From c5f5f1c12caf1c526318956cbcb4f714b9bf24b2 Mon Sep 17 00:00:00 2001 From: David Heinemeier Hansson Date: Wed, 12 Aug 2026 03:23:30 -0700 Subject: [PATCH] Add bin/repo deploy and --host on every server-facing command deploy runs build then push, which is the whole workflow on a local build machine. It resolves the build host before building so a missing --host fails in a second rather than after a long compile. --host now overrides $OMARCHY_BUILD_HOST and .build-host on deploy, push, and the build trigger in omarchy-pkgs release, so a server can be named per invocation without arming the release auto-trigger. Co-Authored-By: Claude Opus 5 (1M context) --- README.md | 20 ++++++++ bin/deploy | 131 +++++++++++++++++++++++++++++++++++++++++++++++ bin/omarchy-pkgs | 6 ++- bin/repo | 5 ++ 4 files changed, 161 insertions(+), 1 deletion(-) create mode 100755 bin/deploy diff --git a/README.md b/README.md index 52a40a9..399d6fd 100644 --- a/README.md +++ b/README.md @@ -80,6 +80,13 @@ bin/repo sync # Sync to remote Large packages build faster on a local machine than on the server. Build them here, then hand the artifacts to the build host, which signs and publishes them: +```bash +bin/repo deploy --package nvidia-580xx-utils # Build here, publish from the host +``` + +`deploy` is `build` followed by `push`. The two steps are also available +separately when a build needs inspecting before it ships: + ```bash bin/repo build --package nvidia-580xx-utils # Build on the fast machine bin/repo push --package nvidia-580xx-utils # Upload + publish on the host @@ -171,6 +178,18 @@ is what pacman resolves against, so a partial one hides every package it does no know about even though the files are still on the mirror. Use `bin/repo push` to publish packages built on another machine. +### Deploy + +```bash +bin/repo deploy --package nvidia-580xx-utils # Build locally, publish from the host +bin/repo deploy --host root@example.com # Point at a specific build host +bin/repo deploy --dry-run # Show the plan, change nothing +``` + +Runs `build` then `push` in one command. The build host is resolved before the +build starts, so a missing `--host` fails immediately rather than after a long +compile. + ### Push to the Build Host ```bash @@ -215,6 +234,7 @@ bin/repo migrate --arch x86_64 # Promote tested edge artifacts -> stable, bin/repo migrate --package # Promote a single package -> stable bin/repo migrate --dry-run # Preview migration and cleanup bin/repo list # List package metadata +bin/repo deploy # Build locally, then publish from the host bin/repo push # Upload local builds to the host and publish bin/add-package # Add an AUR/local package with metadata bin/package-worktree # Create upstream/patched/current scratch workspace diff --git a/bin/deploy b/bin/deploy new file mode 100755 index 0000000..955d74d --- /dev/null +++ b/bin/deploy @@ -0,0 +1,131 @@ +#!/bin/bash +# Build packages locally, then publish them from the build host. +# +# The two halves of shipping a package built on a local machine: bin/build +# produces the artifacts, bin/push-build hands them to the host that owns the +# signing key and the complete repository. + +set -e + +SCRIPT_DIR=$(realpath "${BASH_SOURCE[0]%/*}") +BUILD_ROOT=$(realpath "$SCRIPT_DIR/..") +source "$BUILD_ROOT/helpers/message-helpers.sh" +source "$BUILD_ROOT/helpers/paths.sh" + +PACKAGES=() +HOST="" +REMOTE_ROOT="" +DRY_RUN=false +ASSUME_YES=false + +print_header "Deploy (build + push)" + +while [[ $# -gt 0 ]]; do + case $1 in + --arch) + ARCH="$2" + update_arch_paths + shift 2 + ;; + --mirror) + MIRROR="$2" + if [[ "$MIRROR" != "edge" && "$MIRROR" != "stable" ]]; then + print_error "Invalid mirror: $MIRROR (must be 'edge' or 'stable')" + exit 1 + fi + update_arch_paths + shift 2 + ;; + --package) + shift + while [[ $# -gt 0 && ! "$1" =~ ^-- ]]; do + PACKAGES+=("$1") + shift + done + ;; + --host) + HOST="$2" + shift 2 + ;; + --remote-root) + REMOTE_ROOT="$2" + shift 2 + ;; + --dry-run) + DRY_RUN=true + shift + ;; + -y | --yes) + ASSUME_YES=true + shift + ;; + -h | --help) + echo "Usage: $0 [OPTIONS]" + echo "" + echo "Build packages here, then publish them from the build host." + echo "" + echo "Options:" + echo " --arch Target architecture (default: x86_64)" + echo " --mirror Mirror to publish to (edge or stable, default: edge)" + echo " --package Build and push only these packages (space-separated)" + echo " --host ssh destination (default: \$OMARCHY_BUILD_HOST or .build-host)" + echo " --remote-root Repository path on the host (default: /root/omarchy-pkgs)" + echo " --dry-run Show the plan, build nothing and transfer nothing" + echo " -y, --yes Do not ask for confirmation before publishing" + echo " -h, --help Show this help message" + echo "" + echo "Examples:" + echo " $0 --package nvidia-580xx-utils" + echo " $0 --package nvidia-580xx-utils --host root@example.com" + exit 0 + ;; + *) + print_error "Unknown option: $1" + exit 1 + ;; + esac +done + +echo "" +print_info "This will:" +echo " 1. Build packages locally" +echo " 2. Upload them to the build host" +echo " 3. Sign, promote, update and sync them there" +echo "" + +BUILD_ARGS=("--arch" "$ARCH" "--mirror" "$MIRROR") +PUSH_ARGS=("--arch" "$ARCH" "--mirror" "$MIRROR") + +if [[ ${#PACKAGES[@]} -gt 0 ]]; then + BUILD_ARGS+=("--package" "${PACKAGES[@]}") + PUSH_ARGS+=("--package" "${PACKAGES[@]}") +fi +[[ -n "$HOST" ]] && PUSH_ARGS+=("--host" "$HOST") +[[ -n "$REMOTE_ROOT" ]] && PUSH_ARGS+=("--remote-root" "$REMOTE_ROOT") +[[ "$DRY_RUN" == true ]] && BUILD_ARGS+=("--dry-run") && PUSH_ARGS+=("--dry-run") +[[ "$ASSUME_YES" == true ]] && PUSH_ARGS+=("--yes") + +# Resolve the host before spending build time on packages that cannot ship. +if [[ "$DRY_RUN" != true ]]; then + resolved_host="$HOST" + if [[ -z "$resolved_host" ]]; then + resolved_host="${OMARCHY_BUILD_HOST:-}" + [[ -z "$resolved_host" && -f "$BUILD_ROOT/.build-host" ]] && resolved_host=$(<"$BUILD_ROOT/.build-host") + fi + if [[ -z "$resolved_host" ]]; then + print_error "No build host configured" + echo "" + echo "Pass --host, set OMARCHY_BUILD_HOST, or write the destination to:" + echo " $BUILD_ROOT/.build-host" + exit 1 + fi +fi + +print_info "Step 1/2: Building..." +echo "" +"$SCRIPT_DIR/build" "${BUILD_ARGS[@]}" +echo "" + +print_info "Step 2/2: Pushing to the build host..." +echo "" +"$SCRIPT_DIR/push-build" "${PUSH_ARGS[@]}" diff --git a/bin/omarchy-pkgs b/bin/omarchy-pkgs index 2b151df..2d394ed 100755 --- a/bin/omarchy-pkgs +++ b/bin/omarchy-pkgs @@ -43,6 +43,8 @@ Options for release: --commit (rc) Upstream commit to pin (default: tip of --ref) --ref (rc) Upstream branch whose tip to pin (default: $DEFAULT_RC_REF) --yes Skip confirmation prompts + --host ssh destination of the build host to trigger, overriding + \$OMARCHY_BUILD_HOST and .build-host --no-push Rewrite and commit locally; skip push and build trigger --pr When releasing from a non-master branch, open a GitHub PR to master with gh after pushing @@ -312,7 +314,8 @@ regenerate_checksums() { # --- trigger ----------------------------------------------------------------- trigger_build_host() { - local host="${OMARCHY_BUILD_HOST:-}" + local host="${BUILD_HOST_OVERRIDE:-}" + [[ -z "$host" ]] && host="${OMARCHY_BUILD_HOST:-}" [[ -z "$host" && -f "$BUILD_ROOT/.build-host" ]] && host=$(<"$BUILD_ROOT/.build-host") if [[ -z "$host" ]]; then print_info "No build host configured (set OMARCHY_BUILD_HOST or $BUILD_ROOT/.build-host)." @@ -341,6 +344,7 @@ cmd_release() { --force) force=true; shift ;; --commit) commit_arg="$2"; shift 2 ;; --ref) ref="$2"; shift 2 ;; + --host) BUILD_HOST_OVERRIDE="$2"; shift 2 ;; --yes) assume_yes=true; shift ;; --dry-run) dry_run=true; shift ;; -h | --help) show_usage; exit 0 ;; diff --git a/bin/repo b/bin/repo index 9ee8777..b3255aa 100755 --- a/bin/repo +++ b/bin/repo @@ -59,6 +59,7 @@ show_usage() { echo " remove Remove a specific package" echo " sync Sync repository to remote" echo " push Upload local builds to the build host and publish them there" + echo " deploy Build locally, then push: one command for a local build machine" echo "" echo "Typical workflows:" echo " $0 release # Complete release workflow" @@ -130,6 +131,10 @@ push) "$SCRIPT_DIR/push-build" "$@" 2>&1 | tee "$LOG_FILE" exit ${PIPESTATUS[0]} ;; +deploy) + "$SCRIPT_DIR/deploy" "$@" 2>&1 | tee "$LOG_FILE" + exit ${PIPESTATUS[0]} + ;; -h | --help | help) show_usage ;;