Merge nucleic/olive-ember-seal-q7vk into dev
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
Package: naros-keyring
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: misc
|
||||
Priority: optional
|
||||
Description: narOS apt archive keyring and source entry (NAROS.md §3.2)
|
||||
The narOS apt repository's signing public key
|
||||
(/usr/share/keyrings/naros-archive-keyring.gpg) plus the deb822 source entry
|
||||
for apt.naros.dev pinned to that key. Installing this on any Debian-family
|
||||
system enables `apt install naros-tier-agent` conversion (NAROS.md §7.3).
|
||||
@@ -0,0 +1,5 @@
|
||||
Types: deb
|
||||
URIs: https://apt.naros.dev
|
||||
Suites: stable
|
||||
Components: main
|
||||
Signed-By: /usr/share/keyrings/naros-archive-keyring.gpg
|
||||
@@ -0,0 +1,10 @@
|
||||
# The public key is materialized by CI from the NAROS_APT_PUBLIC_KEY secret (or by an
|
||||
# operator into os/repo/keys/). No key in the tree, no keyring package — skip cleanly.
|
||||
stage() {
|
||||
local dest="$1" key="$OS_DIR/repo/keys/naros-archive-keyring.gpg"
|
||||
if [ ! -f "$key" ]; then
|
||||
echo "public key missing: $key (CI materializes it from secrets)" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0644 "$key" "$dest/usr/share/keyrings/naros-archive-keyring.gpg"
|
||||
}
|
||||
Reference in New Issue
Block a user