diff --git a/.gitea/workflows/renovate_v2.yml b/.gitea/workflows/renovate_v2.yml index 4e9e5b5..6416fd0 100644 --- a/.gitea/workflows/renovate_v2.yml +++ b/.gitea/workflows/renovate_v2.yml @@ -9,11 +9,13 @@ jobs: renovate: runs-on: ubuntu-latest steps: - - name: Checkout Repository - uses: actions/checkout@v7.0.1 - - - name: Run Renovate - uses: renovatebot/github-action:latest + # Bewusst KEIN `uses: ...` Schritt: + # `actions/checkout` und `renovatebot/github-action` werden von + # github.com bzw. ghcr.io geladen und brauchen einen GitHub-Account. + # `docker run renovate/renovate` kommt von Docker Hub und braucht nur + # den Gitea-Token (secrets.RENOVATE_TOKEN). Renovate klont das Repo + # selbst über die Gitea-API, ein Checkout ist daher nicht nötig. + - name: Run Renovate via Docker Hub env: RENOVATE_PLATFORM: 'gitea' RENOVATE_ENDPOINT: 'https://humocs-man.duckdns.org/api/v1' @@ -23,4 +25,18 @@ jobs: RENOVATE_HOST_RULES: '[{"hostType": "github", "matchHost": "github.com", "token": ""}]' RENOVATE_PRODUCT_METADATA_URL: '' RENOVATE_FETCH_CHANGELOGS: 'off' - RENOVATE_REPOSITORY_CACHE: 'enabled' \ No newline at end of file + RENOVATE_REPOSITORY_CACHE: 'enabled' + run: | + set -euo pipefail + docker pull renovate/renovate:44 + docker run --rm \ + -e RENOVATE_PLATFORM \ + -e RENOVATE_ENDPOINT \ + -e RENOVATE_TOKEN \ + -e RENOVATE_REQUIRE_CONFIG \ + -e RENOVATE_REPOSITORIES \ + -e RENOVATE_HOST_RULES \ + -e RENOVATE_PRODUCT_METADATA_URL \ + -e RENOVATE_FETCH_CHANGELOGS \ + -e RENOVATE_REPOSITORY_CACHE \ + renovate/renovate:44 diff --git a/Justfile b/Justfile index 5d79157..cf98ea4 100644 --- a/Justfile +++ b/Justfile @@ -1,3 +1,4 @@ +export registry := env("REGISTRY", "humocs-man.duckdns.org/humocs-man") export image_name := env("IMAGE_NAME", "fluffy-pancake") export default_tag := env("DEFAULT_TAG", "stable") export bib_image := env("BIB_IMAGE", "quay.io/centos-bootc/bootc-image-builder:latest") @@ -15,8 +16,8 @@ default: check: #!/usr/bin/bash find . -type f -name "*.just" | while read -r file; do - echo "Checking syntax: $file" - just --unstable --fmt --check -f "$file" + echo "Checking syntax: $file" + just --unstable --fmt --check -f "$file" done echo "Checking syntax: Justfile" just --unstable --fmt --check -f Justfile @@ -26,8 +27,8 @@ check: fix: #!/usr/bin/bash find . -type f -name "*.just" | while read -r file; do - echo "Checking syntax: $file" - just --unstable --fmt -f "$file" + echo "Checking syntax: $file" + just --unstable --fmt -f "$file" done echo "Checking syntax: Justfile" just --unstable --fmt -f Justfile || { exit 1; } @@ -42,7 +43,7 @@ clean: rm -f previous.manifest.json rm -f changelog.md rm -f output.env - rm -f output/ + rm -rf output/ # Sudo Clean Repo [group('Utility')] @@ -68,24 +69,7 @@ sudoif command *args: } sudoif {{ command }} {{ args }} -# This Justfile recipe builds a container image using Podman. -# -# Arguments: -# $target_image - The tag you want to apply to the image (default: $image_name). -# $tag - The tag for the image (default: $default_tag). -# -# The script constructs the version string using the tag and the current date. -# If the git working directory is clean, it also includes the short SHA of the current HEAD. -# -# just build $target_image $tag -# -# Example usage: -# just build aurora lts -# -# This will build an image 'aurora:lts' with DX and GDX enabled. -# - -# Build the image using the specified parameters +# Build the local image using Podman from Containerfile build $target_image=image_name $tag=default_tag: #!/usr/bin/env bash @@ -100,65 +84,46 @@ build $target_image=image_name $tag=default_tag: --tag "${target_image}:${tag}" \ . -# Command: _rootful_load_image -# Description: This script checks if the current user is root or running under sudo. If not, it attempts to resolve the image tag using podman inspect. -# If the image is found, it loads it into rootful podman. If the image is not found, it pulls it from the repository. -# -# Parameters: -# $target_image - The name of the target image to be loaded or pulled. -# $tag - The tag of the target image to be loaded or pulled. Default is 'default_tag'. -# -# Example usage: -# _rootful_load_image my_image latest -# -# Steps: -# 1. Check if the script is already running as root or under sudo. -# 2. Check if target image is in the non-root podman container storage) -# 3. If the image is found, load it into rootful podman using podman scp. -# 4. If the image is not found, pull it from the remote repository into reootful podman. - -_rootful_load_image $target_image=image_name $tag=default_tag: +# Pulls remote image or loads local image into rootful podman storage for BIB +_rootful_load_image $target_image $tag=default_tag: #!/usr/bin/bash set -eoux pipefail - # Check if already running as root or under sudo + FULL_IMAGE="${target_image}:${tag}" + + # Target ist Remote-Image -> Direkt via Rootful Podman pullen + if [[ "${target_image}" != localhost/* ]]; then + echo "==> Pulle Remote-Image: ${FULL_IMAGE}" + just sudoif podman pull "${FULL_IMAGE}" + exit 0 + fi + + # Target ist lokales Image -> In Rootful Storage kopieren if [[ -n "${SUDO_USER:-}" || "${UID}" -eq "0" ]]; then - echo "Already root or running under sudo, no need to load image from user podman." + echo "Bereits als root aktiv." exit 0 fi - # Try to resolve the image tag using podman inspect set +e - resolved_tag=$(podman inspect -t image "${target_image}:${tag}" | jq -r '.[].RepoTags.[0]') + podman inspect -t image "${FULL_IMAGE}" > /dev/null 2>&1 return_code=$? set -e - USER_IMG_ID=$(podman images --filter reference="${target_image}:${tag}" --format "'{{ '{{.ID}}' }}'") + USER_IMG_ID=$(podman images -q "${FULL_IMAGE}") if [[ $return_code -eq 0 ]]; then - # If the image is found, load it into rootful podman - ID=$(just sudoif podman images --filter reference="${target_image}:${tag}" --format "'{{ '{{.ID}}' }}'") + ID=$(just sudoif podman images -q "${FULL_IMAGE}") if [[ "$ID" != "$USER_IMG_ID" ]]; then - # podman image scp ist deprecated (Podman 5) -> save/load verwenden COPYTMP=$(mktemp -p "${PWD}" -d -t _build_podman_load.XXXXXXXXXX) - podman save "${target_image}:${tag}" -o "${COPYTMP}/image.tar" + podman save "${FULL_IMAGE}" -o "${COPYTMP}/image.tar" just sudoif podman load -i "${COPYTMP}/image.tar" rm -rf "${COPYTMP}" fi else - # If the image is not found, pull it from the repository - just sudoif podman pull "${target_image}:${tag}" + just sudoif podman pull "${FULL_IMAGE}" fi # Build a bootc bootable image using Bootc Image Builder (BIB) -# Converts a container image to a bootable image -# Parameters: -# target_image: The name of the image to build (ex. localhost/fedora) -# tag: The tag of the image to build (ex. latest) -# type: The type of image to build (ex. qcow2, raw, iso) -# config: The configuration file to use for the build (default: iso/disk.toml) - -# Example: just _rebuild-bib localhost/fedora latest qcow2 iso/disk.toml _build-bib $target_image $tag $type $config: (_rootful_load_image target_image tag) #!/usr/bin/env bash set -euo pipefail @@ -176,8 +141,8 @@ _build-bib $target_image $tag $type $config: (_rootful_load_image target_image t --pull=newer \ --net=host \ --security-opt label=type:unconfined_t \ - -v $(pwd)/${config}:/config.toml:ro \ - -v $BUILDTMP:/output \ + -v "$(pwd)/${config}":/config.toml:ro \ + -v "$BUILDTMP":/output \ -v /var/lib/containers/storage:/var/lib/containers/storage \ "${bib_image}" \ ${args} \ @@ -188,57 +153,59 @@ _build-bib $target_image $tag $type $config: (_rootful_load_image target_image t sudo rmdir $BUILDTMP sudo chown -R $USER:$USER output/ -# Podman builds the image from the Containerfile and creates a bootable image -# Parameters: -# target_image: The name of the image to build (ex. localhost/fedora) -# tag: The tag of the image to build (ex. latest) -# type: The type of image to build (ex. qcow2, raw, iso) -# config: The configuration file to use for the build (deafult: iso/disk.toml) - -# Example: just _rebuild-bib localhost/fedora latest qcow2 iso/disk.toml +# Rebuild-Schritt: Führt vor BIB ein lokales 'podman build' aus _rebuild-bib $target_image $tag $type $config: (build target_image tag) && (_build-bib target_image tag type config) -# Build a QCOW2 virtual machine image -[group('Build Virtual Machine Image')] -build-qcow2 $target_image=("localhost/" + image_name) $tag=default_tag: && (_build-bib target_image tag "qcow2" "iso/disk.toml") +# ============================================================================== +# BUILD TARGETS (Pullen aus Remote-Registry) +# ============================================================================== -# Build a RAW virtual machine image +# Build a QCOW2 virtual machine image from Registry [group('Build Virtual Machine Image')] -build-raw $target_image=("localhost/" + image_name) $tag=default_tag: && (_build-bib target_image tag "raw" "iso/disk.toml") +build-qcow2 $target_image=(registry + "/" + image_name) $tag=default_tag: && (_build-bib target_image tag "qcow2" "iso/disk.toml") -# Build an ISO virtual machine image +# Build a RAW virtual machine image from Registry [group('Build Virtual Machine Image')] -build-iso $target_image=("localhost/" + image_name) $tag=default_tag: && (_build-bib target_image tag "iso" "iso/iso.toml") +build-raw $target_image=(registry + "/" + image_name) $tag=default_tag: && (_build-bib target_image tag "raw" "iso/disk.toml") -# Rebuild a QCOW2 virtual machine image +# Build an ISO virtual machine image from Registry +[group('Build Virtual Machine Image')] +build-iso $target_image=(registry + "/" + image_name) $tag=default_tag: && (_build-bib target_image tag "iso" "iso/iso.toml") + +# ============================================================================== +# REBUILD TARGETS (Lokaler Build via Containerfile + Image Builder) +# ============================================================================== + +# Rebuild a QCOW2 virtual machine image locally [group('Build Virtual Machine Image')] rebuild-qcow2 $target_image=("localhost/" + image_name) $tag=default_tag: && (_rebuild-bib target_image tag "qcow2" "iso/disk.toml") -# Rebuild a RAW virtual machine image +# Rebuild a RAW virtual machine image locally [group('Build Virtual Machine Image')] rebuild-raw $target_image=("localhost/" + image_name) $tag=default_tag: && (_rebuild-bib target_image tag "raw" "iso/disk.toml") -# Rebuild an ISO virtual machine image +# Rebuild an ISO virtual machine image locally [group('Build Virtual Machine Image')] rebuild-iso $target_image=("localhost/" + image_name) $tag=default_tag: && (_rebuild-bib target_image tag "iso" "iso/iso.toml") +# ============================================================================== +# RUN TARGETS +# ============================================================================== + # Run a virtual machine with the specified image type and configuration _run-vm $target_image $tag $type $config: #!/usr/bin/bash set -eoux pipefail - # Determine the image file based on the type image_file="output/${type}/disk.${type}" if [[ $type == iso ]]; then image_file="output/bootiso/install.iso" fi - # Build the image if it does not exist if [[ ! -f "${image_file}" ]]; then just "build-${type}" "$target_image" "$tag" fi - # Determine an available port to use port=8006 while grep -q :${port} <<< $(ss -tunalp); do port=$(( port + 1 )) @@ -246,7 +213,6 @@ _run-vm $target_image $tag $type $config: echo "Using Port: ${port}" echo "Connect to http://localhost:${port}" - # Set up the arguments for running the VM run_args=() run_args+=(--rm --privileged) run_args+=(--pull=newer) @@ -260,21 +226,20 @@ _run-vm $target_image $tag $type $config: run_args+=(--volume "${PWD}/${image_file}":"/boot.${type}") run_args+=(docker.io/qemux/qemu) - # Run the VM and open the browser to connect (sleep 30 && xdg-open http://localhost:"$port") & podman run "${run_args[@]}" # Run a virtual machine from a QCOW2 image [group('Run Virtual Machine')] -run-vm-qcow2 $target_image=("localhost/" + image_name) $tag=default_tag: && (_run-vm target_image tag "qcow2" "iso/disk.toml") +run-vm-qcow2 $target_image=(registry + "/" + image_name) $tag=default_tag: && (_run-vm target_image tag "qcow2" "iso/disk.toml") # Run a virtual machine from a RAW image [group('Run Virtual Machine')] -run-vm-raw $target_image=("localhost/" + image_name) $tag=default_tag: && (_run-vm target_image tag "raw" "iso/disk.toml") +run-vm-raw $target_image=(registry + "/" + image_name) $tag=default_tag: && (_run-vm target_image tag "raw" "iso/disk.toml") # Run a virtual machine from an ISO [group('Run Virtual Machine')] -run-vm-iso $target_image=("localhost/" + image_name) $tag=default_tag: && (_run-vm target_image tag "iso" "iso/iso.toml") +run-vm-iso $target_image=(registry + "/" + image_name) $tag=default_tag: && (_run-vm target_image tag "iso" "iso/iso.toml") # Run a virtual machine using systemd-vmspawn [group('Run Virtual Machine')] @@ -298,22 +263,18 @@ spawn-vm rebuild="0" type="qcow2" ram="6G": lint: #!/usr/bin/env bash set -eoux pipefail - # Check if shellcheck is installed if ! command -v shellcheck &> /dev/null; then echo "shellcheck could not be found. Please install it." exit 1 fi - # Run shellcheck on all Bash scripts /usr/bin/find . -iname "*.sh" -type f -exec shellcheck "{}" ';' # Runs shfmt on all Bash scripts format: #!/usr/bin/env bash set -eoux pipefail - # Check if shfmt is installed if ! command -v shfmt &> /dev/null; then echo "shfmt could not be found. Please install it." exit 1 fi - # Run shfmt on all Bash scripts /usr/bin/find . -iname "*.sh" -type f -exec shfmt --write "{}" ';' diff --git a/renovate.json b/renovate.json index 4c8cfe9..ea60315 100644 --- a/renovate.json +++ b/renovate.json @@ -6,12 +6,23 @@ "customManagers": [ { "customType": "regex", + "description": "GitHub-Actions (`uses: org/repo@tag`) in Gitea-Workflows pflegen", "fileMatch": ["^\\.gitea/workflows/[^/]+\\.ya?ml$"], "matchStrings": [ "uses:\\s*(?[a-zA-Z0-9-]+/[a-zA-Z0-9-]+)@(?[^\\s]+)" ], "datasourceTemplate": "git-tags", "lookupNameTemplate": "https://github.com/{{{depName}}}.git" + }, + { + "customType": "regex", + "description": "Renovate-Eigenversion (`renovate/renovate:tag` per docker run) pflegen", + "fileMatch": ["^\\.gitea/workflows/[^/]+\\.ya?ml$"], + "matchStrings": [ + "renovate/renovate:(?[0-9][0-9a-zA-Z._-]*)" + ], + "depNameTemplate": "renovate/renovate", + "datasourceTemplate": "docker" } ] } \ No newline at end of file