From ddcb3fdb23ad5ddbf99dba9740cc70d2be1c2b6b Mon Sep 17 00:00:00 2001 From: Nucleic Date: Sat, 18 Jul 2026 16:27:25 -0700 Subject: [PATCH] Merge nucleic/golden-thistle-badger-sf7s into dev --- repo/r2-sync.sh | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/repo/r2-sync.sh b/repo/r2-sync.sh index 73a3835..55b85a5 100755 --- a/repo/r2-sync.sh +++ b/repo/r2-sync.sh @@ -3,6 +3,7 @@ # NAROS.md §3.2). # Uses rclone's S3 backend with env-provided credentials (CI secrets): # R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, R2_BUCKET (default naros-apt) +# R2_JURISDICTION (optional: default, eu, or fedramp) set -euo pipefail OS_DIR="$(cd "$(dirname "$0")/.." && pwd)" @@ -11,11 +12,28 @@ REPO="$OS_DIR/dist/repo" BUCKET="${R2_BUCKET:-naros-apt}" [ -d "$REPO" ] || { echo "no repo at $REPO — run repo/publish.sh first" >&2; exit 2; } -export RCLONE_CONFIG_R2_TYPE=s3 \ +if [[ ! "$R2_ACCOUNT_ID" =~ ^[[:xdigit:]]{32}$ ]]; then + echo "R2_ACCOUNT_ID must be the 32-character Cloudflare account ID" >&2 + exit 2 +fi + +case "${R2_JURISDICTION:-default}" in + default) ENDPOINT="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com" ;; + eu|fedramp) ENDPOINT="https://${R2_ACCOUNT_ID}.${R2_JURISDICTION}.r2.cloudflarestorage.com" ;; + *) echo "R2_JURISDICTION must be default, eu, or fedramp" >&2; exit 2 ;; +esac + +# /dev/null is intentional: this remote is configured entirely through environment +# variables, so rclone must not search for (and warn about) rclone.conf. +export RCLONE_CONFIG=/dev/null \ + RCLONE_CONFIG_R2_TYPE=s3 \ RCLONE_CONFIG_R2_PROVIDER=Cloudflare \ RCLONE_CONFIG_R2_ACCESS_KEY_ID="$R2_ACCESS_KEY_ID" \ RCLONE_CONFIG_R2_SECRET_ACCESS_KEY="$R2_SECRET_ACCESS_KEY" \ - RCLONE_CONFIG_R2_ENDPOINT="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com" + RCLONE_CONFIG_R2_ENDPOINT="$ENDPOINT" \ + RCLONE_CONFIG_R2_REGION=auto \ + RCLONE_CONFIG_R2_ACL=private \ + RCLONE_CONFIG_R2_NO_CHECK_BUCKET=true # pool/ first, dists/ last: clients never see an index referencing a not-yet-uploaded deb. rclone copy "$REPO/pool" "r2:$BUCKET/pool" --checksum