refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s

Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
2026-09-21 15:11:26 +02:00
parent 63357a4e46
commit bc542f14b2
37 changed files with 547 additions and 3496 deletions
@@ -0,0 +1,4 @@
# Enable the PC/SC smartcard daemon and the token2-fido-bridge daemon so that
# FIDO2 smartcards are exposed to browsers as a virtual USB-HID security key.
enable pcscd.socket
enable token2-fido-bridge.service
@@ -0,0 +1 @@
enable flatpak-user-firstboot.service
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env bash
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
# the first login of each user. Run as a systemd --user oneshot unit.
set -euo pipefail
LIST="/usr/share/flatpak/flatpaks.list"
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
[[ -f "${LIST}" ]] || exit 0
# Make Flathub available for the current user.
flatpak remote-add --user --if-not-exists flathub \
https://flathub.org/repo/flathub.flatpakrepo
mapfile -t apps < <(
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
)
if [[ ${#apps[@]} -gt 0 ]]; then
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
fi
install -dm0755 "$(dirname "${MARKER}")"
touch "${MARKER}"
@@ -0,0 +1,14 @@
[Unit]
Description=Install per-user Flatpak applications on first login
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/usr/libexec/flatpak-user-firstboot
[Install]
WantedBy=default.target
+5
View File
@@ -0,0 +1,5 @@
# Flatpaks installed into each user's per-user installation on first login.
# One application/runtime ID per line. Lines starting with # are ignored.
#
# Firefox is not part of the base system and is installed here instead.
org.mozilla.firefox
+2
View File
@@ -0,0 +1,2 @@
# token2-fido-bridge needs the uhid module to create the virtual FIDO2 device.
uhid