Commit Graph
19 Commits
Author SHA1 Message Date
Ryan Hughes 537c377fa5 Build PRs on ephemeral droplets; publish merged packages from CI
Every pull request now builds the package directories it touches on
ephemeral DigitalOcean droplets, and every merge to master publishes the
resulting artifacts into the channels each package belongs to. The
repository host's timers become the fallback rather than the pipeline.

Build (.github/workflows/build-pr.yml)
  One job per package per architecture, always against edge. The artifact
  is labelled with the package directory's git tree hash. Tooling (bin/,
  helpers/, build/) is checked out from the base branch; the PR supplies
  only pkgbuilds/, so a PR can change what is built, never how. Builds
  run only for trusted authors: collaborators, .github/VOUCHED.td, or a
  PR carrying the build-approved label. A single required check, result,
  aggregates the matrix.

Publish (.github/workflows/publish.yml, bin/publish-artifact)
  One job per merge. It collects the PR artifacts for the merged tree,
  builds anything that has none, then walks each channel/architecture
  slot once: pull that database, repo-add every package that belongs in
  it, upload packages, signatures, then the database. A published
  filename is immutable; identical bytes under an existing name only
  gain a database entry, different bytes are refused. Fast-ring packages
  reach edge, rc and stable in the same run from the same file.

Matrix (bin/build-matrix)
  Package x architecture, with the channels the artifact ships to,
  decided by package_builds_for_mirror so CI and the host agree.
  arch=any packages build once and land in every architecture database.

Builder (build/build.sh, bin/build, build/Dockerfile)
  With no local published tree, plan against and resolve from the public
  channel over HTTPS. PACKAGER is set to Omarchy. rclone is in the image.

Runners (ci/)
  A controller droplet polls GitHub with curl and creates one g5 droplet
  per queued job from cloud-init, deleting them when off or over-age.
  Builders carry QEMU with credential support for aarch64. Operator SSH
  keys come from GitHub. tests/controller.sh and tests/publish-artifact.sh
  cover the decisions against fixtures and real makepkg output.

Tests run on pull requests only; branch protection requires result,
self-tests and build-isolation with up-to-date branches.
2026-09-18 11:25:32 -04:00
Ryan Hughes 76687fcc82 Harden multi-architecture release pipeline 2026-09-04 23:40:49 -04:00
Marcelo Alcantara b677f50358 Pin PKGEXT to .pkg.tar.zst in the builder image
Arch Linux ARM's makepkg.conf defaults PKGEXT to .pkg.tar.xz. build/sign.sh
only signs *.pkg.tar.zst, and push-build, sync-rebuilds and the notifier
parse the same suffix, so an aarch64 package built under the stacked
pipeline came out as .xz and would have been skipped at signing. Seen on a
plain x86_64 runner building aarch64 under QEMU (fork run 33642125077).
Same fix as the PKGEXT line in #240.
2026-09-04 23:40:49 -04:00
Marcelo Alcantara 91843ab099 Make aarch64 a first-class architecture in the scheduled pipeline
One list, PUBLISHED_ARCHES in helpers/paths.sh (default x86_64,
overridable with OMARCHY_ARCHES), now drives everything the repository
host schedules. check-versions compares PKGBUILDs against each
architecture's channel databases and writes one queue per channel and
architecture; auto-release works through the queues one architecture at
a time, each with its own backoff, so a failing build on one never
blocks the other; advance-channel --arch all re-runs an advance for every
published architecture and omarchy-release uses it for start and ship,
building the pinned pair once per architecture in its rc trigger; the
train observes channels through the reference (first) architecture
instead of a hard-coded x86_64. Queue and backoff files written under
the old per-channel names are treated as x86_64 until consumed.

Two things made an aarch64 builder image impossible to create: the
keyring bootstrap fetched omarchy-keyring from the target architecture's
own channel tree, which does not exist before that architecture has
published anything, and the QEMU probe only knew the x86_64-host,
aarch64-target case. The keyring (arch=any) now always comes from the
x86_64 tree, and the probe compares host and target architectures and
runs a container for the target platform.

clean-repo grouped versions with a regex that only knew any, x86_64 and
i686, so aarch64 packages would never have been pruned.
2026-09-04 23:40:49 -04:00
Ryan Hughes e50f868a10 Channel-correct Docker images: keyring from own channel; repo-add uses edge
The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo
pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works
only because a stale copy of the old layout still answers there, and it would
miss a keyring rotation. Each image now pulls omarchy-keyring from its own
channel (edge/rc/stable), matching the base mirror it already selects.

update-repo and remove-package switch to the edge x86_64 image: repo-add and
repo-remove compile nothing, and using the channel image would deadlock
bootstrap-rc — the rc image can only build once the rc channel it pulls the
keyring from exists remotely.
2026-08-27 01:10:33 -04:00
Ryan Hughes e73b843bd2 Add rc as a first-class channel: validation, shared repo root, rc build mirror
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
  set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
  the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
  promote-build, update-repo, clean-repo, remove-package) and widen the
  edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
2026-08-27 01:10:33 -04:00
Ryan Hughes fdcce9465c Better logs and resolution 2026-02-17 11:12:52 -05:00
Ryan Hughes 4c5fb42171 Change how pacman.conf is created 2025-12-13 16:05:31 -05:00
Ryan Hughes 63a1cb039e Fix mirror 2025-11-11 12:37:12 -05:00
Ryan Hughes 92677d3df0 Add stable / edge 2025-11-10 11:03:39 -05:00
Ryan Hughes 78c1ef2658 Unified aarch64 / amd64 image 2025-10-29 22:55:17 -04:00
Ryan Hughes 34297628a3 Update builds 2025-10-27 23:22:17 -04:00
Ryan Hughes 47686bd94e Add our key to the keyring 2025-10-27 00:45:32 -04:00
Ryan Hughes db283dd98a Fix permissions for real this time 2025-10-23 00:16:11 -04:00
Ryan Hughes 26ac717c3a Resolve if root 2025-10-23 00:11:13 -04:00
Ryan Hughes a5232798dc Update builder id and remove src 2025-10-23 00:07:33 -04:00
Ryan Hughes c57c9620de Lots of cleanup 2025-08-28 19:44:01 +03:00
Ryan Hughes 2ad6cd90bb Parse actual repo name 2025-08-25 05:53:28 +02:00
Ryan Hughes e00a529ba9 Probably should have committed a long time ago... 2025-08-25 05:45:19 +02:00