refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s

Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
2026-09-21 15:11:26 +02:00
parent 63357a4e46
commit bc542f14b2
37 changed files with 547 additions and 3496 deletions
+55
View File
@@ -0,0 +1,55 @@
# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests.
packages:
# Fedora integration packages normally provided by the upstream fedora.yaml,
# re-added here without Firefox (which is shipped as a Flatpak instead).
- fedora-bookmarks
- fedora-chromium-config
- fedora-flathub-remote
- fedora-workstation-backgrounds
- fedora-workstation-repositories
- fedora-release-cosmic-atomic
- toolbox
# Smartcard / FIDO2 support for token2-fido-bridge.
# token2-fido-bridge itself is installed from a local repo that build.sh
# generates from the upstream GitHub release (it is not packaged in Fedora).
- pcsc-lite
- pcsc-lite-ccid
- pcsc-tools
- opensc
- libfido2
- fido2-tools
- p11-kit
- pam-u2f
- token2-fido-bridge
# Firefox is intentionally not part of the base system. It is preinstalled as a
# per-user Flatpak on first login instead (see flatpaks.list).
exclude-packages:
- firefox
add-files:
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
- ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"]
- ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"]
postprocess:
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
# Third Party repo list. We opt out of that manifest, so replicate it here.
# Workaround for https://github.com/coreos/rpm-ostree/issues/5494
- |
#!/usr/bin/env bash
set -xeuo pipefail
sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true
# Ensure the first-login script is executable and make sure the
# globally-enabled per-user Flatpak unit is picked up.
- |
#!/usr/bin/env bash
set -xeuo pipefail
chmod 0755 /usr/libexec/flatpak-user-firstboot
systemctl --user --global preset-all