refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s

Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
2026-09-21 15:11:26 +02:00
parent 63357a4e46
commit bc542f14b2
37 changed files with 547 additions and 3496 deletions
+82 -74
View File
@@ -6,31 +6,64 @@ on:
branches: ["main"]
push:
branches: ["main"]
schedule:
- cron: "0 4 * * *"
jobs:
build_push:
name: Build and push image
runs-on: wesley-arm
build:
name: ${{ matrix.image }} (${{ matrix.distro }})
runs-on: ${{ matrix.runner }}
env:
IMAGE: asahi-cosmic
VERSION: 43
strategy:
fail-fast: false
# To build another image, add images/<name>/{manifest.yaml,build.conf}
# and a matching matrix entry here.
matrix:
include:
- image: fedora-cosmic
distro: "44"
arch: x86_64
runner: job-v2
- image: fedora-cosmic
distro: rawhide
arch: x86_64
runner: job-v2
container:
image: "quay.io/fedora-ostree-desktops/buildroot:${{ env.VERSION }}"
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
env:
IMAGE: ${{ matrix.image }}
DISTRO: ${{ matrix.distro }}
ARCH: ${{ matrix.arch }}
REGISTRY: git.plabble.org/misthios
GITEA_URL: https://git.plabble.org
GITEA_REPO: Misthios/bootc-images
steps:
- name: Install rpm-ostree + tools
- name: Install build tools
run: |
dnf upgrade -y --enablerepo=updates-testing --refresh rpm-ostree
dnf install -y nodejs skopeo jq buildah rsync git
mkdir -p ~/.docker
set -xeuo pipefail
dnf install -y jq curl git createrepo_c
dnf install -y skopeo buildah
dnf install -y cosign || true
if ! command -v cosign >/dev/null; then
case "$(uname -m)" in
x86_64) cosign_arch=amd64 ;;
aarch64) cosign_arch=arm64 ;;
*) echo "Unsupported arch for cosign"; exit 1 ;;
esac
curl -fsSL -o /usr/local/bin/cosign \
"https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}"
chmod +x /usr/local/bin/cosign
fi
- name: Fix containers/storage.conf
- name: Configure containers storage
run: |
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
if [ -f /usr/share/containers/storage.conf ]; then
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
fi
- name: Checkout
uses: actions/checkout@v4
@@ -38,72 +71,47 @@ jobs:
fetch-depth: 0
- name: Log in to registry
uses: redhat-actions/podman-login@v1
with:
registry: git.plabble.org
username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_TOKEN }}
auth_file_path: /tmp/auth.json
- name: Build rootfs with rpm-ostree
run: |
sudo -E ./builder.sh "${IMAGE}" "${VERSION}"
- name: Build and push OCI image from rootfs
env:
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: |
set -xeuo pipefail
mkdir -p ~/.docker
registry_host="${REGISTRY%%/*}"
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
--password-stdin --authfile /tmp/auth.json "${registry_host}"
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
REGISTRY="git.plabble.org/misthios"
ROOTFS="images/${IMAGE}/rootfs"
if [[ ! -d "${ROOTFS}" ]]; then
echo "ERROR: rootfs not found at ${ROOTFS}"
exit 1
fi
# Build ID (YYYYMMDD.0)
if [[ -f ".buildid" ]]; then
buildid="$(< .buildid)"
else
buildid="$(date '+%Y%m%d.0')"
echo "${buildid}" > .buildid
fi
full_tag="${VERSION}.${buildid}"
- name: Build image
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
- name: Push and sign image
if: github.event_name != 'pull_request'
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
run: |
set -xeuo pipefail
export STORAGE_DRIVER=vfs
buildid="$(cat .buildid)"
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
tag="${DISTRO}.${buildid}"
ctr="$(buildah from scratch)"
mnt="$(buildah mount "${ctr}")"
skopeo copy --authfile /tmp/auth.json \
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}"
skopeo copy --authfile /tmp/auth.json \
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}"
rsync -aHAX "${ROOTFS}/" "${mnt}/"
printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}"
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}"
rm -f private.key
buildah config --label containers.bootc=1 "${ctr}"
buildah config --env container=oci "${ctr}"
buildah config --cmd "/sbin/init" "${ctr}"
buildah commit "${ctr}" "localhost/${IMAGE}:${full_tag}"
buildah unmount "${ctr}"
skopeo copy \
--authfile /tmp/auth.json \
containers-storage:localhost/${IMAGE}:${full_tag} \
docker://${REGISTRY}/${IMAGE}:${full_tag}
skopeo copy \
--authfile /tmp/auth.json \
containers-storage:localhost/${IMAGE}:${full_tag} \
docker://${REGISTRY}/${IMAGE}:${VERSION}
- name: Generate changelog
- name: Generate changelog and publish release
if: github.event_name != 'pull_request'
env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: |
./changelog.sh "${IMAGE}" "${VERSION}"
- name: Commit and push changelog
if: github.ref == 'refs/heads/main'
run: |
git config user.name "Automation"
git config user.email "actions@invalid.tld"
git add changelogs/
git commit -m "Update changelog for ${IMAGE} ${VERSION} build $(cat .buildid)" || echo "No changes"
git push
buildid="$(cat .buildid)"
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${oci}"