From 90a6f9c8efa612ff3d73296a06d3debae38fe95f Mon Sep 17 00:00:00 2001 From: humocs-man <1+humocs-man@noreply.localhost> Date: Sun, 9 Aug 2026 15:53:19 +0000 Subject: [PATCH] .gitea/workflows/redhat_build.yml aktualisiert --- .gitea/workflows/redhat_build.yml | 34 +++++++++++++++++++------------ 1 file changed, 21 insertions(+), 13 deletions(-) diff --git a/.gitea/workflows/redhat_build.yml b/.gitea/workflows/redhat_build.yml index 1e0a97c..c9ecba6 100644 --- a/.gitea/workflows/redhat_build.yml +++ b/.gitea/workflows/redhat_build.yml @@ -86,20 +86,28 @@ jobs: run: | sudo apt-get update && sudo apt-get install -y buildah fuse-overlayfs - # 5. Image mit Buildah bauen + # 5. Image direkt mit Buildah bauen (erzwingt --isolation chroot) - name: Build Image with Buildah - id: build_image - uses: redhat-actions/buildah-build@v3.0.2 - env: - BUILDAH_ISOLATION: chroot - _BUILDAH_STARTED_IN_USERNS: "" - with: - image: ${{ env.IMAGE_NAME }} - tags: ${{ env.IMAGE_TAG }} - containerfiles: ./Containerfile - labels: ${{ steps.metadata.outputs.labels }} - oci: true - isolation: chroot + run: | + # Systemweite Containers-Konfig auf chroot festlegen + sudo mkdir -p /etc/containers + printf '[containers]\nisolation = "chroot"\n' | sudo tee /etc/containers/containers.conf + + # Metadata-Labels sauber in --label Argumente umwandeln + LABEL_FLAGS="" + while IFS= read -r line; do + if [ -n "$line" ]; then + LABEL_FLAGS="${LABEL_FLAGS} --label ${line}" + fi + done <<< "${{ steps.metadata.outputs.labels }}" + + # Bildah mit explizitem --isolation chroot ausführen + buildah bud \ + --isolation chroot \ + --format oci \ + ${LABEL_FLAGS} \ + -t "${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" \ + -f ./Containerfile . # 6. In lokales OCI-Verzeichnis exportieren - name: Export Image to OCI Layout