unkin-agent 70523ae938 Ship the intermediate CA in unkin-ca-certificates (#177)
`s3.ceph.unkin.net` serves a bare leaf issued by `CN=unkin.net Intermediate Authority`. The package shipped only the root, so images carrying just `unkin-ca-certificates` (container-base, container-gobuilder) cannot verify it — `curl https://s3.ceph.unkin.net/` returns 000.

- Fetch `pki_int` alongside `pki_root` and anchor it as `UNKIN_INTCA_2024.crt`
- Fail the build when a fetch errors or returns a non-certificate
- Bump version to `2026.10.2` on all distro targets

Verified in `gobuilder:0.1.1-alma9`: 000 before, 200 after, no `-k`.

Reviewed-on: #177
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-02 22:24:22 +10:00
2026-03-07 12:28:20 +11:00
S
Description
A repository for building RPMs in docker
1.7 MiB
Languages
Python 64.7%
Shell 33.3%
Makefile 1.4%
Dockerfile 0.6%