47 Commits

Author SHA1 Message Date
unkin-agent f1e2b1a2dc ci: use container-rpmbuilder image
ci/woodpecker/pr/build-fedora43 Pipeline was successful
ci/woodpecker/pr/build-fedora42 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-fedora44 Pipeline was successful
2026-10-05 14:39:54 +11:00
unkin-agent ed50884409 bump kubecolor to 0.8.0 and add fedora builds (#184)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
kubecolor is pinned at 0.6.0 (upstream is 0.8.0) and only builds for el8/el9, so Fedora hosts have no package.

- bump kubecolor el8/el9 builds to 0.8.0
- add fedora 42/43/44 builds, mirroring kubectl-view-secret

Reviewed-on: #184
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-04 22:06:57 +11:00
unkin-agent 4b12f2b718 remove jellyfin-web and jellyfin-server packages (#185)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
The jellyfin-web el8 build breaks CI (OOM-killed, missing nodejs/npm), and the jellyfin packages are no longer built here.

- remove rpms/jellyfin-web
- remove rpms/jellyfin-server

Reviewed-on: #185
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-04 21:59:16 +11:00
unkin-agent ddfcf6c846 add kubectl-view-secret package (#183)
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
kubectl-view-secret decodes Kubernetes secrets as a kubectl plugin; packaging it puts it on hosts with shell completion of secret names. kubectl maps `view-secret` to an underscored binary name, so files use `view_secret`.

- add kubectl-view-secret 0.16.0 for el9 and fedora 42-44 with checksum verification
- install the plugin as /usr/bin/kubectl-view_secret
- add kubectl_complete-view_secret for kubectl plugin completion
- ship bash/zsh/fish completions renamed to the installed binary

Requires terraform-artifactapi github allowlist entries.

Reviewed-on: #183
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 09:17:47 +10:00
unkin-agent 213c218d1e add kubectl-tree package (#180)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
kubectl-tree is not packaged, and its own completion only covers flags while its `completion` scripts register for `kubectl` itself.

- add kubectl-tree 0.6.0 for el9 and fedora 42-44, checksum-verified via artifactapi
- add `kubectl_complete-tree` delegating flags to kubectl-tree and KIND/NAME to `kubectl get` completion

Requires terraform-artifactapi github allowlist entries for ahmetb/kubectl-tree.

Reviewed-on: #180
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 00:27:30 +10:00
unkin-agent 6678762b0c add kubectl-cnpg package (#179)
ci/woodpecker/push/deploy-almalinux9 Pipeline was canceled
ci/woodpecker/push/deploy-fedora44 Pipeline was canceled
ci/woodpecker/push/deploy-fedora43 Pipeline was canceled
ci/woodpecker/push/deploy-fedora42 Pipeline was canceled
ci/woodpecker/push/deploy-almalinux8 Pipeline was canceled
The CloudNativePG kubectl plugin is not packaged, so hosts have no supported way to install it. kubectl only completes plugin args via a `kubectl_complete-<plugin>` helper on PATH. Needs unkin/terraform-artifactapi#50 applied for the download to pass the github remote allowlist.

- add `kubectl-cnpg` 1.30.1 for almalinux/el9 and fedora 42/43/44
- fetch the tarball via the artifactapi github remote and verify it against upstream checksums
- ship `kubectl_complete-cnpg` for `kubectl cnpg` completion
- ship bash/zsh/fish completions generated at build time

Reviewed-on: #179
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 00:26:56 +10:00
unkin-agent 05f44b83c4 add k8up package (#181)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was canceled
ci/woodpecker/push/deploy-almalinux9 Pipeline was canceled
The k8up CLI (`k8up cli restore`) has no package, so restores need a manual GitHub download on each host.

- add k8up package pinned to 2.16.0, matching the deployed operator
- verify the release tarball against upstream checksums.txt
- ship urfave/cli bash, zsh and fish completions
- build for el9 and fedora 42-44

Requires terraform-artifactapi github allowlist for k8up-io/k8up.

Reviewed-on: #181
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 00:23:58 +10:00
unkin-agent abcfe87090 add cmctl package (#182)
ci/woodpecker/push/deploy-fedora42 Pipeline was canceled
ci/woodpecker/push/deploy-fedora43 Pipeline was canceled
ci/woodpecker/push/deploy-almalinux9 Pipeline was canceled
ci/woodpecker/push/deploy-almalinux8 Pipeline was canceled
ci/woodpecker/push/deploy-fedora44 Pipeline was canceled
cmctl, the cert-manager CLI, has no internal RPM, so hosts install it by hand and get no shell or `kubectl cert-manager` completion.

- add cmctl 2.6.1 package for el9 and fedora 42-44, verified against upstream checksums.txt
- generate bash/zsh/fish completions at build time
- ship `kubectl-cert_manager` symlink and `kubectl_complete-cert_manager` for kubectl plugin completion

Requires terraform-artifactapi github allowlist entries for cert-manager/cmctl.

Reviewed-on: #182
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 00:23:32 +10:00
unkin-agent 0dc95f395c feat: bump argocd to 3.5.3 (#176)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
The argocd package is pinned to the 3.3.x series at 3.3.14; upstream is now 3.5.3.

- bump the version and release pattern to the 3.5 series

---------

Co-authored-by: BenVincent <benvin@main.unkin.net>
Reviewed-on: #176
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-02 23:00:31 +10:00
unkin-agent 0922a5c4e3 ci: request 2 cpus for rpm build steps (#178)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
RPM build steps request 1 cpu while limiting to 2, so a build gets throttled whenever the node is contended.

- request 2 cpus in every build/deploy rpm build step, matching the limit

---------

Co-authored-by: BenVincent <benvin@main.unkin.net>
Reviewed-on: #178
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-02 22:35:51 +10:00
unkin-agent 70523ae938 Ship the intermediate CA in unkin-ca-certificates (#177)
`s3.ceph.unkin.net` serves a bare leaf issued by `CN=unkin.net Intermediate Authority`. The package shipped only the root, so images carrying just `unkin-ca-certificates` (container-base, container-gobuilder) cannot verify it — `curl https://s3.ceph.unkin.net/` returns 000.

- Fetch `pki_int` alongside `pki_root` and anchor it as `UNKIN_INTCA_2024.crt`
- Fail the build when a fetch errors or returns a non-certificate
- Bump version to `2026.10.2` on all distro targets

Verified in `gobuilder:0.1.1-alma9`: 000 before, 200 after, no `-k`.

Reviewed-on: #177
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-02 22:24:22 +10:00
unkin-agent df7490388e Probe the RPM filename nfpm actually publishes (#175)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
nfpm re-renders semver versions into the RPM filename, so `2025.08.03` ships as `2025.8.3`. The existence probe asked artifactapi for the raw metadata version, always got a 404, and rebuilt and republished `nzbget_exporter` and `unkin-ca-certificates` on every pipeline run.

- add `nfpm_rpm_version`/`rpm_file_name` mirroring nfpm rendering
- build the probe filename through `rpm_file_name`
- drop dead `normalize_version` and `get_package_full_name`
- cover the nfpm rendering table and the probed URL in tests

Reviewed-on: #175
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-28 22:22:42 +10:00
unkin-agent 1c316e875a Add go-cache-plugin vendored package (#174)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
go-cache-plugin is a GOCACHEPROG implementation that backs the Go build cache with S3, wanted via dnf on workstations and estate hosts. Upstream publishes no tags or releases, so the build pins a commit and the version is that commit's date.

- Add `rpms/go-cache-plugin` metadata, build.sh and nfpm.yaml
- Compile `cmd/go-cache-plugin` at commit 3031b5d with `GOTOOLCHAIN=go1.26.1`
- Ship the single binary at `/usr/bin/go-cache-plugin`
- Build for almalinux/el9 and fedora 42/43/44

Reviewed-on: #174
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-26 21:13:56 +10:00
unkin-agent 327a7c367a feat: add argocd CLI (#173)
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
The ArgoCD CLI is not packaged, so nodes have no supported way to install it alongside the other vendored kubernetes tools. Pin it to the 3.3 series to track the deployed server (v3.3.2).

- Add `argocd` 3.3.14 for almalinux/el9 and fedora 42/43/44
- Fetch the linux-amd64 binary through the artifactapi github remote and verify it against upstream `cli_checksums.txt`
- Generate and package bash, zsh and fish completions
- Hold `update-gh` on the 3.3 series via `github_release_pattern`

Depends on terraform-artifactapi#46; builds 403 until that is merged and applied.

Reviewed-on: #173
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 17:09:12 +10:00
unkinben 0c5684bd9e fix: require openvox-agent instead of puppet-agent in puppet-initial (#172)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
## Why

The estate migrated from Puppet to OpenVox. The `puppet-agent` package name no longer exists in the rpm-vendor repos, so kickstart installs of `puppet-initial` fail dependency resolution with "nothing provides puppet-agent", blocking host provisioning.

(Note: `openvox-agent` does `Provides: puppet-agent = 7`, so an alternative root cause is openvox repo priority/availability during the kickstart solve. This PR changes the explicit `Requires` as requested so puppet-initial depends on the package by its real name.)

## Changes

- Change puppet-initial's dependency from `puppet-agent` to `openvox-agent`.
- Bump el8/el9 build version `1.0.4` -> `1.0.5` so a new RPM is published (deploy dedup skips identical filenames).

## Validation

- `make test` — 72 passed.
- Local `nfpm pkg` build in the almalinux9-rpmbuilder image: RPM assembles as `puppet-initial-1.0.5-1.x86_64`, `rpm -qpR` reports `Requires: openvox-agent`.
- Confirmed `openvox-agent` is resolvable from the openvox el9 remote (7.35.0–7.37.2 available).

https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
Reviewed-on: #172
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-08-06 23:25:11 +10:00
unkinben c6df3a7619 feat: make puppet-initial CA endpoint configurable, default to k8s puppetca (#171)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
## Why

The `puppet-initial` firstrun bootstrap RPM hardcoded the legacy Consul-discovered CA endpoint `puppetca.query.consul:8140`. That VM-era CA is being replaced by the in-cluster puppetserver CA service `puppetca.k8s.syd1.au.unkin.net`. Rather than swap one hardcoded host for another, the endpoint is now configurable so kickstart can override it per host.

Verified the new service serves the same Puppet CA API on the same port: `https://puppetca.k8s.syd1.au.unkin.net:8140/puppet-ca/v1/certificate/ca` returns HTTP 200 with a valid Puppet CA cert.

## Changes

- Default the CA host to `puppetca.k8s.syd1.au.unkin.net` (still port `8140`, same `/puppet-ca/v1/certificate/ca` path).
- Bootstrap script reads `PUPPETCA_HOST` / `PUPPETCA_PORT` from the environment, falling back to the defaults, and uses them for both the CA cert fetch and the `--server` of the initial noop registration run.
- Add `EnvironmentFile=-/etc/sysconfig/puppet-initial` to the systemd unit so kickstart `%post` can drop overrides in there.
- Ship a commented example config at `/etc/sysconfig/puppet-initial` as `%config(noreplace)`.
- Add a package README documenting the override, with a kickstart `%post` example.
- Bump el8/el9 build version `1.0.3` -> `1.0.4` so a new RPM is published (dedup skips identical filenames).

Note: the run loop still targets `puppet.query.consul` (the compile master, a separate host from the CA) — intentionally left unchanged; scope here is the CA endpoint only.

## Validation

- `make test` — 72 passed
- pre-commit (metadata jsonschema, yamllint, shebang/executable checks) — all pass
- Local `nfpm pkg` build: RPM assembles; `/etc/sysconfig/puppet-initial` correctly listed by `rpm -qcp` as a config file; packaged script carries the new default + env wiring.

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
---------

Co-authored-by: Ben Vincent <neotheo@gmail.com>
Reviewed-on: #171
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-29 21:36:47 +10:00
unkinben 3ba9f77c10 fix: build and publish nzbget to artifactapi rpm-vendor repos (#170)
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
## Why

`nzbget` is absent from the artifactapi `rpm-vendor-el9` / `rpm-vendor-el8` repodata, so `dnf install nzbget` fails on the media host (AlmaLinux 9.7). The legacy Gitea RPM registry is being removed from hosts by puppet-prod #496, so nzbget must land in `rpm-vendor-el9` or installs break.

Root cause: nzbget's `build.sh` built the GitHub download URL from `PACKAGE_RELEASE`, which carries the dist tag (e.g. `1.el9`). Upstream only publishes `nzbget-<version>-1.x86_64.rpm` (no dist tag), so the fetch 404s and a 22-byte "upstream returned 404" junk file is what gets published — createrepo cannot index it, so the package never appears in the repo metadata. The stale junk `nzbget-26.1-1.el9` also makes the deploy step's dedup probe return HTTP 200, which would skip re-uploading a corrected 26.1.

## How

- Point the `build.sh` source URL at the upstream release-1 asset name (`nzbget-${PACKAGE_VERSION}-1.x86_64.rpm`) while keeping the dist-tagged local output filename, mirroring the `code-server` package which repackages a prebuilt upstream RPM the same way.
- Bump nzbget el8/el9 to `26.2` (current upstream stable) so the corrected build produces a fresh filename the deploy step will actually PUT (side-stepping the stale-junk dedup skip).

## Validation

- Confirmed the corrected URL fetches a real 9.1MB RPM through artifactapi's github remote: `NAME=nzbget VER=26.2 REL=1 ARCH=x86_64`.
- `pytest` 72 passed; metadata validates against `schema/metadata.json`; all pre-commit hooks pass (yamllint, check-jsonschema, etc.).

## Post-merge

The deploy pipelines (`.woodpecker/deploy-almalinux{8,9}.yaml`) run on push to `master`. On merge they will `build-all --distro almalinux/el{8,9}`, build nzbget 26.2, and PUT `nzbget-26.2-1.el{8,9}.x86_64.rpm` to `rpm-vendor-el{8,9}`; artifactapi regenerates repodata so `dnf install nzbget` resolves.

https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Reviewed-on: #170
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-27 00:45:00 +10:00
unkinben d49667c471 feat: update etcd to 3.6.10 (#140)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Automated version bump: 3.6.7 → 3.6.10

Reviewed-on: #140
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-18 17:04:24 +10:00
unkinben 8c0d23afae Publish RPMs to artifactapi rpm-vendor repos (#169)
Why: vendored RPMs currently upload to Gitea's per-distro RPM registry. Publish them instead to the artifactapi per-distro rpm-vendor local repos (real yum repos; repodata regenerates automatically), keeping them separate from in-house software (rpm-internal). The existing per-distro build-all build jobs are unchanged.

Changes:
- .woodpecker/deploy-*.yaml: retarget the deploy-rpms step from git.unkin.net/api/packages/... to a PUT against artifactapi /api/v2/remotes/rpm-vendor-<distro>/files/ (unauthenticated, like the other repos), with an existence probe to skip re-uploads. Drops the DRONECI_PASSWORD secret.
- tools/build: repoint check_package_exists from the Gitea packages API to the artifactapi rpm-vendor repo so build-all's skip check matches the real publish target; verify artifactapi's internal TLS cert against the OS CA bundle; carry arch on PackageInfo so the probed filename matches the built RPM.

Depends on the already-merged rpm-vendor repos (terraform-artifactapi) and pairs with puppet-prod rpm-vendor yumrepo.

Reviewed-on: #169
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-07-18 16:00:11 +10:00
benvin 5086091807 feat: change vault to use artifactapi (#168)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Co-authored-by: Ben Vincent <ben@unkin.net>
Reviewed-on: #168
2026-06-08 15:18:11 +10:00
benvin cf1b3b9a3d chore: bump claude-code (#167)
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
- upgrade claude-code to 2.1.156

---------

Co-authored-by: Ben Vincent <ben@unkin.net>
Reviewed-on: #167
2026-06-08 14:36:42 +10:00
unkinben 8a3a585f8c fix/distro-aware-package-check (#164)
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Reviewed-on: #164
2026-05-17 23:43:35 +10:00
unkinben 539a63e0a1 feat/metadata-schema-validation (#165)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
Reviewed-on: #165
2026-05-17 12:34:33 +10:00
unkinben aeea587aeb fix: move unkin-undionly-kpxe preinstall.sh to scripts/ subdirectory (#166)
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
nfpm.yaml referenced /app/resources/scripts/preinstall.sh but the file
was at resources/preinstall.sh, causing the build to fail.

Reviewed-on: #166
2026-05-17 12:29:10 +10:00
unkinben 96d0e25e94 feat: update pipelines (#160)
ci/woodpecker/push/deploy-fedora44 Pipeline failed
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
- remove buildah (now in image)
- add fedora42/fedora43/fedora44 pipelines

Reviewed-on: #160
2026-05-16 23:36:13 +10:00
unkinben a61bcb9d60 feat: add kubecolor (#159)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
- quality of life rpm for colorizing kubernetes

Reviewed-on: #159
2026-05-14 23:29:16 +10:00
unkinben 17ce4eb2cf feat: update incus to 6.23.0 (#151)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Automated version bump: 6.20.0 → 6.23.0

Reviewed-on: #151
2026-05-02 17:18:31 +10:00
unkinben 24bba58dfd feat: update per workflow resources (#158)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
trying to avoid contention, where all jobs end up on one host causing
timeouts

- ensure build jobs requests/limits are more specific

Reviewed-on: #158
2026-05-02 17:10:04 +10:00
unkinben d860a9d27f feat: update ruff to 0.15.12 (#123)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Automated version bump: 0.14.10 → 0.15.12

Reviewed-on: #123
2026-05-02 11:47:30 +10:00
unkinben 9e76b1ad83 feat: update pgbouncer_exporter to 0.12.0 (#127)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Automated version bump: 0.11.0 → 0.12.0

Reviewed-on: #127
2026-05-02 11:42:53 +10:00
unkinben a5a6c90b8e feat: update vmagent to 1.142.0 (#124)
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
Automated version bump: 1.132.0 → 1.142.0

Reviewed-on: #124
2026-05-02 11:38:45 +10:00
unkinben 99c4db7b51 feat: update cni-plugins to 1.9.1 (#125)
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
Automated version bump: 1.9.0 → 1.9.1

Reviewed-on: #125
2026-05-02 11:34:08 +10:00
unkinben 9bc820ceaf feat: update jsonnet to 0.22.0 (#126)
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
Automated version bump: 0.21.0 → 0.22.0

Reviewed-on: #126
2026-05-02 11:33:52 +10:00
unkinben 743f272793 Merge pull request 'feat: update stalwart to 0.16.3' (#128) from update/stalwart into master
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
Reviewed-on: #128
2026-05-02 11:33:37 +10:00
unkinben e8f87aa9b5 Merge pull request 'feat: update node_exporter to 1.11.1' (#129) from update/node_exporter into master
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
Reviewed-on: #129
2026-05-02 11:33:29 +10:00
unkinben ddf4b72ec5 Merge pull request 'feat: update terraform to 1.15.0' (#130) from update/terraform into master
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
Reviewed-on: #130
2026-05-02 11:33:21 +10:00
unkinben a915b2c9f4 Merge pull request 'feat: update vmalert to 1.142.0' (#132) from update/vmalert into master
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
Reviewed-on: #132
2026-05-02 11:33:13 +10:00
unkinben fb91ae8240 Merge pull request 'feat: update stalwart-foundationdb to 0.16.3' (#145) from update/stalwart-foundationdb into master
ci/woodpecker/push/deploy-almalinux8 Pipeline failed
ci/woodpecker/push/deploy-almalinux9 Pipeline failed
Reviewed-on: #145
2026-05-02 11:33:02 +10:00
unkinben 7b808bce5c Merge branch 'master' into update/stalwart
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 11:07:26 +10:00
unkinben 084d0f7ebb Merge branch 'master' into update/node_exporter
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 10:17:55 +10:00
unkinben 6b7fe0cf50 Merge branch 'master' into update/terraform
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 10:17:19 +10:00
unkinben a46d30fc95 Merge branch 'master' into update/stalwart-foundationdb
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 09:53:47 +10:00
unkinben 7fd61d945a feat: update stalwart-foundationdb to 0.16.3
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline failed
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 01:47:54 +10:00
unkinben 6a271b988d feat: update vmalert to 1.142.0
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
2026-05-02 01:47:18 +10:00
unkinben 17e0568616 feat: update terraform to 1.15.0
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline failed
2026-05-02 01:47:14 +10:00
unkinben 4ad40ed620 feat: update node_exporter to 1.11.1
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline failed
2026-05-02 01:47:10 +10:00
unkinben 3a7a016592 feat: update stalwart to 0.16.3
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline failed
2026-05-02 01:47:09 +10:00
138 changed files with 2115 additions and 728 deletions
+18
View File
@@ -31,6 +31,24 @@ repos:
"-s",
]
- repo: local
hooks:
- id: pytest
name: Run unit tests
entry: make test
language: system
types: [python]
pass_filenames: false
- repo: https://github.com/python-jsonschema/check-jsonschema
rev: 0.37.2
hooks:
- id: check-jsonschema
name: Validate RPM package metadata
files: ^rpms/[^/]+/metadata\.yaml$
args: [--schemafile, schema/metadata.json]
language_version: python3.11
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: v0.14.7
hooks:
+8 -2
View File
@@ -3,16 +3,22 @@ when:
steps:
- name: build rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- dnf install buildah -y
- ./tools/build build-all --distro almalinux/el8 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show rpms
image: git.unkin.net/unkin/almalinux8-base:latest
+8 -2
View File
@@ -3,16 +3,22 @@ when:
steps:
- name: build rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- dnf install buildah -y
- ./tools/build build-all --distro almalinux/el9 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show rpms
image: git.unkin.net/unkin/almalinux9-base:latest
+26
View File
@@ -0,0 +1,26 @@
when:
- event: pull_request
steps:
- name: build rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/42 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show rpms
image: git.unkin.net/unkin/fedora42-base:latest
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
+26
View File
@@ -0,0 +1,26 @@
when:
- event: pull_request
steps:
- name: build rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/43 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show rpms
image: git.unkin.net/unkin/fedora43-base:latest
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
+26
View File
@@ -0,0 +1,26 @@
when:
- event: pull_request
steps:
- name: build rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/44 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show rpms
image: git.unkin.net/unkin/fedora44-base:latest
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
+26 -7
View File
@@ -4,16 +4,22 @@ when:
steps:
- name: build-rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- dnf install buildah -y
- ./tools/build build-all --distro almalinux/el8 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show-rpms
image: git.unkin.net/unkin/almalinux9-base:latest
@@ -22,16 +28,29 @@ steps:
depends_on: [build-rpms]
- name: deploy-rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-vendor-el8"
for rpm in $(find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"); do
curl --user droneci:$${DRONECI_PASSWORD} --upload-file $rpm https://git.unkin.net/api/packages/unkin/rpm/almalinux/el8/upload
FILE=$$(basename "$$rpm")
# artifactapi has no HEAD route (405); probe the served Packages path.
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO; skipping"
continue
fi
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
done
environment:
DRONECI_PASSWORD:
from_secret: DRONECI_PASSWORD
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
depends_on: [build-rpms, show-rpms]
+26 -7
View File
@@ -4,16 +4,22 @@ when:
steps:
- name: build-rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- dnf install buildah -y
- ./tools/build build-all --distro almalinux/el9 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show-rpms
image: git.unkin.net/unkin/almalinux9-base:latest
@@ -22,16 +28,29 @@ steps:
depends_on: [build-rpms]
- name: deploy-rpms
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-vendor-el9"
for rpm in $(find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"); do
curl --user droneci:$${DRONECI_PASSWORD} --upload-file $rpm https://git.unkin.net/api/packages/unkin/rpm/almalinux/el9/upload
FILE=$$(basename "$$rpm")
# artifactapi has no HEAD route (405); probe the served Packages path.
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO; skipping"
continue
fi
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
done
environment:
DRONECI_PASSWORD:
from_secret: DRONECI_PASSWORD
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
depends_on: [build-rpms, show-rpms]
+56
View File
@@ -0,0 +1,56 @@
when:
- event: push
branch: master
steps:
- name: build-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/42 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora42
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
depends_on: [build-rpms]
- name: deploy-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora42
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-vendor-f42"
for rpm in $(find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"); do
FILE=$$(basename "$$rpm")
# artifactapi has no HEAD route (405); probe the served Packages path.
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO; skipping"
continue
fi
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
done
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
depends_on: [build-rpms, show-rpms]
+56
View File
@@ -0,0 +1,56 @@
when:
- event: push
branch: master
steps:
- name: build-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/43 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora43
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
depends_on: [build-rpms]
- name: deploy-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora43
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-vendor-f43"
for rpm in $(find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"); do
FILE=$$(basename "$$rpm")
# artifactapi has no HEAD route (405); probe the served Packages path.
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO; skipping"
continue
fi
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
done
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
depends_on: [build-rpms, show-rpms]
+56
View File
@@ -0,0 +1,56 @@
when:
- event: push
branch: master
steps:
- name: build-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
commands:
- mkdir -p /woodpecker/rpms
- ln -s /woodpecker/rpms /workspace
- ./tools/build build-all --distro fedora/44 --buildah
privileged: true
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 2
limits:
memory: 2Gi
cpu: 2
- name: show-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora44
commands:
- find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"
depends_on: [build-rpms]
- name: deploy-rpms
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-fedora44
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-vendor-f44"
for rpm in $(find /woodpecker/src/git.unkin.net/unkin/rpmbuilder/ -type f -name "*.rpm"); do
FILE=$$(basename "$$rpm")
# artifactapi has no HEAD route (405); probe the served Packages path.
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO; skipping"
continue
fi
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
done
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
depends_on: [build-rpms, show-rpms]
+1 -1
View File
@@ -1,4 +1,4 @@
ARG BASE_IMAGE=git.unkin.net/unkin/almalinux9-rpmbuilder:latest
ARG BASE_IMAGE=artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
FROM ${BASE_IMAGE}
# Create output directory for RPMs
+5 -1
View File
@@ -11,7 +11,7 @@ DISTRO ?= almalinux/el9
PACKAGES := $(shell find $(ROOT_DIR)/rpms -mindepth 1 -maxdepth 1 -type d -exec test -f {}/metadata.yaml \; -print | xargs -n1 basename | sort)
# Default target to build all packages
.PHONY: all list build clean
.PHONY: all list build clean test
all: build-all
# List all available packages
@@ -47,6 +47,10 @@ dry-run:
@echo "Dry run - showing what would be built for distro $(DISTRO):"
$(BUILD_TOOL) build-all --distro $(DISTRO) --dry-run
# Run unit tests
test:
@uv run --group dev pytest tests/ -q; rc=$$?; [ $$rc -eq 5 ] && exit 0 || exit $$rc
# Clean target
clean:
@echo "Cleaning build artifacts..."
+16
View File
@@ -0,0 +1,16 @@
[project]
name = "rpmbuilder"
version = "0.1.0"
requires-python = ">=3.11"
[dependency-groups]
dev = [
"pytest>=8",
"jsonschema>=4",
"pyyaml>=6",
# tools/build's own script dependencies, so tests can import it
"typer",
"requests",
"hvac",
"cerberus",
]
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 0.2.12
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 0.2.12
description: A runner for Gitea based on act.
name: act_runner
github: unknown/act_runner
description: A runner for Gitea based on act.
arch: amd64
platform: linux
maintainer: Gitea
homepage: https://gitea.com/gitea/act_runner
license: MIT
maintainer: Gitea
name: act_runner
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 0.2.12
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 0.2.12
+24
View File
@@ -0,0 +1,24 @@
name: argocd
github: argoproj/argo-cd
github_release_pattern: ^v3\.5\.
description: Declarative GitOps continuous delivery for Kubernetes - command line
client.
arch: amd64
platform: linux
maintainer: Argo Project
homepage: https://github.com/argoproj/argo-cd
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 3.5.3
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 3.5.3
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/argoproj/argo-cd/releases/download/v${PACKAGE_VERSION}"
wget -O /app/argocd "${BASE_URL}/argocd-linux-amd64"
wget -O /app/cli_checksums.txt "${BASE_URL}/cli_checksums.txt"
# Upstream lists the asset name; check it against the local filename.
cd /app
grep ' argocd-linux-amd64$' cli_checksums.txt | sed 's/argocd-linux-amd64$/argocd/' | sha256sum --check --strict -
chmod +x /app/argocd
mkdir -p /app/completions
/app/argocd completion bash > /app/completions/argocd
/app/argocd completion zsh > /app/completions/_argocd
/app/argocd completion fish > /app/completions/argocd.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+48
View File
@@ -0,0 +1,48 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- argocd
provides:
- argocd
contents:
- src: /app/argocd
dst: /usr/bin/argocd
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/argocd
dst: /usr/share/bash-completion/completions/argocd
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_argocd
dst: /usr/share/zsh/site-functions/_argocd
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/argocd.fish
dst: /usr/share/fish/vendor_completions.d/argocd.fish
file_info:
mode: 0644
owner: root
group: root
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 0.8.0
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 0.8.0
description: Prometheus exporter for BIND
name: bind_exporter
github: prometheus-community/bind_exporter
description: Prometheus exporter for BIND
arch: amd64
platform: linux
maintainer: Prometheus
homepage: https://github.com/prometheus-community/bind_exporter
license: Apache-2.0 license
maintainer: Prometheus
name: bind_exporter
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 0.8.0
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 0.8.0
+2 -1
View File
@@ -7,6 +7,7 @@ platform: linux
maintainer: Gruntwork
homepage: https://github.com/gruntwork-io/boilerplate
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 0.15.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.15.0
+10 -10
View File
@@ -1,19 +1,19 @@
name: claude-code
description: Claude Code - Anthropic's agentic AI coding tool
arch: amd64
platform: linux
maintainer: Anthropic
homepage: https://claude.ai/code
license: Proprietary
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
repository:
- almalinux/el8
version: 2.1.126
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
version: 2.1.156
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
repository:
- almalinux/el9
version: 2.1.126
claude_ai: true
description: Claude Code - Anthropic's agentic AI coding tool
homepage: https://claude.ai/code
license: Proprietary
maintainer: Anthropic
name: claude-code
platform: linux
version: 2.1.156
+22
View File
@@ -0,0 +1,22 @@
name: cmctl
github: cert-manager/cmctl
description: Command line tool to manage and configure cert-manager resources.
arch: amd64
platform: linux
maintainer: The cert-manager Authors
homepage: https://github.com/cert-manager/cmctl
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.6.1
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.6.1
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cert-manager/cmctl/releases/download/v${PACKAGE_VERSION}"
wget -O /app/cmctl "${BASE_URL}/cmctl_linux_amd64"
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
# Upstream lists the asset name; check it against the local filename.
cd /app
grep ' cmctl_linux_amd64$' checksums.txt | sed 's/cmctl_linux_amd64$/cmctl/' | sha256sum --check --strict -
chmod +x /app/cmctl
mkdir -p /app/completions
/app/cmctl completion bash > /app/completions/cmctl
/app/cmctl completion zsh > /app/completions/_cmctl
/app/cmctl completion fish > /app/completions/cmctl.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env sh
exec kubectl cert-manager __complete "$@"
+57
View File
@@ -0,0 +1,57 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- cmctl
provides:
- cmctl
contents:
- src: /app/cmctl
dst: /usr/bin/cmctl
file_info:
mode: 0755
owner: root
group: root
- src: cmctl
dst: /usr/bin/kubectl-cert_manager
type: symlink
- src: /app/resources/kubectl_complete-cert_manager
dst: /usr/bin/kubectl_complete-cert_manager
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/cmctl
dst: /usr/share/bash-completion/completions/cmctl
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_cmctl
dst: /usr/share/zsh/site-functions/_cmctl
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/cmctl.fish
dst: /usr/share/fish/vendor_completions.d/cmctl.fish
file_info:
mode: 0644
owner: root
group: root
+4 -3
View File
@@ -7,14 +7,15 @@ platform: linux
maintainer: ContainerNetworking
homepage: https://github.com/containernetworking/plugins
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: 1.9.0
version: 1.9.1
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.9.0
version: 1.9.1
+2 -2
View File
@@ -1,4 +1,3 @@
---
name: code-server
github: coder/code-server
description: VS Code in the browser.
@@ -7,6 +6,7 @@ platform: linux
maintainer: Coder
homepage: https://github.com/coder/code-server
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +15,6 @@ builds:
version: 4.117.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 4.117.0
+18 -15
View File
@@ -1,18 +1,21 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 1.7.1
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 1.7.1
description: Plugin for Consul on Kubernetes to allow configuring traffic redirection rules without escalated container privileges.
name: consul-cni
github: unknown/consul-cni
description: Plugin for Consul on Kubernetes to allow configuring traffic redirection
rules without escalated container privileges.
arch: amd64
platform: linux
maintainer: Hashicorp
homepage: https://hashicorp.com
license: Mozilla Public License, version 2.0
maintainer: Hashicorp
name: consul-cni
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 1.7.1
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 1.7.1
+9 -1
View File
@@ -7,6 +7,7 @@ platform: linux
maintainer: HashiCorp
homepage: https://github.com/hashicorp/consul
license: BUSL-1.1
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,13 @@ builds:
version: 1.22.7
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.22.7
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.22.7
+4 -3
View File
@@ -7,14 +7,15 @@ platform: linux
maintainer: https://etcd.io/
homepage: https://etcd.io/
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: 3.6.7
version: 3.6.10
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 3.6.7
version: 3.6.10
+2 -1
View File
@@ -7,6 +7,7 @@ platform: linux
maintainer: onedr0p
homepage: https://github.com/onedr0p/exportarr
license: MIT license
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 2.3.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.3.0
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: Prometheus
homepage: https://github.com/tynany/frr_exporter
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 1.11.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.11.0
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 0.9.10
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 0.9.10
description: An r10k fork written in Go, designed to work somwhat similar like puppetlabs/r10k.
name: g10k
github: xorpaul/g10k
description: An r10k fork written in Go, designed to work somwhat similar like puppetlabs/r10k.
arch: amd64
platform: linux
maintainer: xorpaul
homepage: https://github.com/xorpaul/g10k
license: Apache2.0
maintainer: xorpaul
name: g10k
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 0.9.10
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 0.9.10
+2 -2
View File
@@ -1,4 +1,3 @@
---
name: git-delta
github: dandavison/delta
description: A syntax-highlighting pager for git, diff, grep, and blame output.
@@ -7,6 +6,7 @@ platform: linux
maintainer: dandavison
homepage: https://github.com/dandavison/delta
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +15,6 @@ builds:
version: 0.19.2
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.19.2
+22
View File
@@ -0,0 +1,22 @@
name: go-cache-plugin
github: tailscale/go-cache-plugin
description: A GOCACHEPROG implementation that backs the Go build cache with S3.
arch: amd64
platform: linux
maintainer: Tailscale
homepage: https://github.com/tailscale/go-cache-plugin
license: BSD-3-Clause
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2026.7.22
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2026.7.22
+17
View File
@@ -0,0 +1,17 @@
#!/usr/bin/bash
set -e
# Upstream publishes no tags or releases; PACKAGE_VERSION dates this commit.
COMMIT=3031b5d01c50d2748a32c7c9386ea7049883f38e
# go.mod requires go 1.26.1
export GOTOOLCHAIN=go1.26.1
# Compile the go-cache-plugin binary using Go
GOBIN=/app go install github.com/tailscale/go-cache-plugin/cmd/go-cache-plugin@${COMMIT}
# Process nfpm.yaml with envsubst
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
# Build the RPM
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+31
View File
@@ -0,0 +1,31 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- go-cache-plugin
provides:
- go-cache-plugin
# Files to include in the package
contents:
- src: /app/go-cache-plugin
dst: /usr/bin/go-cache-plugin
file_info:
mode: 0755
owner: root
group: root
+4 -3
View File
@@ -1,12 +1,13 @@
---
name: hadolint
github: hadolint/hadolint
description: A smarter Dockerfile linter that helps you build best practice Docker images.
description: A smarter Dockerfile linter that helps you build best practice Docker
images.
arch: amd64
platform: linux
maintainer: hadolint
homepage: https://github.com/hadolint/hadolint
license: GPL-3.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 2.14.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.14.0
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: Helm Contributors
homepage: https://github.com/helm/helm
license: Apache-2.0 license
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 4.1.4
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 4.1.4
+2 -1
View File
@@ -8,6 +8,7 @@ platform: linux
maintainer: Helmfile Contributors
homepage: https://github.com/helmfile/helmfile
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -16,6 +17,6 @@ builds:
version: 1.4.4
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.4.4
+3 -2
View File
@@ -6,9 +6,10 @@ platform: linux
maintainer: unkin
homepage: https://linuxcontainers.org/incus/
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 6.20.0
version: 6.23.0
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: unkin
homepage: https://github.com/jellyfin/jellyfin-ffmpeg
license: GPL-3.0
dist_tag: false
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 7.1.3
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1.1
version: 7.1.3
-13
View File
@@ -1,13 +0,0 @@
---
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 10.10.7
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 10.10.7
description: jellyfin-server package
github: unknown/jellyfin-server
name: jellyfin-server
-21
View File
@@ -1,21 +0,0 @@
#!/usr/bin/bash
# Setup rpmbuild directory structure
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
# Install .NET SDK for building
dnf install dotnet-sdk-8.0 -y
# Download source files using spectool
spectool -g -R /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
# Copy additional files to SOURCES
cp /app/resources/fix-envfile-path.patch /root/rpmbuild/SOURCES/fix-envfile-path.patch
cp /app/resources/tmpfiles.conf /root/rpmbuild/SOURCES/tmpfiles.conf
# Build the RPM
rpmbuild -ba /app/resources/jellyfin-server_${PACKAGE_VERSION}.spec
# Copy the built RPMs to output directory
cp /root/rpmbuild/RPMS/x86_64/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm /app/dist/
cp /root/rpmbuild/SRPMS/jellyfin-server-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
@@ -1,11 +0,0 @@
--- a/debian/conf/jellyfin.service
+++ b/debian/conf/jellyfin.service
@@ -4,7 +4,7 @@ After = network-online.target
[Service]
Type = simple
-EnvironmentFile = /etc/default/jellyfin
+EnvironmentFile = /etc/jellyfin/jellyfin.env
User = jellyfin
Group = jellyfin
WorkingDirectory = /var/lib/jellyfin
@@ -1,127 +0,0 @@
%global debug_package %{nil}
%global jellyfin_version 10.10.7
%global jellyfin_packaging_timestamp 202504051515
%global jellyfin_packaging_version %{jellyfin_version}-%{jellyfin_packaging_timestamp}
%global dotnet_runtime %( \
if [ "%{_arch}" = "x86_64" ]; then \
echo -n "linux-x64"; \
elif [ "%{_arch}" = "aarch64" ]; then \
echo -n "linux-arm64"; \
else \
echo "Unsupported architecture: %{_arch}"; \
exit 1; \
fi \
)
Name: jellyfin-server
Version: %{jellyfin_version}
Release: 1
Summary: The Free Software Media System - Server Backend & API
License: GPL-2.0-or-later
URL: https://github.com/jellyfin/jellyfin
Source0: https://github.com/jellyfin/jellyfin/archive/refs/tags/v%{version}.tar.gz
Source1: https://github.com/jellyfin/jellyfin-packaging/archive/refs/tags/v%{jellyfin_packaging_version}.tar.gz
Source2: tmpfiles.conf
Patch0: fix-envfile-path.patch
ExclusiveArch: x86_64 aarch64
BuildRequires: dotnet-sdk-8.0
BuildRequires: git
BuildRequires: systemd-rpm-macros
Requires: aspnetcore-runtime-8.0
Requires: bash
Requires: fontconfig
Requires: jellyfin-ffmpeg-bin
Requires: sqlite
Recommends: jellyfin-web
Recommends: google-noto-fonts-common
%description
%{summary}.
%prep
tar --extract --file="%{SOURCE1}" --directory="%{_builddir}"
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}
patch -p1 -i "%{PATCH0}"
popd
%setup -q -n jellyfin-%{version}
%build
DOTNET_CLI_TELEMETRY_OPTOUT=1 \
DOTNET_SKIP_FIRST_TIME_EXPERIENCE=1 \
DOTNET_NOLOGO=1 \
dotnet \
publish \
Jellyfin.Server \
--configuration Release \
--output builddir \
--self-contained false \
--runtime %{dotnet_runtime} \
-p:DebugSymbols=false \
-p:DebugType=none
%install
install --directory "%{buildroot}%{_libdir}"
cp --recursive builddir "%{buildroot}%{_libdir}/jellyfin"
install --directory "%{buildroot}%{_bindir}"
ln --symbolic --force "%{_libdir}/jellyfin/jellyfin" "%{buildroot}%{_bindir}/jellyfin"
pushd %{_builddir}/jellyfin-packaging-%{jellyfin_packaging_version}/debian/conf
install -D --mode=644 jellyfin.service "%{buildroot}%{_unitdir}/jellyfin.service"
install -D --mode=640 jellyfin "%{buildroot}%{_sysconfdir}/jellyfin/jellyfin.env"
popd
install -D --mode=0644 "%{SOURCE2}" "%{buildroot}%{_tmpfilesdir}/jellyfin.conf"
install --directory --mode=750 "%{buildroot}%{_localstatedir}/cache/jellyfin"
install --directory --mode=750 "%{buildroot}%{_sharedstatedir}/jellyfin"
find %{buildroot}
%files
%license LICENSE
%{_bindir}/jellyfin
%{_libdir}/jellyfin
%{_tmpfilesdir}/jellyfin.conf
%{_unitdir}/jellyfin.service
%defattr(640,jellyfin,jellyfin,750)
%dir %{_localstatedir}/cache/jellyfin
%dir %{_sharedstatedir}/jellyfin
%dir %{_sysconfdir}/jellyfin
%config(noreplace) %{_sysconfdir}/jellyfin/jellyfin.env
%pre
getent group jellyfin > /dev/null || groupadd --system jellyfin
getent passwd jellyfin > /dev/null || \
useradd --system --home-dir "%{_sharedstatedir}/jellyfin" --gid jellyfin \
-s /sbin/nologin -c "jellyfin daemon" jellyfin
exit 0
%post
%systemd_post jellyfin.service
%preun
%systemd_preun jellyfin.service
%postun
%systemd_postun jellyfin.service
@@ -1 +0,0 @@
d /var/log/jellyfin 0750 jellyfin jellyfin
-13
View File
@@ -1,13 +0,0 @@
---
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 10.10.7
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 10.10.7
description: jellyfin-web package
github: unknown/jellyfin-web
name: jellyfin-web
-18
View File
@@ -1,18 +0,0 @@
#!/usr/bin/bash
# Setup rpmbuild directory structure
mkdir -p /root/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
# Install Node.js for building
dnf module enable nodejs:20 -y
dnf install nodejs npm -y
# Download source files using spectool
spectool -g -R /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
# Build the RPM
rpmbuild -ba /app/resources/jellyfin-web_${PACKAGE_VERSION}.spec
# Copy the built RPMs to output directory
cp /root/rpmbuild/RPMS/noarch/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.noarch.rpm /app/dist/
cp /root/rpmbuild/SRPMS/jellyfin-web-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.src.rpm /app/dist/
@@ -1,43 +0,0 @@
%global jellyfin_version 10.10.7
Name: jellyfin-web
Version: %{jellyfin_version}
Release: 1
Summary: The Free Software Media System - Official Web Client
License: GPL-2.0-or-later
URL: https://github.com/jellyfin/jellyfin-web
Source0: https://github.com/jellyfin/jellyfin-web/archive/refs/tags/v%{version}.tar.gz
BuildArch: noarch
BuildRequires: git
BuildRequires: nodejs
BuildRequires: npm
%description
%{summary}.
%prep
%setup -q -n jellyfin-web-%{version}
%build
SKIP_PREPARE=1 npm ci --no-audit --no-fund --no-update-notifier
npm run build:production
%install
install --directory "%{buildroot}%{_datadir}/jellyfin/web"
cp --recursive dist/* "%{buildroot}%{_datadir}/jellyfin/web"
%files
%license LICENSE
%{_datadir}/jellyfin/web
+10 -9
View File
@@ -1,20 +1,21 @@
name: jsonnet-language-server
github: grafana/jsonnet-language-server
description: Jsonnet Language Server Protocol implementation for the Jsonnet templating
language.
arch: amd64
platform: linux
maintainer: Grafana Labs
homepage: https://github.com/grafana/jsonnet-language-server
license: Apache-2.0
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
repository:
- almalinux/el8
version: 0.17.0
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
repository:
- almalinux/el9
version: 0.17.0
description: Jsonnet Language Server Protocol implementation for the Jsonnet templating
language.
github: grafana/jsonnet-language-server
homepage: https://github.com/grafana/jsonnet-language-server
license: Apache-2.0
maintainer: Grafana Labs
name: jsonnet-language-server
platform: linux
+9 -8
View File
@@ -1,19 +1,20 @@
name: jsonnet-lint
github: google/go-jsonnet
description: Linter for Jsonnet
arch: amd64
platform: linux
maintainer: Google
homepage: https://github.com/google/go-jsonnet
license: Apache-2.0
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
repository:
- almalinux/el8
version: 0.22.0
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
repository:
- almalinux/el9
version: 0.22.0
description: Linter for Jsonnet
github: google/go-jsonnet
homepage: https://github.com/google/go-jsonnet
license: Apache-2.0
maintainer: Google
name: jsonnet-lint
platform: linux
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 0.21.0
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 0.21.0
description: A data templating language
name: jsonnet
github: google/go-jsonnet
description: A data templating language
arch: amd64
platform: linux
maintainer: Google
homepage: https://github.com/google/go-jsonnet
license: Apache-2.0
maintainer: Google
name: jsonnet
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
repository:
- almalinux/el8
version: 0.22.0
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
repository:
- almalinux/el9
version: 0.22.0
+23
View File
@@ -0,0 +1,23 @@
name: k8up
github: k8up-io/k8up
github_release_pattern: ^v2\.
description: K8up Kubernetes backup operator command line client.
arch: amd64
platform: linux
maintainer: K8up Authors
homepage: https://github.com/k8up-io/k8up
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.16.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.16.0
+17
View File
@@ -0,0 +1,17 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/k8up-io/k8up/releases/download/v${PACKAGE_VERSION}"
TARBALL="k8up_${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ k8up
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+16
View File
@@ -0,0 +1,16 @@
#compdef k8up
local -a opts
local cur
cur=${words[-1]}
if [[ "$cur" == "-"* ]]; then
opts=("${(@f)$(${words[@]:0:#words[@]-1} ${cur} --generate-bash-completion 2>/dev/null)}")
else
opts=("${(@f)$(${words[@]:0:#words[@]-1} --generate-bash-completion 2>/dev/null)}")
fi
if [[ "${opts[1]}" != "" ]]; then
_describe 'values' opts
else
_files
fi
+34
View File
@@ -0,0 +1,34 @@
: ${PROG:=$(basename ${BASH_SOURCE})}
# Macs have bash3 for which the bash-completion package doesn't include
# _init_completion. This is a minimal version of that function.
_cli_init_completion() {
COMPREPLY=()
_get_comp_words_by_ref "$@" cur prev words cword
}
_cli_bash_autocomplete() {
if [[ "${COMP_WORDS[0]}" != "source" ]]; then
local cur opts base words
COMPREPLY=()
cur="${COMP_WORDS[COMP_CWORD]}"
if declare -F _init_completion >/dev/null 2>&1; then
_init_completion -n "=:" || return
else
_cli_init_completion -n "=:" || return
fi
words=("${words[@]:0:$cword}")
if [[ "$cur" == "-"* ]]; then
requestComp="${words[*]} ${cur} --generate-bash-completion"
else
requestComp="${words[*]} --generate-bash-completion"
fi
opts=$(eval "${requestComp}" 2>/dev/null)
COMPREPLY=($(compgen -W "${opts}" -- ${cur}))
return 0
fi
}
complete -o bashdefault -o default -o nospace -F _cli_bash_autocomplete $PROG
unset PROG
+11
View File
@@ -0,0 +1,11 @@
function __k8up_complete
set -l words (commandline -opc)
set -l cur (commandline -ct)
if string match -q -- '-*' $cur
$words $cur --generate-bash-completion 2>/dev/null
else
$words --generate-bash-completion 2>/dev/null
end
end
complete -c k8up -f -a '(__k8up_complete)'
+48
View File
@@ -0,0 +1,48 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- k8up
provides:
- k8up
contents:
- src: /app/k8up
dst: /usr/bin/k8up
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/completions/k8up
dst: /usr/share/bash-completion/completions/k8up
file_info:
mode: 0644
owner: root
group: root
- src: /app/resources/completions/_k8up
dst: /usr/share/zsh/site-functions/_k8up
file_info:
mode: 0644
owner: root
group: root
- src: /app/resources/completions/k8up.fish
dst: /usr/share/fish/vendor_completions.d/k8up.fish
file_info:
mode: 0644
owner: root
group: root
+27
View File
@@ -0,0 +1,27 @@
name: kubecolor
github: kubecolor/kubecolor
description: Colorize your kubectl output
arch: amd64
platform: linux
maintainer: kubecolor
homepage: https://github.com/kubecolor/kubecolor
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: 0.8.0
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.8.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.8.0
+10
View File
@@ -0,0 +1,10 @@
#!/usr/bin/bash
set -e
wget -O /app/kubecolor_${PACKAGE_VERSION}_linux_amd64.tar.gz https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/kubecolor/kubecolor/releases/download/v${PACKAGE_VERSION}/kubecolor_${PACKAGE_VERSION}_linux_amd64.tar.gz
tar xf /app/kubecolor_${PACKAGE_VERSION}_linux_amd64.tar.gz -C /app/ kubecolor
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+30
View File
@@ -0,0 +1,30 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubecolor
provides:
- kubecolor
contents:
- src: /app/kubecolor
dst: /usr/bin/kubecolor
file_info:
mode: 0755
owner: root
group: root
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: Yann Hamon
homepage: https://github.com/yannh/kubeconform
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 0.7.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.7.0
+22
View File
@@ -0,0 +1,22 @@
name: kubectl-cnpg
github: cloudnative-pg/cloudnative-pg
description: CloudNativePG kubectl plugin.
arch: amd64
platform: linux
maintainer: The CloudNativePG Contributors
homepage: https://github.com/cloudnative-pg/cloudnative-pg
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.30.1
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.30.1
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/cloudnative-pg/cloudnative-pg/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-cnpg_${PACKAGE_VERSION}_linux_x86_64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/cnpg-${PACKAGE_VERSION}-checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-cnpg
mkdir -p /app/completions
/app/kubectl-cnpg completion bash > /app/completions/kubectl-cnpg
/app/kubectl-cnpg completion zsh > /app/completions/_kubectl-cnpg
/app/kubectl-cnpg completion fish > /app/completions/kubectl-cnpg.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+2
View File
@@ -0,0 +1,2 @@
#!/usr/bin/env sh
exec kubectl cnpg __complete "$@"
+54
View File
@@ -0,0 +1,54 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-cnpg
provides:
- kubectl-cnpg
contents:
- src: /app/kubectl-cnpg
dst: /usr/bin/kubectl-cnpg
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-cnpg
dst: /usr/bin/kubectl_complete-cnpg
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/kubectl-cnpg
dst: /usr/share/bash-completion/completions/kubectl-cnpg
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_kubectl-cnpg
dst: /usr/share/zsh/site-functions/_kubectl-cnpg
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/kubectl-cnpg.fish
dst: /usr/share/fish/vendor_completions.d/kubectl-cnpg.fish
file_info:
mode: 0644
owner: root
group: root
+22
View File
@@ -0,0 +1,22 @@
name: kubectl-tree
github: ahmetb/kubectl-tree
description: kubectl plugin to browse Kubernetes object hierarchies as a tree.
arch: amd64
platform: linux
maintainer: Ahmet Alp Balkan
homepage: https://github.com/ahmetb/kubectl-tree
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.6.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.6.0
+17
View File
@@ -0,0 +1,17 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/ahmetb/kubectl-tree/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-tree_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/kubectl-tree_${PACKAGE_VERSION}_checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-tree
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
+7
View File
@@ -0,0 +1,7 @@
#!/usr/bin/env sh
# kubectl-tree only completes flags; its KIND NAME args match kubectl get
for arg in "$@"; do last=$arg; done
case "$last" in
-*) exec kubectl tree __complete "$@" ;;
*) exec kubectl __complete get "$@" ;;
esac
+36
View File
@@ -0,0 +1,36 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-tree
provides:
- kubectl-tree
contents:
- src: /app/kubectl-tree
dst: /usr/bin/kubectl-tree
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-tree
dst: /usr/bin/kubectl_complete-tree
file_info:
mode: 0755
owner: root
group: root
+22
View File
@@ -0,0 +1,22 @@
name: kubectl-view-secret
github: elsesiy/kubectl-view-secret
description: Kubectl plugin to decode Kubernetes secrets.
arch: amd64
platform: linux
maintainer: Jonas-Taha El Sesiy
homepage: https://github.com/elsesiy/kubectl-view-secret
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.16.0
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.16.0
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/bash
set -e
BASE_URL="https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/elsesiy/kubectl-view-secret/releases/download/v${PACKAGE_VERSION}"
TARBALL="kubectl-view-secret_v${PACKAGE_VERSION}_linux_amd64.tar.gz"
wget -O "/app/${TARBALL}" "${BASE_URL}/${TARBALL}"
wget -O /app/checksums.txt "${BASE_URL}/kubectl-view-secret_${PACKAGE_VERSION}_checksums.txt"
cd /app
grep " ${TARBALL}$" checksums.txt | sha256sum --check --strict -
tar xf "/app/${TARBALL}" -C /app/ kubectl-view-secret
mkdir -p /app/completions
# kubectl resolves `kubectl view-secret` to kubectl-view_secret; upstream completions target "view-secret".
mv /app/kubectl-view-secret /app/kubectl-view_secret
/app/kubectl-view_secret completion bash | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret
/app/kubectl-view_secret completion zsh | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/_kubectl-view_secret
/app/kubectl-view_secret completion fish | sed 's/view-secret/kubectl-view_secret/g' > /app/completions/kubectl-view_secret.fish
envsubst < /app/resources/nfpm.yaml > /app/nfpm.yaml
nfpm pkg --config /app/nfpm.yaml --target /app/dist --packager rpm
@@ -0,0 +1,2 @@
#!/usr/bin/env sh
exec kubectl view-secret __complete "$@"
@@ -0,0 +1,54 @@
# nfpm.yaml
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- kubectl-view-secret
provides:
- kubectl-view-secret
contents:
- src: /app/kubectl-view_secret
dst: /usr/bin/kubectl-view_secret
file_info:
mode: 0755
owner: root
group: root
- src: /app/resources/kubectl_complete-view_secret
dst: /usr/bin/kubectl_complete-view_secret
file_info:
mode: 0755
owner: root
group: root
- src: /app/completions/kubectl-view_secret
dst: /usr/share/bash-completion/completions/kubectl-view_secret
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/_kubectl-view_secret
dst: /usr/share/zsh/site-functions/_kubectl-view_secret
file_info:
mode: 0644
owner: root
group: root
- src: /app/completions/kubectl-view_secret.fish
dst: /usr/share/fish/vendor_completions.d/kubectl-view_secret.fish
file_info:
mode: 0644
owner: root
group: root
+2 -2
View File
@@ -1,4 +1,3 @@
---
name: kubectx
github: ahmetb/kubectx
description: Faster way to switch between clusters and namespaces in kubectl.
@@ -7,6 +6,7 @@ platform: linux
maintainer: ahmetb
homepage: https://github.com/ahmetb/kubectx
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +15,6 @@ builds:
version: 0.11.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.11.0
+11 -9
View File
@@ -1,4 +1,3 @@
---
name: kustomize
github: kubernetes-sigs/kustomize
description: Kubernetes native configuration management
@@ -7,13 +6,16 @@ platform: linux
maintainer: kubernetes-sigs
homepage: https://github.com/kubernetes-sigs/kustomize
license: Apache-2.0
dist_tag: true
github_release_pattern: ^kustomize/v.*
builds:
- repository: [almalinux/el8]
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
version: 5.8.1
- repository: [almalinux/el9]
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
version: 5.8.1
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
version: 5.8.1
- repository:
- almalinux/el9
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
version: 5.8.1
+2 -2
View File
@@ -1,4 +1,3 @@
---
name: lazydocker
github: jesseduffield/lazydocker
description: The lazier way to manage everything docker.
@@ -7,6 +6,7 @@ platform: linux
maintainer: jesseduffield
homepage: https://github.com/jesseduffield/lazydocker
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +15,6 @@ builds:
version: 0.25.2
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.25.2
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 7.3.71
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 7.3.71
description: FoundationDB client library - Shared library for FoundationDB applications
name: libfoundationdb
github: apple/foundationdb
description: FoundationDB client library - Shared library for FoundationDB applications
arch: amd64
platform: linux
maintainer: FoundationDB Community
homepage: https://github.com/apple/foundationdb
license: Apache-2.0
maintainer: FoundationDB Community
name: libfoundationdb
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 7.3.71
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 7.3.71
+4 -3
View File
@@ -1,12 +1,13 @@
---
name: neovim-glibc-2.17
github: neovim/neovim-releases
description: Vim-fork focused on extensibility and usability (glibc 2.17 compatible build).
description: Vim-fork focused on extensibility and usability (glibc 2.17 compatible
build).
arch: amd64
platform: linux
maintainer: neovim
homepage: https://neovim.io
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 0.12.2
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.12.2
+2 -2
View File
@@ -1,4 +1,3 @@
---
name: neovim
github: neovim/neovim
description: Vim-fork focused on extensibility and usability.
@@ -7,6 +6,7 @@ platform: linux
maintainer: neovim
homepage: https://neovim.io
license: Apache-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +15,6 @@ builds:
version: 0.12.2
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.12.2
+9 -1
View File
@@ -7,6 +7,7 @@ platform: linux
maintainer: GoReleaser
homepage: https://nfpm.goreleaser.com/
license: MIT
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,13 @@ builds:
version: 2.46.3
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.46.3
- repository:
- fedora/42
- fedora/43
- fedora/44
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 2.46.3
+4 -3
View File
@@ -6,14 +6,15 @@ platform: linux
maintainer: Prometheus
homepage: https://github.com/prometheus/node_exporter
license: Apache-2.0 license
dist_tag: true
builds:
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: 1.10.2
version: 1.11.1
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.10.2
version: 1.11.1
+2 -1
View File
@@ -8,6 +8,7 @@ platform: linux
maintainer: Hashicorp
homepage: https://github.com/hashicorp/nomad-autoscaler
license: Mozilla Public License, version 2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -16,6 +17,6 @@ builds:
version: 0.4.9
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.4.9
+18 -15
View File
@@ -1,18 +1,21 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 1.10.1
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 1.10.1
description: A simple and flexible scheduler and orchestrator to deploy and manage containers and non-containerized applications across on-premises and clouds at scale.
name: nomad
github: unknown/nomad
description: A simple and flexible scheduler and orchestrator to deploy and manage
containers and non-containerized applications across on-premises and clouds at scale.
arch: amd64
platform: linux
maintainer: HashiCorp
homepage: https://www.nomadproject.io/
license: BUSL-1.1
maintainer: HashiCorp
name: nomad
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 1.10.1
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 1.10.1
+4 -3
View File
@@ -7,14 +7,15 @@ platform: linux
maintainer: nzbgetcom
homepage: https://github.com/nzbgetcom/nzbget
license: GPL-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
version: '26.1'
version: '26.2'
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: '26.1'
version: '26.2'
+6 -2
View File
@@ -2,6 +2,10 @@
set -e
# Download the pre-built RPM from GitHub releases
# Download the pre-built RPM from GitHub releases.
# Upstream always publishes the release-1 asset (nzbget-<version>-1.x86_64.rpm);
# the source URL must use the upstream asset name, not PACKAGE_RELEASE, which
# carries the dist tag (e.g. 1.el9) and does not exist upstream. Only the local
# output filename is dist-tagged, mirroring the code-server package.
curl -L -o /app/dist/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm \
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-${PACKAGE_RELEASE}.x86_64.rpm
https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/nzbgetcom/nzbget/releases/download/v$PACKAGE_VERSION/nzbget-${PACKAGE_VERSION}-1.x86_64.rpm
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 2025.08.03
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 2025.08.03
description: Prometheus exporter for NZBGet
name: nzbget_exporter
github: frebib/nzbget-exporter
description: Prometheus exporter for NZBGet
arch: amd64
platform: linux
maintainer: Prometheus
homepage: https://github.com/frebib/nzbget-exporter
license: MIT
maintainer: Prometheus
name: nzbget_exporter
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 2025.08.03
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 2025.08.03
@@ -1,12 +1,13 @@
name: openbao-plugin-secret-consul
github: openbao/openbao-plugins
github_release_pattern: "^secrets-consul-v.*"
description: OpenBao secrets engine plugin for HashiCorp Consul
arch: amd64
platform: linux
maintainer: OpenBao Community
homepage: https://github.com/openbao/openbao-plugins
license: MPL-2.0
dist_tag: true
github_release_pattern: ^secrets-consul-v.*
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 0.1.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.1.0
@@ -1,12 +1,13 @@
name: openbao-plugin-secret-nomad
github: openbao/openbao-plugins
github_release_pattern: "^secrets-nomad-v.*"
description: OpenBao secrets engine plugin for HashiCorp Nomad
arch: amd64
platform: linux
maintainer: OpenBao Community
homepage: https://github.com/openbao/openbao-plugins
license: MPL-2.0
dist_tag: true
github_release_pattern: ^secrets-nomad-v.*
builds:
- repository:
- almalinux/el8
@@ -15,6 +16,6 @@ builds:
version: 0.1.5
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.1.5
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: OpenBao Community
homepage: https://github.com/openbao/openbao-plugins
license: MPL-2.0
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 1.0.0
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.0.0
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: HashiCorp
homepage: https://www.packer.io/
license: BUSL-1.1
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 1.15.3
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 1.15.3
+17 -15
View File
@@ -1,18 +1,20 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 0.11.0
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 0.11.0
description: Prometheus exporter for PgBouncer
name: pgbouncer_exporter
github: prometheus-community/pgbouncer_exporter
description: Prometheus exporter for PgBouncer
arch: amd64
platform: linux
maintainer: Prometheus
homepage: https://github.com/prometheus-community/pgbouncer_exporter
license: Apache-2.0 license
maintainer: Prometheus
name: pgbouncer_exporter
platform: linux
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: 1
repository:
- almalinux/el8
version: 0.12.0
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
repository:
- almalinux/el9
version: 0.12.0
+2 -1
View File
@@ -6,6 +6,7 @@ platform: linux
maintainer: Prometheus
homepage: https://github.com/prometheus-community/postgres_exporter
license: Apache-2.0 license
dist_tag: true
builds:
- repository:
- almalinux/el8
@@ -14,6 +15,6 @@ builds:
version: 0.19.1
- repository:
- almalinux/el9
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: 1
version: 0.19.1
+38
View File
@@ -0,0 +1,38 @@
# puppet-initial
A firstrun bootstrap script and oneshot systemd service that initialises a
freshly-provisioned host into Puppet:
1. Sets the FQDN under `.main.unkin.net`.
2. Fetches the Puppet CA certificate from the CA service.
3. Registers the node with a noop agent run against the CA.
4. Runs the agent a few times against the compile master, then enables the
`puppet` service and disables itself.
## Puppet CA endpoint
The CA endpoint defaults to the in-cluster puppetserver CA service
`puppetca.k8s.syd1.au.unkin.net:8140` (serving the standard
`/puppet-ca/v1/certificate/ca` API).
It is overridable via the environment. The `puppet-initial.service` unit reads
`/etc/sysconfig/puppet-initial` (`EnvironmentFile=-`, so the file is optional),
which the RPM ships as a commented `%config(noreplace)` example:
| Variable | Default | Purpose |
|-----------------|----------------------------------|-------------------------------------------------------------|
| `PUPPETCA_HOST` | `puppetca.k8s.syd1.au.unkin.net` | CA hostname (CA cert fetch + `--server` for registration). |
| `PUPPETCA_PORT` | `8140` | CA API port. |
### Overriding from kickstart
A kickstart `%post` can point a host at a different CA without rebuilding the
RPM by writing the sysconfig file before the service starts:
```bash
%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF
```
+17 -15
View File
@@ -1,17 +1,19 @@
---
arch: amd64
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository: [almalinux/el8]
version: 1.0.3
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository: [almalinux/el9]
version: 1.0.3
description: A script and service to initialise puppet for the unkin environmnet.
github: unknown/puppet-initial
license: MIT
maintainer: UNKIN
name: puppet-initial
github: unknown/puppet-initial
description: A script and service to initialise puppet for the unkin environmnet.
arch: amd64
platform: linux
maintainer: UNKIN
license: MIT
dist_tag: true
builds:
- image: git.unkin.net/unkin/almalinux8-rpmbuilder:latest
release: '1'
repository:
- almalinux/el8
version: 1.0.5
- image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/rpmbuilder:0.1.0-alma9
release: '1'
repository:
- almalinux/el9
version: 1.0.5
+8 -1
View File
@@ -15,7 +15,7 @@ license: ${PACKAGE_LICENSE}
disable_globbing: false
depends:
- puppet-agent
- openvox-agent
# Files to include in the package
contents:
@@ -31,6 +31,13 @@ contents:
mode: 0644
owner: root
group: root
- src: /app/resources/puppet-initial.sysconfig
dst: /etc/sysconfig/puppet-initial
type: config|noreplace
file_info:
mode: 0644
owner: root
group: root
# Scripts to run during installation/removal (optional)
scripts:
+9 -2
View File
@@ -1,14 +1,21 @@
#!/bin/bash
# Puppet CA endpoint. Overridable via the environment (systemd reads
# /etc/sysconfig/puppet-initial via EnvironmentFile), so kickstart %post can
# point a host at a different CA without rebuilding the RPM. Defaults to the
# in-cluster puppetserver CA service.
PUPPETCA_HOST="${PUPPETCA_HOST:-puppetca.k8s.syd1.au.unkin.net}"
PUPPETCA_PORT="${PUPPETCA_PORT:-8140}"
# Ensure the hostname is set
hostnamectl set-hostname $(hostname -s).main.unkin.net
grep '^HOSTNAME=' /etc/sysconfig/network | cut -d= -f2 | grep -q '\.' || sed -i 's/^\(HOSTNAME=[^\.]*\)$/\1.main.unkin.net/' /etc/sysconfig/network
# Install CA for Puppet
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate https://puppetca.query.consul:8140/puppet-ca/v1/certificate/ca -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate "https://${PUPPETCA_HOST}:${PUPPETCA_PORT}/puppet-ca/v1/certificate/ca" -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
# Registering to Puppet server
/opt/puppetlabs/bin/puppet agent --test --server puppetca.query.consul --noop --onetime --no-daemonize --verbose
/opt/puppetlabs/bin/puppet agent --test --server "${PUPPETCA_HOST}" --noop --onetime --no-daemonize --verbose
# Running Puppet agent five times with a 30-second gap between each run, stop puppet service at the end of each run
for i in {1..5}; do
@@ -5,6 +5,7 @@ Wants=network-online.target
[Service]
Type=simple
EnvironmentFile=-/etc/sysconfig/puppet-initial
ExecStart=/usr/local/bin/puppet-initial
RemainAfterExit=true
ExecStop=/bin/true
@@ -0,0 +1,13 @@
# Environment overrides for the puppet-initial firstrun bootstrap.
# Read by the puppet-initial.service unit (EnvironmentFile=-/etc/sysconfig/puppet-initial).
# A kickstart %post can write this file to point a host at a different Puppet CA
# without rebuilding the RPM. All values are optional; the defaults below match
# the shipped in-cluster puppetserver CA service.
# Hostname of the Puppet CA service. Used both to fetch the CA certificate
# (https://<host>:<port>/puppet-ca/v1/certificate/ca) and as --server for the
# initial noop agent registration run.
#PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
# Port the Puppet CA API listens on.
#PUPPETCA_PORT=8140

Some files were not shown because too many files have changed in this diff Show More