refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build fedora-cosmic from the upstream Fedora manifests in fedora/ostree/ci-test (44 and rawhide) with custom overlays: - remove firefox from the base system - add token2-fido-bridge + PC/SC smartcard stack and uhid - install per-user Flatpaks on first login via a systemd user unit Replace the legacy builder/changelog scripts with: - build.sh: rpm-ostree compose image (upstream overlay or standalone) - release.sh: package changelog published as Gitea releases CI moves to the job-v2 runner with a build matrix, cosign signing and release publishing. Drop the legacy asahi-cosmic/shared/base images, builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
+82
-74
@@ -6,31 +6,64 @@ on:
|
||||
branches: ["main"]
|
||||
push:
|
||||
branches: ["main"]
|
||||
schedule:
|
||||
- cron: "0 4 * * *"
|
||||
|
||||
jobs:
|
||||
build_push:
|
||||
name: Build and push image
|
||||
runs-on: wesley-arm
|
||||
build:
|
||||
name: ${{ matrix.image }} (${{ matrix.distro }})
|
||||
runs-on: ${{ matrix.runner }}
|
||||
|
||||
env:
|
||||
IMAGE: asahi-cosmic
|
||||
VERSION: 43
|
||||
strategy:
|
||||
fail-fast: false
|
||||
# To build another image, add images/<name>/{manifest.yaml,build.conf}
|
||||
# and a matching matrix entry here.
|
||||
matrix:
|
||||
include:
|
||||
- image: fedora-cosmic
|
||||
distro: "44"
|
||||
arch: x86_64
|
||||
runner: job-v2
|
||||
- image: fedora-cosmic
|
||||
distro: rawhide
|
||||
arch: x86_64
|
||||
runner: job-v2
|
||||
|
||||
container:
|
||||
image: "quay.io/fedora-ostree-desktops/buildroot:${{ env.VERSION }}"
|
||||
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
|
||||
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
|
||||
|
||||
env:
|
||||
IMAGE: ${{ matrix.image }}
|
||||
DISTRO: ${{ matrix.distro }}
|
||||
ARCH: ${{ matrix.arch }}
|
||||
REGISTRY: git.plabble.org/misthios
|
||||
GITEA_URL: https://git.plabble.org
|
||||
GITEA_REPO: Misthios/bootc-images
|
||||
|
||||
steps:
|
||||
|
||||
- name: Install rpm-ostree + tools
|
||||
- name: Install build tools
|
||||
run: |
|
||||
dnf upgrade -y --enablerepo=updates-testing --refresh rpm-ostree
|
||||
dnf install -y nodejs skopeo jq buildah rsync git
|
||||
mkdir -p ~/.docker
|
||||
set -xeuo pipefail
|
||||
dnf install -y jq curl git createrepo_c
|
||||
dnf install -y skopeo buildah
|
||||
dnf install -y cosign || true
|
||||
if ! command -v cosign >/dev/null; then
|
||||
case "$(uname -m)" in
|
||||
x86_64) cosign_arch=amd64 ;;
|
||||
aarch64) cosign_arch=arm64 ;;
|
||||
*) echo "Unsupported arch for cosign"; exit 1 ;;
|
||||
esac
|
||||
curl -fsSL -o /usr/local/bin/cosign \
|
||||
"https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}"
|
||||
chmod +x /usr/local/bin/cosign
|
||||
fi
|
||||
|
||||
- name: Fix containers/storage.conf
|
||||
- name: Configure containers storage
|
||||
run: |
|
||||
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
|
||||
if [ -f /usr/share/containers/storage.conf ]; then
|
||||
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
|
||||
fi
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
@@ -38,72 +71,47 @@ jobs:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Log in to registry
|
||||
uses: redhat-actions/podman-login@v1
|
||||
with:
|
||||
registry: git.plabble.org
|
||||
username: ${{ secrets.REGISTRY_USERNAME }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
auth_file_path: /tmp/auth.json
|
||||
|
||||
- name: Build rootfs with rpm-ostree
|
||||
run: |
|
||||
sudo -E ./builder.sh "${IMAGE}" "${VERSION}"
|
||||
|
||||
- name: Build and push OCI image from rootfs
|
||||
env:
|
||||
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||
run: |
|
||||
set -xeuo pipefail
|
||||
mkdir -p ~/.docker
|
||||
registry_host="${REGISTRY%%/*}"
|
||||
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
||||
--password-stdin --authfile /tmp/auth.json "${registry_host}"
|
||||
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
||||
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
||||
|
||||
REGISTRY="git.plabble.org/misthios"
|
||||
ROOTFS="images/${IMAGE}/rootfs"
|
||||
|
||||
if [[ ! -d "${ROOTFS}" ]]; then
|
||||
echo "ERROR: rootfs not found at ${ROOTFS}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Build ID (YYYYMMDD.0)
|
||||
if [[ -f ".buildid" ]]; then
|
||||
buildid="$(< .buildid)"
|
||||
else
|
||||
buildid="$(date '+%Y%m%d.0')"
|
||||
echo "${buildid}" > .buildid
|
||||
fi
|
||||
|
||||
full_tag="${VERSION}.${buildid}"
|
||||
- name: Build image
|
||||
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
||||
|
||||
- name: Push and sign image
|
||||
if: github.event_name != 'pull_request'
|
||||
env:
|
||||
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||
run: |
|
||||
set -xeuo pipefail
|
||||
export STORAGE_DRIVER=vfs
|
||||
buildid="$(cat .buildid)"
|
||||
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
||||
tag="${DISTRO}.${buildid}"
|
||||
|
||||
ctr="$(buildah from scratch)"
|
||||
mnt="$(buildah mount "${ctr}")"
|
||||
skopeo copy --authfile /tmp/auth.json \
|
||||
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}"
|
||||
skopeo copy --authfile /tmp/auth.json \
|
||||
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}"
|
||||
|
||||
rsync -aHAX "${ROOTFS}/" "${mnt}/"
|
||||
printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key
|
||||
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}"
|
||||
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}"
|
||||
rm -f private.key
|
||||
|
||||
buildah config --label containers.bootc=1 "${ctr}"
|
||||
buildah config --env container=oci "${ctr}"
|
||||
buildah config --cmd "/sbin/init" "${ctr}"
|
||||
|
||||
buildah commit "${ctr}" "localhost/${IMAGE}:${full_tag}"
|
||||
buildah unmount "${ctr}"
|
||||
|
||||
skopeo copy \
|
||||
--authfile /tmp/auth.json \
|
||||
containers-storage:localhost/${IMAGE}:${full_tag} \
|
||||
docker://${REGISTRY}/${IMAGE}:${full_tag}
|
||||
|
||||
skopeo copy \
|
||||
--authfile /tmp/auth.json \
|
||||
containers-storage:localhost/${IMAGE}:${full_tag} \
|
||||
docker://${REGISTRY}/${IMAGE}:${VERSION}
|
||||
|
||||
- name: Generate changelog
|
||||
- name: Generate changelog and publish release
|
||||
if: github.event_name != 'pull_request'
|
||||
env:
|
||||
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||
run: |
|
||||
./changelog.sh "${IMAGE}" "${VERSION}"
|
||||
|
||||
- name: Commit and push changelog
|
||||
if: github.ref == 'refs/heads/main'
|
||||
run: |
|
||||
git config user.name "Automation"
|
||||
git config user.email "actions@invalid.tld"
|
||||
git add changelogs/
|
||||
git commit -m "Update changelog for ${IMAGE} ${VERSION} build $(cat .buildid)" || echo "No changes"
|
||||
git push
|
||||
buildid="$(cat .buildid)"
|
||||
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
||||
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${oci}"
|
||||
|
||||
Reference in New Issue
Block a user