Compare commits

..

1 Commits

Author SHA1 Message Date
d505c4e65f test
All checks were successful
Build containers / changes (push) Successful in 3s
Build containers / base-image (push) Successful in 54s
Build containers / dependent-images (go) (push) Successful in 42s
Build containers / dependent-images (infra) (push) Successful in 58s
2025-12-29 15:28:29 +01:00
17 changed files with 152 additions and 152 deletions

View File

@@ -14,10 +14,9 @@ jobs:
changes: changes:
runs-on: job-v2 runs-on: job-v2
outputs: outputs:
base: ${{ steps.filter.outputs.base == 'true' }} fedora: ${{ steps.filter.outputs.fedora == 'true' }}
infra: ${{ steps.filter.outputs.infra == 'true' || steps.filter.outputs.base == 'true' }} infra: ${{ steps.filter.outputs.infra == 'true' || steps.filter.outputs.fedora == 'true' }}
go: ${{ steps.filter.outputs.go == 'true' || steps.filter.outputs.base == 'true' }} go: ${{ steps.filter.outputs.go == 'true' || steps.filter.outputs.fedora == 'true' }}
php: ${{ steps.filter.outputs.php == 'true' || steps.filter.outputs.base == 'true' }}
any_change: ${{ steps.filter.outputs.workflow == 'true' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'}} any_change: ${{ steps.filter.outputs.workflow == 'true' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'}}
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
@@ -26,14 +25,13 @@ jobs:
with: with:
filters: | filters: |
workflow: ['.gitea/workflows/build.yaml'] workflow: ['.gitea/workflows/build.yaml']
base: ['containers/base/**'] fedora: ['containers/fedora/**']
infra: ['containers/infra/**'] infra: ['containers/infra/**']
go: ['containers/go/**'] go: ['containers/go/**']
php: ['containers/php/**']
base-image: base-image:
needs: [changes] needs: [changes]
if: ${{ needs.changes.outputs.base == 'true' || needs.changes.outputs.any_change == 'true' }} if: ${{ needs.changes.outputs.fedora == 'true' || needs.changes.outputs.any_change == 'true' }}
runs-on: job-v2 runs-on: job-v2
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
@@ -47,11 +45,10 @@ jobs:
id: build id: build
uses: job79/buildah-build@65b3793a1370c1ccd74a5c0d090d70eb9637a4ef uses: job79/buildah-build@65b3793a1370c1ccd74a5c0d090d70eb9637a4ef
with: with:
image: job79/base image: job79/fedora
tags: ${{ github.ref_name }} tags: ${{ github.ref_name }}
context: ./containers/base context: ./containers/fedora
containerfiles: ./containers/base/Containerfile containerfiles: ./containers/fedora/Containerfile
platforms: linux/amd64
- name: Push - name: Push
uses: redhat-actions/push-to-registry@v2 uses: redhat-actions/push-to-registry@v2
with: with:
@@ -71,14 +68,13 @@ jobs:
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
container: [infra, go, php] container: [infra, go]
steps: steps:
- name: Check if build needed - name: Check if build needed
id: check id: check
run: | run: |
if [[ "${{ matrix.container }}" == "infra" && "${{ needs.changes.outputs.infra }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi if [[ "${{ matrix.container }}" == "infra" && "${{ needs.changes.outputs.infra }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi
if [[ "${{ matrix.container }}" == "go" && "${{ needs.changes.outputs.go }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi if [[ "${{ matrix.container }}" == "go" && "${{ needs.changes.outputs.go }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi
if [[ "${{ matrix.container }}" == "php" && "${{ needs.changes.outputs.php }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi
if [[ "${{ needs.changes.outputs.any_change }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi if [[ "${{ needs.changes.outputs.any_change }}" == "true" ]]; then echo "run=true" >> $GITHUB_OUTPUT; fi
- name: Clone repo - name: Clone repo
if: steps.check.outputs.run == 'true' if: steps.check.outputs.run == 'true'
@@ -100,7 +96,6 @@ jobs:
context: ./containers/${{ matrix.container }} context: ./containers/${{ matrix.container }}
containerfiles: ./containers/${{ matrix.container }}/Containerfile containerfiles: ./containers/${{ matrix.container }}/Containerfile
build-args: TAG=${{ github.ref_name }} build-args: TAG=${{ github.ref_name }}
platforms: linux/amd64
- name: Push - name: Push
if: steps.check.outputs.run == 'true' if: steps.check.outputs.run == 'true'
uses: redhat-actions/push-to-registry@v2 uses: redhat-actions/push-to-registry@v2

View File

@@ -1,32 +0,0 @@
FROM quay.io/fedora/fedora:44
# === install system packages ===
RUN --mount=type=cache,id=dnf-cache,target=/var/cache/libdnf5 \
dnf update -y && \
dnf -y --setopt=keepcache=1 --setopt=install_weak_deps=False install \
bash-completion git-core fzf curl awk jq fd-find rg unzip which \
host-spawn wl-copy gcc
RUN LAZYGIT_VERSION=$(curl -s "https://api.github.com/repos/jesseduffield/lazygit/releases/latest" | jq -r .tag_name | sed 's/^v//') && \
curl -sL "https://github.com/jesseduffield/lazygit/releases/latest/download/lazygit_${LAZYGIT_VERSION}_linux_x86_64.tar.gz" | tar xz -C /usr/local/bin lazygit && \
curl -sL "https://github.com/jorgerojas26/lazysql/releases/latest/download/lazysql_Linux_x86_64.tar.gz" | tar xz -C /usr/local/bin lazysql && \
curl -sL "https://github.com/neovim/neovim/releases/download/nightly/nvim-linux-x86_64.tar.gz" | tar xz -C /usr/local --strip-components=1
COPY config/bin /usr/local/bin
# === setup user ===
RUN useradd -ms /bin/bash user && \
echo 'user ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/user && \
mkdir -p /run/user/1000 && \
chown user:user /run/user/1000
USER user
WORKDIR /home/user
RUN mkdir -p .config .local .cache && \
git clone https://git.plabble.org/Job79/neovim-config.git .config/nvim
COPY --chown=user:user config/bashrc .bashrc
COPY --chown=user:user config/git .config/git/config
VOLUME /home/user

View File

@@ -1,21 +0,0 @@
source /etc/bashrc
# === bash settings ===
set -o vi
bind -m vi-insert '"\C-l": clear-screen'
# === environment ===
export PS1="\[\e[30;46m\] \h | \w \[\e[0;36m\]\[\e[m\] " \
EDITOR="nvim" \
WAYLAND_DISPLAY="wayland-0" \
XDG_RUNTIME_DIR="/run/user/1000" \
SSH_AUTH_SOCK="/run/user/1000/ssh-auth-sock" \
TZ="Europe/Amsterdam" \
FZF_CTRL_T_COMMAND="fd --type f --hidden --exclude .git --exclude Library --exclude .cache" \
FZF_ALT_C_COMMAND="fd --type d --hidden --exclude .git --exclude Library --exclude .cache"
# === aliases and functions ===
alias vi=nvim
post() { curl -sF "content=<-" "https://paste.plabble.org/$2?lang=$1" && echo; }
eval "$(fzf --bash)"

View File

@@ -1,6 +0,0 @@
#!/bin/bash
export DBUS_SESSION_BUS_ADDRESS="unix:path=/tmp/bus"
cmd="${0##*/}"
[[ "$cmd" == "host" ]] && unset cmd
exec host-spawn -cwd "${PWD/#$HOME/$HOST_HOME}" ${cmd:+"$cmd"} "$@"

View File

@@ -0,0 +1,24 @@
FROM quay.io/fedora/fedora:43
# === install system packages ===
RUN dnf update -y && \
dnf copr enable -y atim/lazygit && \
dnf -y install procps ping bash-completion glibc-langpack-en \
host-spawn dbus-launch \
zoxide git npm neovim awk jq unzip fd-find lazygit && \
dnf clean all
# === setup user ===
RUN useradd -ms /bin/bash user && \
echo 'user ALL=NOPASSWD: ALL' > /etc/sudoers
USER user
WORKDIR /home/user
RUN mkdir .config .local .cache && \
git clone https://git.plabble.org/Job79/neovim-config.git .config/nvim
COPY --chown=user:user config/bashrc .bashrc
COPY --chown=user:user config/git .config/git/config
COPY config/bin /usr/local/bin
VOLUME /home/user

View File

@@ -0,0 +1,16 @@
. /etc/bashrc
# === environment ===
export EDITOR=nvim \
WAYLAND_DISPLAY=wayland-0 \
XDG_RUNTIME_DIR=/run/user/1000 \
SSH_AUTH_SOCK=/run/user/1000/ssh-auth-sock \
PS1="\[\e[30;46m\] \h | \w \[\e[0;36m\]\[\e[m\] " \
TZ="Europe/Amsterdam"
# === aliases and functions ===
alias vi=nvim
post() { curl -sF "content=<-" "https://paste.plabble.org/$2?lang=$1" && echo; }
eval "$(zoxide init --cmd cd bash)"
eval "$(fzf --bash)"

View File

@@ -0,0 +1,4 @@
#!/bin/bash
export DBUS_SESSION_BUS_ADDRESS=unix:path=/tmp/bus
host-spawn -cwd "${PWD/#$HOME/$HOST_HOME}" \
$([ "$(basename "$0")" != "host" ] && echo "$(basename "$0")") "$@"

View File

@@ -1,10 +1,7 @@
ARG TAG ARG TAG
FROM job79/base:${TAG} FROM job79/fedora:${TAG}
USER root USER root
RUN GO_VERSION=$(curl -sL "https://go.dev/VERSION?m=text" | head -n 1 | tr -d '\r\n') && \ RUN dnf -y install go && dnf clean all
curl -sL "https://go.dev/dl/${GO_VERSION}.linux-amd64.tar.gz" | tar xz -C /usr/local && \
ln -sf /usr/local/go/bin/go /usr/local/bin/go && \
ln -sf /usr/local/go/bin/gofmt /usr/local/bin/gofmt
USER user USER user

View File

@@ -1,2 +1,2 @@
#!/bin/bash #!/bin/bash
run_opts+=("-v" "$HOME/Documents/go:/home/user/Documents/go") arg "-v $HOME/Documents/go:/home/user/Documents/go"

View File

@@ -1,10 +1,9 @@
ARG TAG ARG TAG
FROM job79/base:${TAG} FROM job79/fedora:${TAG}
USER root USER root
RUN --mount=type=cache,id=dnf-cache,target=/var/cache/libdnf5 \ RUN dnf -y install kubectl k9s openssl age "$(curl -s https://api.github.com/repos/getsops/sops/releases/latest | jq -r '.assets[] | select(.name | test("sops-.*.x86_64.rpm$")) | .browser_download_url')" && \
dnf -y --setopt=keepcache=1 --setopt=install_weak_deps=False install \ dnf clean all && \
just kubectl k9s openssl age "$(curl -s https://api.github.com/repos/getsops/sops/releases/latest | jq -r ".assets[] | select(.name | test(\"sops-.*.$(arch).rpm\$\")) | .browser_download_url")" && \
curl -sL https://talos.dev/install | sh && \ curl -sL https://talos.dev/install | sh && \
curl -s https://fluxcd.io/install.sh | bash curl -s https://fluxcd.io/install.sh | bash

View File

@@ -1,2 +1,2 @@
#!/bin/bash #!/bin/bash
run_opts+=("-v" "$HOME/Documents/infra:/home/user/Documents/infra") arg "-v $HOME/Documents/infra:/home/user/Documents/infra"

View File

@@ -1,9 +0,0 @@
ARG TAG
FROM job79/base:${TAG}
USER root
RUN --mount=type=cache,id=dnf-cache,target=/var/cache/libdnf5 \
dnf -y --setopt=keepcache=1 install php composer npm && \
composer global require laravel/installer
USER user

View File

@@ -1,2 +0,0 @@
#!/bin/bash
run_opts+=("-v" "$HOME/Documents/php:/home/user/Documents/php")

143
devc.sh
View File

@@ -1,78 +1,113 @@
#!/bin/bash #!/bin/bash
# =============================================== # # =============================================== #
# devc.sh v2.1; job79, maurice # # devc.sh v2.0; job79 #
# Dev container entry script. # # Dev container enter script. Handles setting up #
# different dev containers, resuming sessions and #
# automatic container updates. #
# =============================================== # # =============================================== #
set -euo pipefail set -eu
log() { echo -e "\e[36m○\e[0m $1"; } log() { printf '\e[%sm%s\e[0m %s\n' "${3:-36}" "${2:-}" "$1"; }
die() { echo -e "\e[31mx\e[0m $1" && exit 1; } arg() { echo -n " $@"; }
# default_args configures standard container options. # run_args returns the podman run arguments required for
# starting a new container.
default_args() { default_args() {
run_opts+=( arg "--name $name"
"--name" "$name" arg "--hostname $name"
"--hostname" "$name"
"--pull=newer" # Update image.
"--userns=keep-id" # Map host user.
"-v" "$name:/home/user:copy" # Persistent home volume.
"-v" "dnf-cache:/var/cache/libdnf5" # Cache dnf metadata.
)
# Unix sockets require SELinux label disable. # Pull newer container image if available.
[[ -d /sys/fs/selinux ]] && run_opts+=("--security-opt" "label=disable") arg "--pull=newer"
# Desktop integration (Wayland, SSH). # Use keep-id so the container user matches the host user.
[[ -e "/run/user/$UID/wayland-0" ]] && run_opts+=("-v" "/run/user/$UID/wayland-0:/run/user/1000/wayland-0") arg "--userns=keep-id"
[[ -e "${SSH_AUTH_SOCK:-}" ]] && run_opts+=("-v" "$SSH_AUTH_SOCK:/run/user/1000/ssh-auth-sock")
# Load custom container config. # Disable selinux labeling so unix sockets can be mounted
local config_file="${BASH_SOURCE[0]%/*}/containers/$name/config.sh" # without problems.
[[ -f "$config_file" ]] && source "$config_file" || true arg "--security-opt label=disable"
# Mount the wayland socket. Required to get the system
# clipboard (wl-copy) and gui applications working.
[ -e "/run/user/$UID/wayland-0" ] && arg "-v /run/user/$UID/wayland-0:/run/user/1000/wayland-0"
# Mount the ssh socket to get ssh working.
[ -e "$SSH_AUTH_SOCK" ] && arg "-v $SSH_AUTH_SOCK:/run/user/1000/ssh-auth-sock"
# Make the user home dir a volume so it survives container
# restarts. Use copy to keep the files from the image.
arg "-v $name:/home/user:copy"
# If there is custom configuration for the container, load
# it here.
config_file="$(dirname "$(realpath "$0")")/containers/$name/config.sh"
[ -f "$config_file" ] && source "${config_file}"
} }
# param_args parses CLI arguments into podman run options. # param_args returns the podman run arguments based on the
# arguments provided to this script.
param_args() { param_args() {
while (($# > 0)); do while test $# -gt 0; do
case "$1" in case "$1" in
-gpu) run_opts+=("--device" "/dev/dri") ;; -gpu) # Enable gpu acceleration.
-host-spawn) run_opts+=("-v" "/run/user/$UID/bus:/tmp/bus" "-e" "HOST_HOME=$HOME") ;; arg "--device /dev/dri" ;;
-container-sock) run_opts+=("-v" "$XDG_RUNTIME_DIR/podman/podman.sock:/var/run/docker.sock") ;; -host-spawn) # Enable spawning host commands from inside the container using host-spawn.
-x11) run_opts+=("-v" "/tmp/.X11-unix:/tmp/.X11-unix" "-v" "$XAUTHORITY:/run/user/1000/.Xauthority:ro" "-e" "DISPLAY=$DISPLAY" "-e" "XAUTHORITY=/run/user/1000/.Xauthority") ;; arg "-v /run/user/$UID/bus:/tmp/bus"
-mnt) shift && run_opts+=("-w" "/mnt/" "-v" "$1:/mnt/$([[ -d "$1" ]] || echo "file")") ;; arg "-e HOST_HOME=$HOME" # Used to translate paths.
*) run_opts+=("$1") ;; ;;
-x11) # Enable X11 support.
arg "-v /tmp/.X11-unix:/tmp/.X11-unix"
arg "-v $XAUTHORITY:/run/user/1000/.Xauthority:ro"
arg "-e DISPLAY=$DISPLAY"
arg "-e XAUTHORITY=/run/user/1000/.Xauthority"
;;
-mnt) # Mount directory.
shift
arg "-w /mnt/"
arg "-v $1:/mnt/$([ ! -d "$1" ] && echo 'file')"
;;
*) # Use unknown arguments a podman arguments.
arg "$1" ;;
esac esac
shift shift
done done
} }
main() { ### MAIN ###
local state_file="$HOME/.local/share/devc-previous-container" # Get the devcontainer name from the first argument. If not
local image="${1:-}" # provided, use the last used name when possible.
if [[ $# -gt 0 ]] && [[ ${1:-} != -* ]]; then
# Resolve container name (CLI arg > Last used > Error). image="$1"
if [[ $image && $image != -* ]]; then [[ "$image" != *:* ]] && image="$image:main"
echo "$image" >"$HOME/.local/share/devc-previous-container"
shift shift
[[ $image != *:* ]] && image+=":main" elif [ -f "$HOME/.local/share/devc-previous-container" ]; then
echo "$image" >"$state_file" image=$(<"$HOME/.local/share/devc-previous-container")
elif [[ -f $state_file ]]; then
image=$(<$state_file)
else else
die "no container name specified" log "no container name specified" 'x' 31
exit 1
fi fi
local name="${image%:*}" name="${image%:*}"
# Start/Restart if not running or if arguments change configuration. # Get container registry from the DEVC_REGISTRY env
if [[ -z "$(podman ps -q -f name="^$name$" -f status=running)" ]] || (($# > 0)); then # variable.
log "starting $image..." if [ -n "${DEVC_REGISTRY:-}" ]; then
registry="$DEVC_REGISTRY"
default_args else
param_args "$@" log "registry unknown; set the DEVC_REGISTRY environment variable" 'x' 31
exit 1
[[ -n "${DEVC_REGISTRY:-}" ]] || die "registry unknown; set the DEVC_REGISTRY environment variable"
podman run --replace --stop-timeout 0 -td "${run_opts[@]}" "$DEVC_REGISTRY/$image"
fi fi
exec podman exec --detach-keys "ctrl-@,ctrl-@" -it "$name" ${DEVC_COMMAND:-bash -l} # Get container command from the DEVC_COMMAND env variable
} # if set, else use bash -l.
if [ -z "${DEVC_COMMAND:-}" ]; then
DEVC_COMMAND="bash -l"
fi
main "$@" # When container is not running or arguments are provided,
# recreate it.
if [ "$(podman container inspect "$name" -f {{.State.Running}} 2>&1)" != 'true' ] || [[ $# -gt 0 ]]; then
log "starting devcontainer..."
podman container rm -f -t 0 "$name" 1>/dev/null
podman run -td $(default_args) $(param_args $@) "$registry/$image"
fi
podman exec --detach-keys "ctrl-@" -it "$name" ${DEVC_COMMAND:-}