Commit Graph
36 Commits
Author SHA1 Message Date
Ryan Hughes 537c377fa5 Build PRs on ephemeral droplets; publish merged packages from CI
Every pull request now builds the package directories it touches on
ephemeral DigitalOcean droplets, and every merge to master publishes the
resulting artifacts into the channels each package belongs to. The
repository host's timers become the fallback rather than the pipeline.

Build (.github/workflows/build-pr.yml)
  One job per package per architecture, always against edge. The artifact
  is labelled with the package directory's git tree hash. Tooling (bin/,
  helpers/, build/) is checked out from the base branch; the PR supplies
  only pkgbuilds/, so a PR can change what is built, never how. Builds
  run only for trusted authors: collaborators, .github/VOUCHED.td, or a
  PR carrying the build-approved label. A single required check, result,
  aggregates the matrix.

Publish (.github/workflows/publish.yml, bin/publish-artifact)
  One job per merge. It collects the PR artifacts for the merged tree,
  builds anything that has none, then walks each channel/architecture
  slot once: pull that database, repo-add every package that belongs in
  it, upload packages, signatures, then the database. A published
  filename is immutable; identical bytes under an existing name only
  gain a database entry, different bytes are refused. Fast-ring packages
  reach edge, rc and stable in the same run from the same file.

Matrix (bin/build-matrix)
  Package x architecture, with the channels the artifact ships to,
  decided by package_builds_for_mirror so CI and the host agree.
  arch=any packages build once and land in every architecture database.

Builder (build/build.sh, bin/build, build/Dockerfile)
  With no local published tree, plan against and resolve from the public
  channel over HTTPS. PACKAGER is set to Omarchy. rclone is in the image.

Runners (ci/)
  A controller droplet polls GitHub with curl and creates one g5 droplet
  per queued job from cloud-init, deleting them when off or over-age.
  Builders carry QEMU with credential support for aarch64. Operator SSH
  keys come from GitHub. tests/controller.sh and tests/publish-artifact.sh
  cover the decisions against fixtures and real makepkg output.

Tests run on pull requests only; branch protection requires result,
self-tests and build-isolation with up-to-date branches.
2026-09-18 11:25:32 -04:00
Ryan Hughes 9d5c3eea19 Skip retained published archives when planning builds 2026-09-15 00:13:57 -04:00
Ryan Hughes d96b950901 Publish completed packages when a peer build fails 2026-09-14 02:30:11 -04:00
Ryan Hughes fc3226ff94 Build each package in an isolated container 2026-09-08 22:49:08 -04:00
Ryan Hughes de57b5dfc2 Publish only intended package artifacts 2026-09-05 00:07:11 -04:00
Ryan Hughes 0b67dbab8e Harden emulated ARM builds 2026-09-04 23:40:49 -04:00
Ryan Hughes 76687fcc82 Harden multi-architecture release pipeline 2026-09-04 23:40:49 -04:00
Marcelo Alcantara 191e1e7db5 Add builder flags for CI and resumed builds
Three opt-in knobs for bin/build, each defaulting to today's behaviour:

OMARCHY_KEEP_BUILD_WORKSPACE=1 keeps build-output/$MIRROR/$ARCH instead
of wiping it, and build/build.sh now folds any packages already there
into omarchy-build.db even when no database exists yet, so packages
built by an earlier job (or a previous, interrupted run) resolve as
dependencies of what builds next.

OMARCHY_SKIP_BUILDER_IMAGE=1 uses the omarchy-pkg-builder image already
present instead of building it, so a workflow can build the image once
with an external BuildKit cache and fan out over package jobs that all
run the same bytes. A missing image is an error, not a silent rebuild.

OMARCHY_DEFER_RUNTIME_DEPS=true builds the omarchy/omarchy-settings pair
with --nodeps, installing only their makedepends and checkdepends
explicitly. The pair depends on each other and on packages a sharded
pipeline builds in other jobs, so they cannot resolve in isolation; the
assembled set is installed in one verified transaction downstream. The
request is refused for anything but exactly that pair, on the host
before Docker starts and again inside the container.

Also fix make_dir_writable: chown -R can succeed on part of the tree
and fail on files a previous container left behind as another uid, and
the old `|| chmod` fallback only ran when chown failed outright. Always
follow with chmod.
2026-09-02 23:15:30 +10:00
David Heinemeier HanssonandClaude Opus 5 7732831889 Update the build container before installing makedepends
The builder image is layer-cached, so its glibc drifts behind the
mirror while makepkg -s installs makedepends from the freshly synced
database. omarchy-settings-dev died on that partial upgrade: the new
imagemagick needs GLIBC_2.44 and magick refused to run in package().

pacman -Syu runs before the Omarchy repos are appended, so only
core/extra take part -- in-flight build-output packages can't be
pulled into the container.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-27 10:03:52 -07:00
Ryan Hughes 515b566cb9 Add skip_build 2026-07-13 19:55:23 -04:00
Ryan Hughes 162e9c0ec9 Update to restore .1 if patched 2026-06-26 00:25:52 -04:00
Ryan Hughes c1aed0d8f1 Squash merge omarchy-4 into master 2026-06-02 22:25:07 -04:00
Ryan Hughes 2bca7a3f91 Make existing checks more efficient 2026-05-08 17:14:14 -04:00
Ryan Hughes 830e5aab6c Fix git comparison logic 2026-05-08 16:42:43 -04:00
Ryan Hughes 2ffe4f811c Refactor 2026-05-08 01:04:52 -04:00
David Heinemeier Hansson ad9e338956 Ensure -git pkgs are not needlessly rebuild 2026-05-04 14:13:21 +02:00
David Heinemeier Hansson 5f0e0731ec Import validpgpkeys instead from PKGBUILD 2026-04-23 08:44:17 +02:00
Ryan Hughes ad61f12c11 Remove stable pkgbuilds 2026-03-07 16:25:40 -05:00
Ryan Hughes fdcce9465c Better logs and resolution 2026-02-17 11:12:52 -05:00
Ryan Hughes 45a356eb70 Create shared / fast track for certain packages 2026-01-10 20:18:35 -05:00
Ryan Hughes 02abd5fb51 Ensure repo dirs exist 2025-11-10 12:25:16 -05:00
Ryan Hughes 92677d3df0 Add stable / edge 2025-11-10 11:03:39 -05:00
Ryan Hughes fd5fec490c Add should_build_for_arch check 2025-11-04 11:54:52 -05:00
Ryan Hughes dacf0cd9a4 Simplify and solve cache issue 2025-10-30 00:36:19 -04:00
Ryan Hughes 2dd91a1762 Always add to build db as we go 2025-10-28 10:56:37 -04:00
Ryan Hughes 34297628a3 Update builds 2025-10-27 23:22:17 -04:00
Ryan Hughes 95d1a77659 Overhaul the whole build process 2025-10-26 23:33:22 -04:00
Ryan Hughes 0554b1c684 Simplify build to only local. 2025-10-26 19:38:19 -04:00
Ryan Hughes 2560314886 Add ability to import keys 2025-10-26 14:09:45 -04:00
Ryan Hughes f2e1c227a2 Add ability to run single builds 2025-10-18 18:34:58 -04:00
Ryan Hughes f175eb3574 Update build process to use local files too 2025-10-08 21:34:21 -04:00
Ryan Hughes 926d6892ea Update to support more outputs 2025-09-07 23:23:37 +02:00
Ryan Hughes b32e414279 Fix some build options 2025-09-07 23:07:12 +02:00
Ryan Hughes ea9b3021b9 Add installable packages for dep resolution 2025-08-30 19:49:01 +03:00
Ryan Hughes 3bc7939b4a Add github package support 2025-08-30 19:00:39 +03:00
Ryan Hughes c57c9620de Lots of cleanup 2025-08-28 19:44:01 +03:00