# zeroclaw-profile.yaml
config:
  cloud-init.user-data: |
    #cloud-config
    ssh_genkeytypes: []
    ssh_pwauth: false
    package_update: true
    packages:
      - curl
      - ca-certificates
      - tzdata

    users:
      - name: zeroclaw
        shell: /bin/sh
        home: /home/zeroclaw
        system: true
        setup_home: true

    write_files:
      - path: /etc/init.d/zeroclaw
        permissions: '0755'
        owner: root:root
        content: |
          #!/sbin/openrc-run
          name="zeroclaw"
          description="ZeroClaw daemon"
          supervisor=supervise-daemon
          command="/usr/local/bin/zeroclaw"
          command_args="daemon"
          command_user="zeroclaw:zeroclaw"
          directory="/home/zeroclaw"

          depend() {
              need net
              after firewall
          }

          start_pre() {
              checkpath -d -m 0750 -o zeroclaw:zeroclaw /home/zeroclaw/.zeroclaw
          }

    runcmd:
      - ln -sf /usr/share/zoneinfo/Europe/Helsinki /etc/localtime
      - |
        curl -sSL -o /tmp/zeroclaw.tar.gz \
          https://github.com/zeroclaw-labs/zeroclaw/releases/latest/download/zeroclaw-x86_64-unknown-linux-musl.tar.gz
        tar -xzf /tmp/zeroclaw.tar.gz -C /usr/local/bin
        chmod 0755 /usr/local/bin/zeroclaw
        rm /tmp/zeroclaw.tar.gz

  limits.cpu: "2"
  limits.memory: 1GB        # runtime is a few MB; 1GB is generous headroom
  # security.nesting not needed — Landlock sandbox requires no userns

description: ZeroClaw trial on Alpine Edge
devices:
  root:
    path: /
    pool: default
    type: disk
    size: 4GB
  eth0:
    name: eth0
    nictype: bridged
    parent: br77
    type: nic
# incus profile edit zeroclaw < zeroclaw-profile.yaml
# incus launch images:alpine/edge/cloud zeroclaw --profile zeroclaw

config tweaks

# incus exec zeroclaw -- su - zeroclaw -s /bin/sh -c 'zeroclaw doctor'
# incus exec zeroclaw -- vi /home/zeroclaw/.zeroclaw/config.toml
# incus exec zeroclaw -- rc-service zeroclaw restart