Omarchy 4 no longer uses Elephant or the omarchy-walker meta package, and omarchy-upgrade-to-quattro removes them; every channel serves Omarchy 4.0.4. Nothing else here depends on them. walker itself stays. Deleting a recipe stops it building but leaves it in the channel databases, and the only removal tool worked on the old repository host's local tree. Add bin/unpublish-packages, publish-artifact's counterpart: pull the channel database, repo-remove every entry built from the named pkgbases, upload it. Package files stay in the bucket. unpublish.yml runs it per channel and architecture under the publish lock, for packages with no recipe on master.
80 lines
3.1 KiB
YAML
80 lines
3.1 KiB
YAML
name: Unpublish retired packages
|
|
|
|
# Takes packages out of the channel databases after their recipes are gone
|
|
# from master. Deleting a recipe stops it building; this stops pacman
|
|
# offering it. Files stay in the bucket (see bin/unpublish-packages).
|
|
#
|
|
# Only packages with no recipe on master: one that still has a recipe would
|
|
# come back on its next publish, and refusing it keeps a typo from pulling a
|
|
# live package out of every channel.
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
packages:
|
|
description: "Space-separated pkgbases whose recipes were removed from master"
|
|
required: true
|
|
channels:
|
|
description: "Channels to remove them from"
|
|
required: true
|
|
default: "edge rc stable"
|
|
|
|
jobs:
|
|
unpublish:
|
|
runs-on: ubuntu-latest
|
|
environment: publish
|
|
timeout-minutes: 15
|
|
# The publish job's group: one writer per channel database at a time.
|
|
concurrency:
|
|
group: publish
|
|
cancel-in-progress: false
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Refuse packages that still have a recipe
|
|
env:
|
|
PACKAGES: ${{ github.event.inputs.packages }}
|
|
CHANNELS: ${{ github.event.inputs.channels }}
|
|
run: |
|
|
set -euo pipefail
|
|
for c in $CHANNELS; do
|
|
[[ $c == edge || $c == rc || $c == stable ]] || { echo "::error::Unknown channel: $c"; exit 1; }
|
|
done
|
|
for p in $PACKAGES; do
|
|
[[ $p =~ ^[a-z0-9@._+-]+$ ]] || { echo "::error::Not a package name: $p"; exit 1; }
|
|
if [[ -e pkgbuilds/$p ]]; then
|
|
echo "::error::pkgbuilds/$p still exists on master; remove the recipe first"
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
- name: Unpublish
|
|
env:
|
|
PACKAGES: ${{ github.event.inputs.packages }}
|
|
CHANNELS: ${{ github.event.inputs.channels }}
|
|
RCLONE_CONFIG_R2_TYPE: s3
|
|
RCLONE_CONFIG_R2_PROVIDER: Cloudflare
|
|
RCLONE_CONFIG_R2_NO_CHECK_BUCKET: "true"
|
|
RCLONE_CONFIG_R2_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }}
|
|
RCLONE_CONFIG_R2_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }}
|
|
RCLONE_CONFIG_R2_ENDPOINT: ${{ secrets.R2_ENDPOINT }}
|
|
OMARCHY_PUBLISH_PREFIX: ${{ vars.OMARCHY_PUBLISH_PREFIX }}
|
|
run: |
|
|
set -euo pipefail
|
|
# repo-remove and bsdtar are Arch tools: run in the tested builder
|
|
# image, as the publish job does.
|
|
builder=ghcr.io/omacom/omarchy-pkg-builder:$(bin/builder-image key --arch x86_64 --mirror edge)
|
|
docker pull --quiet "$builder"
|
|
for mirror in $CHANNELS; do
|
|
for arch in x86_64 aarch64; do
|
|
docker run --rm \
|
|
-e OMARCHY_PUBLISH_PREFIX \
|
|
-e RCLONE_CONFIG_R2_TYPE -e RCLONE_CONFIG_R2_PROVIDER -e RCLONE_CONFIG_R2_ENDPOINT -e RCLONE_CONFIG_R2_NO_CHECK_BUCKET \
|
|
-e RCLONE_CONFIG_R2_ACCESS_KEY_ID -e RCLONE_CONFIG_R2_SECRET_ACCESS_KEY \
|
|
-v "$PWD:/w:ro" -w /w "$builder" \
|
|
bin/unpublish-packages --remote R2:omarchy-pkgs --mirror "$mirror" --arch "$arch" $PACKAGES
|
|
done
|
|
done
|