Channel-correct Docker images: keyring from own channel; repo-add uses edge

The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo
pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works
only because a stale copy of the old layout still answers there, and it would
miss a keyring rotation. Each image now pulls omarchy-keyring from its own
channel (edge/rc/stable), matching the base mirror it already selects.

update-repo and remove-package switch to the edge x86_64 image: repo-add and
repo-remove compile nothing, and using the channel image would deadlock
bootstrap-rc — the rc image can only build once the rc channel it pulls the
keyring from exists remotely.
This commit is contained in:
Ryan Hughes
2026-08-27 01:10:33 -04:00
parent 49ca22fa9f
commit e50f868a10
3 changed files with 13 additions and 8 deletions
+3 -2
View File
@@ -89,7 +89,8 @@ if [[ ! $REPLY =~ ^[Yy]$ ]]; then
fi
# Build/update the Docker image (always use x86_64 for removal - it's architecture independent)
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
# repo-remove is mirror-independent — always use the edge x86_64 image
build_docker_image "$BUILD_DIR" "x86_64" "edge"
acquire_release_lock || exit 1
@@ -104,7 +105,7 @@ docker run --rm --platform linux/amd64 \
-e MIRROR="$MIRROR" \
-v "$REPO_ROOT:/pkgs.omarchy.org" \
-v "$BUILD_DIR:/build:ro" \
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/remove-package.sh "$PACKAGE_NAME"
omarchy-pkg-builder:latest-x86_64-edge /build/remove-package.sh "$PACKAGE_NAME"
RESULT=$?
+5 -4
View File
@@ -28,16 +28,17 @@ update_database() {
# Make output directory writable for container
make_dir_writable "$REPO_DIR"
# Build Docker image (always use x86_64 for repo update - it's architecture independent)
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
# repo-add is architecture- and mirror-independent, so always use the edge
# x86_64 image. This also lets bootstrap-rc build the rc database before the
# rc channel exists remotely (an rc image can only build after it does).
build_docker_image "$BUILD_DIR" "x86_64" "edge"
# Run repo-add in Docker container (always use x86_64 image)
docker run --rm --platform linux/amd64 \
-e ARCH="$ARCH" \
-e MIRROR="$MIRROR" \
-v "$REPO_ROOT:/output" \
-v "$BUILD_DIR:/build:ro" \
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/update-repo.sh
omarchy-pkg-builder:latest-x86_64-edge /build/update-repo.sh
}
# Main execution
+5 -2
View File
@@ -106,10 +106,13 @@ RUN ln -sf /usr/lib/os-release /etc/os-release && \
fi
# Setup Omarchy keyring manually before adding repo (avoids keyserver trust issues)
# Note: Repository is removed at the end since build scripts add it dynamically
# Note: Repository is removed at the end since build scripts add it dynamically.
# The keyring comes from this image's own channel (the bare /$arch path is a
# stale legacy layout); %s keeps pacman's $arch literal while MIRROR expands.
ARG MIRROR=edge
RUN pacman-key --recv-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 --keyserver keys.openpgp.org && \
pacman-key --lsign-key 40DFB630FF42BCFFB047046CF0134EE680CAC571 && \
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/$arch\n' >> /etc/pacman.conf && \
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/%s/$arch\n' "${MIRROR}" >> /etc/pacman.conf && \
pacman -Sy --noconfirm && \
pacman -S --noconfirm omarchy-keyring && \
pacman-key --populate omarchy && \