Add bin/repo deploy and --host on every server-facing command

deploy runs build then push, which is the whole workflow on a local build
machine. It resolves the build host before building so a missing --host fails
in a second rather than after a long compile.

--host now overrides $OMARCHY_BUILD_HOST and .build-host on deploy, push, and
the build trigger in omarchy-pkgs release, so a server can be named per
invocation without arming the release auto-trigger.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
David Heinemeier Hansson
2026-08-12 03:23:30 -07:00
co-authored by Claude Opus 5
parent bf53101bbf
commit c5f5f1c12c
4 changed files with 161 additions and 1 deletions
+20
View File
@@ -80,6 +80,13 @@ bin/repo sync # Sync to remote
Large packages build faster on a local machine than on the server. Build them
here, then hand the artifacts to the build host, which signs and publishes them:
```bash
bin/repo deploy --package nvidia-580xx-utils # Build here, publish from the host
```
`deploy` is `build` followed by `push`. The two steps are also available
separately when a build needs inspecting before it ships:
```bash
bin/repo build --package nvidia-580xx-utils # Build on the fast machine
bin/repo push --package nvidia-580xx-utils # Upload + publish on the host
@@ -171,6 +178,18 @@ is what pacman resolves against, so a partial one hides every package it does no
know about even though the files are still on the mirror. Use `bin/repo push` to
publish packages built on another machine.
### Deploy
```bash
bin/repo deploy --package nvidia-580xx-utils # Build locally, publish from the host
bin/repo deploy --host root@example.com # Point at a specific build host
bin/repo deploy --dry-run # Show the plan, change nothing
```
Runs `build` then `push` in one command. The build host is resolved before the
build starts, so a missing `--host` fails immediately rather than after a long
compile.
### Push to the Build Host
```bash
@@ -215,6 +234,7 @@ bin/repo migrate --arch x86_64 # Promote tested edge artifacts -> stable,
bin/repo migrate --package <name> # Promote a single package -> stable
bin/repo migrate --dry-run # Preview migration and cleanup
bin/repo list # List package metadata
bin/repo deploy # Build locally, then publish from the host
bin/repo push # Upload local builds to the host and publish
bin/add-package <package> # Add an AUR/local package with metadata
bin/package-worktree <package> # Create upstream/patched/current scratch workspace
Executable
+131
View File
@@ -0,0 +1,131 @@
#!/bin/bash
# Build packages locally, then publish them from the build host.
#
# The two halves of shipping a package built on a local machine: bin/build
# produces the artifacts, bin/push-build hands them to the host that owns the
# signing key and the complete repository.
set -e
SCRIPT_DIR=$(realpath "${BASH_SOURCE[0]%/*}")
BUILD_ROOT=$(realpath "$SCRIPT_DIR/..")
source "$BUILD_ROOT/helpers/message-helpers.sh"
source "$BUILD_ROOT/helpers/paths.sh"
PACKAGES=()
HOST=""
REMOTE_ROOT=""
DRY_RUN=false
ASSUME_YES=false
print_header "Deploy (build + push)"
while [[ $# -gt 0 ]]; do
case $1 in
--arch)
ARCH="$2"
update_arch_paths
shift 2
;;
--mirror)
MIRROR="$2"
if [[ "$MIRROR" != "edge" && "$MIRROR" != "stable" ]]; then
print_error "Invalid mirror: $MIRROR (must be 'edge' or 'stable')"
exit 1
fi
update_arch_paths
shift 2
;;
--package)
shift
while [[ $# -gt 0 && ! "$1" =~ ^-- ]]; do
PACKAGES+=("$1")
shift
done
;;
--host)
HOST="$2"
shift 2
;;
--remote-root)
REMOTE_ROOT="$2"
shift 2
;;
--dry-run)
DRY_RUN=true
shift
;;
-y | --yes)
ASSUME_YES=true
shift
;;
-h | --help)
echo "Usage: $0 [OPTIONS]"
echo ""
echo "Build packages here, then publish them from the build host."
echo ""
echo "Options:"
echo " --arch <arch> Target architecture (default: x86_64)"
echo " --mirror <mirror> Mirror to publish to (edge or stable, default: edge)"
echo " --package <names> Build and push only these packages (space-separated)"
echo " --host <host> ssh destination (default: \$OMARCHY_BUILD_HOST or .build-host)"
echo " --remote-root <path> Repository path on the host (default: /root/omarchy-pkgs)"
echo " --dry-run Show the plan, build nothing and transfer nothing"
echo " -y, --yes Do not ask for confirmation before publishing"
echo " -h, --help Show this help message"
echo ""
echo "Examples:"
echo " $0 --package nvidia-580xx-utils"
echo " $0 --package nvidia-580xx-utils --host root@example.com"
exit 0
;;
*)
print_error "Unknown option: $1"
exit 1
;;
esac
done
echo ""
print_info "This will:"
echo " 1. Build packages locally"
echo " 2. Upload them to the build host"
echo " 3. Sign, promote, update and sync them there"
echo ""
BUILD_ARGS=("--arch" "$ARCH" "--mirror" "$MIRROR")
PUSH_ARGS=("--arch" "$ARCH" "--mirror" "$MIRROR")
if [[ ${#PACKAGES[@]} -gt 0 ]]; then
BUILD_ARGS+=("--package" "${PACKAGES[@]}")
PUSH_ARGS+=("--package" "${PACKAGES[@]}")
fi
[[ -n "$HOST" ]] && PUSH_ARGS+=("--host" "$HOST")
[[ -n "$REMOTE_ROOT" ]] && PUSH_ARGS+=("--remote-root" "$REMOTE_ROOT")
[[ "$DRY_RUN" == true ]] && BUILD_ARGS+=("--dry-run") && PUSH_ARGS+=("--dry-run")
[[ "$ASSUME_YES" == true ]] && PUSH_ARGS+=("--yes")
# Resolve the host before spending build time on packages that cannot ship.
if [[ "$DRY_RUN" != true ]]; then
resolved_host="$HOST"
if [[ -z "$resolved_host" ]]; then
resolved_host="${OMARCHY_BUILD_HOST:-}"
[[ -z "$resolved_host" && -f "$BUILD_ROOT/.build-host" ]] && resolved_host=$(<"$BUILD_ROOT/.build-host")
fi
if [[ -z "$resolved_host" ]]; then
print_error "No build host configured"
echo ""
echo "Pass --host, set OMARCHY_BUILD_HOST, or write the destination to:"
echo " $BUILD_ROOT/.build-host"
exit 1
fi
fi
print_info "Step 1/2: Building..."
echo ""
"$SCRIPT_DIR/build" "${BUILD_ARGS[@]}"
echo ""
print_info "Step 2/2: Pushing to the build host..."
echo ""
"$SCRIPT_DIR/push-build" "${PUSH_ARGS[@]}"
+5 -1
View File
@@ -43,6 +43,8 @@ Options for release:
--commit <sha> (rc) Upstream commit to pin (default: tip of --ref)
--ref <branch> (rc) Upstream branch whose tip to pin (default: $DEFAULT_RC_REF)
--yes Skip confirmation prompts
--host <host> ssh destination of the build host to trigger, overriding
\$OMARCHY_BUILD_HOST and .build-host
--no-push Rewrite and commit locally; skip push and build trigger
--pr When releasing from a non-master branch, open a GitHub PR
to master with gh after pushing
@@ -312,7 +314,8 @@ regenerate_checksums() {
# --- trigger -----------------------------------------------------------------
trigger_build_host() {
local host="${OMARCHY_BUILD_HOST:-}"
local host="${BUILD_HOST_OVERRIDE:-}"
[[ -z "$host" ]] && host="${OMARCHY_BUILD_HOST:-}"
[[ -z "$host" && -f "$BUILD_ROOT/.build-host" ]] && host=$(<"$BUILD_ROOT/.build-host")
if [[ -z "$host" ]]; then
print_info "No build host configured (set OMARCHY_BUILD_HOST or $BUILD_ROOT/.build-host)."
@@ -341,6 +344,7 @@ cmd_release() {
--force) force=true; shift ;;
--commit) commit_arg="$2"; shift 2 ;;
--ref) ref="$2"; shift 2 ;;
--host) BUILD_HOST_OVERRIDE="$2"; shift 2 ;;
--yes) assume_yes=true; shift ;;
--dry-run) dry_run=true; shift ;;
-h | --help) show_usage; exit 0 ;;
+5
View File
@@ -59,6 +59,7 @@ show_usage() {
echo " remove Remove a specific package"
echo " sync Sync repository to remote"
echo " push Upload local builds to the build host and publish them there"
echo " deploy Build locally, then push: one command for a local build machine"
echo ""
echo "Typical workflows:"
echo " $0 release # Complete release workflow"
@@ -130,6 +131,10 @@ push)
"$SCRIPT_DIR/push-build" "$@" 2>&1 | tee "$LOG_FILE"
exit ${PIPESTATUS[0]}
;;
deploy)
"$SCRIPT_DIR/deploy" "$@" 2>&1 | tee "$LOG_FILE"
exit ${PIPESTATUS[0]}
;;
-h | --help | help)
show_usage
;;