From 2924cbb63db01f059ef8da4a14c55be6ca1116cc Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 12 Sep 2026 01:27:48 +1000 Subject: [PATCH] build: track jellyfin v12.0 - pin UPSTREAM_REF to the v12.0 rebase commit - move publish to dotnet SDK 10.0 and the runtime to aspnet:10.0 - pin jellyfin-web to 12.0+deb12 - bake LDAP Authentication 24.0.0.0 (targetAbi 12.0.0.0) - build PR images with the CA-baked buildx plugin --- .woodpecker/build.yaml | 4 ++-- .woodpecker/docker.yaml | 2 +- Dockerfile.runtime | 27 +++++++++++++-------------- README.md | 6 +++--- UPSTREAM_REF | 2 +- 5 files changed, 20 insertions(+), 21 deletions(-) diff --git a/.woodpecker/build.yaml b/.woodpecker/build.yaml index 1db1e3f..9c8f74b 100644 --- a/.woodpecker/build.yaml +++ b/.woodpecker/build.yaml @@ -5,7 +5,7 @@ steps: # Clone the pinned upstream jellyfin-ha source and publish the .NET server # into ./publish-output (consumed by Dockerfile.runtime). - name: publish - image: mcr.microsoft.com/dotnet/sdk:9.0 + image: mcr.microsoft.com/dotnet/sdk:10.0 commands: - | REF=$$(cat UPSTREAM_REF) @@ -26,7 +26,7 @@ steps: # Validate the runtime image builds (no push on PRs). - name: docker-build - image: woodpeckerci/plugin-docker-buildx + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest settings: repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha dockerfile: Dockerfile.runtime diff --git a/.woodpecker/docker.yaml b/.woodpecker/docker.yaml index 0eb4efb..724d7ec 100644 --- a/.woodpecker/docker.yaml +++ b/.woodpecker/docker.yaml @@ -5,7 +5,7 @@ when: steps: # Same publish step as the PR pipeline: clone pinned upstream + dotnet publish. - name: publish - image: mcr.microsoft.com/dotnet/sdk:9.0 + image: mcr.microsoft.com/dotnet/sdk:10.0 commands: - | REF=$$(cat UPSTREAM_REF) diff --git a/Dockerfile.runtime b/Dockerfile.runtime index 9abef84..18d5368 100644 --- a/Dockerfile.runtime +++ b/Dockerfile.runtime @@ -18,28 +18,27 @@ RUN apt-get update \ && echo "deb [arch=amd64 signed-by=/usr/share/keyrings/jellyfin.gpg] https://repo.jellyfin.org/debian bookworm main" \ > /etc/apt/sources.list.d/jellyfin.list \ && apt-get update \ - && apt-get install -y --no-install-recommends "jellyfin-web=10.11.6+deb12" \ + && apt-get install -y --no-install-recommends "jellyfin-web=12.0+deb12" \ && rm -rf /var/lib/apt/lists/* # ── Plugin stage ────────────────────────────────────────────────────────────── # Download and verify the auth plugins, unpacked into versioned dirs baked into # the image and synced into /config/plugins at start (docker-entrypoint.sh). # Versions are the newest each plugin publishes whose targetAbi <= the pinned -# Jellyfin server version (10.11.6): -# LDAP Authentication 22.0.0.0 targetAbi 10.11.2.0 (v23 needs 10.11.9) -# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0 -# sha256 pins match each release's published .sha256 asset for reproducibility. +# Jellyfin server version (12.0.0): +# LDAP Authentication 24.0.0.0 targetAbi 12.0.0.0 +# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0 (newest release; loads on 12.0) +# sha256 pins make each fetch reproducible. FROM --platform=linux/amd64 debian:bookworm-slim AS plugins RUN apt-get update \ && apt-get install -y --no-install-recommends curl ca-certificates unzip \ && rm -rf /var/lib/apt/lists/* -ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip -ARG LDAP_SHA256=c2386c001be439c9946280a02d62610f29e325d4094e83bd31221de3f7aa20ae +ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_24.0.0.0.zip +ARG LDAP_SHA256=3be1f9d6a6ce9ea375e556dd30136d178a8dbe35cbe866d30d3451dc3ff7e804 # LDAP is served through artifactapi remote. SSO is served through the artifactapi # github proxy, which the CI build network can reach (github is not directly reachable). -# SHA256 pins match each release's published asset for reproducibility and integrity. ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107 @@ -47,8 +46,8 @@ WORKDIR /plugins RUN set -eu; \ curl -fsSL "$LDAP_URL" -o ldap.zip; \ echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \ - mkdir -p "LDAP Authentication_22.0.0.0"; \ - unzip -oq ldap.zip -d "LDAP Authentication_22.0.0.0"; \ + mkdir -p "LDAP Authentication_24.0.0.0"; \ + unzip -oq ldap.zip -d "LDAP Authentication_24.0.0.0"; \ curl -fsSL "$SSO_URL" -o sso.zip; \ echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \ mkdir -p "SSO Authentication_4.0.0.4"; \ @@ -56,10 +55,10 @@ RUN set -eu; \ rm -f ldap.zip sso.zip # ── Runtime stage ───────────────────────────────────────────────────────────── -# .NET 9 runtime: matches the SDK 9.0 publish step (framework-dependent), so the -# app's required Microsoft.NETCore.App 9.0 is present. Keep in lockstep with the -# `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml and the Makefile. -FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:9.0 +# .NET 10 runtime: matches the SDK 10.0 publish step (framework-dependent) and the +# fork's net10.0 TFM, so the app's required Microsoft.NETCore.App 10.0 is present. +# Keep in lockstep with the `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml. +FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:10.0 # FFmpeg and the native deps required by SkiaSharp and fontconfig. RUN apt-get update \ diff --git a/README.md b/README.md index 113000b..cb90dde 100644 --- a/README.md +++ b/README.md @@ -4,12 +4,12 @@ Build-orchestration repo for [ZoltyMat/jellyfin-ha](https://github.com/ZoltyMat/ that adds distributed, Redis-backed transcoding for multi-pod Kubernetes (lease-aware cleanup, HA session takeover, optional PostgreSQL). -This repo does **not** vendor the fork's source. It pins an upstream commit, builds the .NET 9 server, and +This repo does **not** vendor the fork's source. It pins an upstream commit, builds the .NET 10 server, and produces a runtime container image pushed to the Gitea registry. ## What it produces -`artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:` — an `mcr.microsoft.com/dotnet/aspnet:9.0` based image with ffmpeg and +`artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:` — an `mcr.microsoft.com/dotnet/aspnet:10.0` based image with ffmpeg and the prebuilt `jellyfin-web` client, running the published `jellyfin-ha` server. ## Layout @@ -34,7 +34,7 @@ the prebuilt `jellyfin-web` client, running the published `jellyfin-ha` server. make build # clones pinned upstream, dotnet publish, docker build ``` -Requires the .NET 9 SDK and Docker. `make publish` runs just the clone + publish into `./publish-output`. +Requires the .NET 10 SDK and Docker. `make publish` runs just the clone + publish into `./publish-output`. ## Deployment diff --git a/UPSTREAM_REF b/UPSTREAM_REF index e90a32a..9b431ef 100644 --- a/UPSTREAM_REF +++ b/UPSTREAM_REF @@ -1 +1 @@ -2e1e445e470c2f2c1520f66678a73faa226c2058 +d825f8ac8128a1daae7dfee63caad7bfb1ce2f0e