2 Commits

Author SHA1 Message Date
benvin 8df085b9ac Merge branch 'master' into benvin/nfpm_fedora
ci/woodpecker/pr/build-fedora44 Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-fedora42 Pipeline was successful
ci/woodpecker/pr/build-fedora43 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
2026-07-18 23:08:32 +10:00
unkinben 1f5330da76 feat: build nfpm for fedora
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
2026-05-16 22:56:28 +10:00
64 changed files with 317 additions and 1001 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -15,7 +15,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -15,7 +15,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -15,7 +15,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -15,7 +15,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -16,7 +16,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -16,7 +16,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -16,7 +16,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -16,7 +16,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
+1 -1
View File
@@ -16,7 +16,7 @@ steps:
resources:
requests:
memory: 512Mi
cpu: 2
cpu: 1
limits:
memory: 2Gi
cpu: 2
-5
View File
@@ -8,9 +8,4 @@ dev = [
"pytest>=8",
"jsonschema>=4",
"pyyaml>=6",
# tools/build's own script dependencies, so tests can import it
"typer",
"requests",
"hvac",
"cerberus",
]
-24
View File
@@ -1,24 +0,0 @@
name: argocd
github: argoproj/argo-cd
github_release_pattern: ^v3\.5\.
description: Declarative GitOps continuous delivery for Kubernetes - command line
client.
arch: amd64
platform: linux
maintainer: Argo Project
homepage: https://github.com/argoproj/argo-cd
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 3.5.3
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 3.5.3
-22
View File
@@ -1,22 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/argoproj/argo-cd/releases/download/v${PACKAGE_VERSION}"
wget -O /app/argocd "${BASE_URL}/argocd-linux-amd64"
wget -O /app/cli_checksums.txt "${BASE_URL}/cli_checksums.txt"
# Upstream lists the asset name; check it against the local filename.
cd /app
grep ' argocd-linux-amd64$' cli_checksums.txt | sed 's/argocd-linux-amd64$/argocd/' | sha256sum --check --strict -
chmod +x /app/argocd
mkdir -p /app/completions
/app/argocd completion bash > /app/completions/argocd
/app/argocd completion zsh > /app/completions/_argocd
/app/argocd completion fish > /app/completions/argocd.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
-48
View File
@@ -1,48 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- argocd
provides:
- argocd
contents:
- src: /app/argocd
dst: /usr/bin/argocd
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/argocd
dst: /usr/share/bash-completion/completions/argocd
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_argocd
dst: /usr/share/zsh/site-functions/_argocd
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/argocd.fish
dst: /usr/share/fish/vendor_completions.d/argocd.fish
file_info:
mode: 0644
owner: root
group: root
-22
View File
@@ -1,22 +0,0 @@
name: cmctl
github: cert-manager/cmctl
description: Command line tool to manage and configure cert-manager resources.
arch: amd64
platform: linux
maintainer: The cert-manager Authors
homepage: https://github.com/cert-manager/cmctl
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2.6.1
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2.6.1
-22
View File
@@ -1,22 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cert-manager/cmctl/releases/download/v${PACKAGE_VERSION}"
wget -O /app/cmctl "${BASE_URL}/cmctl_linux_amd64"
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
# Upstream lists the asset name; check it against the local filename.
cd /app
grep ' cmctl_linux_amd64$' checksums.txt | sed 's/cmctl_linux_amd64$/cmctl/' | sha256sum --check --strict -
chmod +x /app/cmctl
mkdir -p /app/completions
/app/cmctl completion bash > /app/completions/cmctl
/app/cmctl completion zsh > /app/completions/_cmctl
/app/cmctl completion fish > /app/completions/cmctl.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
@@ -1,2 +0,0 @@
#!/usr/bin/env sh
exec kubectl cert-manager __complete "$@"
-57
View File
@@ -1,57 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- cmctl
provides:
- cmctl
contents:
- src: /app/cmctl
dst: /usr/bin/cmctl
file_info:
mode: 0755
owner: root
group: root
- src: cmctl
dst: /usr/bin/kubectl-cert_manager
type: symlink
- src: /app/resources/kubectl_complete-cert_manager
dst: /usr/bin/kubectl_complete-cert_manager
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/cmctl
dst: /usr/share/bash-completion/completions/cmctl
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_cmctl
dst: /usr/share/zsh/site-functions/_cmctl
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/cmctl.fish
dst: /usr/share/fish/vendor_completions.d/cmctl.fish
file_info:
mode: 0644
owner: root
group: root
-15
View File
@@ -1,15 +0,0 @@
name: envoy
github: envoyproxy/envoy
description: Cloud-native high-performance edge/middle/service proxy.
arch: amd64
platform: linux
maintainer: Envoy Project Authors
homepage: https://github.com/envoyproxy/envoy
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 1.35.13
-18
View File
@@ -1,18 +0,0 @@
#!/usr/bin/bash
set -e
ASSET="envoy-${PACKAGE_VERSION}-linux-x86_64"
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/envoyproxy/envoy/releases/download/v${PACKAGE_VERSION}"
curl -fL -o /app/envoy "${BASE_URL}/${ASSET}"
curl -fL -o /app/checksums.txt.asc "${BASE_URL}/checksums.txt.asc"
# Upstream lists the asset under a temp build path; check it against the local filename.
cd /app
awk -v a="/${ASSET}" '$2 ~ a"$" {print $1" envoy"}' checksums.txt.asc | grep . | sha256sum --check --strict -
chmod +x /app/envoy
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
-38
View File
@@ -1,38 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- envoy
provides:
- envoy
# Files to include in the package
contents:
- src: /app/envoy
dst: /usr/bin/envoy
file_info:
mode: 0755
owner: root
group: root
# Scripts to run during installation/removal (optional)
# scripts:
# preinstall: ./scripts/preinstall.sh
# postinstall: ./scripts/postinstall.sh
# preremove: ./scripts/preremove.sh
# postremove: ./scripts/postremove.sh
-22
View File
@@ -1,22 +0,0 @@
name: go-cache-plugin
github: tailscale/go-cache-plugin
description: A GOCACHEPROG implementation that backs the Go build cache with S3.
arch: amd64
platform: linux
maintainer: Tailscale
homepage: https://github.com/tailscale/go-cache-plugin
license: BSD-3-Clause
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2026.7.22
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2026.7.22
-17
View File
@@ -1,17 +0,0 @@
#!/usr/bin/bash
set -e
# Upstream publishes no tags or releases; PACKAGE_VERSION dates this commit.
COMMIT=3031b5d01c50d2748a32c7c9386ea7049883f38e
# go.mod requires go 1.26.1
export GOTOOLCHAIN=go1.26.1
# Compile the go-cache-plugin binary using Go
GOBIN=/app go install github.com/tailscale/go-cache-plugin/cmd/go-cache-plugin@${COMMIT}
# Process nfpm.yaml with envsubst
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
# Build the RPM
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
-31
View File
@@ -1,31 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- go-cache-plugin
provides:
- go-cache-plugin
# Files to include in the package
contents:
- src: /app/go-cache-plugin
dst: /usr/bin/go-cache-plugin
file_info:
mode: 0755
owner: root
group: root
+15
View File
@@ -0,0 +1,15 @@
name: jellyfin-server
github: unknown/jellyfin-server
description: jellyfin-server package
dist_tag: false
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 10.10.7
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 10.10.7
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/bash
# Setup rpmbuild directory structure
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
# Install .NET SDK for building
dnf install dotnet-sdk-8.0 -y
# Download source files using spectool
spectool -g -R /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
# Copy additional files to SOURCES
cp /app/resources/fix-envfile-path.patch /root/rpmbuild/SOURCES/fix-envfile-path.patch
cp /app/resources/tmpfiles.conf /root/rpmbuild/SOURCES/tmpfiles.conf
# Build the RPM
rpmbuild -ba /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
# Copy the built RPMs to output directory
cp /root/rpmbuild/RPMS/x86_64/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm /app/dist/
cp /root/rpmbuild/SRPMS/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
@@ -0,0 +1,11 @@
--- a/debian/conf/jellyfin.service
+++ b/debian/conf/jellyfin.service
@@ -4,7 +4,7 @@ After = network-online.target
[Service]
Type = simple
-EnvironmentFile = /etc/default/jellyfin
+EnvironmentFile = /etc/jellyfin/jellyfin.env
User = jellyfin
Group = jellyfin
WorkingDirectory = /var/lib/jellyfin
@@ -0,0 +1,127 @@
%global debug_package %{nil}
%global jellyfin_version 10.10.7
%global jellyfin_packaging_timestamp 202504051515
%global jellyfin_packaging_version %{jellyfin_version}-%{jellyfin_packaging_timestamp}
%global dotnet_runtime %( \
if [ "%{_arch}" = "x86_64" ]; then \
echo -n "linux-x64"; \
elif [ "%{_arch}" = "aarch64" ]; then \
echo -n "linux-arm64"; \
else \
echo "Unsupported architecture: %{_arch}"; \
exit 1; \
fi \
)
Name: jellyfin-server
Version: %{jellyfin_version}
Release: 1
Summary: The Free Software Media System - Server Backend & API
License: GPL-2.0-or-later
URL: https://github.com/jellyfin/jellyfin
Source0: https://github.com/jellyfin/jellyfin/archive/refs/tags/v%{version}.tar.gz
Source1: https://github.com/jellyfin/jellyfin-packaging/archive/refs/tags/v%{jellyfin_packaging_version}.tar.gz
Source2: tmpfiles.conf
Patch0: fix-envfile-path.patch
ExclusiveArch: x86_64 aarch64
BuildRequires: dotnet-sdk-8.0
BuildRequires: git
BuildRequires: systemd-rpm-macros
Requires: aspnetcore-runtime-8.0
Requires: bash
Requires: fontconfig
Requires: jellyfin-ffmpeg-bin
Requires: sqlite
Recommends: jellyfin-web
Recommends: google-noto-fonts-common
%description
%{summary}.
%prep
tar --extract --file="%{SOURCE1}" --directory="%{_builddir}"
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}
patch -p1 -i "%{PATCH0}"
popd
%setup -q -n jellyfin-%{version}
%build
DOTNET_CLI_TELEMETRY_OPTOUT=1 \
DOTNET_SKIP_FIRST_TIME_EXPERIENCE=1 \
DOTNET_NOLOGO=1 \
dotnet \
publish \
Jellyfin.Server \
--configuration Release \
--output builddir \
--self-contained false \
--runtime %{dotnet_runtime} \
-p:DebugSymbols=false \
-p:DebugType=none
%install
install --directory "%{buildroot}%{_libdir}"
cp --recursive builddir "%{buildroot}%{_libdir}/jellyfin"
install --directory "%{buildroot}%{_bindir}"
ln --symbolic --force "%{_libdir}/jellyfin/jellyfin" "%{buildroot}%{_bindir}/jellyfin"
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}/debian/conf
install -D --mode=644 jellyfin.service "%{buildroot}%{_unitdir}/jellyfin.service"
install -D --mode=640 jellyfin "%{buildroot}%{_sysconfdir}/jellyfin/jellyfin.env"
popd
install -D --mode=0644 "%{SOURCE2}" "%{buildroot}%{_tmpfilesdir}/jellyfin.conf"
install --directory --mode=750 "%{buildroot}%{_localstatedir}/cache/jellyfin"
install --directory --mode=750 "%{buildroot}%{_sharedstatedir}/jellyfin"
find %{buildroot}
%files
%license LICENSE
%{_bindir}/jellyfin
%{_libdir}/jellyfin
%{_tmpfilesdir}/jellyfin.conf
%{_unitdir}/jellyfin.service
%defattr(640,jellyfin,jellyfin,750)
%dir %{_localstatedir}/cache/jellyfin
%dir %{_sharedstatedir}/jellyfin
%dir %{_sysconfdir}/jellyfin
%config(noreplace) %{_sysconfdir}/jellyfin/jellyfin.env
%pre
getent group jellyfin > /dev/null || groupadd --system jellyfin
getent passwd jellyfin > /dev/null || \
useradd --system --home-dir "%{_sharedstatedir}/jellyfin" --gid jellyfin \
-s /sbin/nologin -c "jellyfin daemon" jellyfin
exit 0
%post
%systemd_post jellyfin.service
%preun
%systemd_preun jellyfin.service
%postun
%systemd_postun jellyfin.service
@@ -0,0 +1 @@
d /var/log/jellyfin 0750 jellyfin jellyfin
+15
View File
@@ -0,0 +1,15 @@
name: jellyfin-web
github: unknown/jellyfin-web
description: jellyfin-web package
dist_tag: false
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 10.10.7
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 10.10.7
+18
View File
@@ -0,0 +1,18 @@
#!/usr/bin/bash
# Setup rpmbuild directory structure
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
# Install Node.js for building
dnf module enable nodejs:20 -y
dnf install nodejs npm -y
# Download source files using spectool
spectool -g -R /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
# Build the RPM
rpmbuild -ba /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
# Copy the built RPMs to output directory
cp /root/rpmbuild/RPMS/noarch/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.noarch.rpm /app/dist/
cp /root/rpmbuild/SRPMS/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
@@ -0,0 +1,43 @@
%global jellyfin_version 10.10.7
Name: jellyfin-web
Version: %{jellyfin_version}
Release: 1
Summary: The Free Software Media System - Official Web Client
License: GPL-2.0-or-later
URL: https://github.com/jellyfin/jellyfin-web
Source0: https://github.com/jellyfin/jellyfin-web/archive/refs/tags/v%{version}.tar.gz
BuildArch: noarch
BuildRequires: git
BuildRequires: nodejs
BuildRequires: npm
%description
%{summary}.
%prep
%setup -q -n jellyfin-web-%{version}
%build
SKIP_PREPARE=1 npm ci --no-audit --no-fund --no-update-notifier
npm run build:production
%install
install --directory "%{buildroot}%{_datadir}/jellyfin/web"
cp --recursive dist/* "%{buildroot}%{_datadir}/jellyfin/web"
%files
%license LICENSE
%{_datadir}/jellyfin/web
-23
View File
@@ -1,23 +0,0 @@
name: k8up
github: k8up-io/k8up
github_release_pattern: ^v2\.
description: K8up Kubernetes backup operator command line client.
arch: amd64
platform: linux
maintainer: K8up Authors
homepage: https://github.com/k8up-io/k8up
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2.16.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 2.16.0
-17
View File
@@ -1,17 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/k8up-io/k8up/releases/download/v${PACKAGE_VERSION}"
TARBALL="k8up_${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ k8up
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
-16
View File
@@ -1,16 +0,0 @@
#compdef k8up
local -a opts
local cur
cur=${words[-1]}
if [[ "$cur" == "-"* ]]; then
opts=("${(@f)$(${words[@]:0:#words[@]-1} ${cur} --generate-bash-completion 2>/dev/null)}")
else
opts=("${(@f)$(${words[@]:0:#words[@]-1} --generate-bash-completion 2>/dev/null)}")
fi
if [[ "${opts[1]}" != "" ]]; then
_describe 'values' opts
else
_files
fi
-34
View File
@@ -1,34 +0,0 @@
: ${PROG:=$(basename ${BASH_SOURCE})}
# Macs have bash3 for which the bash-completion package doesn't include
# _init_completion. This is a minimal version of that function.
_cli_init_completion() {
COMPREPLY=()
_get_comp_words_by_ref "$@" cur prev words cword
}
_cli_bash_autocomplete() {
if [[ "${COMP_WORDS[0]}" != "source" ]]; then
local cur opts base words
COMPREPLY=()
cur="${COMP_WORDS[COMP_CWORD]}"
if declare -F _init_completion >/dev/null 2>&1; then
_init_completion -n "=:" || return
else
_cli_init_completion -n "=:" || return
fi
words=("${words[@]:0:$cword}")
if [[ "$cur" == "-"* ]]; then
requestComp="${words[*]} ${cur} --generate-bash-completion"
else
requestComp="${words[*]} --generate-bash-completion"
fi
opts=$(eval "${requestComp}" 2>/dev/null)
COMPREPLY=($(compgen -W "${opts}" -- ${cur}))
return 0
fi
}
complete -o bashdefault -o default -o nospace -F _cli_bash_autocomplete $PROG
unset PROG
-11
View File
@@ -1,11 +0,0 @@
function __k8up_complete
set -l words (commandline -opc)
set -l cur (commandline -ct)
if string match -q -- '-*' $cur
$words $cur --generate-bash-completion 2>/dev/null
else
$words --generate-bash-completion 2>/dev/null
end
end
complete -c k8up -f -a '(__k8up_complete)'
-48
View File
@@ -1,48 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- k8up
provides:
- k8up
contents:
- src: /app/k8up
dst: /usr/bin/k8up
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/completions/k8up
dst: /usr/share/bash-completion/completions/k8up
file_info:
mode: 0644
owner: root
group: root
- src: /app/resources/completions/_k8up
dst: /usr/share/zsh/site-functions/_k8up
file_info:
mode: 0644
owner: root
group: root
- src: /app/resources/completions/k8up.fish
dst: /usr/share/fish/vendor_completions.d/k8up.fish
file_info:
mode: 0644
owner: root
group: root
+2 -9
View File
@@ -12,16 +12,9 @@ builds:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: 0.8.0
version: 0.6.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.8.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.8.0
version: 0.6.0
-22
View File
@@ -1,22 +0,0 @@
name: kubectl-cnpg
github: cloudnative-pg/cloudnative-pg
description: CloudNativePG kubectl plugin.
arch: amd64
platform: linux
maintainer: The CloudNativePG Contributors
homepage: https://github.com/cloudnative-pg/cloudnative-pg
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 1.30.1
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 1.30.1
-22
View File
@@ -1,22 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cloudnative-pg/cloudnative-pg/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-cnpg_${PACKAGE_VERSION}_linux_x86_64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/cnpg-${PACKAGE_VERSION}-checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-cnpg
mkdir -p /app/completions
/app/kubectl-cnpg completion bash > /app/completions/kubectl-cnpg
/app/kubectl-cnpg completion zsh > /app/completions/_kubectl-cnpg
/app/kubectl-cnpg completion fish > /app/completions/kubectl-cnpg.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
@@ -1,2 +0,0 @@
#!/usr/bin/env sh
exec kubectl cnpg __complete "$@"
-54
View File
@@ -1,54 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-cnpg
provides:
- kubectl-cnpg
contents:
- src: /app/kubectl-cnpg
dst: /usr/bin/kubectl-cnpg
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-cnpg
dst: /usr/bin/kubectl_complete-cnpg
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/kubectl-cnpg
dst: /usr/share/bash-completion/completions/kubectl-cnpg
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_kubectl-cnpg
dst: /usr/share/zsh/site-functions/_kubectl-cnpg
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/kubectl-cnpg.fish
dst: /usr/share/fish/vendor_completions.d/kubectl-cnpg.fish
file_info:
mode: 0644
owner: root
group: root
-22
View File
@@ -1,22 +0,0 @@
name: kubectl-tree
github: ahmetb/kubectl-tree
description: kubectl plugin to browse Kubernetes object hierarchies as a tree.
arch: amd64
platform: linux
maintainer: Ahmet Alp Balkan
homepage: https://github.com/ahmetb/kubectl-tree
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.6.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.6.0
-17
View File
@@ -1,17 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/ahmetb/kubectl-tree/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-tree_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/kubectl-tree_${PACKAGE_VERSION}_checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-tree
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
@@ -1,7 +0,0 @@
#!/usr/bin/env sh
# kubectl-tree only completes flags; its KIND NAME args match kubectl get
for arg in "$@"; do last=$arg; done
case "$last" in
-*) exec kubectl tree __complete "$@" ;;
*) exec kubectl __complete get "$@" ;;
esac
-36
View File
@@ -1,36 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-tree
provides:
- kubectl-tree
contents:
- src: /app/kubectl-tree
dst: /usr/bin/kubectl-tree
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-tree
dst: /usr/bin/kubectl_complete-tree
file_info:
mode: 0755
owner: root
group: root
-22
View File
@@ -1,22 +0,0 @@
name: kubectl-view-secret
github: elsesiy/kubectl-view-secret
description: Kubectl plugin to decode Kubernetes secrets.
arch: amd64
platform: linux
maintainer: Jonas-Taha El Sesiy
homepage: https://github.com/elsesiy/kubectl-view-secret
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.16.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: 0.16.0
@@ -1,24 +0,0 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/elsesiy/kubectl-view-secret/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-view-secret_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/kubectl-view-secret_${PACKAGE_VERSION}_checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-view-secret
mkdir -p /app/completions
# kubectl resolves `kubectl view-secret` to kubectl-view_secret; upstream completions target "view-secret".
mv /app/kubectl-view-secret /app/kubectl-view_secret
/app/kubectl-view_secret completion bash | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret
/app/kubectl-view_secret completion zsh | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/_kubectl-view_secret
/app/kubectl-view_secret completion fish | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
@@ -1,2 +0,0 @@
#!/usr/bin/env sh
exec kubectl view-secret __complete "$@"
@@ -1,54 +0,0 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-view-secret
provides:
- kubectl-view-secret
contents:
- src: /app/kubectl-view_secret
dst: /usr/bin/kubectl-view_secret
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-view_secret
dst: /usr/bin/kubectl_complete-view_secret
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/kubectl-view_secret
dst: /usr/share/bash-completion/completions/kubectl-view_secret
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_kubectl-view_secret
dst: /usr/share/zsh/site-functions/_kubectl-view_secret
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/kubectl-view_secret.fish
dst: /usr/share/fish/vendor_completions.d/kubectl-view_secret.fish
file_info:
mode: 0644
owner: root
group: root
+2 -2
View File
@@ -13,9 +13,9 @@ builds:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: '26.2'
version: '26.1'
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: 1
version: '26.2'
version: '26.1'
+2 -6
View File
@@ -2,10 +2,6 @@
set -e
# Download the pre-built RPM from GitHub releases.
# Upstream always publishes the release-1 asset (nzbget-<version>-1.x86_64.rpm);
# the source URL must use the upstream asset name, not PACKAGE_RELEASE, which
# carries the dist tag (e.g. 1.el9) and does not exist upstream. Only the local
# output filename is dist-tagged, mirroring the code-server package.
# Download the pre-built RPM from GitHub releases
curl -L -o /app/dist/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm \
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-1.x86_64.rpm
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm
-38
View File
@@ -1,38 +0,0 @@
# puppet-initial
A firstrun bootstrap script and oneshot systemd service that initialises a
freshly-provisioned host into Puppet:
1. Sets the FQDN under `.main.unkin.net`.
2. Fetches the Puppet CA certificate from the CA service.
3. Registers the node with a noop agent run against the CA.
4. Runs the agent a few times against the compile master, then enables the
`puppet` service and disables itself.
## Puppet CA endpoint
The CA endpoint defaults to the in-cluster puppetserver CA service
`puppetca.k8s.syd1.au.unkin.net:8140` (serving the standard
`/puppet-ca/v1/certificate/ca` API).
It is overridable via the environment. The `puppet-initial.service` unit reads
`/etc/sysconfig/puppet-initial` (`EnvironmentFile=-`, so the file is optional),
which the RPM ships as a commented `%config(noreplace)` example:
| Variable | Default | Purpose |
|-----------------|----------------------------------|-------------------------------------------------------------|
| `PUPPETCA_HOST` | `puppetca.k8s.syd1.au.unkin.net` | CA hostname (CA cert fetch + `--server` for registration). |
| `PUPPETCA_PORT` | `8140` | CA API port. |
### Overriding from kickstart
A kickstart `%post` can point a host at a different CA without rebuilding the
RPM by writing the sysconfig file before the service starts:
```bash
%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF
```
+2 -2
View File
@@ -11,9 +11,9 @@ builds:
release: '1'
repository:
- almalinux/el8
version: 1.0.5
version: 1.0.3
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 1.0.5
version: 1.0.3
+1 -8
View File
@@ -15,7 +15,7 @@ license: ${PACKAGE_LICENSE}
disable_globbing: false
depends:
- openvox-agent
- puppet-agent
# Files to include in the package
contents:
@@ -31,13 +31,6 @@ contents:
mode: 0644
owner: root
group: root
- src: /app/resources/puppet-initial.sysconfig
dst: /etc/sysconfig/puppet-initial
type: config|noreplace
file_info:
mode: 0644
owner: root
group: root
# Scripts to run during installation/removal (optional)
scripts:
+2 -9
View File
@@ -1,21 +1,14 @@
#!/bin/bash
# Puppet CA endpoint. Overridable via the environment (systemd reads
# /etc/sysconfig/puppet-initial via EnvironmentFile), so kickstart %post can
# point a host at a different CA without rebuilding the RPM. Defaults to the
# in-cluster puppetserver CA service.
PUPPETCA_HOST="${PUPPETCA_HOST:-puppetca.k8s.syd1.au.unkin.net}"
PUPPETCA_PORT="${PUPPETCA_PORT:-8140}"
# Ensure the hostname is set
hostnamectl set-hostname $(hostname -s).main.unkin.net
grep '^HOSTNAME=' /etc/sysconfig/network | cut -d= -f2 | grep -q '\.' || sed -i 's/^\(HOSTNAME=[^\.]*\)$/\1.main.unkin.net/' /etc/sysconfig/network
# Install CA for Puppet
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate "https://${PUPPETCA_HOST}:${PUPPETCA_PORT}/puppet-ca/v1/certificate/ca" -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate https://puppetca.query.consul:8140/puppet-ca/v1/certificate/ca -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
# Registering to Puppet server
/opt/puppetlabs/bin/puppet agent --test --server "${PUPPETCA_HOST}" --noop --onetime --no-daemonize --verbose
/opt/puppetlabs/bin/puppet agent --test --server puppetca.query.consul --noop --onetime --no-daemonize --verbose
# Running Puppet agent five times with a 30-second gap between each run, stop puppet service at the end of each run
for i in {1..5}; do
@@ -5,7 +5,6 @@ Wants=network-online.target
[Service]
Type=simple
EnvironmentFile=-/etc/sysconfig/puppet-initial
ExecStart=/usr/local/bin/puppet-initial
RemainAfterExit=true
ExecStop=/bin/true
@@ -1,13 +0,0 @@
# Environment overrides for the puppet-initial firstrun bootstrap.
# Read by the puppet-initial.service unit (EnvironmentFile=-/etc/sysconfig/puppet-initial).
# A kickstart %post can write this file to point a host at a different Puppet CA
# without rebuilding the RPM. All values are optional; the defaults below match
# the shipped in-cluster puppetserver CA service.
# Hostname of the Puppet CA service. Used both to fetch the CA certificate
# (https://<host>:<port>/puppet-ca/v1/certificate/ca) and as --server for the
# initial noop agent registration run.
#PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
# Port the Puppet CA API listens on.
#PUPPETCA_PORT=8140
+3 -3
View File
@@ -12,16 +12,16 @@ builds:
release: '1'
repository:
- almalinux/el8
version: 2026.10.2
version: 2025.07.13
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 2026.10.2
version: 2025.07.13
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- fedora/42
- fedora/43
- fedora/44
version: 2026.10.2
version: 2025.07.13
@@ -1,15 +1,9 @@
#!/usr/bin/bash
set -euo pipefail
set -e
# Download the CA chain from vault; openssl verifies we got a certificate, not an error page
fetch_ca() {
curl -fsSL -o "$2" "https://vault.query.consul:8200/v1/$1/ca/pem"
openssl x509 -in "$2" -noout -subject
}
fetch_ca pki_root /app/UNKIN_ROOTCA_2024.crt
fetch_ca pki_int /app/UNKIN_INTCA_2024.crt
# Download the CA certificate from vault
curl -L -o /app/UNKIN_ROOTCA_2024.crt https://vault.query.consul:8200/v1/pki_root/ca/pem
# Process the nfpm.yaml template with environment variables
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
@@ -29,12 +29,6 @@ contents:
mode: 0755
owner: root
group: root
- src: /app/UNKIN_INTCA_2024.crt
dst: /etc/pki/ca-trust/source/anchors/UNKIN_INTCA_2024.crt
file_info:
mode: 0755
owner: root
group: root
# Scripts to run during installation/removal (optional)
scripts:
-76
View File
@@ -1,76 +0,0 @@
"""Tests for the RPM filename tools/build reconstructs when probing artifactapi.
The expected values below were captured from the real nfpm; they are the names
the publish step actually uploads, so the existence probe has to ask for
exactly these or it 404s and rebuilds forever.
"""
import importlib.machinery
import importlib.util
from pathlib import Path
import pytest
REPO_ROOT = Path(__file__).parent.parent
_loader = importlib.machinery.SourceFileLoader(
"rpmbuilder_build", str(REPO_ROOT / "tools" / "build")
)
_spec = importlib.util.spec_from_loader(_loader.name, _loader)
build = importlib.util.module_from_spec(_spec)
_loader.exec_module(build)
# nfpm output for `version: <input>` with release 1, arch amd64
NFPM_VERSIONS = [
("2025.08.03", "2025.8.3"),
("2025.07.13", "2025.7.13"),
("1.05.0", "1.5.0"),
("10.02.01", "10.2.1"),
("0.0.09", "0.0.9"),
("0.6.1", "0.6.1"),
("1.2.3", "1.2.3"),
("1.05", "1.5.0"),
("08", "8.0.0"),
("1.0.0-rc1", "1.0.0~rc1"),
("1.05.0-rc1", "1.5.0~rc1"),
("1.0.0-rc.1", "1.0.0~rc.1"),
# not semver: nfpm leaves these verbatim, so we must too
("1.02.3.4", "1.02.3.4"),
("2025.08.03.01", "2025.08.03.01"),
("1.2.3.4", "1.2.3.4"),
("1.0.0-rc.01", "1.0.0-rc.01"),
]
@pytest.mark.parametrize("version,expected", NFPM_VERSIONS)
def test_nfpm_rpm_version(version, expected):
assert build.nfpm_rpm_version(version) == expected
def test_rpm_file_name_matches_nfpm_output():
assert (
build.rpm_file_name("nzbget_exporter", "2025.08.03", "1.el9", "amd64")
== "nzbget_exporter-2025.8.3-1.el9.x86_64.rpm"
)
def test_check_package_exists_probes_published_filename(monkeypatch):
"""A zero-padded version must not probe a filename nfpm can never produce."""
probed = []
class _Session:
def get(self, url, timeout=None):
probed.append(url)
return type("R", (), {"status_code": 404})()
monkeypatch.setattr(build, "_artifactapi_session", _Session())
assert not build.check_package_exists(
"nzbget_exporter", "2025.08.03", "1.el9", "almalinux/el9", "amd64"
)
expected = (
"https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rpm-vendor-el9"
"/files/Packages/nzbget_exporter-2025.8.3-1.el9.x86_64.rpm"
)
assert probed == [expected]
+39 -33
View File
@@ -517,38 +517,37 @@ def get_github_token() -> str:
# ==================== GITEA API FUNCTIONS ====================
def nfpm_rpm_version(version: str) -> str:
def normalize_version(version: str) -> str:
"""
Render a metadata version the way nfpm renders it into an RPM filename.
nfpm re-renders any semver-parseable version: leading zeros are dropped,
missing components padded to three, and the prerelease joined with '~'.
Anything semver cannot parse (four or more components, non-numeric
components, a numeric prerelease identifier with a leading zero) is used
verbatim.
Normalize version string by removing leading zeros from numeric components.
Gitea automatically does this normalization.
Examples:
"2025.08.03" -> "2025.8.3"
"1.05" -> "1.5.0"
"1.2.3-rc1" -> "1.2.3~rc1"
"1.02.3.4" -> "1.02.3.4" (not semver, left alone)
"1.05.0" -> "1.5.0"
"0.6.1" -> "0.6.1" (no change needed)
Args:
version: Original version string
Returns:
Normalized version string
"""
core, sep, prerelease = version.partition('-')
if sep and not prerelease:
return version
import re
components = core.split('.')
if len(components) > 3 or not all(c.isdigit() for c in components):
return version
# Split by common separators and normalize each numeric part
parts = re.split(r'([.\-_])', version)
normalized_parts = []
# semver rejects numeric prerelease identifiers with a leading zero
if any(i.isdigit() and len(i) > 1 and i.startswith('0')
for i in prerelease.split('.')):
return version
for part in parts:
# If this part is purely numeric and has leading zeros, remove them
if part.isdigit() and len(part) > 1 and part.startswith('0'):
# Remove leading zeros but keep at least one digit
normalized_parts.append(str(int(part)))
else:
normalized_parts.append(part)
components += ['0'] * (3 - len(components))
rendered = '.'.join(str(int(c)) for c in components)
return f"{rendered}~{prerelease}" if prerelease else rendered
return ''.join(normalized_parts)
def get_rpm_dist_tag(distro: str) -> str:
@@ -599,14 +598,6 @@ def get_rpm_arch(arch: str) -> str:
return {'amd64': 'x86_64', 'arm64': 'aarch64'}.get(arch, arch)
def rpm_file_name(package_name: str, version: str, release: str, arch: str) -> str:
"""Filename nfpm produces for this package, and therefore the published name."""
return (
f"{package_name}-{nfpm_rpm_version(version)}-{release}"
f".{get_rpm_arch(arch)}.rpm"
)
def check_package_exists(
package_name: str,
version: str,
@@ -636,7 +627,7 @@ def check_package_exists(
base_url = os.getenv('ARTIFACTAPI_URL', 'https://artifactapi.k8s.syd1.au.unkin.net')
repo = get_vendor_repo(distro)
rpm_file = rpm_file_name(package_name, version, release, arch)
rpm_file = f"{package_name}-{version}-{release}.{get_rpm_arch(arch)}.rpm"
url = f"{base_url}/api/v2/remotes/{repo}/files/Packages/{rpm_file}"
try:
@@ -660,6 +651,21 @@ def check_package_exists(
return False
def get_package_full_name(package_name: str, version: str, release: str) -> str:
"""
Generate the full package name as used in the registry.
Args:
package_name: Package name
version: Version string
release: Release number
Returns:
Full package name string
"""
return f"{package_name}-{version}-{release}"
# ==================== DOCKER FUNCTIONS ====================
def check_docker_available() -> bool: