# OS Init Scripts

This page lists the supported OS versions, their image sources, and the `sh/<os>_<version>.sh` script new VMs run during initialization.

## Supported Versions and Images

| `os` | `version` | Image source | Supported until (`sh/pdvm_os.json`) |
|---|---|---|---|
| `debian` | `11` | `cloud.debian.org` `bullseye` generic amd64 | June 2026 |
| | `12` | `cloud.debian.org` `bookworm` generic amd64 | June 2028 |
| | `13` | `cloud.debian.org` `trixie` generic amd64 | June 2030 |
| `ubuntu` | `20.04` | `mirror.twds.com.tw` ubuntu-cloud-images server cloudimg amd64 | April 2030 |
| | `22.04` | same as above | April 2032 |
| | `24.04` | same as above | April 2036 |
| `rockylinux` | `8` | `dl.rockylinux.org` GenericCloud-Base latest x86_64 | May 2029 |
| | `9` | same as above | May 2032 |
| | `10` | same as above | May 2035 |

Any other combination fails at the `getting OS image` step with `unsupported ... version`.

## How It Runs

Once the VM first accepts SSH, the main node logs in as the cloud-init user and runs:

```bash
curl -fsSL http://<NODE_{MAIN_NODE}>:<PORT>/sh/<os>_<version>.sh | sudo bash -s <VM_ROOT_PASSWORD>
```

When `VM_ROOT_PASSWORD` is empty no argument is passed and the script uses its built-in `0123456789`. Each output line is relayed as an SSE event; any failing command (`set -e`) counts as an SSH initialization failure and the VM is purged.

## What the Scripts Do

| Action | Debian | Ubuntu | Rocky Linux |
|---|---|---|---|
| Set the root password | ✓ | ✓ | ✓ |
| Disable `passwd` / `chpasswd` and lock password aging | ✓ | ✓ | ✓ |
| Switch package sources | `ftp.tw.debian.org` | `tw.archive.ubuntu.com` | Enable EPEL |
| Upgrade, install common tools and `qemu-guest-agent` | ✓ | ✓ | ✓ |
| Locale `en_US.UTF-8` | ✓ | ✓ | — |
| Timezone `Asia/Taipei` | ✓ | ✓ | ✓ |
| sysctl: ignore ICMP echo, raise inotify limit | ✓ | ✓ | ✓ |
| Create a 2G `/swapfile` | ✓ | ✓ | ✓ |
| Install the `sysinfo` login banner | ✓ | ✓ | ✓ |
| Clear package cache, `/tmp`, and logs | ✓ | ✓ | ✓ |

After the script finishes, the service reboots the VM to apply GRUB and kernel settings.

## Customization

Edit the matching file under `sh/`; the service serves it as a static file on every request, so no restart is needed. Adding a version also requires updating the supported list and image URL in `internal/service/osImage.go`.
