -07:00
|
|
|
nucleic-linux-agent
|