From abcfe87090954be1c48bd02599f393e368eb0010 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 3 Oct 2026 00:23:32 +1000 Subject: [PATCH] add cmctl package (#182) cmctl, the cert-manager CLI, has no internal RPM, so hosts install it by hand and get no shell or `kubectl cert-manager` completion. - add cmctl 2.6.1 package for el9 and fedora 42-44, verified against upstream checksums.txt - generate bash/zsh/fish completions at build time - ship `kubectl-cert_manager` symlink and `kubectl_complete-cert_manager` for kubectl plugin completion Requires terraform-artifactapi github allowlist entries for cert-manager/cmctl. Reviewed-on: https://git.unkin.net/unkin/rpmbuilder/pulls/182 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- rpms/cmctl/metadata.yaml | 22 +++++++ rpms/cmctl/resources/build.sh | 22 +++++++ .../resources/kubectl_complete-cert_manager | 2 + rpms/cmctl/resources/nfpm.yaml | 57 +++++++++++++++++++ 4 files changed, 103 insertions(+) create mode 100644 rpms/cmctl/metadata.yaml create mode 100755 rpms/cmctl/resources/build.sh create mode 100755 rpms/cmctl/resources/kubectl_complete-cert_manager create mode 100644 rpms/cmctl/resources/nfpm.yaml diff --git a/rpms/cmctl/metadata.yaml b/rpms/cmctl/metadata.yaml new file mode 100644 index 0000000..990ced2 --- /dev/null +++ b/rpms/cmctl/metadata.yaml @@ -0,0 +1,22 @@ +name: cmctl +github: cert-manager/cmctl +description: Command line tool to manage and configure cert-manager resources. +arch: amd64 +platform: linux +maintainer: The cert-manager Authors +homepage: https://github.com/cert-manager/cmctl +license: Apache-2.0 +dist_tag: true +builds: +- repository: + - almalinux/el9 + image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest + release: 1 + version: 2.6.1 +- repository: + - fedora/42 + - fedora/43 + - fedora/44 + image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest + release: 1 + version: 2.6.1 diff --git a/rpms/cmctl/resources/build.sh b/rpms/cmctl/resources/build.sh new file mode 100755 index 0000000..88a95dc --- /dev/null +++ b/rpms/cmctl/resources/build.sh @@ -0,0 +1,22 @@ +#!/usr/bin/bash + +set -e + +BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cert-manager/cmctl/releases/download/v${PACKAGE_VERSION}" + +wget -O /app/cmctl "${BASE_URL}/cmctl_linux_amd64" +wget -O /app/checksums.txt "${BASE_URL}/checksums.txt" + +# Upstream lists the asset name; check it against the local filename. +cd /app +grep ' cmctl_linux_amd64$' checksums.txt | sed 's/cmctl_linux_amd64$/cmctl/' | sha256sum --check --strict - +chmod +x /app/cmctl + +mkdir -p /app/completions +/app/cmctl completion bash > /app/completions/cmctl +/app/cmctl completion zsh > /app/completions/_cmctl +/app/cmctl completion fish > /app/completions/cmctl.fish + +envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml + +nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm diff --git a/rpms/cmctl/resources/kubectl_complete-cert_manager b/rpms/cmctl/resources/kubectl_complete-cert_manager new file mode 100755 index 0000000..859976c --- /dev/null +++ b/rpms/cmctl/resources/kubectl_complete-cert_manager @@ -0,0 +1,2 @@ +#!/usr/bin/env sh +exec kubectl cert-manager __complete "$@" diff --git a/rpms/cmctl/resources/nfpm.yaml b/rpms/cmctl/resources/nfpm.yaml new file mode 100644 index 0000000..f8cb6ae --- /dev/null +++ b/rpms/cmctl/resources/nfpm.yaml @@ -0,0 +1,57 @@ +# nfpm.yaml + +name: ${PACKAGE_NAME} +version: ${PACKAGE_VERSION} +release: ${PACKAGE_RELEASE} +arch: ${PACKAGE_ARCH} +platform: ${PACKAGE_PLATFORM} +section: default +priority: extra +description: "${PACKAGE_DESCRIPTION}" + +maintainer: ${PACKAGE_MAINTAINER} +homepage: ${PACKAGE_HOMEPAGE} +license: ${PACKAGE_LICENSE} + +disable_globbing: false + +replaces: + - cmctl + +provides: + - cmctl + +contents: + - src: /app/cmctl + dst: /usr/bin/cmctl + file_info: + mode: 0755 + owner: root + group: root + - src: cmctl + dst: /usr/bin/kubectl-cert_manager + type: symlink + - src: /app/resources/kubectl_complete-cert_manager + dst: /usr/bin/kubectl_complete-cert_manager + file_info: + mode: 0755 + owner: root + group: root + - src: /app/completions/cmctl + dst: /usr/share/bash-completion/completions/cmctl + file_info: + mode: 0644 + owner: root + group: root + - src: /app/completions/_cmctl + dst: /usr/share/zsh/site-functions/_cmctl + file_info: + mode: 0644 + owner: root + group: root + - src: /app/completions/cmctl.fish + dst: /usr/share/fish/vendor_completions.d/cmctl.fish + file_info: + mode: 0644 + owner: root + group: root