Compare commits
17 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| cb3f3efd5b | |||
| ed50884409 | |||
| 4b12f2b718 | |||
| ddfcf6c846 | |||
| 213c218d1e | |||
| 6678762b0c | |||
| 05f44b83c4 | |||
| abcfe87090 | |||
| 0dc95f395c | |||
| 0922a5c4e3 | |||
| 70523ae938 | |||
| df7490388e | |||
| 1c316e875a | |||
| 327a7c367a | |||
| 0c5684bd9e | |||
| c6df3a7619 | |||
| 3ba9f77c10 |
@@ -15,7 +15,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -15,7 +15,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -15,7 +15,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -15,7 +15,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -15,7 +15,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -16,7 +16,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -16,7 +16,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -16,7 +16,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -16,7 +16,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -16,7 +16,7 @@ steps:
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
cpu: 2
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
@@ -8,4 +8,9 @@ dev = [
|
||||
"pytest>=8",
|
||||
"jsonschema>=4",
|
||||
"pyyaml>=6",
|
||||
# tools/build's own script dependencies, so tests can import it
|
||||
"typer",
|
||||
"requests",
|
||||
"hvac",
|
||||
"cerberus",
|
||||
]
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
name: argocd
|
||||
github: argoproj/argo-cd
|
||||
github_release_pattern: ^v3\.5\.
|
||||
description: Declarative GitOps continuous delivery for Kubernetes - command line
|
||||
client.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: Argo Project
|
||||
homepage: https://github.com/argoproj/argo-cd
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 3.5.3
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 3.5.3
|
||||
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/argoproj/argo-cd/releases/download/v${PACKAGE_VERSION}"
|
||||
|
||||
wget -O /app/argocd "${BASE_URL}/argocd-linux-amd64"
|
||||
wget -O /app/cli_checksums.txt "${BASE_URL}/cli_checksums.txt"
|
||||
|
||||
# Upstream lists the asset name; check it against the local filename.
|
||||
cd /app
|
||||
grep ' argocd-linux-amd64$' cli_checksums.txt | sed 's/argocd-linux-amd64$/argocd/' | sha256sum --check --strict -
|
||||
chmod +x /app/argocd
|
||||
|
||||
mkdir -p /app/completions
|
||||
/app/argocd completion bash > /app/completions/argocd
|
||||
/app/argocd completion zsh > /app/completions/_argocd
|
||||
/app/argocd completion fish > /app/completions/argocd.fish
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
@@ -0,0 +1,48 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- argocd
|
||||
|
||||
provides:
|
||||
- argocd
|
||||
|
||||
contents:
|
||||
- src: /app/argocd
|
||||
dst: /usr/bin/argocd
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/argocd
|
||||
dst: /usr/share/bash-completion/completions/argocd
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/_argocd
|
||||
dst: /usr/share/zsh/site-functions/_argocd
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/argocd.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/argocd.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
@@ -0,0 +1,22 @@
|
||||
name: cmctl
|
||||
github: cert-manager/cmctl
|
||||
description: Command line tool to manage and configure cert-manager resources.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: The cert-manager Authors
|
||||
homepage: https://github.com/cert-manager/cmctl
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2.6.1
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2.6.1
|
||||
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cert-manager/cmctl/releases/download/v${PACKAGE_VERSION}"
|
||||
|
||||
wget -O /app/cmctl "${BASE_URL}/cmctl_linux_amd64"
|
||||
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
|
||||
|
||||
# Upstream lists the asset name; check it against the local filename.
|
||||
cd /app
|
||||
grep ' cmctl_linux_amd64$' checksums.txt | sed 's/cmctl_linux_amd64$/cmctl/' | sha256sum --check --strict -
|
||||
chmod +x /app/cmctl
|
||||
|
||||
mkdir -p /app/completions
|
||||
/app/cmctl completion bash > /app/completions/cmctl
|
||||
/app/cmctl completion zsh > /app/completions/_cmctl
|
||||
/app/cmctl completion fish > /app/completions/cmctl.fish
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
+2
@@ -0,0 +1,2 @@
|
||||
#!/usr/bin/env sh
|
||||
exec kubectl cert-manager __complete "$@"
|
||||
@@ -0,0 +1,57 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- cmctl
|
||||
|
||||
provides:
|
||||
- cmctl
|
||||
|
||||
contents:
|
||||
- src: /app/cmctl
|
||||
dst: /usr/bin/cmctl
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: cmctl
|
||||
dst: /usr/bin/kubectl-cert_manager
|
||||
type: symlink
|
||||
- src: /app/resources/kubectl_complete-cert_manager
|
||||
dst: /usr/bin/kubectl_complete-cert_manager
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/cmctl
|
||||
dst: /usr/share/bash-completion/completions/cmctl
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/_cmctl
|
||||
dst: /usr/share/zsh/site-functions/_cmctl
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/cmctl.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/cmctl.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
@@ -0,0 +1,15 @@
|
||||
name: envoy
|
||||
github: envoyproxy/envoy
|
||||
description: Cloud-native high-performance edge/middle/service proxy.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: Envoy Project Authors
|
||||
homepage: https://github.com/envoyproxy/envoy
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 1.35.13
|
||||
Executable
+18
@@ -0,0 +1,18 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
ASSET="envoy-${PACKAGE_VERSION}-linux-x86_64"
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/envoyproxy/envoy/releases/download/v${PACKAGE_VERSION}"
|
||||
|
||||
curl -fL -o /app/envoy "${BASE_URL}/${ASSET}"
|
||||
curl -fL -o /app/checksums.txt.asc "${BASE_URL}/checksums.txt.asc"
|
||||
|
||||
# Upstream lists the asset under a temp build path; check it against the local filename.
|
||||
cd /app
|
||||
awk -v a="/${ASSET}" '$2 ~ a"$" {print $1" envoy"}' checksums.txt.asc | grep . | sha256sum --check --strict -
|
||||
chmod +x /app/envoy
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
@@ -0,0 +1,38 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- envoy
|
||||
|
||||
provides:
|
||||
- envoy
|
||||
|
||||
# Files to include in the package
|
||||
contents:
|
||||
- src: /app/envoy
|
||||
dst: /usr/bin/envoy
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
# Scripts to run during installation/removal (optional)
|
||||
# scripts:
|
||||
# preinstall: ./scripts/preinstall.sh
|
||||
# postinstall: ./scripts/postinstall.sh
|
||||
# preremove: ./scripts/preremove.sh
|
||||
# postremove: ./scripts/postremove.sh
|
||||
@@ -0,0 +1,22 @@
|
||||
name: go-cache-plugin
|
||||
github: tailscale/go-cache-plugin
|
||||
description: A GOCACHEPROG implementation that backs the Go build cache with S3.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: Tailscale
|
||||
homepage: https://github.com/tailscale/go-cache-plugin
|
||||
license: BSD-3-Clause
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2026.7.22
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2026.7.22
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/bash
|
||||
set -e
|
||||
|
||||
# Upstream publishes no tags or releases; PACKAGE_VERSION dates this commit.
|
||||
COMMIT=3031b5d01c50d2748a32c7c9386ea7049883f38e
|
||||
|
||||
# go.mod requires go 1.26.1
|
||||
export GOTOOLCHAIN=go1.26.1
|
||||
|
||||
# Compile the go-cache-plugin binary using Go
|
||||
GOBIN=/app go install github.com/tailscale/go-cache-plugin/cmd/go-cache-plugin@${COMMIT}
|
||||
|
||||
# Process nfpm.yaml with envsubst
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
# Build the RPM
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
@@ -0,0 +1,31 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- go-cache-plugin
|
||||
|
||||
provides:
|
||||
- go-cache-plugin
|
||||
|
||||
# Files to include in the package
|
||||
contents:
|
||||
- src: /app/go-cache-plugin
|
||||
dst: /usr/bin/go-cache-plugin
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
@@ -1,15 +0,0 @@
|
||||
name: jellyfin-server
|
||||
github: unknown/jellyfin-server
|
||||
description: jellyfin-server package
|
||||
dist_tag: false
|
||||
builds:
|
||||
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el8
|
||||
version: 10.10.7
|
||||
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el9
|
||||
version: 10.10.7
|
||||
@@ -1,21 +0,0 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
# Setup rpmbuild directory structure
|
||||
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
|
||||
|
||||
# Install .NET SDK for building
|
||||
dnf install dotnet-sdk-8.0 -y
|
||||
|
||||
# Download source files using spectool
|
||||
spectool -g -R /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
|
||||
|
||||
# Copy additional files to SOURCES
|
||||
cp /app/resources/fix-envfile-path.patch /root/rpmbuild/SOURCES/fix-envfile-path.patch
|
||||
cp /app/resources/tmpfiles.conf /root/rpmbuild/SOURCES/tmpfiles.conf
|
||||
|
||||
# Build the RPM
|
||||
rpmbuild -ba /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
|
||||
|
||||
# Copy the built RPMs to output directory
|
||||
cp /root/rpmbuild/RPMS/x86_64/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm /app/dist/
|
||||
cp /root/rpmbuild/SRPMS/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
|
||||
@@ -1,11 +0,0 @@
|
||||
--- a/debian/conf/jellyfin.service
|
||||
+++ b/debian/conf/jellyfin.service
|
||||
@@ -4,7 +4,7 @@ After = network-online.target
|
||||
|
||||
[Service]
|
||||
Type = simple
|
||||
-EnvironmentFile = /etc/default/jellyfin
|
||||
+EnvironmentFile = /etc/jellyfin/jellyfin.env
|
||||
User = jellyfin
|
||||
Group = jellyfin
|
||||
WorkingDirectory = /var/lib/jellyfin
|
||||
@@ -1,127 +0,0 @@
|
||||
%global debug_package %{nil}
|
||||
|
||||
%global jellyfin_version 10.10.7
|
||||
%global jellyfin_packaging_timestamp 202504051515
|
||||
%global jellyfin_packaging_version %{jellyfin_version}-%{jellyfin_packaging_timestamp}
|
||||
|
||||
%global dotnet_runtime %( \
|
||||
if [ "%{_arch}" = "x86_64" ]; then \
|
||||
echo -n "linux-x64"; \
|
||||
elif [ "%{_arch}" = "aarch64" ]; then \
|
||||
echo -n "linux-arm64"; \
|
||||
else \
|
||||
echo "Unsupported architecture: %{_arch}"; \
|
||||
exit 1; \
|
||||
fi \
|
||||
)
|
||||
|
||||
Name: jellyfin-server
|
||||
Version: %{jellyfin_version}
|
||||
Release: 1
|
||||
Summary: The Free Software Media System - Server Backend & API
|
||||
|
||||
|
||||
License: GPL-2.0-or-later
|
||||
URL: https://github.com/jellyfin/jellyfin
|
||||
Source0: https://github.com/jellyfin/jellyfin/archive/refs/tags/v%{version}.tar.gz
|
||||
Source1: https://github.com/jellyfin/jellyfin-packaging/archive/refs/tags/v%{jellyfin_packaging_version}.tar.gz
|
||||
Source2: tmpfiles.conf
|
||||
Patch0: fix-envfile-path.patch
|
||||
|
||||
|
||||
ExclusiveArch: x86_64 aarch64
|
||||
|
||||
|
||||
BuildRequires: dotnet-sdk-8.0
|
||||
BuildRequires: git
|
||||
BuildRequires: systemd-rpm-macros
|
||||
|
||||
|
||||
Requires: aspnetcore-runtime-8.0
|
||||
Requires: bash
|
||||
Requires: fontconfig
|
||||
Requires: jellyfin-ffmpeg-bin
|
||||
Requires: sqlite
|
||||
|
||||
|
||||
Recommends: jellyfin-web
|
||||
Recommends: google-noto-fonts-common
|
||||
|
||||
|
||||
%description
|
||||
%{summary}.
|
||||
|
||||
|
||||
%prep
|
||||
tar --extract --file="%{SOURCE1}" --directory="%{_builddir}"
|
||||
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}
|
||||
patch -p1 -i "%{PATCH0}"
|
||||
popd
|
||||
%setup -q -n jellyfin-%{version}
|
||||
|
||||
|
||||
%build
|
||||
DOTNET_CLI_TELEMETRY_OPTOUT=1 \
|
||||
DOTNET_SKIP_FIRST_TIME_EXPERIENCE=1 \
|
||||
DOTNET_NOLOGO=1 \
|
||||
dotnet \
|
||||
publish \
|
||||
Jellyfin.Server \
|
||||
--configuration Release \
|
||||
--output builddir \
|
||||
--self-contained false \
|
||||
--runtime %{dotnet_runtime} \
|
||||
-p:DebugSymbols=false \
|
||||
-p:DebugType=none
|
||||
|
||||
|
||||
%install
|
||||
install --directory "%{buildroot}%{_libdir}"
|
||||
cp --recursive builddir "%{buildroot}%{_libdir}/jellyfin"
|
||||
|
||||
install --directory "%{buildroot}%{_bindir}"
|
||||
ln --symbolic --force "%{_libdir}/jellyfin/jellyfin" "%{buildroot}%{_bindir}/jellyfin"
|
||||
|
||||
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}/debian/conf
|
||||
install -D --mode=644 jellyfin.service "%{buildroot}%{_unitdir}/jellyfin.service"
|
||||
install -D --mode=640 jellyfin "%{buildroot}%{_sysconfdir}/jellyfin/jellyfin.env"
|
||||
popd
|
||||
|
||||
install -D --mode=0644 "%{SOURCE2}" "%{buildroot}%{_tmpfilesdir}/jellyfin.conf"
|
||||
|
||||
install --directory --mode=750 "%{buildroot}%{_localstatedir}/cache/jellyfin"
|
||||
install --directory --mode=750 "%{buildroot}%{_sharedstatedir}/jellyfin"
|
||||
find %{buildroot}
|
||||
|
||||
|
||||
%files
|
||||
%license LICENSE
|
||||
%{_bindir}/jellyfin
|
||||
%{_libdir}/jellyfin
|
||||
%{_tmpfilesdir}/jellyfin.conf
|
||||
%{_unitdir}/jellyfin.service
|
||||
%defattr(640,jellyfin,jellyfin,750)
|
||||
%dir %{_localstatedir}/cache/jellyfin
|
||||
%dir %{_sharedstatedir}/jellyfin
|
||||
%dir %{_sysconfdir}/jellyfin
|
||||
%config(noreplace) %{_sysconfdir}/jellyfin/jellyfin.env
|
||||
|
||||
|
||||
%pre
|
||||
getent group jellyfin > /dev/null || groupadd --system jellyfin
|
||||
getent passwd jellyfin > /dev/null || \
|
||||
useradd --system --home-dir "%{_sharedstatedir}/jellyfin" --gid jellyfin \
|
||||
-s /sbin/nologin -c "jellyfin daemon" jellyfin
|
||||
exit 0
|
||||
|
||||
|
||||
%post
|
||||
%systemd_post jellyfin.service
|
||||
|
||||
|
||||
%preun
|
||||
%systemd_preun jellyfin.service
|
||||
|
||||
|
||||
%postun
|
||||
%systemd_postun jellyfin.service
|
||||
@@ -1 +0,0 @@
|
||||
d /var/log/jellyfin 0750 jellyfin jellyfin
|
||||
@@ -1,15 +0,0 @@
|
||||
name: jellyfin-web
|
||||
github: unknown/jellyfin-web
|
||||
description: jellyfin-web package
|
||||
dist_tag: false
|
||||
builds:
|
||||
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el8
|
||||
version: 10.10.7
|
||||
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el9
|
||||
version: 10.10.7
|
||||
@@ -1,18 +0,0 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
# Setup rpmbuild directory structure
|
||||
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
|
||||
|
||||
# Install Node.js for building
|
||||
dnf module enable nodejs:20 -y
|
||||
dnf install nodejs npm -y
|
||||
|
||||
# Download source files using spectool
|
||||
spectool -g -R /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
|
||||
|
||||
# Build the RPM
|
||||
rpmbuild -ba /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
|
||||
|
||||
# Copy the built RPMs to output directory
|
||||
cp /root/rpmbuild/RPMS/noarch/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.noarch.rpm /app/dist/
|
||||
cp /root/rpmbuild/SRPMS/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
|
||||
@@ -1,43 +0,0 @@
|
||||
%global jellyfin_version 10.10.7
|
||||
|
||||
|
||||
Name: jellyfin-web
|
||||
Version: %{jellyfin_version}
|
||||
Release: 1
|
||||
Summary: The Free Software Media System - Official Web Client
|
||||
|
||||
|
||||
License: GPL-2.0-or-later
|
||||
URL: https://github.com/jellyfin/jellyfin-web
|
||||
Source0: https://github.com/jellyfin/jellyfin-web/archive/refs/tags/v%{version}.tar.gz
|
||||
|
||||
|
||||
BuildArch: noarch
|
||||
|
||||
|
||||
BuildRequires: git
|
||||
BuildRequires: nodejs
|
||||
BuildRequires: npm
|
||||
|
||||
|
||||
%description
|
||||
%{summary}.
|
||||
|
||||
|
||||
%prep
|
||||
%setup -q -n jellyfin-web-%{version}
|
||||
|
||||
|
||||
%build
|
||||
SKIP_PREPARE=1 npm ci --no-audit --no-fund --no-update-notifier
|
||||
npm run build:production
|
||||
|
||||
|
||||
%install
|
||||
install --directory "%{buildroot}%{_datadir}/jellyfin/web"
|
||||
cp --recursive dist/* "%{buildroot}%{_datadir}/jellyfin/web"
|
||||
|
||||
|
||||
%files
|
||||
%license LICENSE
|
||||
%{_datadir}/jellyfin/web
|
||||
@@ -0,0 +1,23 @@
|
||||
name: k8up
|
||||
github: k8up-io/k8up
|
||||
github_release_pattern: ^v2\.
|
||||
description: K8up Kubernetes backup operator command line client.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: K8up Authors
|
||||
homepage: https://github.com/k8up-io/k8up
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2.16.0
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 2.16.0
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/k8up-io/k8up/releases/download/v${PACKAGE_VERSION}"
|
||||
TARBALL="k8up_${PACKAGE_VERSION}_linux_amd64.tar.gz"
|
||||
|
||||
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
|
||||
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
|
||||
|
||||
cd /app
|
||||
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
|
||||
tar xf "/app/${TARBALL}" -C /app/ k8up
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
@@ -0,0 +1,16 @@
|
||||
#compdef k8up
|
||||
|
||||
local -a opts
|
||||
local cur
|
||||
cur=${words[-1]}
|
||||
if [[ "$cur" == "-"* ]]; then
|
||||
opts=("${(@f)$(${words[@]:0:#words[@]-1} ${cur} --generate-bash-completion 2>/dev/null)}")
|
||||
else
|
||||
opts=("${(@f)$(${words[@]:0:#words[@]-1} --generate-bash-completion 2>/dev/null)}")
|
||||
fi
|
||||
|
||||
if [[ "${opts[1]}" != "" ]]; then
|
||||
_describe 'values' opts
|
||||
else
|
||||
_files
|
||||
fi
|
||||
@@ -0,0 +1,34 @@
|
||||
|
||||
: ${PROG:=$(basename ${BASH_SOURCE})}
|
||||
|
||||
# Macs have bash3 for which the bash-completion package doesn't include
|
||||
# _init_completion. This is a minimal version of that function.
|
||||
_cli_init_completion() {
|
||||
COMPREPLY=()
|
||||
_get_comp_words_by_ref "$@" cur prev words cword
|
||||
}
|
||||
|
||||
_cli_bash_autocomplete() {
|
||||
if [[ "${COMP_WORDS[0]}" != "source" ]]; then
|
||||
local cur opts base words
|
||||
COMPREPLY=()
|
||||
cur="${COMP_WORDS[COMP_CWORD]}"
|
||||
if declare -F _init_completion >/dev/null 2>&1; then
|
||||
_init_completion -n "=:" || return
|
||||
else
|
||||
_cli_init_completion -n "=:" || return
|
||||
fi
|
||||
words=("${words[@]:0:$cword}")
|
||||
if [[ "$cur" == "-"* ]]; then
|
||||
requestComp="${words[*]} ${cur} --generate-bash-completion"
|
||||
else
|
||||
requestComp="${words[*]} --generate-bash-completion"
|
||||
fi
|
||||
opts=$(eval "${requestComp}" 2>/dev/null)
|
||||
COMPREPLY=($(compgen -W "${opts}" -- ${cur}))
|
||||
return 0
|
||||
fi
|
||||
}
|
||||
|
||||
complete -o bashdefault -o default -o nospace -F _cli_bash_autocomplete $PROG
|
||||
unset PROG
|
||||
@@ -0,0 +1,11 @@
|
||||
function __k8up_complete
|
||||
set -l words (commandline -opc)
|
||||
set -l cur (commandline -ct)
|
||||
if string match -q -- '-*' $cur
|
||||
$words $cur --generate-bash-completion 2>/dev/null
|
||||
else
|
||||
$words --generate-bash-completion 2>/dev/null
|
||||
end
|
||||
end
|
||||
|
||||
complete -c k8up -f -a '(__k8up_complete)'
|
||||
@@ -0,0 +1,48 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- k8up
|
||||
|
||||
provides:
|
||||
- k8up
|
||||
|
||||
contents:
|
||||
- src: /app/k8up
|
||||
dst: /usr/bin/k8up
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/completions/k8up
|
||||
dst: /usr/share/bash-completion/completions/k8up
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/completions/_k8up
|
||||
dst: /usr/share/zsh/site-functions/_k8up
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/completions/k8up.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/k8up.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
@@ -12,9 +12,16 @@ builds:
|
||||
- almalinux/el8
|
||||
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.6.0
|
||||
version: 0.8.0
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.6.0
|
||||
version: 0.8.0
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.8.0
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
name: kubectl-cnpg
|
||||
github: cloudnative-pg/cloudnative-pg
|
||||
description: CloudNativePG kubectl plugin.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: The CloudNativePG Contributors
|
||||
homepage: https://github.com/cloudnative-pg/cloudnative-pg
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 1.30.1
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 1.30.1
|
||||
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cloudnative-pg/cloudnative-pg/releases/download/v${PACKAGE_VERSION}"
|
||||
TARBALL="kubectl-cnpg_${PACKAGE_VERSION}_linux_x86_64.tar.gz"
|
||||
|
||||
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
|
||||
wget -O /app/checksums.txt "${BASE_URL}/cnpg-${PACKAGE_VERSION}-checksums.txt"
|
||||
|
||||
cd /app
|
||||
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
|
||||
tar xf "/app/${TARBALL}" -C /app/ kubectl-cnpg
|
||||
|
||||
mkdir -p /app/completions
|
||||
/app/kubectl-cnpg completion bash > /app/completions/kubectl-cnpg
|
||||
/app/kubectl-cnpg completion zsh > /app/completions/_kubectl-cnpg
|
||||
/app/kubectl-cnpg completion fish > /app/completions/kubectl-cnpg.fish
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
+2
@@ -0,0 +1,2 @@
|
||||
#!/usr/bin/env sh
|
||||
exec kubectl cnpg __complete "$@"
|
||||
@@ -0,0 +1,54 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- kubectl-cnpg
|
||||
|
||||
provides:
|
||||
- kubectl-cnpg
|
||||
|
||||
contents:
|
||||
- src: /app/kubectl-cnpg
|
||||
dst: /usr/bin/kubectl-cnpg
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/kubectl_complete-cnpg
|
||||
dst: /usr/bin/kubectl_complete-cnpg
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/kubectl-cnpg
|
||||
dst: /usr/share/bash-completion/completions/kubectl-cnpg
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/_kubectl-cnpg
|
||||
dst: /usr/share/zsh/site-functions/_kubectl-cnpg
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/kubectl-cnpg.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/kubectl-cnpg.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
@@ -0,0 +1,22 @@
|
||||
name: kubectl-tree
|
||||
github: ahmetb/kubectl-tree
|
||||
description: kubectl plugin to browse Kubernetes object hierarchies as a tree.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: Ahmet Alp Balkan
|
||||
homepage: https://github.com/ahmetb/kubectl-tree
|
||||
license: Apache-2.0
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.6.0
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.6.0
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/ahmetb/kubectl-tree/releases/download/v${PACKAGE_VERSION}"
|
||||
TARBALL="kubectl-tree_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
|
||||
|
||||
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
|
||||
wget -O /app/checksums.txt "${BASE_URL}/kubectl-tree_${PACKAGE_VERSION}_checksums.txt"
|
||||
|
||||
cd /app
|
||||
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
|
||||
tar xf "/app/${TARBALL}" -C /app/ kubectl-tree
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
#!/usr/bin/env sh
|
||||
# kubectl-tree only completes flags; its KIND NAME args match kubectl get
|
||||
for arg in "$@"; do last=$arg; done
|
||||
case "$last" in
|
||||
-*) exec kubectl tree __complete "$@" ;;
|
||||
*) exec kubectl __complete get "$@" ;;
|
||||
esac
|
||||
@@ -0,0 +1,36 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- kubectl-tree
|
||||
|
||||
provides:
|
||||
- kubectl-tree
|
||||
|
||||
contents:
|
||||
- src: /app/kubectl-tree
|
||||
dst: /usr/bin/kubectl-tree
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/kubectl_complete-tree
|
||||
dst: /usr/bin/kubectl_complete-tree
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
@@ -0,0 +1,22 @@
|
||||
name: kubectl-view-secret
|
||||
github: elsesiy/kubectl-view-secret
|
||||
description: Kubectl plugin to decode Kubernetes secrets.
|
||||
arch: amd64
|
||||
platform: linux
|
||||
maintainer: Jonas-Taha El Sesiy
|
||||
homepage: https://github.com/elsesiy/kubectl-view-secret
|
||||
license: MIT
|
||||
dist_tag: true
|
||||
builds:
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.16.0
|
||||
- repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: 0.16.0
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/elsesiy/kubectl-view-secret/releases/download/v${PACKAGE_VERSION}"
|
||||
TARBALL="kubectl-view-secret_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
|
||||
|
||||
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
|
||||
wget -O /app/checksums.txt "${BASE_URL}/kubectl-view-secret_${PACKAGE_VERSION}_checksums.txt"
|
||||
|
||||
cd /app
|
||||
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
|
||||
tar xf "/app/${TARBALL}" -C /app/ kubectl-view-secret
|
||||
|
||||
mkdir -p /app/completions
|
||||
# kubectl resolves `kubectl view-secret` to kubectl-view_secret; upstream completions target "view-secret".
|
||||
mv /app/kubectl-view-secret /app/kubectl-view_secret
|
||||
/app/kubectl-view_secret completion bash | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret
|
||||
/app/kubectl-view_secret completion zsh | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/_kubectl-view_secret
|
||||
/app/kubectl-view_secret completion fish | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret.fish
|
||||
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
|
||||
@@ -0,0 +1,2 @@
|
||||
#!/usr/bin/env sh
|
||||
exec kubectl view-secret __complete "$@"
|
||||
@@ -0,0 +1,54 @@
|
||||
# nfpm.yaml
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- kubectl-view-secret
|
||||
|
||||
provides:
|
||||
- kubectl-view-secret
|
||||
|
||||
contents:
|
||||
- src: /app/kubectl-view_secret
|
||||
dst: /usr/bin/kubectl-view_secret
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/kubectl_complete-view_secret
|
||||
dst: /usr/bin/kubectl_complete-view_secret
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/kubectl-view_secret
|
||||
dst: /usr/share/bash-completion/completions/kubectl-view_secret
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/_kubectl-view_secret
|
||||
dst: /usr/share/zsh/site-functions/_kubectl-view_secret
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/completions/kubectl-view_secret.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/kubectl-view_secret.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
@@ -13,9 +13,9 @@ builds:
|
||||
- almalinux/el8
|
||||
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
|
||||
release: 1
|
||||
version: '26.1'
|
||||
version: '26.2'
|
||||
- repository:
|
||||
- almalinux/el9
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: 1
|
||||
version: '26.1'
|
||||
version: '26.2'
|
||||
|
||||
@@ -2,6 +2,10 @@
|
||||
|
||||
set -e
|
||||
|
||||
# Download the pre-built RPM from GitHub releases
|
||||
# Download the pre-built RPM from GitHub releases.
|
||||
# Upstream always publishes the release-1 asset (nzbget-<version>-1.x86_64.rpm);
|
||||
# the source URL must use the upstream asset name, not PACKAGE_RELEASE, which
|
||||
# carries the dist tag (e.g. 1.el9) and does not exist upstream. Only the local
|
||||
# output filename is dist-tagged, mirroring the code-server package.
|
||||
curl -L -o /app/dist/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm \
|
||||
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm
|
||||
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-1.x86_64.rpm
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
# puppet-initial
|
||||
|
||||
A firstrun bootstrap script and oneshot systemd service that initialises a
|
||||
freshly-provisioned host into Puppet:
|
||||
|
||||
1. Sets the FQDN under `.main.unkin.net`.
|
||||
2. Fetches the Puppet CA certificate from the CA service.
|
||||
3. Registers the node with a noop agent run against the CA.
|
||||
4. Runs the agent a few times against the compile master, then enables the
|
||||
`puppet` service and disables itself.
|
||||
|
||||
## Puppet CA endpoint
|
||||
|
||||
The CA endpoint defaults to the in-cluster puppetserver CA service
|
||||
`puppetca.k8s.syd1.au.unkin.net:8140` (serving the standard
|
||||
`/puppet-ca/v1/certificate/ca` API).
|
||||
|
||||
It is overridable via the environment. The `puppet-initial.service` unit reads
|
||||
`/etc/sysconfig/puppet-initial` (`EnvironmentFile=-`, so the file is optional),
|
||||
which the RPM ships as a commented `%config(noreplace)` example:
|
||||
|
||||
| Variable | Default | Purpose |
|
||||
|-----------------|----------------------------------|-------------------------------------------------------------|
|
||||
| `PUPPETCA_HOST` | `puppetca.k8s.syd1.au.unkin.net` | CA hostname (CA cert fetch + `--server` for registration). |
|
||||
| `PUPPETCA_PORT` | `8140` | CA API port. |
|
||||
|
||||
### Overriding from kickstart
|
||||
|
||||
A kickstart `%post` can point a host at a different CA without rebuilding the
|
||||
RPM by writing the sysconfig file before the service starts:
|
||||
|
||||
```bash
|
||||
%post
|
||||
cat > /etc/sysconfig/puppet-initial <<'EOF'
|
||||
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
|
||||
PUPPETCA_PORT=8140
|
||||
EOF
|
||||
```
|
||||
@@ -11,9 +11,9 @@ builds:
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el8
|
||||
version: 1.0.3
|
||||
version: 1.0.5
|
||||
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el9
|
||||
version: 1.0.3
|
||||
version: 1.0.5
|
||||
|
||||
@@ -15,7 +15,7 @@ license: ${PACKAGE_LICENSE}
|
||||
disable_globbing: false
|
||||
|
||||
depends:
|
||||
- puppet-agent
|
||||
- openvox-agent
|
||||
|
||||
# Files to include in the package
|
||||
contents:
|
||||
@@ -31,6 +31,13 @@ contents:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/resources/puppet-initial.sysconfig
|
||||
dst: /etc/sysconfig/puppet-initial
|
||||
type: config|noreplace
|
||||
file_info:
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
# Scripts to run during installation/removal (optional)
|
||||
scripts:
|
||||
|
||||
@@ -1,14 +1,21 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Puppet CA endpoint. Overridable via the environment (systemd reads
|
||||
# /etc/sysconfig/puppet-initial via EnvironmentFile), so kickstart %post can
|
||||
# point a host at a different CA without rebuilding the RPM. Defaults to the
|
||||
# in-cluster puppetserver CA service.
|
||||
PUPPETCA_HOST="${PUPPETCA_HOST:-puppetca.k8s.syd1.au.unkin.net}"
|
||||
PUPPETCA_PORT="${PUPPETCA_PORT:-8140}"
|
||||
|
||||
# Ensure the hostname is set
|
||||
hostnamectl set-hostname $(hostname -s).main.unkin.net
|
||||
grep '^HOSTNAME=' /etc/sysconfig/network | cut -d= -f2 | grep -q '\.' || sed -i 's/^\(HOSTNAME=[^\.]*\)$/\1.main.unkin.net/' /etc/sysconfig/network
|
||||
|
||||
# Install CA for Puppet
|
||||
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate https://puppetca.query.consul:8140/puppet-ca/v1/certificate/ca -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
|
||||
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate "https://${PUPPETCA_HOST}:${PUPPETCA_PORT}/puppet-ca/v1/certificate/ca" -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
|
||||
|
||||
# Registering to Puppet server
|
||||
/opt/puppetlabs/bin/puppet agent --test --server puppetca.query.consul --noop --onetime --no-daemonize --verbose
|
||||
/opt/puppetlabs/bin/puppet agent --test --server "${PUPPETCA_HOST}" --noop --onetime --no-daemonize --verbose
|
||||
|
||||
# Running Puppet agent five times with a 30-second gap between each run, stop puppet service at the end of each run
|
||||
for i in {1..5}; do
|
||||
|
||||
@@ -5,6 +5,7 @@ Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
EnvironmentFile=-/etc/sysconfig/puppet-initial
|
||||
ExecStart=/usr/local/bin/puppet-initial
|
||||
RemainAfterExit=true
|
||||
ExecStop=/bin/true
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# Environment overrides for the puppet-initial firstrun bootstrap.
|
||||
# Read by the puppet-initial.service unit (EnvironmentFile=-/etc/sysconfig/puppet-initial).
|
||||
# A kickstart %post can write this file to point a host at a different Puppet CA
|
||||
# without rebuilding the RPM. All values are optional; the defaults below match
|
||||
# the shipped in-cluster puppetserver CA service.
|
||||
|
||||
# Hostname of the Puppet CA service. Used both to fetch the CA certificate
|
||||
# (https://<host>:<port>/puppet-ca/v1/certificate/ca) and as --server for the
|
||||
# initial noop agent registration run.
|
||||
#PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
|
||||
|
||||
# Port the Puppet CA API listens on.
|
||||
#PUPPETCA_PORT=8140
|
||||
@@ -12,16 +12,16 @@ builds:
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el8
|
||||
version: 2025.07.13
|
||||
version: 2026.10.2
|
||||
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- almalinux/el9
|
||||
version: 2025.07.13
|
||||
version: 2026.10.2
|
||||
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
release: '1'
|
||||
repository:
|
||||
- fedora/42
|
||||
- fedora/43
|
||||
- fedora/44
|
||||
version: 2025.07.13
|
||||
version: 2026.10.2
|
||||
|
||||
@@ -1,9 +1,15 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
set -e
|
||||
set -euo pipefail
|
||||
|
||||
# Download the CA certificate from vault
|
||||
curl -L -o /app/UNKIN_ROOTCA_2024.crt https://vault.query.consul:8200/v1/pki_root/ca/pem
|
||||
# Download the CA chain from vault; openssl verifies we got a certificate, not an error page
|
||||
fetch_ca() {
|
||||
curl -fsSL -o "$2" "https://vault.query.consul:8200/v1/$1/ca/pem"
|
||||
openssl x509 -in "$2" -noout -subject
|
||||
}
|
||||
|
||||
fetch_ca pki_root /app/UNKIN_ROOTCA_2024.crt
|
||||
fetch_ca pki_int /app/UNKIN_INTCA_2024.crt
|
||||
|
||||
# Process the nfpm.yaml template with environment variables
|
||||
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
|
||||
|
||||
@@ -29,6 +29,12 @@ contents:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: /app/UNKIN_INTCA_2024.crt
|
||||
dst: /etc/pki/ca-trust/source/anchors/UNKIN_INTCA_2024.crt
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
# Scripts to run during installation/removal (optional)
|
||||
scripts:
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
"""Tests for the RPM filename tools/build reconstructs when probing artifactapi.
|
||||
|
||||
The expected values below were captured from the real nfpm; they are the names
|
||||
the publish step actually uploads, so the existence probe has to ask for
|
||||
exactly these or it 404s and rebuilds forever.
|
||||
"""
|
||||
|
||||
import importlib.machinery
|
||||
import importlib.util
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
REPO_ROOT = Path(__file__).parent.parent
|
||||
|
||||
_loader = importlib.machinery.SourceFileLoader(
|
||||
"rpmbuilder_build", str(REPO_ROOT / "tools" / "build")
|
||||
)
|
||||
_spec = importlib.util.spec_from_loader(_loader.name, _loader)
|
||||
build = importlib.util.module_from_spec(_spec)
|
||||
_loader.exec_module(build)
|
||||
|
||||
|
||||
# nfpm output for `version: <input>` with release 1, arch amd64
|
||||
NFPM_VERSIONS = [
|
||||
("2025.08.03", "2025.8.3"),
|
||||
("2025.07.13", "2025.7.13"),
|
||||
("1.05.0", "1.5.0"),
|
||||
("10.02.01", "10.2.1"),
|
||||
("0.0.09", "0.0.9"),
|
||||
("0.6.1", "0.6.1"),
|
||||
("1.2.3", "1.2.3"),
|
||||
("1.05", "1.5.0"),
|
||||
("08", "8.0.0"),
|
||||
("1.0.0-rc1", "1.0.0~rc1"),
|
||||
("1.05.0-rc1", "1.5.0~rc1"),
|
||||
("1.0.0-rc.1", "1.0.0~rc.1"),
|
||||
# not semver: nfpm leaves these verbatim, so we must too
|
||||
("1.02.3.4", "1.02.3.4"),
|
||||
("2025.08.03.01", "2025.08.03.01"),
|
||||
("1.2.3.4", "1.2.3.4"),
|
||||
("1.0.0-rc.01", "1.0.0-rc.01"),
|
||||
]
|
||||
|
||||
|
||||
@pytest.mark.parametrize("version,expected", NFPM_VERSIONS)
|
||||
def test_nfpm_rpm_version(version, expected):
|
||||
assert build.nfpm_rpm_version(version) == expected
|
||||
|
||||
|
||||
def test_rpm_file_name_matches_nfpm_output():
|
||||
assert (
|
||||
build.rpm_file_name("nzbget_exporter", "2025.08.03", "1.el9", "amd64")
|
||||
== "nzbget_exporter-2025.8.3-1.el9.x86_64.rpm"
|
||||
)
|
||||
|
||||
|
||||
def test_check_package_exists_probes_published_filename(monkeypatch):
|
||||
"""A zero-padded version must not probe a filename nfpm can never produce."""
|
||||
probed = []
|
||||
|
||||
class _Session:
|
||||
def get(self, url, timeout=None):
|
||||
probed.append(url)
|
||||
return type("R", (), {"status_code": 404})()
|
||||
|
||||
monkeypatch.setattr(build, "_artifactapi_session", _Session())
|
||||
|
||||
assert not build.check_package_exists(
|
||||
"nzbget_exporter", "2025.08.03", "1.el9", "almalinux/el9", "amd64"
|
||||
)
|
||||
expected = (
|
||||
"https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/rpm-vendor-el9"
|
||||
"/files/Packages/nzbget_exporter-2025.8.3-1.el9.x86_64.rpm"
|
||||
)
|
||||
assert probed == [expected]
|
||||
+33
-39
@@ -517,37 +517,38 @@ def get_github_token() -> str:
|
||||
|
||||
# ==================== GITEA API FUNCTIONS ====================
|
||||
|
||||
def normalize_version(version: str) -> str:
|
||||
def nfpm_rpm_version(version: str) -> str:
|
||||
"""
|
||||
Normalize version string by removing leading zeros from numeric components.
|
||||
Gitea automatically does this normalization.
|
||||
Render a metadata version the way nfpm renders it into an RPM filename.
|
||||
|
||||
nfpm re-renders any semver-parseable version: leading zeros are dropped,
|
||||
missing components padded to three, and the prerelease joined with '~'.
|
||||
Anything semver cannot parse (four or more components, non-numeric
|
||||
components, a numeric prerelease identifier with a leading zero) is used
|
||||
verbatim.
|
||||
|
||||
Examples:
|
||||
"2025.08.03" -> "2025.8.3"
|
||||
"1.05.0" -> "1.5.0"
|
||||
"0.6.1" -> "0.6.1" (no change needed)
|
||||
|
||||
Args:
|
||||
version: Original version string
|
||||
|
||||
Returns:
|
||||
Normalized version string
|
||||
"1.05" -> "1.5.0"
|
||||
"1.2.3-rc1" -> "1.2.3~rc1"
|
||||
"1.02.3.4" -> "1.02.3.4" (not semver, left alone)
|
||||
"""
|
||||
import re
|
||||
core, sep, prerelease = version.partition('-')
|
||||
if sep and not prerelease:
|
||||
return version
|
||||
|
||||
# Split by common separators and normalize each numeric part
|
||||
parts = re.split(r'([.\-_])', version)
|
||||
normalized_parts = []
|
||||
components = core.split('.')
|
||||
if len(components) > 3 or not all(c.isdigit() for c in components):
|
||||
return version
|
||||
|
||||
for part in parts:
|
||||
# If this part is purely numeric and has leading zeros, remove them
|
||||
if part.isdigit() and len(part) > 1 and part.startswith('0'):
|
||||
# Remove leading zeros but keep at least one digit
|
||||
normalized_parts.append(str(int(part)))
|
||||
else:
|
||||
normalized_parts.append(part)
|
||||
# semver rejects numeric prerelease identifiers with a leading zero
|
||||
if any(i.isdigit() and len(i) > 1 and i.startswith('0')
|
||||
for i in prerelease.split('.')):
|
||||
return version
|
||||
|
||||
return ''.join(normalized_parts)
|
||||
components += ['0'] * (3 - len(components))
|
||||
rendered = '.'.join(str(int(c)) for c in components)
|
||||
return f"{rendered}~{prerelease}" if prerelease else rendered
|
||||
|
||||
|
||||
def get_rpm_dist_tag(distro: str) -> str:
|
||||
@@ -598,6 +599,14 @@ def get_rpm_arch(arch: str) -> str:
|
||||
return {'amd64': 'x86_64', 'arm64': 'aarch64'}.get(arch, arch)
|
||||
|
||||
|
||||
def rpm_file_name(package_name: str, version: str, release: str, arch: str) -> str:
|
||||
"""Filename nfpm produces for this package, and therefore the published name."""
|
||||
return (
|
||||
f"{package_name}-{nfpm_rpm_version(version)}-{release}"
|
||||
f".{get_rpm_arch(arch)}.rpm"
|
||||
)
|
||||
|
||||
|
||||
def check_package_exists(
|
||||
package_name: str,
|
||||
version: str,
|
||||
@@ -627,7 +636,7 @@ def check_package_exists(
|
||||
|
||||
base_url = os.getenv('ARTIFACTAPI_URL', 'https://artifactapi.k8s.syd1.au.unkin.net')
|
||||
repo = get_vendor_repo(distro)
|
||||
rpm_file = f"{package_name}-{version}-{release}.{get_rpm_arch(arch)}.rpm"
|
||||
rpm_file = rpm_file_name(package_name, version, release, arch)
|
||||
url = f"{base_url}/api/v2/remotes/{repo}/files/Packages/{rpm_file}"
|
||||
|
||||
try:
|
||||
@@ -651,21 +660,6 @@ def check_package_exists(
|
||||
return False
|
||||
|
||||
|
||||
def get_package_full_name(package_name: str, version: str, release: str) -> str:
|
||||
"""
|
||||
Generate the full package name as used in the registry.
|
||||
|
||||
Args:
|
||||
package_name: Package name
|
||||
version: Version string
|
||||
release: Release number
|
||||
|
||||
Returns:
|
||||
Full package name string
|
||||
"""
|
||||
return f"{package_name}-{version}-{release}"
|
||||
|
||||
|
||||
# ==================== DOCKER FUNCTIONS ====================
|
||||
|
||||
def check_docker_available() -> bool:
|
||||
|
||||
Reference in New Issue
Block a user