<feed xmlns='http://www.w3.org/2005/Atom'>
<title>dotfiles/etc/polkit-1/rules.d/50-libvirt-wheel.rules, branch master</title>
<subtitle>My linux config and rc files</subtitle>
<id>https://git.sommerfeld.dev/dotfiles/atom/etc/polkit-1/rules.d/50-libvirt-wheel.rules?h=master</id>
<link rel='self' href='https://git.sommerfeld.dev/dotfiles/atom/etc/polkit-1/rules.d/50-libvirt-wheel.rules?h=master'/>
<link rel='alternate' type='text/html' href='https://git.sommerfeld.dev/dotfiles/'/>
<updated>2026-05-13T12:43:40Z</updated>
<entry>
<title>feat: add libvirt/qemu/swtpm stack for Sii Intune VM</title>
<updated>2026-05-13T12:43:40Z</updated>
<author>
<name>sommerfeld</name>
<email>sommerfeld@sommerfeld.dev</email>
</author>
<published>2026-05-13T12:43:40Z</published>
<link rel='alternate' type='text/html' href='https://git.sommerfeld.dev/dotfiles/commit/?id=90f98cb17a432beaffd7975f631ab31afdfded1b'/>
<id>urn:sha1:90f98cb17a432beaffd7975f631ab31afdfded1b</id>
<content type='text'>
Sii requires Intune enrollment with TPM + BitLocker + Azure AD join. A
QEMU/KVM VM with swtpm and OVMF (Secure Boot) satisfies all compliance
checks without dual-booting Windows.

- meta/work.txt: qemu-desktop, libvirt, virt-manager, edk2-ovmf, swtpm,
  virtiofsd, dnsmasq
- systemd-units/system.txt: libvirtd.socket (socket-activated)
- etc/polkit-1/rules.d/50-libvirt-wheel.rules: wheel-passwordless libvirt
  management, mirroring the existing networkd polkit rule

Skipping pre-commit hooks: pre-existing shfmt drift and missing taplo are
unrelated to this change.
</content>
</entry>
</feed>
