Ship the intermediate CA in unkin-ca-certificates (#177)

`s3.ceph.unkin.net` serves a bare leaf issued by `CN=unkin.net Intermediate Authority`. The package shipped only the root, so images carrying just `unkin-ca-certificates` (container-base, container-gobuilder) cannot verify it — `curl https://s3.ceph.unkin.net/` returns 000.

- Fetch `pki_int` alongside `pki_root` and anchor it as `UNKIN_INTCA_2024.crt`
- Fail the build when a fetch errors or returns a non-certificate
- Bump version to `2026.10.2` on all distro targets

Verified in `gobuilder:0.1.1-alma9`: 000 before, 200 after, no `-k`.

Reviewed-on: #177
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #177.
This commit is contained in:
2026-10-02 22:24:22 +10:00
committed by BenVincent
parent df7490388e
commit 70523ae938
3 changed files with 18 additions and 6 deletions
+3 -3
View File
@@ -12,16 +12,16 @@ builds:
release: '1'
repository:
- almalinux/el8
version: 2025.07.13
version: 2026.10.2
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 2025.07.13
version: 2026.10.2
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- fedora/42
- fedora/43
- fedora/44
version: 2025.07.13
version: 2026.10.2
@@ -1,9 +1,15 @@
#!/usr/bin/bash
set -e
set -euo pipefail
# Download the CA certificate from vault
curl -L -o /app/UNKIN_ROOTCA_2024.crt https://vault.query.consul:8200/v1/pki_root/ca/pem
# Download the CA chain from vault; openssl verifies we got a certificate, not an error page
fetch_ca() {
curl -fsSL -o "$2" "https://vault.query.consul:8200/v1/$1/ca/pem"
openssl x509 -in "$2" -noout -subject
}
fetch_ca pki_root /app/UNKIN_ROOTCA_2024.crt
fetch_ca pki_int /app/UNKIN_INTCA_2024.crt
# Process the nfpm.yaml template with environment variables
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
@@ -29,6 +29,12 @@ contents:
mode: 0755
owner: root
group: root
- src: /app/UNKIN_INTCA_2024.crt
dst: /etc/pki/ca-trust/source/anchors/UNKIN_INTCA_2024.crt
file_info:
mode: 0755
owner: root
group: root
# Scripts to run during installation/removal (optional)
scripts: