image: alpine/edge packages: - abuild - go - git - rclone secrets: # File secret `apk-ci-s3`, installed at ~/.apk-ci.env, containing # APK_CI_S3_ACCESS_KEY / APK_CI_S3_SECRET_KEY for the Garage `repo` bucket. - apk-ci-s3 sources: - https://git.srht.bigb.es/~bigbes/sr-ht-compare environment: REPO: sr-ht-compare APK_REPO: alpine/v3.22/bigbes/x86_64 S3_BUCKET: repo S3_ENDPOINT: https://s3.bigb.es submitter: git.sr.ht: allow-refs: - refs/heads/master tasks: - keygen: | # abuild insists on signing what it builds, but this key is deliberately # throwaway: generated per build, dies with the VM, trusted by nothing. # Clients verify against the index instead, which is rebuilt and signed on # phoebe by the garage stack's apk-mirror service — it indexes this repo # with --allow-untrusted precisely because of this. # # -i installs the public half into /etc/apk/keys. Without it abuild's own # final "update the local repository index" step dies with UNTRUSTED # signature, after having built the package perfectly well. SUDO=sudo abuild-keygen -a -n -i -q - version: | cd "$REPO" ver="0.0.$(git rev-list --count HEAD)" sed -i "s/^pkgver=.*/pkgver=$ver/" APKBUILD echo "export PKGVER=$ver" >> ~/.buildenv echo "building $ver" - build: | cd "$REPO" # -d: makedepends are already installed via `packages:` above, so skip # abuild's own dependency resolution (which would want to sudo apk add). REPODEST=$HOME/packages abuild -d find "$HOME/packages" -name '*.apk' - publish: | set +x # never echo the S3 credentials into the build log . ~/.apk-ci.env export RCLONE_CONFIG_GARAGE_TYPE=s3 export RCLONE_CONFIG_GARAGE_PROVIDER=Other export RCLONE_CONFIG_GARAGE_ENDPOINT="$S3_ENDPOINT" export RCLONE_CONFIG_GARAGE_REGION=garage export RCLONE_CONFIG_GARAGE_FORCE_PATH_STYLE=true export RCLONE_CONFIG_GARAGE_ACCESS_KEY_ID="$APK_CI_S3_ACCESS_KEY" export RCLONE_CONFIG_GARAGE_SECRET_ACCESS_KEY="$APK_CI_S3_SECRET_KEY" set -x # Upload only; never delete. Old versions stay so a pinned deployment can # always be rebuilt — the same reason the upstream mirror is append-only. # abuild nests output under $REPODEST///, so flatten by # uploading each file to a fixed prefix rather than mirroring the tree. find "$HOME/packages" -name '*.apk' -print | while read -r f; do rclone copyto "$f" "garage:$S3_BUCKET/$APK_REPO/$(basename "$f")" echo "uploaded $(basename "$f")" done echo "published; apk-mirror on phoebe re-indexes within 15 minutes"