18 Commits

Author SHA1 Message Date
benvin 26d399b8d5 Merge pull request 'Bake LDAP + SSO auth plugins into the image' (#8) from benvin/auth-plugins into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #8
v0.2.0
2026-08-29 12:03:44 +10:00
unkin-agent ac61265ea0 Route LDAP plugin through artifactapi remote for secure image builds.
ci/woodpecker/pr/build Pipeline was successful
Replace direct repo.jellyfin.org download with artifactapi.k8s.syd1.au.unkin.net
remote. SHA256 pin guarantees integrity over HTTP. Both plugins now consistent
in sourcing from artifactapi infrastructure.
2026-08-29 12:00:03 +10:00
unkin-agent 72290bbacd fix(ci): pull SSO plugin via artifactapi github proxy
ci/woodpecker/pr/build Pipeline failed
The PR build failed at the plugins stage: the CI build network can reach
artifactapi and package mirrors (repo.jellyfin.org) but not github.com
directly, so the SSO plugin download from github failed (curl exit 7).
Route the SSO fetch through the artifactapi github remote proxy instead;
SSO_SHA256 still pins the exact bytes. LDAP is unchanged.
2026-08-26 23:28:56 +10:00
unkin-agent 2001204e0b Bake LDAP + SSO auth plugins into the image
ci/woodpecker/pr/build Pipeline failed
Phase-1 SSO/app-passwords for jellyfin needs the ldapauth and sso plugins
present without relying on the in-app catalog (which the plugins-baked PVC
would otherwise let drift). Pin the newest release of each whose targetAbi
is <= the pinned server version (10.11.6) and let the image own the version.

- Add a plugins build stage that downloads, sha256-verifies (matching each
  release's published .sha256), and unpacks the plugin zips into versioned
  dirs baked at /usr/share/jellyfin/plugins-baked.
- LDAP Authentication 22.0.0.0 (targetAbi 10.11.2.0; v23 needs 10.11.9).
- SSO Authentication 4.0.0.4 (targetAbi 10.11.0.0).
- Add docker-entrypoint.sh that syncs baked plugin dirs into /config/plugins
  on every start, removing any stale versioned dir of the same plugin so the
  image controls the version across restarts; preserves plugin configurations.
- Point ENTRYPOINT at the new script.
2026-08-26 22:13:40 +10:00
benvin 4a4965921f Merge pull request 'fix: align runtime image .NET to the app (9.0)' (#7) from benvin/jellyfin-dotnet9 into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #7
v0.1.3
2026-08-15 18:44:51 +10:00
unkin-agent c7409d0812 fix: align runtime image .NET to the app (9.0)
ci/woodpecker/pr/build Pipeline was successful
The runtime image based on aspnet:10.0 provides only .NET 10.x, but the
publish step builds framework-dependent against SDK 9.0, so the app requires
Microsoft.NETCore.App 9.0.0 and crashes on start under 10.x.

Pin the runtime base to aspnet:9.0 to match the SDK 9.0 publish.
2026-08-15 18:40:05 +10:00
benvin 248027aaea Merge pull request 'ci: use CA-baked plugin-docker-buildx image for artifactapi push' (#6) from benvin/jellyfin-buildx-plugin-image into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #6
v0.1.2
2026-08-15 18:20:05 +10:00
unkin-agent 0020ee2a58 ci: use CA-baked plugin-docker-buildx image for artifactapi push
ci/woodpecker/pr/build Pipeline was successful
Point the release docker step at the custom
artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx
image, which bakes artifactapi's internal Vault CA into
/etc/docker/certs.d/<registry>/ca.crt.

- Swap the docker step image from upstream woodpeckerci/plugin-docker-buildx
  to the CA-baked custom image.
- Drop the separate ca-trust step (and its almalinux9-base dependency) that
  staged the CA into the workspace.
- Repoint buildkit_config ca= at the in-image baked CA path so the buildx
  docker-container builder still hands the CA to buildkitd for the push.
2026-08-15 18:06:11 +10:00
benvin b1470f3158 Merge pull request 'ci: trust artifactapi internal CA when pushing docker-internal' (#5) from benvin/jellyfin-buildkit-ca into main
ci/woodpecker/tag/docker Pipeline failed
Reviewed-on: #5
v0.1.1
2026-08-15 16:42:06 +10:00
unkin-agent ec04b35b39 ci: trust artifactapi internal CA when pushing docker-internal
ci/woodpecker/pr/build Pipeline was successful
The v0.1.0 release pipeline built the runtime image fine but failed the
push to artifactapi.k8s.syd1.au.unkin.net/docker-internal with a TLS
x509 unknown-authority error: buildkit did not trust artifactapi's
Vault-signed cert.

Stage the internal CA into the shared workspace via the almalinux9-base
image (already trusts the unkin CA; same image the RPM release pipelines
use to reach artifactapi over HTTPS) and point the docker-buildx plugin
at it through buildkit_config. buildx copies the referenced CA into the
buildkitd container at builder-create time, so the push handshake now
verifies. No credentials needed: anonymous push to docker-internal is
allowed for trusted clients.
2026-08-15 16:34:44 +10:00
benvin a369c49457 Merge pull request 'build: source release image from fork main (scan-leader)' (#4) from benvin/upstream-ref-scanleader into main
ci/woodpecker/tag/docker Pipeline failed
Reviewed-on: #4
v0.1.0
2026-08-12 00:30:32 +10:00
unkinben 8738315c52 build: bump UPSTREAM_REF to fork main with scan-leader
ci/woodpecker/pr/build Pipeline was successful
2026-08-11 22:03:13 +10:00
benvin ac507021f3 Merge pull request 'build: container build from the unkin jellyfin-ha-src fork' (#3) from benvin/jellyfin-ha-build into main
Reviewed-on: #3
2026-08-11 21:13:46 +10:00
unkinben 26e57c8655 ci: pin .NET SDK image to 9.0 to match global.json
ci/woodpecker/pr/build Pipeline was successful
The pinned jellyfin-ha-src fork sets global.json sdk 9.0.0 (rollForward
latestMinor), so the publish steps in build.yaml and docker.yaml must run
on the .NET 9 SDK. They referenced sdk:10.0, which fails the pinned build.
Repoint both publish steps to mcr.microsoft.com/dotnet/sdk:9.0.
2026-08-11 20:41:43 +10:00
unkinben 9f8d9014d3 build: source from the unkin jellyfin-ha-src fork
Why:
- The build should pull from our own source fork so local HA patches can be
  carried and pinned, rather than cloning the upstream GitHub tree directly.

How:
- Point the clone URL in the Makefile and both Woodpecker pipelines at
  https://git.unkin.net/unkin/jellyfin-ha-src.git.
- Keep UPSTREAM_REF at d4f9c12c22d3a640f3b0a3622b23b8cd01d044ad, which is the
  seeded fork main, so the produced image is byte-identical for now; the
  feature bump is a later change.
2026-08-11 07:25:03 +10:00
unkinben 84f9158e9b ci: push images to artifactapi registry instead of gitea
Hard switch of the docker push target from the Gitea registry to the
artifactapi local docker registry (docker-internal); the Gitea VM and its
registry are being retired. Drops the droneci/DRONECI_PASSWORD creds since
artifactapi accepts unauthenticated in-cluster pushes. Also repoints the Makefile IMAGE and README image paths.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-30 00:34:59 +10:00
Ben Vin a0983157a0 Add jellyfin-ha container build
Build-orchestration for the jellyfin-ha Jellyfin fork: pins an upstream
commit (UPSTREAM_REF), publishes the .NET 10 server, and builds/pushes the
runtime image to git.unkin.net/unkin/jellyfin-ha on v* tags.

- UPSTREAM_REF pinned to d4f9c12
- Dockerfile.runtime (vendored runtime-only image + jellyfin-web 10.11.6)
- .woodpecker/{build,docker}.yaml (publish + docker-buildx, k8s resources)
- Makefile (publish/build + patch/minor/major release tagging)
2026-07-05 22:48:15 +10:00
gitadmin 1540f864c3 Initial commit 2026-07-05 22:43:34 +10:00