Make bin/setup work on Ubuntu, which is what the host runs

The first version checked for pacman and refused anything else, so it would
have declined to run on the actual repository host. Nothing about that host
needs to be Arch: makepkg, repo-add and signing all happen inside containers.

Setup now detects apt or pacman and installs the right names for each --
bsdtar is libarchive-tools on Debian and libarchive on Arch. The requirement
list drops gnupg and the Arch build tools, which the host never runs directly,
leaving Docker, rclone, bsdtar, jq, git and rsync.

Docker is checked before being installed. A host may be running a version from
Docker's own repository, and replacing that underneath a working builder would
be a poor trade for consistency; setup starts it if stopped and otherwise
leaves it alone.

Verified both paths: apt installs the five dependencies and docker.io on a
bare Ubuntu 24.04 container, and an Arch host with Docker already running is
left untouched. A missing systemctl now reports that a container cannot be a
repository host instead of failing on an unknown command.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
David Heinemeier Hansson
2026-08-12 05:43:23 -07:00
co-authored by Claude Opus 5
parent f8c1cbb072
commit daf98026bc
2 changed files with 100 additions and 35 deletions
+9 -3
View File
@@ -563,9 +563,15 @@ State files are stored in `/root/.state/`:
ssh root@<host> 'cd /root/omarchy-pkgs && bin/setup' ssh root@<host> 'cd /root/omarchy-pkgs && bin/setup'
``` ```
`bin/setup` installs the dependencies, enables Docker, creates the state `bin/setup` installs the dependencies, ensures Docker is running, creates the
directory, and installs and enables the release timers. It is idempotent, so state directory, and installs and enables the release timers. It works on
run it again whenever a dependency is added. Debian/Ubuntu and on Arch, and is idempotent, so run it again whenever a
dependency is added.
The host does not need to be Arch: makepkg, repo-add and package signing all
run inside containers, so it needs only Docker, rclone, bsdtar, jq, git and
rsync. Docker is left alone when it already works, rather than replacing a
working installation from Docker's own repository with the distribution's.
```bash ```bash
bin/repo setup --check # Report what is missing, change nothing bin/repo setup --check # Report what is missing, change nothing
+93 -34
View File
@@ -1,10 +1,10 @@
#!/bin/bash #!/bin/bash
# Prepare this machine to serve as the Omarchy repository host. # Prepare this machine to serve as the Omarchy repository host.
# #
# The repository host builds packages, signs them, keeps the published tree, and # The host receives uploads, promotes packages into the published tree, and
# syncs it to the mirror. Everything it needs is installed and enabled here, so # syncs that tree to the mirror. Everything Arch-specific — makepkg, repo-add,
# the tooling can assume its toolchain instead of working around whatever # package signing — happens inside containers, so the host itself needs very
# happens to be present. # little and does not need to be Arch. The production host is Ubuntu.
# #
# Run this on the host itself: # Run this on the host itself:
# ssh root@<host> 'cd /root/omarchy-pkgs && bin/setup' # ssh root@<host> 'cd /root/omarchy-pkgs && bin/setup'
@@ -19,23 +19,6 @@ source "$BUILD_ROOT/helpers/message-helpers.sh"
CHECK_ONLY=false CHECK_ONLY=false
SKIP_TIMERS=false SKIP_TIMERS=false
# Packages, in "command:package" form so a missing tool names its own fix.
#
# tar, vercmp and repo-add come from base and pacman, which any Arch install
# already has. bsdtar does not: libarchive ships the library pacman links
# against without necessarily installing the binary.
REQUIREMENTS=(
"bsdtar:libarchive" # reads repo databases and .PKGINFO out of packages
"git:git" # PKGBUILD sources and release commits
"jq:jq" # package metadata in .omarchy/package.json
"curl:curl" # upstream version checks
"rsync:rsync" # receives uploads from bin/repo push
"gpg:gnupg" # package signing
"rclone:rclone" # publishes to the mirror
"docker:docker" # builds run in containers
"makepkg:base-devel" # source verification for releases
)
STATE_DIR="${OMARCHY_STATE_DIR:-/root/.state}" STATE_DIR="${OMARCHY_STATE_DIR:-/root/.state}"
CREDENTIALS="/root/.omarchy/build-credentials" CREDENTIALS="/root/.omarchy/build-credentials"
@@ -55,6 +38,7 @@ while [[ $# -gt 0 ]]; do
echo "Usage: $0 [OPTIONS]" echo "Usage: $0 [OPTIONS]"
echo "" echo ""
echo "Install and enable everything the repository host needs." echo "Install and enable everything the repository host needs."
echo "Works on Debian/Ubuntu (apt) and Arch (pacman)."
echo "" echo ""
echo "Options:" echo "Options:"
echo " --check Report what is missing, change nothing" echo " --check Report what is missing, change nothing"
@@ -69,18 +53,65 @@ while [[ $# -gt 0 ]]; do
esac esac
done done
if ! command -v pacman >/dev/null 2>&1; then # --- distribution ------------------------------------------------------------
print_error "This is not an Arch system — the repository host must be Arch"
# Package names differ where it matters: bsdtar is libarchive-tools on Debian
# and libarchive on Arch, and Docker is docker.io rather than docker.
if command -v apt-get >/dev/null 2>&1; then
DISTRO="debian"
PKG_BSDTAR="libarchive-tools"
PKG_DOCKER="docker.io"
elif command -v pacman >/dev/null 2>&1; then
DISTRO="arch"
PKG_BSDTAR="libarchive"
PKG_DOCKER="docker"
else
print_error "Unsupported distribution — need apt-get or pacman"
exit 1 exit 1
fi fi
print_info "Distribution: $DISTRO"
if [[ "$CHECK_ONLY" != true && $EUID -ne 0 ]]; then if [[ "$CHECK_ONLY" != true && $EUID -ne 0 ]]; then
print_error "Run as root (installing packages and systemd units)" print_error "Run as root (installing packages and systemd units)"
exit 1 exit 1
fi fi
# Docker and the release timers are both systemd units. Say so plainly rather
# than failing later on a missing command — a container is the usual way to end
# up here, and it cannot be a repository host.
if [[ "$CHECK_ONLY" != true ]] && ! command -v systemctl >/dev/null 2>&1; then
print_error "systemctl not found — the repository host must run systemd"
echo ""
echo "Docker and the release timers are systemd units. This looks like a"
echo "container; run setup on the host itself."
exit 1
fi
install_packages() {
case "$DISTRO" in
debian)
apt-get update -qq
DEBIAN_FRONTEND=noninteractive apt-get install -y "$@"
;;
arch)
pacman -S --needed --noconfirm "$@"
;;
esac
}
# --- dependencies ------------------------------------------------------------ # --- dependencies ------------------------------------------------------------
# Only what the host runs directly. Signing and repo-add happen in containers,
# so gnupg and the Arch build tools are deliberately absent from this list.
REQUIREMENTS=(
"bsdtar:$PKG_BSDTAR" # reads repo databases and .PKGINFO out of packages
"git:git" # pulls this repository
"jq:jq" # package metadata in .omarchy/package.json
"rsync:rsync" # receives uploads from bin/repo push
"rclone:rclone" # publishes to the mirror
)
print_info "Checking dependencies..." print_info "Checking dependencies..."
MISSING_PACKAGES=() MISSING_PACKAGES=()
for requirement in "${REQUIREMENTS[@]}"; do for requirement in "${REQUIREMENTS[@]}"; do
@@ -100,7 +131,7 @@ if [[ ${#MISSING_PACKAGES[@]} -gt 0 ]]; then
print_warning "Would install: ${MISSING_PACKAGES[*]}" print_warning "Would install: ${MISSING_PACKAGES[*]}"
else else
print_info "Installing: ${MISSING_PACKAGES[*]}" print_info "Installing: ${MISSING_PACKAGES[*]}"
pacman -S --needed --noconfirm "${MISSING_PACKAGES[@]}" install_packages "${MISSING_PACKAGES[@]}"
print_success "Dependencies installed" print_success "Dependencies installed"
fi fi
else else
@@ -110,16 +141,42 @@ echo ""
# --- docker ------------------------------------------------------------------ # --- docker ------------------------------------------------------------------
if [[ "$CHECK_ONLY" == true ]]; then # Docker is left alone when it already works. A host may well be running a
if systemctl is-enabled docker.service >/dev/null 2>&1; then # version from Docker's own repository rather than the distribution's, and
print_success "docker.service is enabled" # replacing that underneath a working builder would be a poor trade for
# tidiness.
print_info "Checking Docker..."
if command -v docker >/dev/null 2>&1; then
print_step "docker present: $(docker --version 2>/dev/null | head -1)"
if docker info >/dev/null 2>&1; then
print_success "Docker is installed and running — leaving it alone"
elif [[ "$CHECK_ONLY" == true ]]; then
print_warning "Docker is installed but not running; would start it"
else else
print_warning "docker.service would be enabled" print_info "Docker is installed but not running — starting it"
fi
else
print_info "Enabling docker..."
systemctl enable --now docker.service systemctl enable --now docker.service
print_success "docker.service enabled" if docker info >/dev/null 2>&1; then
print_success "Docker started"
else
print_error "Docker is installed but still not responding"
echo " Check 'systemctl status docker' — builds cannot run without it."
exit 1
fi
fi
elif [[ "$CHECK_ONLY" == true ]]; then
print_warning "Would install $PKG_DOCKER and enable it"
else
print_info "Installing $PKG_DOCKER..."
install_packages "$PKG_DOCKER"
systemctl enable --now docker.service
if docker info >/dev/null 2>&1; then
print_success "Docker installed and running"
else
print_error "Docker installed but not responding"
echo " Check 'systemctl status docker' — builds cannot run without it."
exit 1
fi
fi fi
echo "" echo ""
@@ -137,10 +194,12 @@ echo ""
# --- release timers ---------------------------------------------------------- # --- release timers ----------------------------------------------------------
TIMERS=(omarchy-check-versions omarchy-auto-release-edge omarchy-auto-release-stable)
if [[ "$SKIP_TIMERS" == true ]]; then if [[ "$SKIP_TIMERS" == true ]]; then
print_info "Skipping release timers (--skip-timers)" print_info "Skipping release timers (--skip-timers)"
elif [[ "$CHECK_ONLY" == true ]]; then elif [[ "$CHECK_ONLY" == true ]]; then
for timer in omarchy-check-versions omarchy-auto-release-edge omarchy-auto-release-stable; do for timer in "${TIMERS[@]}"; do
if systemctl is-enabled "$timer.timer" >/dev/null 2>&1; then if systemctl is-enabled "$timer.timer" >/dev/null 2>&1; then
print_success "$timer.timer is enabled" print_success "$timer.timer is enabled"
else else
@@ -151,7 +210,7 @@ else
print_info "Installing release timers..." print_info "Installing release timers..."
cp "$BUILD_ROOT"/systemd/*.service "$BUILD_ROOT"/systemd/*.timer /etc/systemd/system/ cp "$BUILD_ROOT"/systemd/*.service "$BUILD_ROOT"/systemd/*.timer /etc/systemd/system/
systemctl daemon-reload systemctl daemon-reload
for timer in omarchy-check-versions omarchy-auto-release-edge omarchy-auto-release-stable; do for timer in "${TIMERS[@]}"; do
systemctl enable --now "$timer.timer" systemctl enable --now "$timer.timer"
print_step "$timer.timer" print_step "$timer.timer"
done done