Gitea does not expand a dynamic fromJson matrix (the job name stayed literal
and it queued with no matching runner). Instead, compute cosmic/remote booleans
in a changes job and gate static-matrix build jobs with job-level if.
Add a changes job that diffs the pushed range (or PR base) and emits a matrix
via ci-matrix.sh. Shared files or build tooling changes rebuild all images.
Also fix the upstream package trim to drop top-level keys left empty (e.g.
packages-x86_64 when every entry is excluded), which broke fedora-remote.
New image built from upstream base-atomic (no desktop), adding only gnome-shell
+ gdm + gnome-remote-desktop + pipewire/portal + foot + Flatpak + Kanidm.
recommends=false to stay lean. Configures GNOME Remote Desktop headless remote
login on first boot (TLS + credentials + enable). Firefox preinstalled as a
per-user Flatpak. Add it to the CI matrix and prune both images.
Add prune-registry.sh: keeps the moving tag and newest versioned tag per
distro plus their cosign signature tags, deletes the rest via the Gitea
packages API. Wire it into the prune job (uses REGISTRY_TOKEN).
Schedule moves to Mondays 04:00 UTC. release.sh now deletes older releases
for the same image/distro (and their assets and tags) after publishing, so
only the newest is kept. Add prune-releases.sh for a one-off cleanup.
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the
secret is set, via a generated add-files include. Without the secret the image
is built unchanged and the token must be provisioned on the host.
Avoid mounting the built image with buildah (ran out of disk); the
finalize.d hook records the rpm list next to the treefile and release.sh
consumes it directly.
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:
- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit
Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases
CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.