diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 8be05f0..d67d0f8 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -1,60 +1,12 @@ --- -# CI for fedora-bootc base images. -# -# All build and test logic lives in the Justfile so that CI flows -# are easily replicable locally: just install `just` and run the -# same targets that CI does. -workflow: +include: + - remote: https://gitlab.com/platform-engineering-org/gitlab-ci/-/raw/main/templates/build-image.gitlab-ci.yml + +build-image: + extends: .build-image + variables: + EXTRA_ARGS: "--security-opt=label=disable --cap-add=all" rules: - # Skip CI if only non-build files changed - - changes: - - renovate.json - - README.md - - LICENSE - - .tekton/* + - if: $CI_PROJECT_NAMESPACE != "fedora/bootc" when: never - - when: always - -stages: - - build - -variables: - BUILDER: buildah - JUST_VERSION: "1.49.0" - -.build-image: - stage: build - image: quay.io/buildah/stable:v1.42.2 - needs: [] - before_script: - # just is not packaged in the buildah image; grab a pinned static binary - - curl -sSfL -o /tmp/just.tar.gz "https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-x86_64-unknown-linux-musl.tar.gz" - - tar -xzf /tmp/just.tar.gz -C /usr/local/bin just - -basic-checks: - stage: build - image: quay.io/fedora/fedora:latest - needs: [] - script: | - set -xeuo pipefail - dnf install -y file jq python3-yaml ShellCheck just - just validate - -# Test each tier against rawhide and the latest stable release -build-and-test: - extends: .build-image - parallel: - matrix: - - FEDORA_VERSION: [rawhide, "44"] - TIER: [minimal, minimal-plus, standard] - script: - - just test - -# Smoke-test older Fedora versions (standard tier, build only) -build-fedora-version: - extends: .build-image - parallel: - matrix: - - FEDORA_VERSION: ["43"] - script: - - just build + - if: $CI_PIPELINE_SOURCE == "merge_request_event" diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 6383196..e955059 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,7 +1,7 @@ --- repos: - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v6.0.0 + rev: v5.0.0 hooks: - id: end-of-file-fixer - id: trailing-whitespace @@ -22,6 +22,6 @@ repos: - id: check-json - id: check-yaml - repo: https://github.com/markdownlint/markdownlint - rev: v0.15.0 + rev: v0.13.0 hooks: - id: markdownlint diff --git a/.tekton/fedora-bootc-43-iot-pull-request.yaml b/.tekton/fedora-bootc-43-iot-pull-request.yaml deleted file mode 100644 index 3d310ab..0000000 --- a/.tekton/fedora-bootc-43-iot-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-iot-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-iot-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-iot - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-iot:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-iot diff --git a/.tekton/fedora-bootc-43-iot-push.yaml b/.tekton/fedora-bootc-43-iot-push.yaml deleted file mode 100644 index f027a70..0000000 --- a/.tekton/fedora-bootc-43-iot-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-iot-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-iot-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-iot - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-iot:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-iot diff --git a/.tekton/fedora-bootc-43-iot-renovate-push.yaml b/.tekton/fedora-bootc-43-iot-renovate-push.yaml deleted file mode 100644 index 00c653d..0000000 --- a/.tekton/fedora-bootc-43-iot-renovate-push.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch.startsWith("renovate/")) - ) && ( - ".tekton/fedora-bootc-43-iot-renovate-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-iot - pipelines.appstudio.openshift.io/type: build - release.appstudio.openshift.io/auto-release: "false" - name: fedora-bootc-43-iot-renovate-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-iot - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-iot:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-iot diff --git a/.tekton/fedora-bootc-43-minimal-plus-pull-request.yaml b/.tekton/fedora-bootc-43-minimal-plus-pull-request.yaml deleted file mode 100644 index 5d89391..0000000 --- a/.tekton/fedora-bootc-43-minimal-plus-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-minimal-plus-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-minimal-plus-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-minimal-plus - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-minimal-plus:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-minimal-plus diff --git a/.tekton/fedora-bootc-43-minimal-plus-push.yaml b/.tekton/fedora-bootc-43-minimal-plus-push.yaml deleted file mode 100644 index e5b62b3..0000000 --- a/.tekton/fedora-bootc-43-minimal-plus-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-minimal-plus-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-minimal-plus-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-minimal-plus - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-minimal-plus:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-minimal-plus diff --git a/.tekton/fedora-bootc-43-minimal-pull-request.yaml b/.tekton/fedora-bootc-43-minimal-pull-request.yaml deleted file mode 100644 index 9a7a0be..0000000 --- a/.tekton/fedora-bootc-43-minimal-pull-request.yaml +++ /dev/null @@ -1,71 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-minimal-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-minimal-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-minimal - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-minimal:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-minimal diff --git a/.tekton/fedora-bootc-43-minimal-push.yaml b/.tekton/fedora-bootc-43-minimal-push.yaml deleted file mode 100644 index 690e055..0000000 --- a/.tekton/fedora-bootc-43-minimal-push.yaml +++ /dev/null @@ -1,68 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-minimal-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-minimal-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-minimal - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-minimal:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-minimal diff --git a/.tekton/fedora-bootc-43-standard-pull-request.yaml b/.tekton/fedora-bootc-43-standard-pull-request.yaml deleted file mode 100644 index adf02a7..0000000 --- a/.tekton/fedora-bootc-43-standard-pull-request.yaml +++ /dev/null @@ -1,75 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-standard-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-standard-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-standard - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-standard:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-standard diff --git a/.tekton/fedora-bootc-43-standard-push.yaml b/.tekton/fedora-bootc-43-standard-push.yaml deleted file mode 100644 index b89bb44..0000000 --- a/.tekton/fedora-bootc-43-standard-push.yaml +++ /dev/null @@ -1,72 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-43-standard-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-43 - appstudio.openshift.io/component: fedora-bootc-43-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-43-standard-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-43-compose:Fedora-43-updates-20260727.0@sha256:af8e3cce0623d775670a68562f69e1050805cdd5ba8799c05088e9acf3f372c0 - - MANIFEST=fedora-standard - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-43-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=43 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:8ff57394418faad7722c144f77494cf654007d60f63526357c007700bfc34edd - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-43-standard diff --git a/.tekton/fedora-bootc-44-iot-pull-request.yaml b/.tekton/fedora-bootc-44-iot-pull-request.yaml deleted file mode 100644 index e184549..0000000 --- a/.tekton/fedora-bootc-44-iot-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-iot-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-iot-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-20260209.n.0@sha256:c947e0988e3f00078d3ff59eaff5ee18fe1d6fd39dc1fd15d268de0d074df45f - - MANIFEST=fedora-iot - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-iot:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-iot diff --git a/.tekton/fedora-bootc-44-iot-push.yaml b/.tekton/fedora-bootc-44-iot-push.yaml deleted file mode 100644 index 3d39c40..0000000 --- a/.tekton/fedora-bootc-44-iot-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-iot-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-iot-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-20260209.n.0@sha256:c947e0988e3f00078d3ff59eaff5ee18fe1d6fd39dc1fd15d268de0d074df45f - - MANIFEST=fedora-iot - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-iot:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-iot diff --git a/.tekton/fedora-bootc-44-minimal-plus-pull-request.yaml b/.tekton/fedora-bootc-44-minimal-plus-pull-request.yaml deleted file mode 100644 index d7631a5..0000000 --- a/.tekton/fedora-bootc-44-minimal-plus-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-minimal-plus-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-minimal-plus-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-minimal-plus - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-minimal-plus:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-minimal-plus diff --git a/.tekton/fedora-bootc-44-minimal-plus-push.yaml b/.tekton/fedora-bootc-44-minimal-plus-push.yaml deleted file mode 100644 index c4b145d..0000000 --- a/.tekton/fedora-bootc-44-minimal-plus-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-minimal-plus-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-minimal-plus-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-minimal-plus - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-minimal-plus:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-minimal-plus diff --git a/.tekton/fedora-bootc-44-minimal-pull-request.yaml b/.tekton/fedora-bootc-44-minimal-pull-request.yaml deleted file mode 100644 index 34b99c1..0000000 --- a/.tekton/fedora-bootc-44-minimal-pull-request.yaml +++ /dev/null @@ -1,71 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-minimal-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-minimal-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-minimal - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-minimal:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-minimal diff --git a/.tekton/fedora-bootc-44-minimal-push.yaml b/.tekton/fedora-bootc-44-minimal-push.yaml deleted file mode 100644 index a06712e..0000000 --- a/.tekton/fedora-bootc-44-minimal-push.yaml +++ /dev/null @@ -1,68 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-minimal-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-minimal-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-minimal - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-minimal:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-minimal diff --git a/.tekton/fedora-bootc-44-standard-pull-request.yaml b/.tekton/fedora-bootc-44-standard-pull-request.yaml deleted file mode 100644 index d1d9af2..0000000 --- a/.tekton/fedora-bootc-44-standard-pull-request.yaml +++ /dev/null @@ -1,75 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-standard-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-standard-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-standard - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-standard:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-standard diff --git a/.tekton/fedora-bootc-44-standard-push.yaml b/.tekton/fedora-bootc-44-standard-push.yaml deleted file mode 100644 index 337ab83..0000000 --- a/.tekton/fedora-bootc-44-standard-push.yaml +++ /dev/null @@ -1,72 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-44-standard-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-44 - appstudio.openshift.io/component: fedora-bootc-44-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-44-standard-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-44-compose:Fedora-44-updates-20260827.0@sha256:2f39b27325602d36383d0a320edad60de595e0bafd8983f0a2aeeeb87d7e3b9d - - MANIFEST=fedora-standard - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-44-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=44 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-44-standard diff --git a/.tekton/fedora-bootc-45-iot-pull-request.yaml b/.tekton/fedora-bootc-45-iot-pull-request.yaml deleted file mode 100644 index 0475788..0000000 --- a/.tekton/fedora-bootc-45-iot-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-iot-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-iot-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260821.n.0@sha256:55b3460339b8c7aa0a2511e33c623310e17b16118764011059b2e8f35c5bedaf - - MANIFEST=fedora-iot - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-iot:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-iot diff --git a/.tekton/fedora-bootc-45-iot-push.yaml b/.tekton/fedora-bootc-45-iot-push.yaml deleted file mode 100644 index 65e6370..0000000 --- a/.tekton/fedora-bootc-45-iot-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-iot-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-iot-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260821.n.0@sha256:55b3460339b8c7aa0a2511e33c623310e17b16118764011059b2e8f35c5bedaf - - MANIFEST=fedora-iot - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-iot:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-iot diff --git a/.tekton/fedora-bootc-45-minimal-plus-pull-request.yaml b/.tekton/fedora-bootc-45-minimal-plus-pull-request.yaml deleted file mode 100644 index c590839..0000000 --- a/.tekton/fedora-bootc-45-minimal-plus-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-minimal-plus-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-minimal-plus-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-minimal-plus - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-minimal-plus:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-minimal-plus diff --git a/.tekton/fedora-bootc-45-minimal-plus-push.yaml b/.tekton/fedora-bootc-45-minimal-plus-push.yaml deleted file mode 100644 index 766b64b..0000000 --- a/.tekton/fedora-bootc-45-minimal-plus-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-minimal-plus-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-minimal-plus-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-minimal-plus - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-minimal-plus:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-minimal-plus diff --git a/.tekton/fedora-bootc-45-minimal-pull-request.yaml b/.tekton/fedora-bootc-45-minimal-pull-request.yaml deleted file mode 100644 index fc96291..0000000 --- a/.tekton/fedora-bootc-45-minimal-pull-request.yaml +++ /dev/null @@ -1,71 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-minimal-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-minimal-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-minimal - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-minimal:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-minimal diff --git a/.tekton/fedora-bootc-45-minimal-push.yaml b/.tekton/fedora-bootc-45-minimal-push.yaml deleted file mode 100644 index 22afdff..0000000 --- a/.tekton/fedora-bootc-45-minimal-push.yaml +++ /dev/null @@ -1,68 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-minimal-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-minimal-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-minimal - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-minimal:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-minimal diff --git a/.tekton/fedora-bootc-45-standard-pull-request.yaml b/.tekton/fedora-bootc-45-standard-pull-request.yaml deleted file mode 100644 index 78bd426..0000000 --- a/.tekton/fedora-bootc-45-standard-pull-request.yaml +++ /dev/null @@ -1,75 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-standard-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-standard-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-standard - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-standard:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-standard diff --git a/.tekton/fedora-bootc-45-standard-push.yaml b/.tekton/fedora-bootc-45-standard-push.yaml deleted file mode 100644 index b5f1f7b..0000000 --- a/.tekton/fedora-bootc-45-standard-push.yaml +++ /dev/null @@ -1,72 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-45-standard-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-45 - appstudio.openshift.io/component: fedora-bootc-45-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-45-standard-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-45-compose:Fedora-45-20260826.n.0@sha256:ae4bedc5740a4e3f984f879c66ca026aa94ce8aec641a804f4ede0bc4ddd2c19 - - MANIFEST=fedora-standard - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-45-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=45 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-45-standard diff --git a/.tekton/fedora-bootc-eln-standard-pull-request.yaml b/.tekton/fedora-bootc-eln-standard-pull-request.yaml deleted file mode 100644 index b7a7f56..0000000 --- a/.tekton/fedora-bootc-eln-standard-pull-request.yaml +++ /dev/null @@ -1,77 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-eln-standard-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/eln.yaml".pathChanged() || - "fedora-eln.yaml".pathChanged() || - "eln/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-eln - appstudio.openshift.io/component: fedora-bootc-eln-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-eln-standard-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-eln-compose:Fedora-eln-20260802.n.0@sha256:12f9b31a07ea270b65d5869a904fd1509c56b470df6c8f2586492fc0f006f213 - - MANIFEST=fedora-eln - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-eln-standard:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=eln - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:c587d9400c89e21225fee03a080dcb0816919d39770b6af0cd6f990c7f8404b8 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-eln-standard diff --git a/.tekton/fedora-bootc-eln-standard-push.yaml b/.tekton/fedora-bootc-eln-standard-push.yaml deleted file mode 100644 index b239205..0000000 --- a/.tekton/fedora-bootc-eln-standard-push.yaml +++ /dev/null @@ -1,74 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-eln-standard-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/eln.yaml".pathChanged() || - "fedora-eln.yaml".pathChanged() || - "eln/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-eln - appstudio.openshift.io/component: fedora-bootc-eln-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-eln-standard-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-eln-compose:Fedora-eln-20260802.n.0@sha256:12f9b31a07ea270b65d5869a904fd1509c56b470df6c8f2586492fc0f006f213 - - MANIFEST=fedora-eln - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-eln-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=eln - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:c587d9400c89e21225fee03a080dcb0816919d39770b6af0cd6f990c7f8404b8 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-eln-standard diff --git a/.tekton/fedora-bootc-eln-standard-renovate-push.yaml b/.tekton/fedora-bootc-eln-standard-renovate-push.yaml deleted file mode 100644 index 953bbd6..0000000 --- a/.tekton/fedora-bootc-eln-standard-renovate-push.yaml +++ /dev/null @@ -1,77 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch.startsWith("renovate/")) - ) && ( - ".tekton/fedora-bootc-eln-standard-renovate-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/eln.yaml".pathChanged() || - "fedora-eln.yaml".pathChanged() || - "eln/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) && true == false - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-eln - appstudio.openshift.io/component: fedora-bootc-eln-standard - pipelines.appstudio.openshift.io/type: build - release.appstudio.openshift.io/auto-release: "false" - name: fedora-bootc-eln-standard-renovate-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-eln-compose:Fedora-eln-20260802.n.0@sha256:12f9b31a07ea270b65d5869a904fd1509c56b470df6c8f2586492fc0f006f213 - - MANIFEST=fedora-eln - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-eln-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=eln - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:c587d9400c89e21225fee03a080dcb0816919d39770b6af0cd6f990c7f8404b8 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-eln-standard diff --git a/.tekton/fedora-bootc-rawhide-iot-pull-request.yaml b/.tekton/fedora-bootc-rawhide-iot-pull-request.yaml deleted file mode 100644 index b351374..0000000 --- a/.tekton/fedora-bootc-rawhide-iot-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-iot-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-iot-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260209.n.0@sha256:a46fca7ce98fd36b5edb6ef96867de573479af69c645801cdc8c53ad6708114c - - MANIFEST=fedora-iot - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-iot:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-iot diff --git a/.tekton/fedora-bootc-rawhide-iot-push.yaml b/.tekton/fedora-bootc-rawhide-iot-push.yaml deleted file mode 100644 index 89e9523..0000000 --- a/.tekton/fedora-bootc-rawhide-iot-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-iot-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "iot.yaml".pathChanged() || - "iot/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-iot - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-iot-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260209.n.0@sha256:a46fca7ce98fd36b5edb6ef96867de573479af69c645801cdc8c53ad6708114c - - MANIFEST=fedora-iot - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-iot:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:44d0e8034a19a1ced7817c117c9c15230def1f3e7941666a72a3e47919951f51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-iot diff --git a/.tekton/fedora-bootc-rawhide-minimal-plus-pull-request.yaml b/.tekton/fedora-bootc-rawhide-minimal-plus-pull-request.yaml deleted file mode 100644 index 9fb1b50..0000000 --- a/.tekton/fedora-bootc-rawhide-minimal-plus-pull-request.yaml +++ /dev/null @@ -1,73 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-minimal-plus-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-minimal-plus-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-minimal-plus - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-minimal-plus:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-minimal-plus diff --git a/.tekton/fedora-bootc-rawhide-minimal-plus-push.yaml b/.tekton/fedora-bootc-rawhide-minimal-plus-push.yaml deleted file mode 100644 index 2794cc9..0000000 --- a/.tekton/fedora-bootc-rawhide-minimal-plus-push.yaml +++ /dev/null @@ -1,70 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-minimal-plus-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-minimal-plus - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-minimal-plus-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-minimal-plus - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-minimal-plus:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-minimal-plus diff --git a/.tekton/fedora-bootc-rawhide-minimal-pull-request.yaml b/.tekton/fedora-bootc-rawhide-minimal-pull-request.yaml deleted file mode 100644 index 58a8164..0000000 --- a/.tekton/fedora-bootc-rawhide-minimal-pull-request.yaml +++ /dev/null @@ -1,71 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-minimal-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-minimal-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-minimal - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-minimal:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-minimal diff --git a/.tekton/fedora-bootc-rawhide-minimal-push.yaml b/.tekton/fedora-bootc-rawhide-minimal-push.yaml deleted file mode 100644 index ef33c65..0000000 --- a/.tekton/fedora-bootc-rawhide-minimal-push.yaml +++ /dev/null @@ -1,68 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-minimal-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-minimal - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-minimal-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-minimal - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-minimal:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-minimal diff --git a/.tekton/fedora-bootc-rawhide-standard-pull-request.yaml b/.tekton/fedora-bootc-rawhide-standard-pull-request.yaml deleted file mode 100644 index 771cf13..0000000 --- a/.tekton/fedora-bootc-rawhide-standard-pull-request.yaml +++ /dev/null @@ -1,75 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "true" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "pull_request" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-standard-pull-request.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-standard-on-pull-request -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-standard - - name: image-expires-after - value: 5d - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-standard:on-pr-{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-standard diff --git a/.tekton/fedora-bootc-rawhide-standard-push.yaml b/.tekton/fedora-bootc-rawhide-standard-push.yaml deleted file mode 100644 index 451d569..0000000 --- a/.tekton/fedora-bootc-rawhide-standard-push.yaml +++ /dev/null @@ -1,72 +0,0 @@ -apiVersion: tekton.dev/v1 -kind: PipelineRun -metadata: - annotations: - build.appstudio.openshift.io/repo: https://gitlab.com/fedora/bootc/base-images/-/tree/{{revision}} - build.appstudio.redhat.com/commit_sha: '{{revision}}' - build.appstudio.redhat.com/target_branch: '{{target_branch}}' - pipelinesascode.tekton.dev/cancel-in-progress: "false" - pipelinesascode.tekton.dev/max-keep-runs: "3" - pipelinesascode.tekton.dev/on-cel-expression: | - ( - (event == "push" && target_branch == "main") - ) && ( - ".tekton/fedora-bootc-rawhide-standard-push.yaml".pathChanged() || - "Containerfile".pathChanged() || - "bootc-base-imagectl".pathChanged() || - "install-manifests".pathChanged() || - "fedora-includes/generic.yaml".pathChanged() || - "minimal.yaml".pathChanged() || - "minimal/***".pathChanged() || - "minimal-plus.hidden.yaml".pathChanged() || - "minimal-plus/***".pathChanged() || - "standard.yaml".pathChanged() || - "standard/***".pathChanged() - ) - test.appstudio.openshift.io/comment_strategy: "disable_all" - creationTimestamp: null - labels: - appstudio.openshift.io/application: fedora-bootc-rawhide - appstudio.openshift.io/component: fedora-bootc-rawhide-standard - pipelines.appstudio.openshift.io/type: build - name: fedora-bootc-rawhide-standard-on-push -spec: - params: - - name: git-url - value: '{{source_url}}' - - name: revision - value: '{{revision}}' - - name: build-platforms - value: - - linux/amd64 - - linux/arm64 - - linux/ppc64le - - linux/s390x - - name: dockerfile - value: Containerfile - - name: path-context - value: . - - name: privileged-nested - value: true - - name: build-args - value: - - REPOS_IMAGE=quay.io/bootc-devel/fedora-bootc-rawhide-compose:Fedora-Rawhide-20260827.n.0@sha256:fcfd7db08ce2a2bf993fb11a15d21490b06017d879ece5d62e5d797107e3f9ab - - MANIFEST=fedora-standard - - name: output-image - value: quay.io/konflux-fedora/bootc-tenant/fedora-bootc-rawhide-standard:{{revision}} - - name: labels - value: - - org.opencontainers.image.version=46 - pipelineRef: - params: - - name: bundle - value: quay.io/bootc-devel/tekton-catalog/pipeline-buildah-build-bootc-multi-platform-oci-ta@sha256:9eb1decf91e0d678a613f7d4767091c05b37bec8a02163087254328f1e848c51 - - name: name - value: buildah-build-bootc-multi-platform-oci-ta - - name: kind - value: pipeline - resolver: bundles - timeouts: - pipeline: 6h - taskRunTemplate: - serviceAccountName: build-pipeline-fedora-bootc-rawhide-standard diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md deleted file mode 100644 index 1695c09..0000000 --- a/CONTRIBUTING.md +++ /dev/null @@ -1,37 +0,0 @@ -# Contributing to fedora-bootc base images - -## Prerequisites - -Everything revolves around our Containerfile, but there's -a high level wrapper in `Justfile` which you should use. -So installing `podman` (or `buildah`) and `just` are strongly recommended. - -## Building and testing - -Run `just --list` to see available targets and `just show-config` to -see current settings. The Justfile is also what CI invokes, so anything -you run locally is the same as what runs in the pipeline. - -Configuration is via environment variables — see the comments at the -top of the `Justfile` for the full list. For example: - -```bash -just build # defaults -TIER=minimal just build # different tier -FEDORA_VERSION=43 just test # different Fedora version -BUILDER=podman just build # use podman instead of buildah -just ci # full CI run (validate + test all tiers) -``` - -## Building a split image - -The Containerfile supports building a split (content-based layered) -image using [chunkah](https://github.com/coreos/chunkah) via the -`chunked` build target: - -```bash -just build --chunkah -``` - -Extra arguments can be passed to chunkah via the `CHUNKAH_ARGS` build -arg (e.g. `BUILDER_EXTRA='--build-arg CHUNKAH_ARGS="--max-layers 128"' just build --chunkah`). diff --git a/Containerfile b/Containerfile index 1aa0330..2120056 100644 --- a/Containerfile +++ b/Containerfile @@ -1,83 +1,46 @@ -# In order to make a base image as part of a Dockerfile, this container build uses -# nested containerization, so you must build with e.g. -# podman build --security-opt=label=disable --cap-add=all --device /dev/fuse <...> - -# NOTE: This container build will output a single giant layer. You can either -# run the "rechunker" on the output of this build (see bootc-base-imagectl.md), -# or build the split version directly with `just build --chunkah` -# (or if using podman/buildah directly, add `--build-arg FINAL=chunked -# --skip-unused-stages=false -v $PWD:/run/src`). - -# Override this repos container to control the base image package versions. For -# example, podman build --from=quay.io/fedora/fedora:41 will get you a system -# that uses Fedora 41 packages. Or inject arbitrary yum repos (COPR, etc) here. +# This container build uses some special features of podman that allow +# a process executing as part of a container build to generate a new container +# image "from scratch". # -# Note we also support --build-arg REPOS_IMAGE=quay.io/fedora/fedora:41 here -# since konflux doesn't yet support --from. -ARG REPOS_IMAGE=quay.io/fedora/fedora:rawhide -ARG BUILDER_IMAGE=quay.io/fedora/fedora:rawhide -# Either 'unchunked' or 'chunked'. Determines whether we take the chunkah path. -ARG FINAL=unchunked +# This container build uses nested containerization, so you must build with e.g. +# podman build --security-opt=label=disable --cap-add=all --device /dev/fuse <...> +# +# # Why are we doing this? +# +# Today this base image build process uses rpm-ostree. There is a lot of things that +# rpm-ostree does when generating a container image...but important parts include: +# +# - auto-updating labels in the container metadata +# - Generating "chunked" content-addressed reproducible image layers (notice +# how there are ~60 layers in the generated image) +# +# The latter bit in particular is currently impossible to do from Containerfile. +# A future goal is adding some support for this in a way that can be honored by +# buildah (xref https://github.com/containers/podman/discussions/12605) +# +# # Why does this build process require additional privileges? +# +# Because it's generating a base image and uses containerbuildcontextization features itself. +# In the future some of this can be lifted. -FROM $REPOS_IMAGE as repos -# BOOTSTRAPPING: This can be any image that has rpm-ostree, selinux-policy-targeted -# and python3 (for bootc-base-imagectl). -FROM $BUILDER_IMAGE as builder -RUN dnf -y install rpm-ostree selinux-policy-targeted python3 -ARG MANIFEST=fedora-standard +FROM quay.io/fedora/fedora:40 as repos + +FROM quay.io/centos-bootc/bootc-image-builder:latest as builder +ARG MANIFEST=fedora-bootc.yaml +COPY --from=repos /etc/dnf/vars /etc/dnf/vars +COPY --from=repos /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-* /etc/pki/rpm-gpg # The input git repository has .repo files committed to git rpm-ostree has historically # emphasized that. But here, we are fetching the repos from the container base image. # So copy the source, and delete the hardcoded ones in git, and use the container base # image ones. We can drop the ones commited to git when we hard switch to Containerfile. COPY . /src -# Avoid umask/permission leakage from the outer environment; ref e.g. -# - https://github.com/coreos/coreos-assembler/pull/4277 -# - https://gitlab.com/fedora/bootc/base-images/-/merge_requests/254 -# This invocation preserves only the executable bit, and specifically we want to remove: -# - setuid/setgid -# - world writability -# NOTE: This adds world-readability, which is what we intend here as all the content -# is public; there's no secrets in our container build. -RUN chmod -R a=rX,u+w /src WORKDIR /src RUN rm -vf /src/*.repo -RUN --mount=type=cache,rw,id=bootc-base-image-cache,target=/cache \ - --mount=type=bind,rw,from=repos,src=/,dst=/repos </dev/null -# Run the build script in the same way we expect custom images to do, and also -# "re-inject" the manifests into the target, so secondary container builds can use it. -/usr/libexec/bootc-base-imagectl build-rootfs \ - --cachedir=/cache --reinject --manifest=${MANIFEST} /repos /target-rootfs -EORUN +COPY --from=repos /etc/yum.repos.d/*.repo /src +RUN --mount=type=cache,target=/workdir --mount=type=bind,rw=true,src=.,dst=/buildcontext,bind-propagation=shared rpm-ostree compose image \ + --image-config fedora-bootc-config.json --cachedir=/workdir --format=ociarchive --initialize ${MANIFEST} /buildcontext/out.ociarchive -# This pulls in the rootfs generated in the previous step -FROM scratch AS unchunked -COPY --from=builder /target-rootfs/ / - -FROM builder AS rechunker -RUN dnf -y install chunkah -ARG CHUNKAH_ARGS="" -RUN --mount=from=unchunked,src=/,target=/chunkah,ro \ - --mount=type=bind,target=/run/src,rw \ - /usr/libexec/bootc-base-imagectl rechunk --chunkah ${CHUNKAH_ARGS} \ - > /run/src/out.ociarchive -FROM oci-archive:out.ociarchive AS chunked - -FROM $FINAL -LABEL containers.bootc 1 -# This is an ad-hoc way for us to reference bootc-image-builder in -# a way that in theory client tooling can inspect and find. Today -# it isn't widely used. -LABEL bootc.diskimage-builder quay.io/centos-bootc/bootc-image-builder -# https://pagure.io/fedora-kiwi-descriptions/pull-request/52 -ENV container=oci -# Make systemd the default -STOPSIGNAL SIGRTMIN+3 -CMD ["/sbin/init"] +FROM oci-archive:./out.ociarchive +# Need to reference builder here to force ordering. But since we have to run +# something anyway, we might as well cleanup after ourselves. +RUN --mount=type=bind,from=builder,src=.,target=/var/tmp --mount=type=bind,rw=true,src=.,dst=/buildcontext,bind-propagation=shared rm /buildcontext/out.ociarchive diff --git a/Justfile b/Justfile deleted file mode 100644 index eec0a0a..0000000 --- a/Justfile +++ /dev/null @@ -1,91 +0,0 @@ -# Development entry point for fedora-bootc base images. -# Run `just --list` to see available targets. -# See CONTRIBUTING.md for more information. -# -------------------------------------------------------------------- - -# Content tier: standard (default), minimal, minimal-plus, iot -tier := env("TIER", "standard") -# Fedora version: rawhide (default), 43, 44, etc. -fedora_version := env("FEDORA_VERSION", "rawhide") -# Container build tool -builder := env("BUILDER", "buildah") -# Extra arguments for the builder -builder_extra := env("BUILDER_EXTRA", "") -# Output image name -image := "localhost/fedora-bootc" - -# These are required for the nested containerization used by rpm-ostree -# inside the Containerfile. -priv_args := "--security-opt=label=disable --cap-add=all --device /dev/fuse" - -# Internal -_build_cmd := builder + " build" -_tag := image + if tier == "standard" { "" } else { ":" + tier } -_base_image := "quay.io/fedora/fedora:" + fedora_version -_version_args := if fedora_version == "rawhide" { "" } else { "--build-arg=REPOS_IMAGE=" + _base_image + " --build-arg=BUILDER_IMAGE=" + _base_image } -_chunkah_args := "--build-arg FINAL=chunked --skip-unused-stages=false -v " + justfile_directory() + ":/run/src" - -# ============================================================================ -# Core targets -# ============================================================================ - -# Build the container image -[group('core')] -[arg("chunkah", long, value="true")] -build chunkah="": _check-tier - {{_build_cmd}} -f Containerfile --no-cache \ - -t {{_tag}} {{priv_args}} \ - {{_version_args}} {{builder_extra}} \ - {{if chunkah != "" { _chunkah_args } else { "" }}} \ - --build-arg=MANIFEST=fedora-{{tier}} . - -# Build and test -[group('core')] -test: build - #!/usr/bin/env bash - set -xeuo pipefail - {{_build_cmd}} -f tests/rootfs/Dockerfile -t localhost/test --from {{_tag}} tests/rootfs - # The derive and sysusers tests only apply to the standard tier - if [ "{{tier}}" = "standard" ]; then - {{_build_cmd}} -f tests/Containerfile.test-derive --no-cache \ - -t localhost/fedora-bootc-derived {{priv_args}} {{builder_extra}} tests - {{_build_cmd}} -f tests/Containerfile.test-sysusers --no-cache \ - -t localhost/fedora-bootc-derived {{priv_args}} {{builder_extra}} tests - fi - -# Run validation checks (whitespace, shellcheck, YAML) -[group('core')] -validate: - #!/usr/bin/env bash - set -xeuo pipefail - ./ci/find-whitespace - ./ci/shellcheck - ./ci/validate - -# Show current configuration -[group('core')] -show-config: - @echo "TIER={{tier}}" - @echo "FEDORA_VERSION={{fedora_version}}" - @echo "BUILDER={{builder}}" - @echo "image tag={{_tag}}" - @echo "base image={{_base_image}}" - -# ============================================================================ -# CI targets (used by .gitlab-ci.yml) -# ============================================================================ - -# Run all CI checks: validate + build and test all tiers -[group('ci')] -ci: validate - just tier=minimal test - just tier=minimal-plus test - just tier=standard test - -# ============================================================================ -# Internal -# ============================================================================ - -[private] -_check-tier: - @test -f fedora-{{tier}}.yaml || { echo "error: unknown tier '{{tier}}' (valid: standard, minimal, minimal-plus, iot)"; exit 1; } diff --git a/README.md b/README.md index 11a2fb3..c2b6f16 100644 --- a/README.md +++ b/README.md @@ -9,57 +9,24 @@ been extremely successful. This project aims to apply the same technique for bootable host systems - using standard OCI/Docker containers as a transport and delivery format for base operating system updates. -## Building images +## Building -The current default user experience is to build *layered* images on top of the official -binary base images produced and tested by this project. See the documentation[5] for more info. +First, the expectation is that most users will want to build *layered* images +on top of the official base images. See the documentation[5] for more info. -If you want total control over the image, you don't need to fork this repository. -Instead, you can use the existing container as a "builder" to make new images. -For more information, see the documentation[6]. +Building the images in this repo can be done with `podman build` as with any +other application image (note that building with `docker` is not currently +supported). You need to enable some privileges for technical reasons. -## Contributing - -See [CONTRIBUTING.md](CONTRIBUTING.md) for the full development workflow. - -## Fedora versions - -By default, the base images are built for Fedora rawhide. To build against a -different Fedora version: - -```bash -FEDORA_VERSION=43 just build +``` +podman build --security-opt=label=disable --cap-add=all \ + --device /dev/fuse -t localhost/fedora-bootc . ``` -## Content sets/tiers +See the `Containerfile` for more details. -Documentation above referenced the scratch[6] flow, -but there is also a `minimal-plus` that is not exposed as a stable -interface, but may be used by other images in Fedora. - -- **standard**: This image is the default, what is published as - -- **minimal**: This content set is more of a convenient centralization point for CI - and curation around a package set that is intended as a starting point for - a container base image. -- **minimal-plus**: This content set is intended to be the shared base used by all image-based - Fedora variants (IoT, Atomic Desktops, and CoreOS). - -**standard** inherits from **minimal-plus** and **minimal-plus** in turn inherit from **minimal**. - -- **eln** (manifest `fedora-eln`): Standard base image for Enterprise Linux Next (ELN). Uses distro `fedora` and inherits from standard; built with ELN repos. The image produced by this manifest is published as **fedora-eln**. - -All non-trivial changes to **minimal** and **minimal-plus** should be ACKed by at least -one stakeholder of each Fedora variant WGs. - -### Available Tiers + Versions - -> **NOTE:** The location and naming of these images is subject to change. - -| Version | standard | minimal | minimal-plus | -| ------- | -------- | ------- | ------------ | -| Rawhide | quay.io/bootc-devel/fedora-bootc-rawhide-standard | quay.io/bootc-devel/fedora-bootc-rawhide-minimal | quay.io/bootc-devel/fedora-bootc-rawhide-minimal-plus | -| Fedora 43 | quay.io/bootc-devel/fedora-bootc-43-standard | quay.io/bootc-devel/fedora-bootc-43-minimal | quay.io/bootc-devel/fedora-bootc-43-minimal-plus | +You are of course also free to fork, customize, and build base images yourself. +See this page[6] of the documentation for more information. ## More information @@ -77,4 +44,4 @@ Documentation: [3]: https://img.shields.io/badge/pre--commit-enabled-brightgreen?logo=pre-commit [4]: https://pre-commit.com/ [5]: https://docs.fedoraproject.org/en-US/bootc/building-containers/ -[6]: https://docs.fedoraproject.org/en-US/bootc/building-from-scratch/ +[6]: https://docs.fedoraproject.org/en-US/bootc/building-custom-base/ diff --git a/RELEASE.md b/RELEASE.md deleted file mode 100644 index fe2f647..0000000 --- a/RELEASE.md +++ /dev/null @@ -1,306 +0,0 @@ -# Fedora Base Bootc Container Publishing - -## Overview - -The `fedora-base-bootc` image is published via **two parallel mechanisms**: - -1. **Pungi-IoT + cloud-image-uploader** → `quay.io/fedora/fedora-bootc` (Production) -2. **Konflux** → `quay.io/bootc-devel/fedora-bootc-*` (Development) - -The goal is to move to Konflux and deprecate the Pungi-IoT mechanism. - ---- - -## Part 1: Production Flow (Pungi-IoT) - -### Repositories - -| Repository | URL | Purpose | -|------------|-----|---------| -| base-images | https://pagure.io/fedora-iot/base-images | Image definition (treefiles, packages) | -| pungi-iot | https://pagure.io/fedora-iot/pungi-iot | Compose configuration | -| cloud-image-uploader | https://pagure.io/cloud-image-uploader | Uploads images to registries | -| ansible | https://pagure.io/fedora-infra/ansible | Infrastructure deployment | - -### Compose Cadence - -| Compose | Schedule | Host | -|---------|----------|------| -| IoT Rawhide | **Nightly** | compose-iot01.rdu3.fedoraproject.org | - -### Flow - -``` -┌──────────────────────────────────────────────────────────────────┐ -│ 1. IoT COMPOSE (compose-iot01.rdu3.fedoraproject.org) │ -│ Trigger: Daily cron │ -│ Script: pungi-iot/nightly.sh │ -│ Config: pungi-iot/fedora-iot.conf │ -│ Treefile: base-images/fedora-rawhide.yaml │ -│ │ -│ Output: /mnt/koji/compose/iot//compose/ │ -│ └── /images/Fedora-base-bootc-.ociarchive │ -└──────────────────────────────────────────────────────────────────┘ - │ - ▼ (fedora-messaging) -┌──────────────────────────────────────────────────────────────────┐ -│ 2. CLOUD-IMAGE-UPLOADER (OpenShift) │ -│ │ -│ Listens: org.fedoraproject.prod.pungi.compose.status.change │ -│ Maps: subvariant "base" → repository "fedora-bootc" │ -│ Pushes via skopeo to configured registries │ -└──────────────────────────────────────────────────────────────────┘ - │ - ▼ -┌──────────────────────────────────────────────────────────────────┐ -│ 3. CONTAINER REGISTRIES │ -│ │ -│ - quay.io/fedora/fedora-bootc │ -│ - registry.fedoraproject.org/fedora-bootc │ -└──────────────────────────────────────────────────────────────────┘ -``` - -### Key Configuration Files - -#### 1. Compose: Image Build Definition - -**File:** `pungi-iot/fedora-iot.conf` (lines 276-300) - -```python -ostree_container = { - "^IoT$": [ - { - "config_url": "https://pagure.io/fedora-iot/base-images", - "config_branch": "main", - "treefile": "fedora-rawhide.yaml", - "arches": ["x86_64", "aarch64", "ppc64le", "s390x"], - "subvariant": "base", # <-- Used for mapping - "name": "Fedora-base-bootc", - }, - ] -} -``` - -#### 2. Uploader: Subvariant to Repository Mapping - -**File:** `ansible/roles/openshift-apps/cloud-image-uploader/templates/config.toml` - -```toml -[consumer_config.container.repos] -base = "fedora-bootc" # subvariant "base" → repo "fedora-bootc" -IoT = "fedora-iot" -``` - -#### 3. Uploader: Target Registries - -**File:** `ansible/roles/openshift-apps/cloud-image-uploader/templates/config.toml` - -```toml -[[consumer_config.container.registries]] -url = "registry.fedoraproject.org" - -[[consumer_config.container.registries]] -url = "quay.io/fedora" -``` - -### Tags Applied - -| Compose Type | Tags | -|--------------|------| -| Rawhide | ``, `rawhide` | -| Current Stable | ``, `latest` | -| Branched | `` | - -### Common Changes (Production) - -| Task | Where to Change | -|------|-----------------| -| Add/remove packages from image | `base-images/` repo (manifest YAML files) | -| Change architectures | `pungi-iot/fedora-iot.conf` → `ostree_container.arches` | -| Add new registry | `ansible/.../cloud-image-uploader/templates/config.toml` → `registries` | -| Change repository name | `ansible/.../cloud-image-uploader/templates/config.toml` → `repos` mapping | -| Change tagging logic | `cloud-image-uploader/.../handler.py` | - ---- - -## Part 2: Development Flow (Konflux) - -### Repositories - -| Repository | URL | Purpose | -|------------|-----|---------| -| compose-images | https://gitlab.com/fedora/bootc/compose-images | Generates images containing RPMs used by base-images | -| base-images | https://gitlab.com/fedora/bootc/base-images | Image definitions + Tekton build pipelines | -| tekton-catalog | https://gitlab.com/fedora/bootc/tekton-catalog | Release pipeline definitions | -| tenants-config | https://gitlab.com/fedora/infrastructure/konflux/tenants-config | Konflux tenant configuration | - -### Flow - -``` -┌──────────────────────────────────────────────────────────────────────┐ -│ 0. COMPOSE IMAGES │ -│ │ -│ Source: gitlab.com/fedora/bootc/compose-images │ -│ Output: quay.io/bootc-devel/fedora-bootc--compose │ -│ │ -│ These images contain the RPM repositories used by base-images. │ -└──────────────────────────────────────────────────────────────────────┘ - │ - ▼ -┌──────────────────────────────────────────────────────────────────────┐ -│ 1. BUILD (triggered by git push or Renovate) │ -│ │ -│ Source: gitlab.com/fedora/bootc/base-images │ -│ Pipeline: .tekton/fedora-bootc-*-push.yaml │ -│ Input: REPOS_IMAGE from compose-images │ -│ │ -│ Output: quay.io/konflux-fedora/bootc-tenant/ │ -│ fedora-bootc--:{{revision}} │ -└──────────────────────────────────────────────────────────────────────┘ - │ - ▼ (Konflux creates Snapshot) -┌──────────────────────────────────────────────────────────────────────┐ -│ 2. RELEASE (auto-triggered by ReleasePlan) │ -│ │ -│ ReleasePlan: release-fedora-bootc-to-quay-io │ -│ Pipeline: push-to-external-registry │ -└──────────────────────────────────────────────────────────────────────┘ - │ - ▼ -┌──────────────────────────────────────────────────────────────────────┐ -│ 3. OUTPUT │ -│ │ -│ quay.io/bootc-devel/fedora-bootc--standard │ -│ quay.io/bootc-devel/fedora-bootc--minimal │ -│ quay.io/bootc-devel/fedora-bootc--minimal-plus │ -│ quay.io/bootc-devel/fedora-bootc--iot │ -└──────────────────────────────────────────────────────────────────────┘ -``` - -### Image Tiers - -See the [README](README.md) for details on the different image tiers (minimal, minimal-plus, standard, iot). - -### Renovate Automation - -Renovate automatically updates dependencies. See the description comments in [renovate.json](renovate.json) for scheduling and configuration details. - -### Common Changes (Development) - -| Task | Where to Change | -|------|-----------------| -| Add new component | `tenants-config/.../components/` | -| Change destination registry | `tenants-config/.../releaseplans/release-to-quay-io/` | -| Modify release pipeline | `tekton-catalog/pipelines/push-to-external-registry/` | -| Add new Fedora version | See [Adding a New Fedora Version](#adding-a-new-fedora-version-to-konflux) | -| Remove EOL Fedora version | See [Removing an EOL Fedora Version](#removing-an-eol-fedora-version-from-konflux) | - ---- - -## Part 3: Managing Fedora Versions in Konflux - -This section describes how to add a new Fedora version or remove an EOL version from Konflux. - -**Example scenario:** Fedora 42 is going EOL and needs to be removed. Rawhide (F45) is branching, so we need to add Fedora 44 as the new branched release. - -### Adding a New Fedora Version to Konflux - -#### Step 1: Add Release to compose-images Repo - -**Repository:** https://gitlab.com/fedora/bootc/compose-images - -Add the new release definition so that compose images are generated for the new version. This must be done first as base-images depends on these compose images. - -1. Create new Tekton pipelines in `.tekton/` for the new version (copy from existing version) -2. Update `RELEASEVER`, `COMPOSE_BRANCHED`, and labels in the new pipelines -3. Add a package rule for the new version in `renovate.json` - -See [MR !187](https://gitlab.com/fedora/bootc/compose-images/-/merge_requests/187) for reference (F44 addition). - -#### Step 2: Create Tekton Pipelines (base-images repo) - -**Repository:** https://gitlab.com/fedora/bootc/base-images - -Copy the current release pipelines to the new version and update rawhide for the next version. - -See the code snippets used for F44 in [MR !363 comment](https://gitlab.com/fedora/bootc/base-images/-/merge_requests/363#note_3071603283) for reference. - -#### Step 3: Update Renovate Configuration (base-images repo) - -Add package rules for the new version in `renovate.json`. See the existing rules for other versions as a template. - -#### Step 4: Create Tenant Configuration (tenants-config repo) - -**Repository:** https://gitlab.com/fedora/infrastructure/konflux/tenants-config - -```bash -cd clusters/kflux-fedora-01/tenants/bootc-tenant/applications/fedora-bootc/ -NEW_RELEASE=44 - -# Copy from rawhide -cp -r rawhide $NEW_RELEASE - -# Update version references -sed -i "s/compose-rawhide-id/compose-branched-id/" $NEW_RELEASE/releaseplans/release-to-quay-io/kustomization.yaml -find "${NEW_RELEASE}/" -type f | xargs sed -i "s/rawhide/$NEW_RELEASE/g" -``` - - -Add the new version to `fedora-bootc/kustomization.yaml`: - -```yaml -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization -resources: - - "rawhide" - - "44" # <-- Add new version - - "43" - - "42" -``` - -See [MR !237](https://gitlab.com/fedora/infrastructure/konflux/tenants-config/-/merge_requests/237) for reference (F45 addition). - -### Removing an EOL Fedora Version from Konflux - -When a Fedora version reaches EOL (e.g., F42), follow these steps: - -#### Step 1: Remove Tekton Pipelines (base-images repo) - -**Repository:** https://gitlab.com/fedora/bootc/base-images - -```bash -cd .tekton/ -git rm fedora-bootc-42-*.yaml -``` - -#### Step 2: Remove Renovate Rules (base-images repo) - -Remove the package rules for F42 from `renovate.json` (the two blocks matching `fedora-bootc-42-*`). - -#### Step 3: Remove Tenant Configuration (tenants-config repo) - -**Repository:** https://gitlab.com/fedora/infrastructure/konflux/tenants-config - -Remove the version from `fedora-bootc/kustomization.yaml` and delete the directory: - -```bash -cd cluster/kfluxfedorap01/bootc-tenant/applications/fedora-bootc/ - -# Edit kustomization.yaml to remove "42" from resources - -# Delete the version directory -rm -rf 42/ -``` - -#### Step 4: Remove from compose-images Repo - -**Repository:** https://gitlab.com/fedora/bootc/compose-images - -Remove the EOL release pipelines and renovate rules: - -```bash -cd .tekton/ -git rm fedora-bootc-42-compose-*.yaml -``` - -Also remove the package rule for F42 from `renovate.json` (the block matching `fedora-42-.*-compose`). diff --git a/bootc-base-imagectl b/bootc-base-imagectl deleted file mode 100755 index 3064986..0000000 --- a/bootc-base-imagectl +++ /dev/null @@ -1,237 +0,0 @@ -#!/usr/bin/env python3 - -import argparse -import json -import os -import os.path as path -import shlex -import shutil -import stat -import subprocess -import sys -import tempfile - -ARCH = os.uname().machine -MANIFESTDIR = 'usr/share/doc/bootc-base-imagectl/manifests' - -def run_build_rootfs(args): - """ - Regenerates a base image using a build configuration. - """ - target = args.target - for fn in [f'{args.manifest}.yaml', f'{args.manifest}.hidden.yaml']: - manifest_path = f'/{MANIFESTDIR}/{fn}' - if os.path.exists(manifest_path): - break - else: - raise Exception(f"manifest not found: {args.manifest}") - - # A fix for https://issues.redhat.com/browse/RHEL-108989 - subprocess.check_call(['dnf', 'repolist'], stdout=subprocess.DEVNULL) - - rpmostree_argv = ['rpm-ostree', 'compose', 'rootfs'] - - override_manifest = {} - tmp_ostree_repo = None - if args.install: - additional_pkgs = [shlex.quote(p) for p in set(args.install)] - if len(additional_pkgs) > 0: - override_manifest['packages'] = list(additional_pkgs) - if args.exclude: - exclude_pkgs = [shlex.quote(p) for p in set(args.exclude)] - if len(exclude_pkgs) > 0: - override_manifest['exclude-packages'] = list(exclude_pkgs) - if args.add_dir: - tmp_ostree_repo = tempfile.mkdtemp(dir='/var/tmp') - subprocess.check_call(['ostree', 'init', '--repo', tmp_ostree_repo, '--mode=bare']) - rpmostree_argv.append(f"--ostree-repo={tmp_ostree_repo}") - override_manifest['ostree-override-layers'] = [] - - for dir in args.add_dir: - print(f"Processing --add-dir for {dir}") - base = os.path.basename(dir) - abs = os.path.realpath(dir) - if not os.path.exists(abs): - raise Exception(f"add dir directory not found: {abs}") - # capture output to hide commit digest printed - subprocess.check_output(['ostree', 'commit', '--repo', tmp_ostree_repo, '-b', f'overlay/{base}', abs, - '--owner-uid=0', '--owner-gid=0', '--no-xattrs', '--mode-ro-executables']) - override_manifest['ostree-override-layers'].append(f'overlay/{base}') - if args.no_docs: - override_manifest['documentation'] = False - if args.recommends: - override_manifest['recommends'] = True - if args.no_initramfs: - override_manifest['no-initramfs'] = True - if args.sysusers: - override_manifest['sysusers'] = 'compose-forced' - passwd_mode = 'nobody' if args.nobody_99 else 'none' - override_manifest['variables'] = {'passwd_mode': passwd_mode} - if args.repo: - override_manifest['repos'] = args.repo - - tmp_manifest = None - if override_manifest: - override_manifest['include'] = manifest_path - tmp_manifest = tempfile.NamedTemporaryFile(mode='w', encoding='utf-8', suffix='.json', delete=False) - json.dump(override_manifest, tmp_manifest) - tmp_manifest.close() - manifest_path = tmp_manifest.name - - tmp_lockfile = None - if args.lock: - lockfile = {'packages': {}} - for nevra in args.lock: - # we support passing either a NEVRA or a NEVR - name, ev, r_or_ra = nevra.rsplit('-', 2) - evr_or_evra = f'{ev}-{r_or_ra}' - field = 'evra' if r_or_ra.endswith(('.noarch', f'.{ARCH}')) else 'evr' - lockfile['packages'][name] = {field: evr_or_evra} - - tmp_lockfile = tempfile.NamedTemporaryFile(mode='w', encoding='utf-8', suffix='.json', delete=False) - json.dump(lockfile, tmp_lockfile) - tmp_lockfile.close() - rpmostree_argv.append(f"--lockfile={tmp_lockfile.name}") - - try: - if args.cachedir != "": - rpmostree_argv.append(f"--cachedir={args.cachedir}") - # Assume we can mutate alternative roots - if args.source_root != '/': - rpmostree_argv.append(f'--source-root-rw={args.source_root}') - else: - # But we shouldn't need to mutate the default root - rpmostree_argv.append('--source-root=/') - rpmostree_argv.extend([manifest_path, target]) - # Perform the build - subprocess.run(rpmostree_argv, check=True) - # Work around https://github.com/coreos/rpm-ostree/pull/5322 - root_mode = os.lstat(target).st_mode - if (root_mode & stat.S_IXOTH) == 0: - print("Updating rootfs mode") - os.chmod(target, root_mode | (0o555)) - # And run the bootc linter for good measure - subprocess.run([ - 'bootc', - 'container', - 'lint', - f'--rootfs={target}', - ], check=True) - except subprocess.CalledProcessError as e: - print(f"Error executing command: {e}") - sys.exit(1) - finally: - if tmp_lockfile is not None: - os.unlink(tmp_lockfile.name) - if tmp_manifest is not None: - os.unlink(tmp_manifest.name) - if tmp_ostree_repo: - shutil.rmtree(tmp_ostree_repo) - - # Copy our own build configuration into the target if configured; - # this is used for the first stage build. But by default *secondary* - # builds don't get this. - if args.reinject: - for d in [MANIFESTDIR]: - dst = path.join(target, d) - print(f"Copying /{d} to {dst}") - shutil.copytree('/' + d, dst, symlinks=True) - for f in ['usr/libexec/bootc-base-imagectl']: - dst = path.join(target, f) - print(f"Copying /{f} to {dst}") - shutil.copy('/' + f, dst) - -def run_rechunk(args): - if args.chunkah: - argv = ['chunkah', 'build', '--rootfs=/chunkah'] - if args.max_layers is not None: - argv.append(f"--max-layers={args.max_layers}") - # Strip OSTree data and labels for bootc compatibility; see - # https://github.com/coreos/chunkah#compatibility-with-bootable-bootc-images - argv.extend(['--prune', '/sysroot/', - '--label', 'ostree.commit-', - '--label', 'ostree.final-diffid-']) - try: - subprocess.run(argv, check=True) - except subprocess.CalledProcessError as e: - print(f"Error executing command: {e}", file=sys.stderr) - sys.exit(1) - else: - if not args.from_image or not args.to_image: - print("Error: from_image and to_image are required when not using --chunkah", file=sys.stderr) - sys.exit(1) - argv = [ - 'rpm-ostree', - 'experimental', - 'compose', - 'build-chunked-oci'] - if args.max_layers is not None: - argv.append(f"--max-layers={args.max_layers}") - argv.extend(['--bootc', - '--format-version=1', - f'--from={args.from_image}', - f'--output=containers-storage:{args.to_image}']) - try: - subprocess.run(argv, check=True) - except subprocess.CalledProcessError as e: - print(f"Error executing command: {e}") - sys.exit(1) - -def run_list(args): - d = '/' + MANIFESTDIR - for ent in sorted(os.listdir(d)): - name, ext = os.path.splitext(ent) - if ext != '.yaml' or name.endswith('.hidden'): - continue - fullpath = os.path.join(d, ent) - if os.path.islink(fullpath): - continue - o = subprocess.check_output(['rpm-ostree', 'compose', 'tree', '--print-only', fullpath]) - manifest = json.loads(o) - description = manifest['metadata']['summary'] - print(f"{name}: {description}") - print("---") - -if __name__ == "__main__": - parser = argparse.ArgumentParser(description="Operate on the build configuration for this container") - parser.add_argument("--args-file", help="File containing arguments to parse (one argument per line)", metavar='FILE') - subparsers = parser.add_subparsers(help='Subcommands', required=True) - - build_rootfs = subparsers.add_parser('build-rootfs', help='Generate a container root filesystem') - build_rootfs.add_argument("--reinject", help="Also reinject the build configurations into the target", action='store_true') - build_rootfs.add_argument("--manifest", help="Use the specified manifest", action='store', default='default') - build_rootfs.add_argument("--install", help="Add a package", action='append', default=[], metavar='PACKAGE') - build_rootfs.add_argument("--exclude", help="Exclude a package", action='append', default=[], metavar='PACKAGE') - build_rootfs.add_argument("--cachedir", help="Cache repo metadata and RPMs in specified directory", action='store', default='') - build_rootfs.add_argument("--add-dir", help='Copy dir contents into the target', action='append', default=[], metavar='DIR') - build_rootfs.add_argument("--no-docs", help="Don't install documentation", action='store_true') - build_rootfs.add_argument("--recommends", help="Whether to install recommended packages", action='store_true') - build_rootfs.add_argument("--no-initramfs", help="Whether to generate an initramfs for the roots", action='store_true') - build_rootfs.add_argument("--sysusers", help="Run systemd-sysusers instead of injecting hardcoded passwd/group entries", action='store_true') - build_rootfs.add_argument("--nobody-99", help=argparse.SUPPRESS, action='store_true') - build_rootfs.add_argument("--repo", help="Enable specific repositories only", action='append', default=[], metavar='REPO') - build_rootfs.add_argument("--lock", help="Lock package to specific version; can be NEVRA or NEVR", action='append', default=[], metavar='NEVRA') - build_rootfs.add_argument("source_root", help="Path to the source root directory used for dnf configuration (default=/)", nargs='?', default='/') - build_rootfs.add_argument("target", help="Path to the target root directory that will be generated.") - build_rootfs.set_defaults(func=run_build_rootfs) - - cmd_rechunk = subparsers.add_parser('rechunk', help="Generate a new container image with split, reproducible, chunked layers") - cmd_rechunk.add_argument("--chunkah", help="Use chunkah instead of rpm-ostree (reads rootfs from /chunkah, writes OCI archive to stdout)", action='store_true') - cmd_rechunk.add_argument("--max-layers", help="Configure the number of output layers") - cmd_rechunk.add_argument("from_image", help="Operate on this image in the container storage", nargs='?') - cmd_rechunk.add_argument("to_image", help="Output a new image to the container storage", nargs='?') - cmd_rechunk.set_defaults(func=run_rechunk) - - cmd_list = subparsers.add_parser('list', help='List available manifests') - cmd_list.set_defaults(func=run_list) - - args = parser.parse_args() - if args.args_file: - add_args = [] - with open(args.args_file) as f: - for line in f: - add_args += [line.strip()] - args = parser.parse_args(sys.argv[1:] + add_args) - - args.func(args) - diff --git a/bootc-base-imagectl.md b/bootc-base-imagectl.md deleted file mode 100644 index b98d01c..0000000 --- a/bootc-base-imagectl.md +++ /dev/null @@ -1,182 +0,0 @@ -# bootc-base-imagectl - -A core premise of the bootc model is that rich -control over Linux system customization can be accomplished -with a "default" container build: - -``` -FROM -RUN ... -``` - -As of recently, it is possible to e.g. swap the kernel -and other fundamental components as part of default derivation. - -However, some use cases want even more control - for example, -as an organization deploying a bootc system, I may want to ensure -the base image version carries a set of packages at -exactly specific versions (perhaps defined by a lockfile, -or an rpm-md repository). There are many tools which -manage snapshots of yum (rpm-md) repositories. - -There are currently issues where it won't quite work to e.g. -`dnf -y upgrade selinux-policy-targeted`. - -The `/usr/libexec/bootc-base-imagectl` tool which is -included in the base image is designed to enable building -a root filesystem in ostree-container format from a set -of RPMs controlled by the user. - -## Understanding the base image content - -Most, but not all content from the base image comes from RPMs. -There is some additional non-RPM content, as well as postprocessing -that operates on the filesystem root. At the current time the -implementation of the base image build uses `rpm-ostree`, -but this is considered an implementation detail subject to change. - -## Using bootc-base-imagectl build-rootfs - -The core operation is `bootc-base-imagectl build-rootfs`. - -This command takes just two arguments: - -- A "source root" which should have an `/etc/yum.repos.d` - that defines the input RPM content. This source root is also used - to control things like the `$releasever`. -- A path to the target root filesystem which will be generated as - a directory. The target should not already exist (but its parent must exist). - -### Implementation - -The current implementation uses `rpm-ostree` on a manifest (treefile) -embedded in the container image itself. These manifests are not intended -to be editable directly. - -To emphasize: the implementation of this command (especially the configuration -files that it reads) are subject to change. - -## Using bootc-base-imagectl rechunk - -This operation is strongly related to `build-rootfs` but is also orthogonal; -it can be used on a "regular" container build as well. - -This command assumes it will be run as a container image, and defaults -to wanting write access to the container storage. - -``` -podman run --rm --privileged -v /var/lib/containers:/var/lib/containers quay.io/fedora/fedora-bootc:rawhide \ - bootc-base-imagectl rechunk quay.io/exampleos/exampleos:build quay.io/exampleos/exampleos:latest -``` - -### Rationale - -When performing a complex container derivation, there are several issues: - -#### Replaced duplicate content - -When e.g. upgrading or replacing the kernel or other large packages -as part of a container build (without squashing all layers) then -the old replaced content will still be present. - -#### Removed content still present - -Similarly, `RUN dnf -y remove` etc. will still retain that removed -content in prior layers. - -#### Timestamp drift - -By default, many tools will use the current timestamp when writing -files. `rpm` will do this (unless `SOURCE_DATE_EPOCH` is set), and -other tools like `cp` and `curl` will as well. - -This means that every build of the image will produce a new -tar stream (with new timestamps) - that will get pushed to a registry -and downloaded by clients, even if the content didn't actually change. - -### What rechunk does: split reproducible chunked images - -The `bootc-base-imagectl rechunk` command fixes all of these issues -by taking an input container, operates on its final merged filesystem -tree (hence removed/overridden files are handled), and then splits it up -(currently based on the RPM database) into separate layers (tarballs). - -Further, because bootc uses OSTree today, and OSTree canonializes all timestamps -to zero on the client side, this tool does that at build time. - -### Using chunkah instead of rpm-ostree - -The `--chunkah` flag switches rechunk to use [chunkah] instead of -rpm-ostree for layer splitting. In this mode, chunkah reads the rootfs -from `/chunkah` (its default) and writes an OCI archive to stdout. -The `from_image` and `to_image` positional arguments are not used. -The `--max-layers` option is respected and passed through to chunkah. - -This mode automatically passes `--prune /sysroot/` to strip OSTree data -and `--label ostree.commit-` / `--label ostree.final-diffid-` to remove -OSTree-specific labels. In other words, this produces plain OCI bootc images -without any OSTree content. - -To rechunk an existing image using chunkah: - -``` -IMG=quay.io/exampleos/exampleos:latest -podman run --rm --mount=type=image,src=$IMG,dest=/chunkah \ - -e CHUNKAH_CONFIG_STR="$(podman inspect $IMG)" \ - quay.io/fedora/fedora-bootc:rawhide \ - /usr/libexec/bootc-base-imagectl rechunk --chunkah | podman load -``` - -The `CHUNKAH_CONFIG_STR` environment variable passes the original -image's metadata (labels, environment, command, etc.) to chunkah so -that it is retained in the rechunked output. - -[chunkah]: https://github.com/coreos/chunkah - -### Other options - -`bootc-base-imagectl list` will enumerate available configurations that -can be selected by passing `--manifest` to `build-rootfs`. - -### Implementation - -The default rechunking implementation also uses `rpm-ostree`. The `--chunkah` -mode uses [chunkah] instead, which is content-agnostic and not tied to -rpm-ostree. - -### Cross builds and the builder image - -The build tooling is designed to support "cross builds"; the -repository root could e.g. be CentOS Stream 10, while the -builder root is Fedora or RHEL, etc. - -In other words, one given base image can be used as a "builder" to produce another -using different RPMs. - -### Example: Generate a new image using CentOS Stream 10 content from RHEL - -FROM quay.io/centos/centos:stream10 as repos - -FROM registry.redhat.io/rhel10/rhel-bootc:10 as builder -RUN --mount=type=bind,from=repos,src=/,dst=/repos,rw /usr/libexec/bootc-base-imagectl build-rootfs --manifest=minimal /repos /target-rootfs - -# This container image uses the "artifact pattern"; it has some -# basic configuration we expect to apply to multiple container images. -FROM quay.io/exampleos/baseconfig@sha256:.... as baseconfig - -FROM scratch -COPY --from=builder /target-rootfs/ / -# Now we make other arbitrary changes. Copy our systemd units and -# other tweaks from the baseconfig container image. -COPY --from=baseconfig /usr/ /usr/ -RUN < /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF' - # We want a generic image; hostonly makes no sense as part of a server side build - hostonly=no - # Dracut will always fail to set security.selinux xattrs at build time - # https://github.com/dracut-ng/dracut-ng/issues/1561 - export DRACUT_NO_XATTR=1 - add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree bootc " - EOF - cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF' - # Extra modules that we want by default that are known to exist in the kernel - add_dracutmodules+=" virtiofs " - EOF - cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF' - # We want this for systemd-cryptsetup tpm2 locking - add_dracutmodules+=" tpm2-tss " - EOF - cat > /usr/lib/dracut/dracut.conf.d/59-altfiles.conf << 'EOF' - # https://issues.redhat.com/browse/RHEL-49590 - # On image mode systems we use nss-altfiles for passwd and group, - # this makes sure dracut uses them which also fixes kdump writing to NFS. - install_items+=" /usr/lib/passwd /usr/lib/group " - EOF diff --git a/minimal/kernel-install.yaml b/minimal/kernel-install.yaml deleted file mode 100644 index 2df40d6..0000000 --- a/minimal/kernel-install.yaml +++ /dev/null @@ -1,26 +0,0 @@ -# Configuration to enable kernel-install integration -postprocess: - - | - #!/usr/bin/env bash - set -xeuo pipefail - source /usr/lib/os-release - mkdir -p /usr/lib/kernel/install.conf.d - echo -e "# kernel-install will not try to run dracut and allow rpm-ostree to\n\ - # take over. Rpm-ostree will use this to know that it is responsible\n\ - # to run dracut and ensure that there is only one kernel in the image\n\ - layout=ostree" | tee /usr/lib/kernel/install.conf /usr/lib/kernel/install.conf.d/00-bootc-kernel-layout.conf > /dev/null - # By default dnf keeps multiple versions of the kernel, with this - # configuration we tell dnf to treat the kernel as everything else. - # https://dnf.readthedocs.io/en/latest/conf_ref.html#main-options - # Let's add the config to a distribution configuration file if dnf5 - # is used, we append to /etc/dnf/dnf.conf if not. - # Also set protect_running_kernel=False, dnf/yum pre-dates Containers and - # uses uname to protect the running kernel even on Container builds. - if [ -d "/usr/share/dnf5/libdnf.conf.d/" ]; then - echo -e "[main]\ninstallonlypkgs=''" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-installonlypkgs.conf - echo -e "[main]\nprotect_running_kernel=False" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-protect_running_kernel.conf - else - echo "installonlypkgs=''" >> /etc/dnf/dnf.conf - echo "protect_running_kernel=False" >> /etc/dnf/dnf.conf - fi - diff --git a/minimal/kernel.yaml b/minimal/kernel.yaml deleted file mode 100644 index 8921348..0000000 --- a/minimal/kernel.yaml +++ /dev/null @@ -1,12 +0,0 @@ -# Enable the Linux kernel; see also kernel-rt. -packages: - - kernel - -exclude-packages: - - kernel-debug - - kernel-debug-core - - kernel-debug-modules - - kernel-debug-modules-core - - kernel-debug-modules-extra - - kernel-debug-uki-virt - - kernel-debug-uki-virt-addons diff --git a/minimal/manifest.yaml b/minimal/manifest.yaml deleted file mode 100644 index 443353e..0000000 --- a/minimal/manifest.yaml +++ /dev/null @@ -1,45 +0,0 @@ -metadata: - summary: Effectively just bootc, systemd, kernel, and dnf as a starting point. - -edition: "2024" - -variables: - passwd_mode: full - -# Be minimal -recommends: false - -# Default to `bash` in our container, the same as other containers we ship. -container-cmd: - - /sbin/init - -remove-from-packages: - # Generally we expect other tools to do this (e.g. Ignition or cloud-init) - - [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service] - -include: - - kernel.yaml - - postprocess-conf.yaml - - tmpfiles.yaml - - bootc.yaml - - bootupd.yaml - - ostree.yaml - - initramfs.yaml - - basic-fixes.yaml - - kernel-install.yaml - - systemd-presets.yaml - -packages: - # this is implied by dependencies but let's make it explicit - - coreutils - # We need dnf for building derived container images. In Fedora, this pulls - # in dnf5. In CentOS/RHEL, this pulls in dnf(4). We can simplify this back to - # just `dnf` once the `dnf` package is retired from Fedora. - - /usr/bin/dnf - # Even in minimal, we have this. If you don't want SELinux today, you'll need - # to build a custom image. - - selinux-policy-targeted - # And we want container-selinux because trying to layer it on later currently causes issues. - - container-selinux - # Needed for tpm2 bound luks - - tpm2-tools diff --git a/minimal/passwd-nobody b/minimal/passwd-nobody deleted file mode 100644 index 44d2866..0000000 --- a/minimal/passwd-nobody +++ /dev/null @@ -1,4 +0,0 @@ -# this is used with the --nobody-99 option for backwards compatibility with -# systems that had nobody set to 99 -nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin -nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin diff --git a/minimal/postprocess-conf.yaml b/minimal/postprocess-conf.yaml deleted file mode 100644 index 75762ad..0000000 --- a/minimal/postprocess-conf.yaml +++ /dev/null @@ -1,38 +0,0 @@ -# This file configures things relevant to `rpm-ostree compose postprocess`. - -# We want content lifecycled with the image -opt-usrlocal: "root" - -# https://github.com/CentOS/centos-bootc/issues/167 -machineid-compat: true - -rpmdb: target -# We never want rpmdb.sqlite-shm as it's unreproducible -rpmdb-normalize: true - -ignore-removed-users: - - root -ignore-removed-groups: - - root -# By default users and groups are injected to nss-altfiles -# which is immutable. This list moves a selected set -# to /etc/group instead, which is mutable per system -# and allows local users to become part of these groups. -etc-group-members: - - wheel - - systemd-journal - - tss # https://issues.redhat.com/browse/BIFROST-618 - - kvm # https://issues.redhat.com/browse/RHEL-115278 - - adm - -conditional-include: - - if: passwd_mode == "full" - include: check-passwd.yaml - - if: passwd_mode == "nobody" - include: check-passwd-nobody.yaml - - if: passwd_mode == "none" - include: - check-passwd: - type: "none" - check-groups: - type: "none" diff --git a/minimal/systemd-presets.yaml b/minimal/systemd-presets.yaml deleted file mode 100644 index 6bedd4f..0000000 --- a/minimal/systemd-presets.yaml +++ /dev/null @@ -1,43 +0,0 @@ -# Postprocessing relating to systemd presets on the system. -postprocess: - - | - #!/bin/bash - set -xeuo pipefail - # Override some of the default presets. - cat < usr/lib/systemd/system-preset/85-bootc.preset - # Disable dnf-makecache.timer on bootc/image mode systems - # https://github.com/coreos/fedora-coreos-tracker/issues/1896#issuecomment-2848251507 - disable dnf-makecache.timer - EOF - # Enable bootloader-update.service on F43+ and CentOS9+ - # https://github.com/coreos/fedora-coreos-tracker/issues/1468#issuecomment-2996654547 - # https://fedoraproject.org/wiki/Changes/AutomaticBootloaderUpdatesBootc - - | - #!/bin/bash - set -xeuo pipefail - source /usr/lib/os-release - - preset_file_name=/usr/lib/systemd/system-preset/85-bootc-bootloader-update.preset - - case "$ID" in - fedora) - if [ "$VERSION_ID" -ge 43 ]; then - echo "enable bootloader-update.service" >> "$preset_file_name" - fi - ;; - centos) - if [ "$VERSION_ID" -ge 9 ]; then - echo "enable bootloader-update.service" >> "$preset_file_name" - fi - ;; - *) ;; - esac - # Undo RPM scripts enabling units; we want the presets to be canonical - # https://github.com/projectatomic/rpm-ostree/issues/1803 - - | - #!/bin/bash - set -xeuo pipefail - rm -rf /etc/systemd/system/* - systemctl preset-all - rm -rf /etc/systemd/user/* - systemctl --user --global preset-all diff --git a/minimal/tmpfiles.yaml b/minimal/tmpfiles.yaml deleted file mode 100644 index e9846cb..0000000 --- a/minimal/tmpfiles.yaml +++ /dev/null @@ -1,18 +0,0 @@ -postprocess: - - | - #!/bin/bash - set -xeuo pipefail - cat >/usr/lib/tmpfiles.d/bootc-base-rpmstate.conf <<'EOF' - # Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=771713 - d /var/lib/rpm-state 0755 - - - - EOF - cat > /usr/lib/tmpfiles.d/konflux-buildinfo-contentsets.conf <<'EOF' - # Workaround for https://github.com/konflux-ci/build-tasks-dockerfiles/pull/243 - d /var/roothome/buildinfo 0755 - - - - d /var/roothome/buildinfo/content_manifests 0755 - - - - # Note we don't actually try to recreate the content; this just makes the linter ignore it - f /var/roothome/buildinfo/content_manifests/content-sets.json 0644 - - - - f /var/roothome/buildinfo/labels.json 0644 - - - - EOF - # Workaround for https://issues.redhat.com/browse/RHEL-106203 - rm -f /usr/lib/tmpfiles.d/home.conf diff --git a/renovate.json b/renovate.json index 50ab8d0..580a55f 100644 --- a/renovate.json +++ b/renovate.json @@ -1,203 +1,12 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "description": [ - "Renovate configuration for bootc-base-image repository.", - "", - "This configuration separates updates into different PRs per release (e.g., Fedora 44, Rawhide)", - "to prevent blocking all releases if tests fail on one.", - "", - "Update schedules:", - "- Fedora 43 bootc-pipeline: 2-5 AM UTC daily", - "- Fedora 43 REPOS_IMAGE: at any time", - "- Fedora 44 bootc-pipeline: 2-5 AM UTC daily", - "- Fedora 44 REPOS_IMAGE: at any time", - "- Fedora 45 bootc-pipeline: 2-5 AM UTC daily", - "- Fedora 45 REPOS_IMAGE: at any time", - "- Rawhide bootc-pipeline: 2-5 AM UTC daily", - "- Rawhide REPOS_IMAGE: at any time", - "", - "Each update type (bootc-pipeline, REPOS_IMAGE) also has its own PR", - "for independent review and merge.", - "", - "rebaseWhen is set to 'never' for REPOS_IMAGE PRs because as different PRs", - "for each release are merged to main, automatic rebasing would reset pipelines", - "and cause tests to rerun multiple times. The operator can manually rebase if needed.", - "", - "Automerge is enabled for all PRs - they will be merged automatically when all checks pass." - ], "extends": [ "github>platform-engineering-org/.github" ], - "dependencyDashboard": true, - "automergeType": "pr", - "enabledManagers": [ - "custom.regex", - "tekton" - ], - "tekton": { - "additionalBranchPrefix": "", - "includePaths": [ - ".tekton/**" - ], - "managerFilePatterns": [ - "/\\.ya?ml$/" - ] - }, - "baseBranchPatterns": [ - "main" - ], - "customManagers": [ - { - "customType": "regex", - "description": [ - "Update 'REPOS_IMAGE' in tekton files" - ], - "managerFilePatterns": [ - "/.tekton/.*\\.ya?ml$/" - ], - "matchStrings": [ - "REPOS_IMAGE=(?.*):(?.*)@(?.*)\\n" - ], - "versioningTemplate": "regex:(?.*)-(?\\d{8})(\\.n)?\\.(?\\d)", - "datasourceTemplate": "docker" - } - ], "packageRules": [ { - "description": [ - "Disable REPOS_IMAGE updates for 44-iot, 45-iot and rawhide-iot tekton files", - "until we fix https://gitlab.com/fedora/bootc/base-images/-/issues/74" - ], - "matchManagers": ["custom.regex", "tekton"], - "matchFileNames": [".tekton/*-44-iot-*", ".tekton/*-45-iot-*", ".tekton/*-rawhide-iot-*"], - "enabled": false - }, - { - "matchManagers": ["tekton"], - "matchPackageNames": ["/quay.io/bootc-devel/tekton-catalog/"], - "matchFileNames": [".tekton/fedora-bootc-43-*"], - "groupName": "Fedora 43 bootc-pipeline", - "groupSlug": "fedora-43-bootc-pipeline", - "branchPrefix": "renovate/fedora-43/", - "commitMessageTopic": "Fedora 43 bootc build pipeline", - "schedule": ["after 2am and before 5am"], - "timezone": "UTC", - "recreateWhen": "always", - "rebaseWhen": "always", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["custom.regex"], - "matchPackageNames": ["/quay.io/bootc-devel/fedora-bootc-43-compose/"], - "matchFileNames": [".tekton/fedora-bootc-43-*"], - "groupName": "Fedora 43 REPOS_IMAGE", - "groupSlug": "fedora-43-repos-image", - "branchPrefix": "renovate/fedora-43/", - "commitMessageTopic": "Fedora 43 REPOS_IMAGE", - "schedule": ["at any time"], - "recreateWhen": "always", - "rebaseWhen": "never", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["tekton"], - "matchPackageNames": ["/quay.io/bootc-devel/tekton-catalog/"], - "matchFileNames": [".tekton/fedora-bootc-44-*"], - "groupName": "Fedora 44 bootc-pipeline", - "groupSlug": "fedora-44-bootc-pipeline", - "branchPrefix": "renovate/fedora-44/", - "commitMessageTopic": "Fedora 44 bootc build pipeline", - "schedule": ["after 2am and before 5am"], - "timezone": "UTC", - "recreateWhen": "always", - "rebaseWhen": "always", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["custom.regex"], - "matchPackageNames": ["/quay.io/bootc-devel/fedora-bootc-44-compose/"], - "matchFileNames": [".tekton/fedora-bootc-44-*"], - "groupName": "Fedora 44 REPOS_IMAGE", - "groupSlug": "fedora-44-repos-image", - "branchPrefix": "renovate/fedora-44/", - "commitMessageTopic": "Fedora 44 REPOS_IMAGE", - "schedule": ["at any time"], - "recreateWhen": "always", - "rebaseWhen": "never", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["tekton"], - "matchPackageNames": ["/quay.io/bootc-devel/tekton-catalog/"], - "matchFileNames": [".tekton/fedora-bootc-45-*"], - "groupName": "Fedora 45 bootc-pipeline", - "groupSlug": "fedora-45-bootc-pipeline", - "branchPrefix": "renovate/fedora-45/", - "commitMessageTopic": "Fedora 45 bootc build pipeline", - "schedule": ["after 2am and before 5am"], - "timezone": "UTC", - "recreateWhen": "always", - "rebaseWhen": "always", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["custom.regex"], - "matchPackageNames": ["/quay.io/bootc-devel/fedora-bootc-45-compose/"], - "matchFileNames": [".tekton/fedora-bootc-45-*"], - "groupName": "Fedora 45 REPOS_IMAGE", - "groupSlug": "fedora-45-repos-image", - "branchPrefix": "renovate/fedora-45/", - "commitMessageTopic": "Fedora 45 REPOS_IMAGE", - "schedule": ["at any time"], - "recreateWhen": "always", - "rebaseWhen": "never", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["tekton"], - "matchPackageNames": ["/quay.io/bootc-devel/tekton-catalog/"], - "matchFileNames": [".tekton/fedora-bootc-rawhide-*"], - "groupName": "Fedora Rawhide bootc-pipeline", - "groupSlug": "fedora-rawhide-bootc-pipeline", - "branchPrefix": "renovate/fedora-rawhide/", - "commitMessageTopic": "Fedora Rawhide bootc build pipeline", - "schedule": ["after 2am and before 5am"], - "timezone": "UTC", - "recreateWhen": "always", - "rebaseWhen": "always", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchManagers": ["custom.regex"], - "matchPackageNames": ["/quay.io/bootc-devel/fedora-bootc-rawhide-compose/"], - "matchFileNames": [".tekton/fedora-bootc-rawhide-*"], - "groupName": "Fedora Rawhide REPOS_IMAGE", - "groupSlug": "fedora-rawhide-repos-image", - "branchPrefix": "renovate/fedora-rawhide/", - "commitMessageTopic": "Fedora Rawhide REPOS_IMAGE", - "schedule": ["at any time"], - "recreateWhen": "always", - "rebaseWhen": "never", - "additionalBranchPrefix": "", - "automerge": true - }, - { - "matchPackageNames": [ - "/quay.io/bootc-devel/fedora-bootc-eln-compose/" - ], - "groupName": "Fedora ELN compose dependencies", - "groupSlug": "fedora-eln-compose-dependencies", - "schedule": [ - "at any time" - ], - "automerge": true + "matchPackageNames": ["quay.io/fedora/fedora"], + "allowedVersions": "=40" } ] } diff --git a/standard.yaml b/standard.yaml deleted file mode 100644 index debffcd..0000000 --- a/standard.yaml +++ /dev/null @@ -1,11 +0,0 @@ -include: - - fedora-includes/generic.yaml - - standard/manifest.yaml - -packages: - # Make Ansible "package" builtin work by default - - python3-libdnf5 - # Content-based container layer splitting for rechunking - # Note we should be able to move this back to the base standard/manifest.yaml - # once chunkah is in CentOS Stream and RHEL. - - chunkah diff --git a/standard/coreos-user-experience.yaml b/standard/coreos-user-experience.yaml deleted file mode 100644 index 1ca6463..0000000 --- a/standard/coreos-user-experience.yaml +++ /dev/null @@ -1,24 +0,0 @@ -# This file was forked/copied from Fedora CoreOS. TODO: resync -# once we have a good generic mechanism for sharing. -packages: - # Additional file compression/decompression - - bzip2 zstd - # Improved MOTD experience - - console-login-helper-messages-issuegen - - console-login-helper-messages-profile - # kdump support - # https://github.com/coreos/fedora-coreos-tracker/issues/622 - # The makedumpfile and kdump-utils RPMs were broken out in - # Fedora and EL10+. To be able to use the same package list - # Across EL9 + Fedora + EL10 let's just name paths for now. - # We can go back to just specifying the RPM names when we - # no longer support EL9. - - kexec-tools - - /usr/share/makedumpfile # makedumpfile RPM - - /usr/bin/kdumpctl # kdump-utils RPM - # Container tooling - - toolbox - # nvme-cli for managing nvme disks - - nvme-cli - # Used by admins interactively - - lsof diff --git a/standard/initramfs-full.yaml b/standard/initramfs-full.yaml deleted file mode 100644 index cc9179d..0000000 --- a/standard/initramfs-full.yaml +++ /dev/null @@ -1,20 +0,0 @@ -# Configuration for the initramfs -postprocess: - - | - #!/usr/bin/env bash - set -xeuo pipefail - mkdir -p /usr/lib/dracut/dracut.conf.d - cat > /usr/lib/dracut/dracut.conf.d/30-bootc-standard.conf << 'EOF' - add_dracutmodules+=" lvm crypt fips " - EOF - # Clevis in initramfs for LUKS auto-unlock. - # clevis-pin-tpm2 is only on x86_64/aarch64 (TPM2 hardware arches). - if test -x /usr/bin/clevis-pin-tpm2; then - cat > /usr/lib/dracut/dracut.conf.d/50-bootc-clevis.conf << 'EOF' - add_dracutmodules+=" clevis clevis-pin-tpm2 " - EOF - else - cat > /usr/lib/dracut/dracut.conf.d/50-bootc-clevis.conf << 'EOF' - add_dracutmodules+=" clevis " - EOF - fi diff --git a/tests/Containerfile.test-derive b/tests/Containerfile.test-derive deleted file mode 100644 index 72864ff..0000000 --- a/tests/Containerfile.test-derive +++ /dev/null @@ -1,34 +0,0 @@ -# This test case exercises using the fedora-bootc image as a builder to -# generate a minimal target image, and then further extends it in a secondary -# phase. - -# This is intentionally a locally built image -FROM localhost/fedora-bootc as builder -RUN < args.txt -/usr/libexec/bootc-base-imagectl --args-file args.txt build-rootfs --manifest=standard/manifest /target-rootfs -EORUN - -# This pulls in the rootfs generated in the previous step -FROM scratch -COPY --from=builder /target-rootfs/ / -RUN < overlay/usr/lib/sysusers.d/00-chrony.conf </dev/null - # and these need to be directly in /etc - grep -q $grp /etc/group -done diff --git a/tests/rootfs/cases/fedora-only b/tests/rootfs/cases/fedora-only deleted file mode 100755 index d44148c..0000000 --- a/tests/rootfs/cases/fedora-only +++ /dev/null @@ -1,13 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -. /usr/lib/os-release -case "${ID}" in - fedora) - # https://gitlab.com/fedora/bootc/base-images/-/merge_requests/172 - if rpm -q python3 &>/dev/null; then - rpm -q python3-libdnf5 - fi - ;; - *) - ;; -esac diff --git a/tests/rootfs/cases/no-iptables-legacy b/tests/rootfs/cases/no-iptables-legacy deleted file mode 100755 index 0100c5d..0000000 --- a/tests/rootfs/cases/no-iptables-legacy +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -output=$(rpm -q iptables-legacy || true) -grep "is not installed" <<< "$output" diff --git a/tests/rootfs/cases/root-mode b/tests/rootfs/cases/root-mode deleted file mode 100755 index 475f3ef..0000000 --- a/tests/rootfs/cases/root-mode +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -# Verify we didn't lose the executable bit for others on / -test $(($(stat -c '0%a' .) % 2)) = 1 diff --git a/tests/rootfs/cases/rpmdb b/tests/rootfs/cases/rpmdb deleted file mode 100755 index 34f9c1d..0000000 --- a/tests/rootfs/cases/rpmdb +++ /dev/null @@ -1,7 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -for d in usr/share/rpm usr/lib/sysimage/rpm; do - if test -d "$d"; then - test '!' -f "$d/rpmdb.sqlite-shm" - fi -done diff --git a/tests/rootfs/cases/tmpfiles-konflux-buildinfo b/tests/rootfs/cases/tmpfiles-konflux-buildinfo deleted file mode 100755 index e03a3b6..0000000 --- a/tests/rootfs/cases/tmpfiles-konflux-buildinfo +++ /dev/null @@ -1,18 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -# Verify our custom tmpfiles.d configs by actually running systemd-tmpfiles -# against a temporary root and checking the expected paths are created. -# Workaround for https://github.com/konflux-ci/build-tasks-dockerfiles/pull/243 - -tmproot=$(mktemp -d) -trap 'rm -rf "${tmproot}"' EXIT - -systemd-tmpfiles --create --root="${tmproot}" \ - /usr/lib/tmpfiles.d/bootc-base-rpmstate.conf \ - /usr/lib/tmpfiles.d/konflux-buildinfo-contentsets.conf - -test -d "${tmproot}/var/lib/rpm-state" -test -d "${tmproot}/var/roothome/buildinfo" -test -d "${tmproot}/var/roothome/buildinfo/content_manifests" -test -f "${tmproot}/var/roothome/buildinfo/content_manifests/content-sets.json" -test -f "${tmproot}/var/roothome/buildinfo/labels.json" diff --git a/tests/rootfs/cases/var b/tests/rootfs/cases/var deleted file mode 100755 index 7c87d32..0000000 --- a/tests/rootfs/cases/var +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/bash -set -xeuo pipefail -# Verify directories we expect to exist -test -d var/tmp diff --git a/tests/rootfs/run b/tests/rootfs/run deleted file mode 100755 index a372861..0000000 --- a/tests/rootfs/run +++ /dev/null @@ -1,13 +0,0 @@ -#!/bin/bash -set -euo pipefail -srcdir=$(cd $(dirname $0) && pwd) -rootfs=$1 -shift -cd $rootfs -for case in ${srcdir}/cases/*; do - if test -x "$case"; then - echo "Running $case" - $case - echo "ok $case" - fi -done diff --git a/standard/autoupdates.yaml b/tier-0/autoupdates.yaml similarity index 86% rename from standard/autoupdates.yaml rename to tier-0/autoupdates.yaml index 04b35f3..a416699 100644 --- a/standard/autoupdates.yaml +++ b/tier-0/autoupdates.yaml @@ -2,7 +2,8 @@ postprocess: - | #!/usr/bin/env bash - set -xeuo pipefail + set -euo pipefail target=/usr/lib/systemd/system/default.target.wants mkdir -p $target + set -x ln -s ../bootc-fetch-apply-updates.timer $target diff --git a/minimal/basic-fixes.yaml b/tier-0/basic-fixes.yaml similarity index 70% rename from minimal/basic-fixes.yaml rename to tier-0/basic-fixes.yaml index c636e8c..d9fe059 100644 --- a/minimal/basic-fixes.yaml +++ b/tier-0/basic-fixes.yaml @@ -23,13 +23,7 @@ postprocess: # tmpfiles.d unit for `/var/roothome` is fine, but this actually doesn't # work if we want to use tmpfiles.d to write to `/root/.ssh` because # tmpfiles gives up on that before getting to `/var/roothome`. - # - # Redirect stdout to /dev/null because of some weird stdout issue - # with newer rpm-ostree: https://github.com/coreos/rpm-ostree/pull/5388#issuecomment-2971623787 - sed -i -e 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf > /dev/null + sed -ie 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf # Because /var/roothome is also defined in rpm-ostree-0-integration.conf # we need to delete /var/roothome - # - # Redirect stdout to /dev/null because of some weird stdout issue - # with newer rpm-ostree: https://github.com/coreos/rpm-ostree/pull/5388#issuecomment-2971623787 - sed -i -e '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf > /dev/null + sed -ie '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf diff --git a/tier-0/bootc-config.yaml b/tier-0/bootc-config.yaml new file mode 100644 index 0000000..e69de29 diff --git a/tier-0/bootc.yaml b/tier-0/bootc.yaml new file mode 100644 index 0000000..a862e6c --- /dev/null +++ b/tier-0/bootc.yaml @@ -0,0 +1,12 @@ +# The bootc components. +packages: + - systemd + - bootc + # Required by bootc install today, though we'll likely switch bootc to use a Rust crate instead of sgdisk + - gdisk xfsprogs e2fsprogs dosfstools + +exclude-packages: + # Exclude kernel-debug-core to make sure that it doesn't somehow get + # chosen as the package to satisfy the `kernel-core` dependency from + # the kernel package. + - kernel-debug-core diff --git a/minimal/bootupd.yaml b/tier-0/bootupd.yaml similarity index 53% rename from minimal/bootupd.yaml rename to tier-0/bootupd.yaml index 2932317..7d3ebf3 100644 --- a/minimal/bootupd.yaml +++ b/tier-0/bootupd.yaml @@ -8,17 +8,10 @@ packages-aarch64: - grub2-efi-aa64 efibootmgr shim packages-ppc64le: - grub2 ostree-grub2 -packages-riscv64: - - grub2-efi-riscv64 efibootmgr - # Don't specify just `shim` for now because riscv isn't built in - # main koji instance yet and thus isn't signed. Here we specify - # the path to the provided file so when we do switch to the signed - # `shim` package it will transparently happen and we can clean up - # this packagelist entry later. - - /boot/efi/EFI/fedora/shimriscv64.efi packages-s390x: - # For zipl - - s390utils-core + # On Fedora, this is provided by s390utils-core. on RHEL, this is for now + # provided by s390utils-base, but soon will be -core too. + - /usr/sbin/zipl packages-x86_64: - grub2 grub2-efi-x64 efibootmgr shim - microcode_ctl @@ -32,10 +25,7 @@ postprocess: - | #!/bin/bash set -xeuo pipefail + # Until we have https://github.com/coreos/rpm-ostree/pull/2275 + mkdir -p /run # Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload /usr/bin/bootupctl backend generate-update-metadata - - | - #!/bin/bash - # Workaround for https://issues.redhat.com/browse/RHEL-78104 - set -xeuo pipefail - rm -vrf /usr/lib/ostree-boot/loader diff --git a/minimal/group b/tier-0/group similarity index 90% rename from minimal/group rename to tier-0/group index 5d5326c..2fd197c 100644 --- a/minimal/group +++ b/tier-0/group @@ -1,5 +1,3 @@ -# keep sorted by GID (e.g. pass through `sort -t: --key 3 -g`) - root:x:0: bin:x:1: daemon:x:2: @@ -14,34 +12,35 @@ wheel:x:10: cdrom:x:11: mail:x:12: man:x:15: +sudo:x:16: dialout:x:18: floppy:x:19: games:x:20: -rpcuser:x:29: tape:x:33: video:x:39: -dip:x:40: ftp:x:50: lock:x:54: audio:x:63: -tcpdump:x:72: nobody:x:99: users:x:100: -input:x:104: -ceph:x:167: -avahi-autoipd:x:170: -systemd-journal:x:190: -dockerroot:x:986: -cockpit-ws:x:987: -systemd-bus-proxy:x:988: -systemd-resolve:x:989: -systemd-network:x:990: -systemd-timesync:x:991: -chrony:x:992: -sssd:x:993: -kube:x:994: -cgred:x:996: -etcd:x:997: -polkitd:x:998: ssh_keys:x:999: +systemd-journal:x:190: +polkitd:x:998: +etcd:x:997: +dip:x:40: +cgred:x:996: +avahi-autoipd:x:170: +sssd:x:993: +dockerroot:x:986: +rpcuser:x:29: nfsnobody:x:65534: +kube:x:994: +chrony:x:992: +tcpdump:x:72: +ceph:x:167: +input:x:104: +systemd-timesync:x:991: +systemd-network:x:990: +systemd-resolve:x:989: +systemd-bus-proxy:x:988: +cockpit-ws:x:987: diff --git a/minimal/grub2-removals.yaml b/tier-0/grub2-removals.yaml similarity index 100% rename from minimal/grub2-removals.yaml rename to tier-0/grub2-removals.yaml diff --git a/tier-0/initramfs.yaml b/tier-0/initramfs.yaml new file mode 100644 index 0000000..de65333 --- /dev/null +++ b/tier-0/initramfs.yaml @@ -0,0 +1,18 @@ +# Configuration for the initramfs +postprocess: + - | + #!/usr/bin/env bash + mkdir -p /usr/lib/dracut/dracut.conf.d + cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF' + # We want a generic image; hostonly makes no sense as part of a server side build + hostonly=no + dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree " + EOF + cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF' + # Extra modules that we want by default that are known to exist in the kernel + dracutmodules+=" virtiofs " + EOF + cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF' + # We want this for systemd-cryptsetup tpm2 locking + dracutmodules+=" tpm2-tss " + EOF diff --git a/tier-0/kernel-rt.yaml b/tier-0/kernel-rt.yaml new file mode 100644 index 0000000..cdcff10 --- /dev/null +++ b/tier-0/kernel-rt.yaml @@ -0,0 +1,10 @@ +repos: + - rt + - nfv + +# Enable the "realtime" AKA soft-realtime AKA latency-optimized kernel. +packages: + - kernel-rt-core kernel-rt-modules kernel-rt-modules-extra kernel-rt-kvm + +exclude-packages: + - kernel-rt-debug-core diff --git a/tier-0/kernel.yaml b/tier-0/kernel.yaml new file mode 100644 index 0000000..0dd777d --- /dev/null +++ b/tier-0/kernel.yaml @@ -0,0 +1,6 @@ +# Enable the Linux kernel; see also kernel-rt. +packages: + - kernel + +exclude-packages: + - kernel-debug diff --git a/tier-0/manifest.yaml b/tier-0/manifest.yaml new file mode 100644 index 0000000..117b144 --- /dev/null +++ b/tier-0/manifest.yaml @@ -0,0 +1,72 @@ + +# Modern defaults we want +boot-location: modules +tmp-is-dir: true +# https://github.com/CentOS/centos-bootc/issues/167 +machineid-compat: true +# Be minimal +recommends: false + +ignore-removed-users: + - root +ignore-removed-groups: + - root +etc-group-members: + - wheel + - sudo + - systemd-journal + - adm + +# Default to `bash` in our container, the same as other containers we ship. +container-cmd: + - /sbin/init + +# Note that the default for c9s+ is sqlite; we can't rely on rpm being +# in the target (it isn't in tier-0!) so turn this to host here. This +# does break the "hermetic build" aspect a bit. Maybe eventually +# what we should do is special case this and actually install RPM temporarily +# and then remove it... +rpmdb: host + +check-passwd: + type: "file" + filename: "passwd" +check-groups: + type: "file" + filename: "group" + +automatic-version-prefix: "${releasever}." +mutate-os-release: "${releasever}" + +remove-from-packages: + # Generally we expect other tools to do this (e.g. Ignition or cloud-init) + - [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service] + # We don't want auto-generated mount units. See also + # https://github.com/systemd/systemd/issues/13099 + - [systemd-udev, /usr/lib/systemd/system-generators/systemd-gpt-auto-generator] + # Drop some buggy sysusers fragments which do not match static IDs allocation: + # https://bugzilla.redhat.com/show_bug.cgi?id=2105177 + - [dbus-common, /usr/lib/sysusers.d/dbus.conf] + +include: + - bootc.yaml + - ostree.yaml + - initramfs.yaml + - autoupdates.yaml + - basic-fixes.yaml + +packages: + # needed for building derived container images + - dnf + # Even in tier-0, we have this. If you don't want SELinux today, you'll need + # to build a custom image. + - selinux-policy-targeted + # And we want container-selinux because trying to layer it on later currently causes issues. + - container-selinux + # Needed for tpm2 bound luks + - tpm2-tools + +# See https://github.com/coreos/bootupd +arch-include: + x86_64: bootupd.yaml + aarch64: bootupd.yaml diff --git a/minimal/ostree.yaml b/tier-0/ostree.yaml similarity index 80% rename from minimal/ostree.yaml rename to tier-0/ostree.yaml index 99e256e..6f30861 100644 --- a/minimal/ostree.yaml +++ b/tier-0/ostree.yaml @@ -1,11 +1,13 @@ packages: - ostree nss-altfiles +# We want content lifecycled with the image +opt-usrlocal: "root" + postprocess: # Set up default root config - | #!/usr/bin/env bash - set -xeuo pipefail mkdir -p /usr/lib/ostree cat > /usr/lib/ostree/prepare-root.conf << EOF [composefs] diff --git a/minimal/passwd b/tier-0/passwd similarity index 93% rename from minimal/passwd rename to tier-0/passwd index bf8fc7c..ea84802 100644 --- a/minimal/passwd +++ b/tier-0/passwd @@ -1,34 +1,32 @@ -# keep sorted by UID (e.g. pass through `sort -t: --key 3 -g`) - -root:x:0:0:Super User:/root:/bin/bash -bin:x:1:1:bin:/bin:/usr/sbin/nologin -daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin adm:x:3:4:adm:/var/adm:/usr/sbin/nologin -lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin -sync:x:5:0:sync:/sbin:/bin/sync -shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown -halt:x:7:0:halt:/sbin:/sbin/halt -mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin -operator:x:11:0:operator:/root:/usr/sbin/nologin -games:x:12:100:games:/usr/games:/usr/sbin/nologin -ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin -rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin -rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin -tcpdump:x:72:72::/:/usr/sbin/nologin -sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin -dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin -nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin -ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin -cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin -systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin -systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin -systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin -systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin +bin:x:1:1:bin:/bin:/usr/sbin/nologin +ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin -sssd:x:995:993:User for sssd:/run/sssd:/usr/sbin/nologin -kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin +cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin +daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin +dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin -polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin +ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin +games:x:12:100:games:/usr/games:/usr/sbin/nologin +halt:x:7:0:halt:/sbin:/sbin/halt +kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin +lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin +mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin +nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin +operator:x:11:0:operator:/root:/usr/sbin/nologin +polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin +root:x:0:0:Super User:/root:/bin/bash +rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin +rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin +shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown +sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin +sssd:x:995:993:User for sssd:/:/usr/sbin/nologin +sync:x:5:0:sync:/sbin:/bin/sync +systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin +systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin +systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin +systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin +tcpdump:x:72:72::/:/usr/sbin/nologin diff --git a/tier-1/autoupdates.yaml b/tier-1/autoupdates.yaml new file mode 120000 index 0000000..9c9cbd1 --- /dev/null +++ b/tier-1/autoupdates.yaml @@ -0,0 +1 @@ +../tier-0/autoupdates.yaml \ No newline at end of file diff --git a/tier-1/basic-fixes.yaml b/tier-1/basic-fixes.yaml new file mode 120000 index 0000000..d3d038c --- /dev/null +++ b/tier-1/basic-fixes.yaml @@ -0,0 +1 @@ +../tier-0/basic-fixes.yaml \ No newline at end of file diff --git a/tier-1/bootable-rpm-ostree.yaml b/tier-1/bootable-rpm-ostree.yaml new file mode 100644 index 0000000..4a1f243 --- /dev/null +++ b/tier-1/bootable-rpm-ostree.yaml @@ -0,0 +1,8 @@ +packages: + - rpm-ostree nss-altfiles + +exclude-packages: + # Exclude kernel-debug-core to make sure that it doesn't somehow get + # chosen as the package to satisfy the `kernel-core` dependency from + # the kernel package. + - kernel-debug-core diff --git a/tier-1/bootc-config.yaml b/tier-1/bootc-config.yaml new file mode 120000 index 0000000..9f9c8ab --- /dev/null +++ b/tier-1/bootc-config.yaml @@ -0,0 +1 @@ +../tier-0/bootc-config.yaml \ No newline at end of file diff --git a/standard/bootc-generic-growpart b/tier-1/bootc-generic-growpart similarity index 94% rename from standard/bootc-generic-growpart rename to tier-1/bootc-generic-growpart index cc62051..c2277ba 100755 --- a/standard/bootc-generic-growpart +++ b/tier-1/bootc-generic-growpart @@ -3,18 +3,15 @@ set -eu backing_device=$(findmnt -vno SOURCE /sysroot) echo "Backing device: ${backing_device}" - -# Handling devicemapper targets is a whole other thing -case $backing_device in - /dev/mapper/*) echo "Not growing $backing_device"; exit 0 ;; -esac - syspath=/sys/class/block/$(basename "${backing_device}") if ! test -d "${syspath}"; then echo "failed to find backing device ${syspath}"; exit 1 fi - +# Handling devicemapper targets is a whole other thing +case $backing_device in + /dev/mapper/*) "Not growing $backing_device"; exit 0 ;; +esac # Note that we expect that the rootfs is on a partition partition=$(cat "${syspath}"/partition) diff --git a/standard/bootc-generic-growpart.service b/tier-1/bootc-generic-growpart.service similarity index 86% rename from standard/bootc-generic-growpart.service rename to tier-1/bootc-generic-growpart.service index c37d2d7..77bb310 100644 --- a/standard/bootc-generic-growpart.service +++ b/tier-1/bootc-generic-growpart.service @@ -6,8 +6,6 @@ Documentation=https://gitlab.com/fedora/bootc/docs ConditionVirtualization=vm # This helps verify that we're running in a bootc/ostree based target. ConditionPathIsMountPoint=/sysroot -# For someone making a smaller image, assume they have this handled. -ConditionPathExists=/usr/bin/growpart # We want to run before any e.g. large container images might be pulled. DefaultDependencies=no Requires=sysinit.target diff --git a/tier-1/bootc.yaml b/tier-1/bootc.yaml new file mode 120000 index 0000000..e4ff72c --- /dev/null +++ b/tier-1/bootc.yaml @@ -0,0 +1 @@ +../tier-0/bootc.yaml \ No newline at end of file diff --git a/tier-1/bootupd.yaml b/tier-1/bootupd.yaml new file mode 120000 index 0000000..6b1db4e --- /dev/null +++ b/tier-1/bootupd.yaml @@ -0,0 +1 @@ +../tier-0/bootupd.yaml \ No newline at end of file diff --git a/tier-1/coreos-user-experience.yaml b/tier-1/coreos-user-experience.yaml new file mode 100644 index 0000000..5fc58be --- /dev/null +++ b/tier-1/coreos-user-experience.yaml @@ -0,0 +1,41 @@ +# This file was forked/copied from Fedora CoreOS. TODO: resync +# once we have a good generic mechanism for sharing. +packages: + # Basic user tools + ## jq - parsing/interacting with JSON data + - bash-completion + - coreutils + - file + - jq + - less + - sudo + - vim-minimal + # File compression/decompression + ## bsdtar - dependency of 35coreos-live dracut module + - bsdtar + - bzip2 + - gzip + - tar + - xz + - zstd + # Improved MOTD experience + - console-login-helper-messages-issuegen + - console-login-helper-messages-profile + # kdump support + # https://github.com/coreos/fedora-coreos-tracker/issues/622 + - kexec-tools + # Remote Access + - openssh-clients openssh-server + # Container tooling + ## crun recommends but doesn't require criu and criu-libs. We want them for + ## checkpoint/restore. https://github.com/coreos/fedora-coreos-tracker/issues/1370 + - crun criu criu-libs + - podman + - skopeo + - toolbox + # passt provides user-mode networking daemons for namespaces + - passt + # nvme-cli for managing nvme disks + - nvme-cli + # Used by admins interactively + - lsof diff --git a/tier-1/firmware.yaml b/tier-1/firmware.yaml new file mode 100644 index 0000000..1c778cf --- /dev/null +++ b/tier-1/firmware.yaml @@ -0,0 +1,7 @@ + packages: + # linux-firmware now a recommends so let's explicitly include it + # https://gitlab.com/cki-project/kernel-ark/-/commit/32271d0cd9bd52d386eb35497c4876a8f041f70b + # https://src.fedoraproject.org/rpms/kernel/c/f55c3e9ed8605ff28cb9a922efbab1055947e213?branch=rawhide + - linux-firmware + # If you're using linux-firmware, you probably also want fwupd + - fwupd diff --git a/tier-1/fwupd.yaml b/tier-1/fwupd.yaml new file mode 100644 index 0000000..0045a30 --- /dev/null +++ b/tier-1/fwupd.yaml @@ -0,0 +1,5 @@ +# Firmware updates +packages-aarch64: + - fwupd +packages-x86_64: + - fwupd diff --git a/standard/generic-growfs.yaml b/tier-1/generic-growfs.yaml similarity index 80% rename from standard/generic-growfs.yaml rename to tier-1/generic-growfs.yaml index 0604cdb..f64be92 100644 --- a/standard/generic-growfs.yaml +++ b/tier-1/generic-growfs.yaml @@ -7,7 +7,6 @@ add-files: postprocess: - | #!/bin/bash - set -xeuo pipefail - chmod 0644 /usr/lib/systemd/system/bootc-generic-growpart.service + set -euo pipefail mkdir -p /usr/lib/systemd/system/local-fs.target.wants ln -s ../bootc-generic-growpart.service /usr/lib/systemd/system/local-fs.target.wants/bootc-generic-growpart.service diff --git a/tier-1/group b/tier-1/group new file mode 120000 index 0000000..f4ca078 --- /dev/null +++ b/tier-1/group @@ -0,0 +1 @@ +../tier-0/group \ No newline at end of file diff --git a/tier-1/grub2-removals.yaml b/tier-1/grub2-removals.yaml new file mode 120000 index 0000000..7fecbad --- /dev/null +++ b/tier-1/grub2-removals.yaml @@ -0,0 +1 @@ +../tier-0/grub2-removals.yaml \ No newline at end of file diff --git a/tier-1/initramfs-full.yaml b/tier-1/initramfs-full.yaml new file mode 100644 index 0000000..d5547ef --- /dev/null +++ b/tier-1/initramfs-full.yaml @@ -0,0 +1,8 @@ +# Configuration for the "tier-1" initramfs +postprocess: + - | + #!/usr/bin/env bash + mkdir -p /usr/lib/dracut/dracut.conf.d + cat > /usr/lib/dracut/dracut.conf.d/30-bootc-tier-1.conf << 'EOF' + dracutmodules+=" lvm crypt " + EOF diff --git a/tier-1/initramfs.yaml b/tier-1/initramfs.yaml new file mode 120000 index 0000000..c268845 --- /dev/null +++ b/tier-1/initramfs.yaml @@ -0,0 +1 @@ +../tier-0/initramfs.yaml \ No newline at end of file diff --git a/tier-1/kdump-aarch64-aws-workaround.yaml b/tier-1/kdump-aarch64-aws-workaround.yaml new file mode 100644 index 0000000..c198739 --- /dev/null +++ b/tier-1/kdump-aarch64-aws-workaround.yaml @@ -0,0 +1,12 @@ +# This file includes a fixup for kdump on aarch64 AWS instances. +# The issue seems specific to aarch64 AWS instances, but we'll go +# ahead and apply it across the board for aarch64, since that's +# the easiest thing to do. Hopefully the upstream issue will get +# resolved soon. +postprocess: + - | + #!/usr/bin/env bash + # Remove irqpoll from the list of KDUMP_COMMANDLINE_APPEND. This + # causes issues on aarch64 AWS instances. + # https://github.com/coreos/fedora-coreos-tracker/issues/1187 + sed -i -e 's/irqpoll //' /etc/sysconfig/kdump diff --git a/tier-1/kernel.yaml b/tier-1/kernel.yaml new file mode 120000 index 0000000..d6f64cc --- /dev/null +++ b/tier-1/kernel.yaml @@ -0,0 +1 @@ +../tier-0/kernel.yaml \ No newline at end of file diff --git a/tier-1/manifest-tier-0.yaml b/tier-1/manifest-tier-0.yaml new file mode 120000 index 0000000..8d5a3e1 --- /dev/null +++ b/tier-1/manifest-tier-0.yaml @@ -0,0 +1 @@ +../tier-0/manifest.yaml \ No newline at end of file diff --git a/standard/manifest.yaml b/tier-1/manifest.yaml similarity index 52% rename from standard/manifest.yaml rename to tier-1/manifest.yaml index 3cea76c..2242b17 100644 --- a/standard/manifest.yaml +++ b/tier-1/manifest.yaml @@ -1,18 +1,15 @@ -metadata: - summary: | - A relatively full, but still generic base image. Roughly - similar to a headless server installation. Automatic updates - are on by default. - # Flip this back on, we're going to be a larger system recommends: true include: - - ../minimal-plus/manifest.yaml - - autoupdates.yaml + - manifest-tier-0.yaml + - bootable-rpm-ostree.yaml + - podman.yaml + - firmware.yaml - networking-tools.yaml - system-configuration.yaml - coreos-user-experience.yaml + - fwupd.yaml - persistent-journal.yaml - initramfs-full.yaml - generic-growfs.yaml @@ -20,10 +17,13 @@ include: packages: # Include and set the default editor - nano + # And we expect this in general + - vim-minimal - nfs-utils # Additional firewall support; we aren't including these in RHCOS or they # don't exist in RHEL - - iptables-services + - iptables-nft iptables-services + - WALinuxAgent-udev # Allow communication between sudo and SSSD # for caching sudo rules by SSSD. # https://github.com/coreos/fedora-coreos-tracker/issues/445 @@ -31,7 +31,9 @@ packages: # SSSD; we only ship a subset of the backends - sssd-client sssd-ad sssd-ipa sssd-krb5 sssd-ldap # Used by admins interactively + - attr - openssl + - lsof # Provides terminal tools like clear, reset, tput, and tset - ncurses # i18n @@ -39,21 +41,14 @@ packages: # zram-generator (but not zram-generator-defaults) for F33 change # https://github.com/coreos/fedora-coreos-tracker/issues/509 - zram-generator + # resolved was broken out to its own package in rawhide/f35 + - systemd-resolved # This one is in Python so isn't in FCOS, but we can safely add it here. - sos - # Make Ansible "package_facts" builtin work by default - - python3-rpm - # Initramfs Clevis for LUKS auto-unlock (dracut modules wired in initramfs-full.yaml) - - clevis-dracut - # Used by admins interactively - - man-db # These are random architecture-specific packages packages-x86_64: - irqbalance - - WALinuxAgent-udev - # TPM2 pin for Clevis LUKS auto-unlock - - clevis-pin-tpm2 packages-ppc64le: - irqbalance - librtas @@ -61,9 +56,39 @@ packages-ppc64le: - ppc64-diag-rtas packages-aarch64: - irqbalance - - WALinuxAgent-udev - # TPM2 pin for Clevis LUKS auto-unlock - - clevis-pin-tpm2 + +postprocess: + # Undo RPM scripts enabling units; we want the presets to be canonical + # https://github.com/projectatomic/rpm-ostree/issues/1803 + - | + #!/usr/bin/env bash + set -xeuo pipefail + rm -rf /etc/systemd/system/* + systemctl preset-all + rm -rf /etc/systemd/user/* + systemctl --user --global preset-all + # Default to iptables-nft. Otherwise, legacy wins. We can drop this once/if we + # remove iptables-legacy. This is needed because alternatives don't work + # https://github.com/coreos/fedora-coreos-tracker/issues/677 + # https://github.com/coreos/fedora-coreos-tracker/issues/676 + - | + #!/usr/bin/env bash + set -xeuo pipefail + ln -sf /usr/sbin/ip6tables-nft /etc/alternatives/ip6tables + ln -sf /usr/sbin/ip6tables-nft-restore /etc/alternatives/ip6tables-restore + ln -sf /usr/sbin/ip6tables-nft-save /etc/alternatives/ip6tables-save + ln -sf /usr/sbin/iptables-nft /etc/alternatives/iptables + ln -sf /usr/sbin/iptables-nft-restore /etc/alternatives/iptables-restore + ln -sf /usr/sbin/iptables-nft-save /etc/alternatives/iptables-save + # See: https://github.com/coreos/fedora-coreos-tracker/issues/1253 + # https://bugzilla.redhat.com/show_bug.cgi?id=2112857 + # https://github.com/coreos/rpm-ostree/issues/3918 + # Temporary workaround to remove the SetGID binary from liblockfile that is + # pulled by the s390utils but not needed for /usr/sbin/zipl. + - | + #!/usr/bin/env bash + set -xeuo pipefail + rm -f /usr/bin/dotlockfile # Things we don't expect to ship on the host. We currently # have recommends: false so these could only come in via @@ -73,7 +98,7 @@ exclude-packages: - perl-interpreter - nodejs - grubby - - cowsay # Just in case + - cowsay # Just in case # Let's make sure initscripts doesn't get pulled back in # https://github.com/coreos/fedora-coreos-tracker/issues/220#issuecomment-611566254 - initscripts @@ -83,6 +108,3 @@ exclude-packages: # Do not use legacy ifcfg config format in NetworkManager # See https://github.com/coreos/fedora-coreos-config/pull/1991 - NetworkManager-initscripts-ifcfg-rh - # Let's not have both legacy and nft versions in the image. Users are free to - # also layer legacy themselves if they want. - - iptables-legacy diff --git a/standard/networking-tools.yaml b/tier-1/networking-tools.yaml similarity index 89% rename from standard/networking-tools.yaml rename to tier-1/networking-tools.yaml index 7d6e7d1..7ff54e5 100644 --- a/standard/networking-tools.yaml +++ b/tier-1/networking-tools.yaml @@ -3,6 +3,8 @@ # generic enough to be shared downstream with RHCOS. packages: + # Standard tools for configuring network/hostname + - NetworkManager hostname # Interactive Networking configuration during coreos-install - NetworkManager-tui # Support for cloud quirks and dynamic config in real rootfs: diff --git a/tier-1/ostree.yaml b/tier-1/ostree.yaml new file mode 120000 index 0000000..174954e --- /dev/null +++ b/tier-1/ostree.yaml @@ -0,0 +1 @@ +../tier-0/ostree.yaml \ No newline at end of file diff --git a/tier-1/passwd b/tier-1/passwd new file mode 120000 index 0000000..dc62c0b --- /dev/null +++ b/tier-1/passwd @@ -0,0 +1 @@ +../tier-0/passwd \ No newline at end of file diff --git a/standard/persistent-journal.yaml b/tier-1/persistent-journal.yaml similarity index 93% rename from standard/persistent-journal.yaml rename to tier-1/persistent-journal.yaml index bb2d0c9..ccc6c5f 100644 --- a/standard/persistent-journal.yaml +++ b/tier-1/persistent-journal.yaml @@ -5,9 +5,7 @@ # rid of this once we move to sysusers and create the dir in the initrd. postprocess: - - | - #!/bin/bash - set -xeuo pipefail + - | #!/bin/bash mkdir -p /usr/lib/systemd/journald.conf.d/ cat >/usr/lib/systemd/journald.conf.d/10-centos-bootc-persistent.conf << EOF [Journal] diff --git a/tier-1/podman.yaml b/tier-1/podman.yaml new file mode 100644 index 0000000..6c40c5d --- /dev/null +++ b/tier-1/podman.yaml @@ -0,0 +1,7 @@ +# Core podman bits + +packages: + - crun + - podman + - container-selinux + - skopeo diff --git a/standard/system-configuration.yaml b/tier-1/system-configuration.yaml similarity index 94% rename from standard/system-configuration.yaml rename to tier-1/system-configuration.yaml index 561da50..7534975 100644 --- a/standard/system-configuration.yaml +++ b/tier-1/system-configuration.yaml @@ -1,15 +1,17 @@ # These are packages that are related to configuring parts of the system. packages: - # Explicit dep for RHEL >= 10 - - crypto-policies-scripts # Configuring SSH keys, cloud provider check-in, etc # TODO: needs Ignition kargs # - afterburn afterburn-dracut # NTP support - chrony # Storage configuration/management + - lvm2 + - cryptsetup + - e2fsprogs - sg3_utils + - xfsprogs ## This is generally useful... https://github.com/CentOS/centos-bootc/issues/394 - cloud-utils-growpart # User configuration