Compare commits

..

9 commits

Author SHA1 Message Date
Paul Whalen
13e0d4ee7c F40: add bootc to packages
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-05-03 11:02:22 -04:00
Paul Whalen
c1eb922887 F40: Update for final
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-04-22 08:45:48 -04:00
Paul Whalen
2abc5fd444 F40: Add bootc image
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-04-17 16:20:11 -04:00
Paul Whalen
d3196216a1 F40: enable fdo-client-linuxapp.service
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-04-12 08:53:55 -04:00
366b454614 add passt userspace network for podmn5 requirements
It seems podman5 has changed the rootless container network
stack to passt so add this into our compose alongside the
exisitng slirp4netns while we find out how the migration
works so we can document it.

Signed-off-by: Peter Robinson <pbrobinson@gmail.com>
2024-03-19 14:18:33 +00:00
Paul Whalen
dc36d6caf0 F40: Temporarily remove bootupd support
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-03-18 09:50:50 -04:00
Paul Whalen
58d264b766 F40: Enable bootupd
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-02-26 13:50:26 -05:00
Paul Whalen
368201d566 Drop podman-plugins package
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-02-14 17:00:04 -05:00
Paul Whalen
88079a655b Setup for F-40 branched
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2024-02-13 12:56:56 -05:00
27 changed files with 336 additions and 314 deletions

View file

@ -1,26 +1,9 @@
# KEEP THIS IN SYNC WITH https://github.com/coreos/fedora-coreos-config/blob/testing-devel/manifests/bootupd.yaml
# See also: https://forge.fedoraproject.org/atomic-desktops/config/src/branch/main/bootupd.yaml
#
# Integration with https://github.com/coreos/bootupd
packages:
- bootupd
postprocess:
- |
#!/bin/bash
set -xeuo pipefail
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
/usr/bin/bootupctl backend generate-update-metadata
# Enable migration to a static GRUB config
install -dm0755 /usr/lib/systemd/system/bootloader-update.service.d
cat > /usr/lib/systemd/system/bootloader-update.service.d/migrate-static-grub-config.conf << 'EOF'
[Service]
ExecStart=/usr/bin/bootupctl migrate-static-grub-config
EOF
echo "enable bootloader-update.service" >> /usr/lib/systemd/system-preset/80-iot.preset
# Turn permissive mode on for bootupd until all SELinux issues are fixed
semanage permissive --noreload --add bootupd_t

View file

@ -1,57 +0,0 @@
#!/usr/bin/python3
# Validate basic syntax of shell script and yaml.
import os
import stat
import subprocess
import yaml
validated=0
def openat(dirfd, name, mode='r'):
def opener(path, flags):
return os.open(path, flags, dir_fd=dirfd)
return open(name, mode, opener=opener)
def validate_shell(rootfd, name):
subprocess.check_call(['bash', '-n', name], preexec_fn=lambda: os.fchdir(rootfd))
global validated
validated +=1
for root, dirs, files, rootfd in os.fwalk('.'):
# Skip folders that do not include content to validate
for d in ['.git', '.github', 'repo', 'cache', 'tmp', 'logs', 'fedora-comps']:
if d in dirs:
dirs.remove(d)
for f in ['.gitlab-ci.yml']:
if f in files:
files.remove(f)
for name in files:
if name.endswith(('.yaml', '.yml')):
print("Validating:", name)
with open(os.open(name, dir_fd=rootfd, flags=os.O_RDONLY)) as f:
yaml.safe_load(f)
result = subprocess.run(['grep', '-RniEv', '^( )*[a-z#/-]|^( )*\\[|^$|^#', name], encoding='UTF-8',
preexec_fn=lambda: os.fchdir(rootfd))
if result.returncode == 0:
raise Exception("Found likely invalid indentation in YAML file: {}".format(name))
validated +=1
continue
elif name.endswith('.sh'):
print("Validating:", name)
validate_shell(rootfd, name)
continue
stbuf = os.lstat(name, dir_fd=rootfd)
if not stat.S_ISREG(stbuf.st_mode):
continue
if not stbuf.st_mode & stat.S_IXUSR:
continue
mimetype = subprocess.check_output(['file', '-b', '--mime-type', name], encoding='UTF-8',
preexec_fn=lambda: os.fchdir(rootfd)).strip()
if mimetype == 'text/x-shellscript':
print("Validating:", name)
validate_shell(rootfd, name)
print(f"Validated {validated} files")

View file

@ -1,12 +0,0 @@
# Enable composefs
# See: https://fedoraproject.org/wiki/Changes/ComposefsAtomicDesktops
# https://fedoraproject.org/wiki/Changes/ComposefsAtomicCoreOSIoT
postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
cat >> /usr/lib/ostree/prepare-root.conf << 'EOF'
[composefs]
enabled = yes
EOF

View file

@ -10,9 +10,9 @@ os_pretty_name = Fedora IoT
tree_name = docker-host
tree_file = %(os_name)s-%(tree_name)s.json
arch = x86_64
release = f46
ref = %(os_name)s/rawhide/%(arch)s/%(tree_name)s
yum_baseurl = http://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/%(arch)s/os/
release = f40
ref = %(os_name)s/stable/%(arch)s/%(tree_name)s
yum_baseurl = http://dl.fedoraproject.org/pub/fedora/linux/releases/40/Everything/%(arch)s/os/
# lorax_additional_repos = http://127.0.0.1/fedora-iot/local-overrides
lorax_include_packages = fedora-productimg-iot
docker_os_name = fedora

View file

@ -1,12 +1,12 @@
[fedora-46]
name=Fedora 46 - $basearch
[fedora-40]
name=Fedora 40 - $basearch
failovermethod=priority
#baseurl=http://download.fedoraproject.org/pub/fedora/linux/releases/46/Everything/$basearch/os/
metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-46&arch=$basearch
#baseurl=http://download.fedoraproject.org/pub/fedora/linux/releases/40/Everything/$basearch/os/
metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-40&arch=$basearch
enabled=1
#metadata_expire=7d
repo_gpgcheck=0
type=rpm
gpgcheck=1
gpgkey=file:///usr/share/pki/rpm-gpg/RPM-GPG-KEY-fedora-46-$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-40-$basearch
skip_if_unavailable=False

View file

@ -0,0 +1,9 @@
# Enable automatic updates by default
postprocess:
- |
#!/usr/bin/env bash
set -euo pipefail
target=/usr/lib/systemd/system/default.target.wants
mkdir -p $target
set -x
ln -s ../bootc-fetch-apply-updates.timer $target

View file

@ -0,0 +1,29 @@
# Fix general bugs
postprocess:
# See also https://github.com/openshift/os/blob/f6cde963ee140c02364674db378b2bc4ac42675b/common.yaml#L156
# This one is undoes the effect of
# # RHEL-only: Disable /tmp on tmpfs.
#Wants=tmp.mount
# in /usr/lib/systemd/system/basic.target
# We absolutely must have tmpfs-on-tmp for multiple reasons,
# but the biggest is that when we have composefs for / it's read-only,
# and for units with ProtectSystem=full systemd clones / but needs
# a writable place.
- |
#!/usr/bin/env bash
set -xeuo pipefail
mkdir -p /usr/lib/systemd/system/local-fs.target.wants
if test '!' -f /usr/lib/systemd/system/local-fs.target.wants/tmp.mount; then
ln -sf ../tmp.mount /usr/lib/systemd/system/local-fs.target.wants
fi
# See https://github.com/containers/bootc/issues/358
# basically systemd-tmpfiles doesn't follow symlinks; ordinarily our
# tmpfiles.d unit for `/var/roothome` is fine, but this actually doesn't
# work if we want to use tmpfiles.d to write to `/root/.ssh` because
# tmpfiles gives up on that before getting to `/var/roothome`.
sed -ie 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf
# Because /var/roothome is also defined in rpm-ostree-0-integration.conf
# we need to delete /var/roothome
sed -ie '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf

View file

@ -0,0 +1,10 @@
# Configuration for bootc
postprocess:
# ext4 is our default filesystem in iot
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/bootc/install/
cat > /usr/lib/bootc/install/20-default-root.toml << EOF
[install]
root-fs-type = "ext4"
EOF

View file

@ -0,0 +1,12 @@
# The bootc components.
packages:
- systemd
- bootc
# Required by bootc install today, though we'll likely switch bootc to use a Rust crate instead of sgdisk
- gdisk xfsprogs e2fsprogs dosfstools
exclude-packages:
# Exclude kernel-debug-core to make sure that it doesn't somehow get
# chosen as the package to satisfy the `kernel-core` dependency from
# the kernel package.
- kernel-debug-core

View file

@ -0,0 +1,31 @@
# Integration with https://github.com/coreos/bootupd and bootloader logic
# xref https://github.com/coreos/fedora-coreos-tracker/issues/510
packages:
- bootupd
# bootloader
packages-aarch64:
- grub2-efi-aa64 efibootmgr shim
packages-ppc64le:
- grub2 ostree-grub2
packages-s390x:
# On Fedora, this is provided by s390utils-core. on RHEL, this is for now
# provided by s390utils-base, but soon will be -core too.
- /usr/sbin/zipl
packages-x86_64:
- grub2 grub2-efi-x64 efibootmgr shim
- microcode_ctl
conditional-include:
- if: basearch != "s390x"
# And remove some cruft from grub2
include: grub2-removals.yaml
postprocess:
- |
#!/bin/bash
set -xeuo pipefail
# Until we have https://github.com/coreos/rpm-ostree/pull/2275
mkdir -p /run
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
/usr/bin/bootupctl backend generate-update-metadata

46
fedora-bootc-base/group Normal file
View file

@ -0,0 +1,46 @@
root:x:0:
bin:x:1:
daemon:x:2:
sys:x:3:
adm:x:4:
tty:x:5:
disk:x:6:
lp:x:7:
mem:x:8:
kmem:x:9:
wheel:x:10:
cdrom:x:11:
mail:x:12:
man:x:15:
sudo:x:16:
dialout:x:18:
floppy:x:19:
games:x:20:
tape:x:33:
video:x:39:
ftp:x:50:
lock:x:54:
audio:x:63:
nobody:x:99:
users:x:100:
ssh_keys:x:999:
systemd-journal:x:190:
polkitd:x:998:
etcd:x:997:
dip:x:40:
cgred:x:996:
avahi-autoipd:x:170:
sssd:x:993:
dockerroot:x:986:
rpcuser:x:29:
nfsnobody:x:65534:
kube:x:994:
chrony:x:992:
tcpdump:x:72:
ceph:x:167:
input:x:104:
systemd-timesync:x:991:
systemd-network:x:990:
systemd-resolve:x:989:
systemd-bus-proxy:x:988:
cockpit-ws:x:987:

View file

@ -0,0 +1,8 @@
remove-from-packages:
# The grub bits are mainly designed for desktops, and IMO haven't seen
# enough testing in concert with ostree. At some point we'll flesh out
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
- [grub2-tools, /etc/grub.d/08_fallback_counting,
/etc/grub.d/10_reset_boot_success,
/etc/grub.d/12_menu_auto_hide,
/usr/lib/systemd/.*]

View file

@ -0,0 +1,18 @@
# Configuration for the initramfs
postprocess:
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/dracut/dracut.conf.d
cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF'
# We want a generic image; hostonly makes no sense as part of a server side build
hostonly=no
dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
EOF
cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF'
# Extra modules that we want by default that are known to exist in the kernel
dracutmodules+=" virtiofs "
EOF
cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF'
# We want this for systemd-cryptsetup tpm2 locking
dracutmodules+=" tpm2-tss "
EOF

View file

@ -0,0 +1,6 @@
# Enable the Linux kernel; see also kernel-rt.
packages:
- kernel
exclude-packages:
- kernel-debug

View file

@ -0,0 +1,71 @@
# Modern defaults we want
boot-location: modules
tmp-is-dir: true
# https://github.com/CentOS/centos-bootc/issues/167
machineid-compat: true
# Be minimal
recommends: false
ignore-removed-users:
- root
ignore-removed-groups:
- root
etc-group-members:
- wheel
- sudo
- systemd-journal
- adm
# Default to `bash` in our container, the same as other containers we ship.
container-cmd:
- /sbin/init
# Note that the default for c9s+ is sqlite; we can't rely on rpm being
# in the target (it isn't in tier-0!) so turn this to host here. This
# does break the "hermetic build" aspect a bit. Maybe eventually
# what we should do is special case this and actually install RPM temporarily
# and then remove it...
rpmdb: host
check-passwd:
type: "file"
filename: "passwd"
check-groups:
type: "file"
filename: "group"
automatic-version-prefix: "${releasever}.<date:%Y%m%d>"
mutate-os-release: "${releasever}"
remove-from-packages:
# Generally we expect other tools to do this (e.g. Ignition or cloud-init)
- [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service]
# We don't want auto-generated mount units. See also
# https://github.com/systemd/systemd/issues/13099
- [systemd-udev, /usr/lib/systemd/system-generators/systemd-gpt-auto-generator]
# Drop some buggy sysusers fragments which do not match static IDs allocation:
# https://bugzilla.redhat.com/show_bug.cgi?id=2105177
- [dbus-common, /usr/lib/sysusers.d/dbus.conf]
include:
- bootc.yaml
- ostree.yaml
- bootc-config.yaml
- initramfs.yaml
- autoupdates.yaml
- basic-fixes.yaml
packages:
# Even in tier-0, we have this. If you don't want SELinux today, you'll need
# to build a custom image.
- selinux-policy-targeted
# And we want container-selinux because trying to layer it on later currently causes issues.
- container-selinux
# Needed for tpm2 bound luks
- tpm2-tools
# See https://github.com/coreos/bootupd
arch-include:
x86_64: bootupd.yaml
aarch64: bootupd.yaml

View file

@ -0,0 +1,17 @@
packages:
- ostree nss-altfiles
# We want content lifecycled with the image
opt-usrlocal: "root"
postprocess:
# Set up default root config
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/ostree
cat > /usr/lib/ostree/prepare-root.conf << EOF
[composefs]
enabled = yes
[sysroot]
readonly = true
EOF

32
fedora-bootc-base/passwd Normal file
View file

@ -0,0 +1,32 @@
adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
bin:x:1:1:bin:/bin:/usr/sbin/nologin
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
games:x:12:100:games:/usr/games:/usr/sbin/nologin
halt:x:7:0:halt:/sbin:/sbin/halt
kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
operator:x:11:0:operator:/root:/usr/sbin/nologin
polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
root:x:0:0:Super User:/root:/bin/bash
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
sssd:x:995:993:User for sssd:/:/usr/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
tcpdump:x:72:72::/:/usr/sbin/nologin

15
fedora-bootc.yaml Normal file
View file

@ -0,0 +1,15 @@
releasever: 40
variables:
distro: "fedora"
repos:
- fedora-40
metadata:
name: fedora-bootc
summary: Fedora base bootc image
include:
- fedora-bootc-base/manifest.yaml
- fedora-bootc-base/kernel.yaml

View file

@ -1,17 +1,14 @@
include:
- bootupd.yaml
# Enable composefs
- composefs.yaml
# Read only sysroot
- sysroot-ro.yaml
ref: fedora/rawhide/${basearch}/iot
# https://github.com/fedora-iot/iot-distro/issues/34
#include: bootupd.yaml
ref: fedora/stable/${basearch}/iot
repos: []
selinux: true
ima: true
tmp-is-dir: true
recommends: false
documentation: false
automatic_version_prefix: '46'
mutate-os-release: '46'
automatic_version_prefix: '40'
mutate-os-release: '40'
initramfs-args:
- "--no-hostonly"
- "--add"
@ -74,15 +71,12 @@ check-groups:
type: file
filename: group
packages:
# This list of packages should be kept in sync with
# the iot-commit definition is osbuild, as found here:
# https://github.com/osbuild/images/blob/0584c20b0c14a89e833b875252114ceff61805e8/pkg/distro/fedora/package_sets.go#L123
- fedora-release-iot
- fedora-iot-config
- aardvark-dns
- atheros-firmware
- attr
- authselect
- basesystem
- bash
- bash-completion
- bootc
@ -100,16 +94,14 @@ packages:
- criu-libs
- cryptsetup
- curl
- dnf5
- dnf5-plugins
- dbus-parsec
- dnsmasq
- dosfstools
- dracut-config-generic
- dracut-network
- e2fsprogs
- efibootmgr
- fdo-client
- fdo-owner-cli
- filesystem
- firewalld
- fwupd
- fwupd-efi
@ -122,15 +114,15 @@ packages:
- greenboot-default-health-checks
- gzip
- hostname
- ignition-edge
- ignition
- ima-evm-utils
- iproute
- iputils
- iwd
- iwlwifi-mvm-firmware
- kernel
- kernel-tools
- keyutils
- kmscon
- less
- libsss_sudo
- linux-firmware
@ -145,9 +137,11 @@ packages:
- openssh-server
- passt
- passt-selinux
- parsec
- pinentry
- podman
- policycoreutils
- policycoreutils-python-utils
- polkit
- procps-ng
- realtek-firmware
@ -163,7 +157,6 @@ packages:
- sssd-client
- sudo
- systemd
- systemd-pam
- systemd-resolved
- tar
- tmux
@ -176,6 +169,7 @@ packages:
- wireless-regdb
- xfsprogs
- xz
- zezere-ignition
- zram-generator
- zram-generator-defaults
packages-aarch64:
@ -196,10 +190,13 @@ units:
- fedora-iot-config-remote-fix.service
- firewalld.service
- sshd.service
- systemd-firstboot.service
- greenboot-grub2-set-counter.service
- greenboot-grub2-set-success.service
- greenboot-healthcheck.service
- greenboot-rpm-ostree-grub2-check-fallback.service
- greenboot-status.service
- greenboot-task-runner.service
- parsec.service
- dbus-parsec.service
- zezere_ignition.timer
- zezere_ignition_banner.service

View file

@ -1,15 +0,0 @@
releasever: rawhide
variables:
distro: "fedora-iot"
repos:
- fedora-rawhide
metadata:
name: fedora-iot-bootc-base
summary: Fedora IoT bootc base image
include:
- fedora-bootc-base/manifest.yaml
- fedora-bootc-base/kernel.yaml

View file

@ -1,2 +1,2 @@
include: fedora-iot-base.yaml
ref: fedora/rawhide/${basearch}/updates/iot
ref: fedora/stable/${basearch}/updates/iot

View file

@ -1,2 +1,2 @@
include: fedora-iot-base.yaml
ref: fedora/rawhide/${basearch}/testing/iot
ref: fedora/stable/${basearch}/testing/iot

View file

@ -1,5 +1,4 @@
include: fedora-iot-base.yaml
ref: fedora/rawhide/${basearch}/iot
ref: fedora/stable/${basearch}/iot
repos:
- fedora-46
- fedora-40

View file

@ -1,6 +0,0 @@
[fedora-rawhide]
name=Fedora rawhide $basearch
mirrorlist=https://mirrors.fedoraproject.org/metalink?repo=rawhide&arch=$basearch
enabled=1
gpgcheck=1
metadata_expire=1d

156
justfile
View file

@ -1,156 +0,0 @@
# This is a justfile. See https://github.com/casey/just
# This is only used for local development. The builds made on the Fedora
# infrastructure are run via Pungi in a Koji runroot.
# Set a default for some recipes
default_variant := "fedora-iot"
default_arch := "default"
# Current default in Pungi
force_nocache := "true"
# Just doesn't have a native dict type, but quoted bash dictionary works fine
pretty_names := '(
[fedora-iot]="IoT"
)'
# Default is to only validate the manifests
all: validate
# Basic validation to make sure the manifests are not completely broken
validate:
./ci/validate
# Output the processed manifest for a given variant (defaults to Silverblue)
manifest variant=default_variant:
#!/bin/bash
set -euo pipefail
rpm-ostree compose tree --print-only --repo=repo {{variant}}.yaml
# Perform dependency resolution for a given variant (defaults to Silverblue)
compose-dry-run variant=default_variant:
#!/bin/bash
set -euxo pipefail
mkdir -p repo cache logs
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
rpm-ostree compose tree --unified-core --repo=repo --dry-run {{variant}}.yaml
# Alias/shortcut for compose-image command
compose variant=default_variant: (compose-image variant)
# Compose a variant using the legacy non container path (defaults to Silverblue)
compose-legacy variant=default_variant:
#!/bin/bash
set -euxo pipefail
declare -A pretty_names={{pretty_names}}
variant={{variant}}
variant_pretty=${pretty_names[$variant]-}
if [[ -z $variant_pretty ]]; then
echo "Unknown variant"
exit 1
fi
./ci/validate > /dev/null || (echo "Failed manifest validation" && exit 1)
mkdir -p repo cache logs
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
# Set option to reduce fsync for transient builds
ostree --repo=repo config set 'core.fsync' 'false'
buildid="$(date '+%Y%m%d.0')"
timestamp="$(date --iso-8601=sec)"
echo "${buildid}" > .buildid
version="$(rpm-ostree compose tree --print-only --repo=repo ${variant}.yaml | jq -r '."mutate-os-release"')"
echo "Composing ${variant_pretty} ${version}.${buildid} ..."
ARGS="--repo=repo --cachedir=cache"
ARGS+=" --unified-core"
if [[ {{force_nocache}} == "true" ]]; then
ARGS+=" --force-nocache"
fi
CMD="rpm-ostree"
if [[ ${EUID} -ne 0 ]]; then
CMD="sudo rpm-ostree"
fi
${CMD} compose tree ${ARGS} \
--add-metadata-string="version=${variant_pretty} ${version}.${buildid}" \
"${variant}.yaml" \
|& tee "logs/${variant}_${version}_${buildid}.${timestamp}.log"
if [[ ${EUID} -ne 0 ]]; then
sudo chown --recursive "$(id --user --name):$(id --group --name)" repo cache
fi
ostree summary --repo=repo --update
# Compose an Ostree Native Container OCI image
compose-image variant=default_variant:
#!/bin/bash
set -euxo pipefail
declare -A pretty_names={{pretty_names}}
variant={{variant}}
variant_pretty=${pretty_names[$variant]-}
if [[ -z $variant_pretty ]]; then
echo "Unknown variant"
exit 1
fi
./ci/validate > /dev/null || (echo "Failed manifest validation" && exit 1)
mkdir -p repo cache
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
# Set option to reduce fsync for transient builds
ostree --repo=repo config set 'core.fsync' 'false'
buildid="$(date '+%Y%m%d.0')"
timestamp="$(date --iso-8601=sec)"
echo "${buildid}" > .buildid
version="$(rpm-ostree compose tree --print-only --repo=repo ${variant}.yaml | jq -r '."mutate-os-release"')"
echo "Composing ${variant_pretty} ${version}.${buildid} ..."
ARGS="--cachedir=cache --initialize"
if [[ {{force_nocache}} == "true" ]]; then
ARGS+=" --force-nocache"
fi
# To debug with gdb, use: gdb --args ...
CMD="rpm-ostree"
if [[ ${EUID} -ne 0 ]]; then
CMD="sudo rpm-ostree"
fi
${CMD} compose image ${ARGS} \
--label="quay.expires-after=4w" \
"${variant}.yaml" \
"${variant}.ociarchive"
# Clean up everything
clean-all:
just clean-repo
just clean-cache
# Only clean the ostree repo
clean-repo:
rm -rf ./repo
# Only clean the package and repo caches
clean-cache:
rm -rf ./cache

View file

@ -1,15 +0,0 @@
# Set up default root config to mount sysroot as read only
# https://fedoraproject.org/wiki/Changes/Silverblue_Kinoite_readonly_sysroot
# See: https://gitlab.com/fedora/bootc/base-images/-/blob/main/tier-0/ostree.yaml
# See: https://github.com/fedora-iot/iot-distro/issues/81
postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
install -dm 0755 -o 0 -g 0 /usr/lib/ostree
cat >> /usr/lib/ostree/prepare-root.conf << 'EOF'
[sysroot]
readonly = true
EOF

View file

@ -18,7 +18,7 @@ done
# Remove loader directory causing issues in Anaconda in unified core mode
# Will be obsolete once we start using bootupd
# See - https://forge.fedoraproject.org/atomic-desktops/config/pulls/344
# See - https://pagure.io/workstation-ostree-config/pull-request/344
rm -rf /usr/lib/ostree-boot/loader
# Undo RPM scripts enabling units; we want the presets to be canonical