Merge nucleic/olive-ember-seal-q7vk into dev

This commit is contained in:
2026-07-18 15:14:54 -07:00
commit d919c693dd
34 changed files with 624 additions and 0 deletions
+55
View File
@@ -0,0 +1,55 @@
#!/usr/bin/env bash
# Publish dist/pool as a static apt tree (NAROS.md §3.2): dist/repo/dists/<channel>/main/
# with per-arch Packages(.xz) and a signed InRelease when a key is available.
#
# publish.sh [--channel edge|stable] [--sign KEYID]
#
# Unsigned mode is for local/dev use only (consume with [trusted=yes]); CI always signs
# (key from the NAROS_APT_SIGNING_KEY secret). Sync to R2 is r2-sync.sh's job.
set -euo pipefail
OS_DIR="$(cd "$(dirname "$0")/.." && pwd)"
CHANNEL="${NAROS_CHANNEL:-edge}" KEYID="${NAROS_APT_KEYID:-}"
while [ $# -gt 0 ]; do
case "$1" in
--channel) CHANNEL="$2"; shift 2 ;;
--sign) KEYID="$2"; shift 2 ;;
*) echo "unknown arg: $1" >&2; exit 2 ;;
esac
done
POOL="$OS_DIR/dist/pool"
REPO="$OS_DIR/dist/repo"
DISTS="$REPO/dists/$CHANNEL/main"
[ -d "$POOL" ] || { echo "no pool at $POOL — run packages/build-all.sh first" >&2; exit 2; }
rm -rf "$REPO/dists/$CHANNEL"
mkdir -p "$REPO/pool/main"
cp -a "$POOL/." "$REPO/pool/main/" 2>/dev/null || true
rm -f "$REPO/pool/main/Packages"
cd "$REPO"
for arch in arm64 amd64; do
bindir="dists/$CHANNEL/main/binary-$arch"
mkdir -p "$bindir"
# Arch-specific debs for this arch + arch:all debs, one Packages per binary-<arch>.
dpkg-scanpackages --multiversion --arch "$arch" pool > "$bindir/Packages"
xz -k -f "$bindir/Packages"
done
apt-ftparchive \
-o "APT::FTPArchive::Release::Origin=narOS" \
-o "APT::FTPArchive::Release::Label=narOS" \
-o "APT::FTPArchive::Release::Suite=$CHANNEL" \
-o "APT::FTPArchive::Release::Codename=$CHANNEL" \
-o "APT::FTPArchive::Release::Architectures=arm64 amd64" \
-o "APT::FTPArchive::Release::Components=main" \
release "dists/$CHANNEL" > "dists/$CHANNEL/Release"
if [ -n "$KEYID" ]; then
gpg --batch --yes -u "$KEYID" --clearsign -o "dists/$CHANNEL/InRelease" "dists/$CHANNEL/Release"
gpg --batch --yes -u "$KEYID" --detach-sign --armor -o "dists/$CHANNEL/Release.gpg" "dists/$CHANNEL/Release"
echo "published SIGNED repo: $REPO (channel $CHANNEL, key $KEYID)"
else
echo "published UNSIGNED repo: $REPO (channel $CHANNEL) — dev only, consume with [trusted=yes]"
fi
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
# Sync the published apt tree to Cloudflare R2 (served as apt.naros.dev; NAROS.md §3.2).
# Uses rclone's S3 backend with env-provided credentials (CI secrets):
# R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, R2_BUCKET (default naros-apt)
set -euo pipefail
OS_DIR="$(cd "$(dirname "$0")/.." && pwd)"
REPO="$OS_DIR/dist/repo"
: "${R2_ACCOUNT_ID:?}" "${R2_ACCESS_KEY_ID:?}" "${R2_SECRET_ACCESS_KEY:?}"
BUCKET="${R2_BUCKET:-naros-apt}"
[ -d "$REPO" ] || { echo "no repo at $REPO — run repo/publish.sh first" >&2; exit 2; }
export RCLONE_CONFIG_R2_TYPE=s3 \
RCLONE_CONFIG_R2_PROVIDER=Cloudflare \
RCLONE_CONFIG_R2_ACCESS_KEY_ID="$R2_ACCESS_KEY_ID" \
RCLONE_CONFIG_R2_SECRET_ACCESS_KEY="$R2_SECRET_ACCESS_KEY" \
RCLONE_CONFIG_R2_ENDPOINT="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com"
# pool/ first, dists/ last: clients never see an index referencing a not-yet-uploaded deb.
rclone copy "$REPO/pool" "r2:$BUCKET/pool" --checksum
rclone sync "$REPO/dists" "r2:$BUCKET/dists" --checksum
echo "synced $REPO -> r2:$BUCKET"