Files
bootc-images/build.sh
T
Misthios bc542f14b2
Build containers / fedora-cosmic (rawhide) (push) Failing after 49s
Build containers / fedora-cosmic (44) (push) Failing after 56s
refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build fedora-cosmic from the upstream Fedora manifests in
fedora/ostree/ci-test (44 and rawhide) with custom overlays:

- remove firefox from the base system
- add token2-fido-bridge + PC/SC smartcard stack and uhid
- install per-user Flatpaks on first login via a systemd user unit

Replace the legacy builder/changelog scripts with:
- build.sh: rpm-ostree compose image (upstream overlay or standalone)
- release.sh: package changelog published as Gitea releases

CI moves to the job-v2 runner with a build matrix, cosign signing and
release publishing. Drop the legacy asahi-cosmic/shared/base images,
builder.sh, changelog.sh, Containerfile and changelogs/.
2026-09-21 15:11:26 +02:00

157 lines
4.6 KiB
Bash
Executable File

#!/usr/bin/env bash
# Build a bootc OCI image from an image definition under images/<image>.
#
# Usage: build.sh <image> <distro> [arch]
#
# The per-image build.conf selects the build mode:
#
# upstream Clone the upstream Fedora manifest repo at a ref mapped from
# <distro>, overlay this image's manifests and support files, then
# compose the OCI image with `rpm-ostree compose image`.
#
# standalone Compose from this image's own manifest.yaml, wrapping it with the
# releasever/ref from build.conf.
set -euo pipefail
if [[ $# -lt 2 ]]; then
echo "Usage: $0 <image> <distro> [arch]" >&2
exit 1
fi
IMAGE="$1"
DISTRO="$2"
ARCH="${3:-$(uname -m)}"
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
IMAGE_DIR="${REPO_ROOT}/images/${IMAGE}"
CONF="${IMAGE_DIR}/build.conf"
[[ -d "${IMAGE_DIR}" ]] || { echo "Unknown image: ${IMAGE}" >&2; exit 1; }
[[ -f "${CONF}" ]] || { echo "Missing build config: ${CONF}" >&2; exit 1; }
# Defaults, overridden by build.conf.
BUILD_MODE=""
UPSTREAM_REPO=""
TOKEN2=0
RUN_TEST_SH=0
RELEASEVER=""
REF=""
declare -A UPSTREAM_REFS=()
# shellcheck disable=SC1090
source "${CONF}"
BUILD_DIR="${REPO_ROOT}/build/${IMAGE}-${DISTRO}-${ARCH}"
OCI_ARCHIVE="${BUILD_DIR}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
CACHE_DIR="${REPO_ROOT}/cache"
[[ -n "${BUILD_MODE}" ]] || { echo "BUILD_MODE not set in ${CONF}" >&2; exit 1; }
buildid="$(date '+%Y%m%d.0')"
echo "${buildid}" > "${REPO_ROOT}/.buildid"
rm -rf "${BUILD_DIR}"
mkdir -p "${BUILD_DIR}" "${CACHE_DIR}"
if [[ "${RUN_TEST_SH}" == "1" && -x "${IMAGE_DIR}/test.sh" ]]; then
echo "Running ${IMAGE_DIR}/test.sh"
( cd "${IMAGE_DIR}" && ./test.sh )
fi
# Download the latest token2-fido-bridge RPM from GitHub and turn it into a
# local yum repo so the manifest can install it.
setup_token2_repo() {
local dest="$1"
local api url
api="https://api.github.com/repos/token2/token2-fido-bridge/releases/latest"
url="$(curl -fsSL "${api}" \
| jq -r '.assets[] | select(.name | endswith(".rpm")) | .browser_download_url' \
| head -n1)"
if [[ -z "${url}" || "${url}" == "null" ]]; then
echo "ERROR: no token2-fido-bridge .rpm found in the latest GitHub release" >&2
exit 1
fi
mkdir -p "${dest}/token2-repo"
curl -fsSL "${url}" -o "${dest}/token2-repo/$(basename "${url}")"
createrepo_c "${dest}/token2-repo"
cat > "${dest}/token2-fido-bridge.repo" <<EOF
[token2-fido-bridge]
name=token2-fido-bridge
baseurl=file://${dest}/token2-repo
enabled=1
gpgcheck=0
EOF
}
case "${BUILD_MODE}" in
upstream)
[[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; }
upstream_ref="${UPSTREAM_REFS[${DISTRO}]:-}"
[[ -n "${upstream_ref}" ]] || { echo "No upstream ref configured for distro '${DISTRO}'" >&2; exit 1; }
git clone --depth 1 --branch "${upstream_ref}" "${UPSTREAM_REPO}" "${BUILD_DIR}/upstream"
# Overlay our manifests/support files into the upstream tree so that
# relative includes and *.repo discovery keep working.
cp "${IMAGE_DIR}/manifest.yaml" "${BUILD_DIR}/upstream/"
cp "${IMAGE_DIR}/custom.yaml" "${BUILD_DIR}/upstream/"
if compgen -G "${IMAGE_DIR}/repos/*.repo" >/dev/null; then
cp "${IMAGE_DIR}"/repos/*.repo "${BUILD_DIR}/upstream/"
fi
if [[ -d "${IMAGE_DIR}/files" ]]; then
cp -a "${IMAGE_DIR}/files/." "${BUILD_DIR}/upstream/"
fi
if [[ "${TOKEN2}" == "1" ]]; then
setup_token2_repo "${BUILD_DIR}/upstream"
fi
MANIFEST="${BUILD_DIR}/upstream/manifest.yaml"
;;
standalone)
[[ -n "${RELEASEVER}" ]] || { echo "RELEASEVER not set in ${CONF}" >&2; exit 1; }
[[ -n "${REF}" ]] || { echo "REF not set in ${CONF}" >&2; exit 1; }
# Build from a copy so we never mutate the checked-in image definition.
mkdir -p "${BUILD_DIR}/images"
cp -a "${IMAGE_DIR}" "${BUILD_DIR}/images/${IMAGE}"
local_dir="${BUILD_DIR}/images/${IMAGE}"
if compgen -G "${local_dir}/repos/*.repo" >/dev/null; then
cp "${local_dir}"/repos/*.repo "${local_dir}/"
fi
if [[ "${TOKEN2}" == "1" ]]; then
setup_token2_repo "${local_dir}"
fi
cat > "${local_dir}/.build-manifest.yaml" <<EOF
releasever: ${RELEASEVER}
ref: ${REF}
include:
- manifest.yaml
EOF
MANIFEST="${local_dir}/.build-manifest.yaml"
;;
*)
echo "Unknown BUILD_MODE: ${BUILD_MODE}" >&2
exit 1
;;
esac
echo "Composing ${IMAGE} ${DISTRO} (${ARCH}) build ${buildid} ..."
RPM_OSTREE=(rpm-ostree)
if [[ "${EUID}" -ne 0 ]]; then
RPM_OSTREE=(sudo -E rpm-ostree)
fi
"${RPM_OSTREE[@]}" compose image \
--cachedir="${CACHE_DIR}" \
--initialize \
--max-layers=256 \
"${MANIFEST}" \
"${OCI_ARCHIVE}"
echo "Built: ${OCI_ARCHIVE}"