+# generating a hashed password:
+# under debian, you can do
+# mkpasswd -m sha-512 -s >/q/root/shadow/standard
+# On arch, best seems to be copy your shadow file to a temp location,
+# then passwd, get out the new pass, then copy the shadow file back.
+sed 's/^/root:/' $root_pw_f | $ROOTCMD chpasswd -e
+
+# only setup root pass for bootstrap vol
+if ifclass VOL_BULLSEYE_BOOTSTRAP; then
+ exit 0
+fi
+
+
+# return of 9 = user already exists. so we are idempotent.
+au iank
+sed 's/^/iank:/' $root_pw_f | $ROOTCMD chpasswd -e
+
+au user2
+if ifclass frodo; then
+ sed 's/^/user2:/' /q/root/shadow/user2 | $ROOTCMD chpasswd -e
+fi
+# comparing iank's groups to user2, I see none she should join on arch
+$ROOTCMD usermod -a -G user2 iank
+
+
+$ROOTCMD getent group docker &>/dev/null || $ROOTCMD groupadd -r docker
+$ROOTCMD usermod -a -G docker iank