Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 105487c090 |
@@ -1,81 +0,0 @@
|
||||
when:
|
||||
- event: tag
|
||||
ref: refs/tags/node-image-*
|
||||
|
||||
# Builds the AlmaLinux 9 node rootfs with dnf --installroot, tars it as
|
||||
# almalinux9-node-<ver>.tar.zst and PUTs it to the artifactapi rootfs-images
|
||||
# local (generic) repo, where the almalinux9-image catalog entry's liveimg
|
||||
# points. Tag as node-image-<ver> (e.g. node-image-20260729); the tarball
|
||||
# version is that suffix. Baked here = everything the image %post assumes is
|
||||
# already installed (kernel/grub/dracut, NetworkManager, openssh, chrony,
|
||||
# kexec-tools, curl, puppet-agent, ...). Per-host config stays in image.ks.tmpl.
|
||||
steps:
|
||||
- name: build-rootfs
|
||||
image: git.unkin.net/unkin/almalinux9-base:20260606
|
||||
commands:
|
||||
- dnf -y install tar zstd dnf-plugins-core
|
||||
- VER="${CI_COMMIT_TAG#node-image-}"
|
||||
- ROOT="$${CI_WORKSPACE}/rootfs"
|
||||
- mkdir -p "$$ROOT"
|
||||
# Base system + boot chain (BIOS + UEFI), storage, networking, node tools.
|
||||
- |
|
||||
dnf -y --installroot="$$ROOT" --releasever=9 --setopt=install_weak_deps=False install \
|
||||
@core kernel \
|
||||
grub2-pc grub2-efi-x64 shim-x64 grub2-tools grub2-tools-efi efibootmgr \
|
||||
dracut dracut-config-generic \
|
||||
lvm2 xfsprogs e2fsprogs dosfstools \
|
||||
NetworkManager selinux-policy-targeted policycoreutils \
|
||||
openssh-server chrony kexec-tools bind-utils vim-minimal tmux git curl \
|
||||
glibc-langpack-en
|
||||
# Puppet agent baked in; image.ks.tmpl %post only configures it.
|
||||
- dnf -y --installroot="$$ROOT" install https://yum.puppet.com/puppet8-release-el-9.noarch.rpm
|
||||
- dnf -y --installroot="$$ROOT" install puppet-agent
|
||||
- dnf -y --installroot="$$ROOT" clean all
|
||||
- rm -rf "$$ROOT"/var/cache/dnf/* "$$ROOT"/var/log/dnf* "$$ROOT"/etc/machine-id
|
||||
# Reproducible, ownership/xattr/SELinux-preserving tarball.
|
||||
- tar --numeric-owner --acls --xattrs --selinux -C "$$ROOT" -caf "almalinux9-node-$${VER}.tar.zst" .
|
||||
- ls -lh "almalinux9-node-$${VER}.tar.zst"
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
ephemeral-storage: 8Gi
|
||||
limits:
|
||||
memory: 4Gi
|
||||
cpu: 4
|
||||
ephemeral-storage: 16Gi
|
||||
|
||||
- name: upload
|
||||
image: git.unkin.net/unkin/almalinux9-base:20260606
|
||||
commands:
|
||||
- VER="${CI_COMMIT_TAG#node-image-}"
|
||||
- |
|
||||
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
|
||||
REPO="rootfs-images"
|
||||
FILE="almalinux9-node-$${VER}.tar.zst"
|
||||
# Local generic repo: PUT stores the raw file; overwrites 409-reject, so
|
||||
# skip if this version already exists (probe the GET path).
|
||||
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" || true)
|
||||
if [ "$$code" = "200" ]; then
|
||||
echo "$$FILE already exists (HTTP $$code); skipping upload"
|
||||
exit 0
|
||||
fi
|
||||
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" \
|
||||
-H "Content-Type: application/zstd" \
|
||||
--data-binary @"$$FILE"
|
||||
depends_on: [build-rootfs]
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 500m
|
||||
ephemeral-storage: 8Gi
|
||||
limits:
|
||||
memory: 1Gi
|
||||
cpu: 1
|
||||
ephemeral-storage: 16Gi
|
||||
+7
-5
@@ -86,11 +86,13 @@ vars:
|
||||
- **Networking is templated per-host in `%post`** (NetworkManager keyfiles from
|
||||
the same NetBox interface data), because the generic image has no per-host
|
||||
identity and the `liveimg` unpack overwrites `/etc`.
|
||||
- The tarball is built by `.woodpecker/build-image.yaml` (tag `node-image-<ver>`)
|
||||
and uploaded to the artifactapi `rootfs-images` local repo. Baked into the
|
||||
image = everything the `%post` assumes present (kernel/grub/dracut,
|
||||
NetworkManager, openssh, chrony, kexec-tools, curl, puppet-agent). Bump an
|
||||
image = new tag + one-line `rootfs_tarball` edit here.
|
||||
- The tarball is built by the separate
|
||||
[bootapi-images](https://git.unkin.net/unkin/bootapi-images) repo (a `v*` tag
|
||||
builds and uploads `almalinux9-node-<ver>.tar.zst` to the artifactapi
|
||||
`rootfs-images` local repo). Baked into the image = everything the `%post`
|
||||
assumes present (kernel/grub/dracut, NetworkManager, openssh, chrony,
|
||||
kexec-tools, curl, puppet-agent). Bump an image = new bootapi-images release +
|
||||
a one-line `rootfs_tarball` edit here.
|
||||
|
||||
## Adding another distro (the intended path)
|
||||
|
||||
|
||||
@@ -16,7 +16,7 @@ kernel_args:
|
||||
- inst.text
|
||||
- net.ifnames=0
|
||||
vars:
|
||||
# Prebuilt node rootfs on the artifactapi rootfs-images local repo, built by
|
||||
# .woodpecker/build-image.yaml. Immutable, date-versioned; bump this one line
|
||||
# to roll the fleet forward (overwrites are 409-rejected).
|
||||
rootfs_tarball: "https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rootfs-images/files/almalinux9-node-20260729.tar.zst"
|
||||
# Prebuilt node rootfs on the artifactapi rootfs-images local repo, built and
|
||||
# published by the bootapi-images repo (v* tag). Immutable, semver-versioned;
|
||||
# bump this one line to roll the fleet forward (overwrites are 409-rejected).
|
||||
rootfs_tarball: "https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rootfs-images/files/almalinux9-node-1.0.0.tar.zst"
|
||||
|
||||
@@ -16,6 +16,6 @@ kernel_args:
|
||||
- inst.text
|
||||
- net.ifnames=0
|
||||
vars:
|
||||
rootfs_tarball: "https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rootfs-images/files/almalinux9-node-20260729.tar.zst"
|
||||
rootfs_tarball: "https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rootfs-images/files/almalinux9-node-1.0.0.tar.zst"
|
||||
storage_mode: auto-nvme
|
||||
vg_grow: "true"
|
||||
|
||||
Reference in New Issue
Block a user