Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
166 commits
Select commit Hold shift + click to select a range
0fe9733
Prepare 1877
5kt Nov 21, 2025
50f9d49
Add rel-1877-dev branch to workflow triggers
toanju Nov 21, 2025
87e6550
fixup: build workflow is now from 1877
toanju Nov 21, 2025
b5a82ed
ci: avoid using potentially missing xargs during emergency debugprinting
anokfireball Nov 21, 2025
d8391a3
Add demo iso
5kt Nov 25, 2025
7804549
Merge pull request #153 from gardenlinux/1877iso
5kt Nov 25, 2025
e6170f1
update package version of libvirtd and cloud hypervisor
toanju Nov 28, 2025
cd34a76
Merge pull request #154 from gardenlinux/bump-versions
toanju Nov 28, 2025
83876ef
bump to 1877.8
toanju Dec 5, 2025
6662893
update libvirt and cloud hypervisor packages
toanju Dec 5, 2025
3cfe3df
Update libvirt and cloud hypervisor packages
toanju Dec 10, 2025
4952d64
Preload debug container
5kt Dec 11, 2025
81bc868
Update features/_usi/initrd.include/usr/bin/persist
toanju Dec 12, 2025
7c1db2a
Update features/_usi/file.include/etc/systemd/system/dbgimport.service
toanju Dec 12, 2025
38b73e4
Pull in oras from a more recent version of GL
5kt Dec 16, 2025
5298e97
Merge pull request #157 from gardenlinux/rel-1877-oras
5kt Dec 16, 2025
a0e94ba
Cloud Hypervisor: Update version from 48.0-6 to 48.0-7
toanju Dec 16, 2025
3ee6e43
Add presets and improve build output
toanju Dec 17, 2025
b23d127
1877 does not have cut available using awk
toanju Dec 17, 2025
215271d
bump libvirtd to libvirt_11.3.0-32gl0+bp1877
toanju Dec 17, 2025
4535bb5
Update to Garden Linux 1877.9
toanju Jan 5, 2026
250ff56
Use custom 1877.9.x version
5kt Jan 8, 2026
3d3cdb0
disable efi pstore
5kt Jan 5, 2026
9de58bc
Merge pull request #162 from gardenlinux/customver
toanju Jan 8, 2026
f3add87
bump libvirt and cloud hypervisor
toanju Jan 12, 2026
6bb2b44
Bump Version to 1877.9.2
toanju Jan 12, 2026
b9618d7
Fix versioning
toanju Jan 12, 2026
e9e2a20
Update edk2 version
toanju Jan 13, 2026
d0f0ee1
Bump Version to 1877.9.3
toanju Jan 14, 2026
346fe02
Update packges
toanju Jan 16, 2026
5766488
Bump Version to 1877.9.4
toanju Jan 16, 2026
092e6ec
Bump libvirt and cloud hypervisor
toanju Jan 26, 2026
63fc187
Bump version to 1877.9.5
toanju Jan 26, 2026
a96c167
Bump libvirt and cloud hypvervior
toanju Jan 27, 2026
d55a5e6
Bump version to 1877.9.6
toanju Jan 27, 2026
dddc800
Upgrade to 1877.10
toanju Jan 30, 2026
b3e6649
Test dev build in 1877 branch
toanju Jan 30, 2026
2f2334d
Merge pull request #166 from gardenlinux/bump-version
toanju Feb 2, 2026
74b5160
Update libvirt
toanju Feb 2, 2026
96d8f81
Merge pull request #167 from gardenlinux/update-libvirt
toanju Feb 2, 2026
f7272af
Update khost feature for CAPI image
toanju Feb 3, 2026
c3d2f40
Merge pull request #168 from gardenlinux/fixup-khost
toanju Feb 3, 2026
1ea1352
1877.10.1
toanju Feb 3, 2026
ff5406e
Update cloud hypervisor
toanju Feb 4, 2026
992cde3
Merge pull request #172 from gardenlinux/update-packages-1877
toanju Feb 4, 2026
1f1b422
Update version to 1877.10.2
toanju Feb 4, 2026
fed15f3
ci: directly trigger test from nightly, drop ORAS image tag parsing
anokfireball Feb 4, 2026
bb5096b
ci: centralize image tag computation in reusable script
anokfireball Feb 4, 2026
1645aea
update libvirt and cloud hypervisor
toanju Feb 12, 2026
1ecf960
Merge pull request #175 from gardenlinux/bump-packages
toanju Feb 12, 2026
4ac5994
Update to 1877.10.3
toanju Feb 12, 2026
0adbdd9
ci: disable libvirt TLS/TCP sockets for CI tests
anokfireball Jan 27, 2026
76c7369
Merge pull request #177 from gardenlinux/fix-tls-socket-1877
toanju Feb 13, 2026
b163611
Bump libvirt and cloud hypervisor
toanju Feb 19, 2026
2ec3151
Update to 1877.10.4
toanju Feb 19, 2026
2cdc2ac
[usi] add further presets
toanju Feb 23, 2026
dea4c8c
Update to 1877.13
toanju Feb 23, 2026
2b665be
Merge pull request #181 from gardenlinux/disable-update-timer-service
toanju Feb 23, 2026
607c960
Merge pull request #182 from gardenlinux/bump-gl-1877
toanju Feb 23, 2026
a220301
ci: cancel dev workflow before cleanup
anokfireball Feb 13, 2026
ff0b137
Update to 1877.13.1
toanju Feb 23, 2026
1acf531
fix: replace gpg --dearmor with direct .asc file usage for apt keys
anokfireball Feb 26, 2026
22834d4
root-hints: improve installation to disk
toanju Feb 26, 2026
899c425
Merge pull request #186 from gardenlinux/backport-gpg-fix-to-rel-1877…
toanju Feb 26, 2026
69c98fc
Merge pull request #185 from gardenlinux/improve-root-hints-1877
toanju Feb 26, 2026
527f7f4
bump libvirt and cloud hypervisor packages
toanju Feb 26, 2026
12afb57
Merge pull request #187 from gardenlinux/bump-packages
toanju Feb 26, 2026
f116c03
Update to 1877.13.2
toanju Feb 26, 2026
2e15fd3
sci: load kvm modules via modules-load.d to fix libvirtd boot race
anokfireball Mar 4, 2026
9db096e
Update packages
toanju Mar 5, 2026
feb5ebb
Update to 1877.13.3
toanju Mar 5, 2026
ea6903f
CI: create folder for virt-secret-init-encryption.service
toanju Mar 6, 2026
480c820
Revert "CI: create folder for virt-secret-init-encryption.service"
toanju Mar 6, 2026
ded4a06
bump libvirtd packge
toanju Mar 6, 2026
971c397
Update to 1877.13.4
toanju Mar 6, 2026
f73a9ab
Update libvirt and cloud hypervisor packages
toanju Mar 13, 2026
1fc0128
Merge pull request #192 from gardenlinux/bump-packages-1877
toanju Mar 13, 2026
c4e65fc
Update to 1877.13.5
toanju Mar 13, 2026
7c0d116
Update libvirt and cloud hypervior
toanju Mar 18, 2026
40eef81
Merge pull request #193 from gardenlinux/bump-packages
toanju Mar 18, 2026
a0b7389
Update to 1877.13.6
toanju Mar 18, 2026
48338c2
Update packages libvirt and cloud hypervisor
toanju Mar 19, 2026
d77c6a2
Merge pull request #194 from gardenlinux/bump-packages
toanju Mar 19, 2026
6d5b90a
Update to 1877.13.7
toanju Mar 19, 2026
ff0fba4
Update upload_oci.yml
5kt Mar 24, 2026
5a24251
Merge pull request #196 from gardenlinux/ocifix
toanju Mar 24, 2026
0a55f58
Update cloud hypervisor package
toanju Mar 23, 2026
e5bbbdb
bump build_flavors_matrix.yml ref and update gl-oci tool usage
toanju Mar 24, 2026
cb857ca
Merge pull request #195 from gardenlinux/bump-packages
toanju Mar 24, 2026
5917a4b
Update to 1877.13.8
toanju Mar 24, 2026
c8047d8
Load kvm_* only when the proper cpu is present
5kt Mar 25, 2026
817356a
Merge pull request #203 from gardenlinux/kvmmod-1877
toanju Mar 26, 2026
2f983fb
Remove cronjobs
5kt Mar 25, 2026
708cdac
Merge pull request #204 from gardenlinux/no-cron
toanju Mar 26, 2026
ac625a5
Add preset to disable ipmievd
5kt Mar 26, 2026
663c3ce
mask systemd-repart for _usi
5kt Mar 26, 2026
62bb1b1
Update libvirt and cloud hypervisor
toanju Mar 26, 2026
9fef864
Merge pull request #209 from gardenlinux/bump-packages
toanju Mar 26, 2026
4fa4a04
Merge pull request #208 from gardenlinux/repart-1877
toanju Mar 26, 2026
e28e9fc
Merge pull request #207 from gardenlinux/ipmievd-1877
toanju Mar 26, 2026
947cb29
Update to 1877.13.9
toanju Mar 26, 2026
ced4967
fix ipmievd preset (#211)
toanju Mar 27, 2026
790e26d
Bump cloud hypervisor package
toanju Mar 27, 2026
66ee02e
Update to 1877.13.10
toanju Mar 27, 2026
a9af970
Update cloud hypervisor
toanju Mar 30, 2026
ffb62fa
Merge pull request #213 from gardenlinux/bump-chv
toanju Mar 30, 2026
1af5633
Update to 1877.13.11
toanju Mar 30, 2026
57eb015
Bump packages libvirt and cloud hypervisor
toanju Mar 31, 2026
bc1992c
Merge pull request #214 from gardenlinux/bump-packages
toanju Mar 31, 2026
4624643
Update to 1877.13.12
toanju Mar 31, 2026
f8e4f50
Update refs to 1877.14
toanju Apr 14, 2026
9bc007b
Merge pull request #216 from gardenlinux/bump-to-1877-14
toanju Apr 15, 2026
85db532
remove whitespace from flavors
toanju Apr 16, 2026
9229e13
Merge pull request #218 from gardenlinux/cleanup-flavors
toanju Apr 16, 2026
166c392
Add ignition from package repo
toanju Apr 15, 2026
1105f4a
Merge pull request #217 from gardenlinux/add-ignition
toanju Apr 17, 2026
cf86244
Update libvirt and cloud hypervisor packages
toanju Apr 23, 2026
d2cbd10
Merge pull request #221 from gardenlinux/bump-packages
toanju Apr 23, 2026
b06f541
Update to 1877.14.1
toanju Apr 24, 2026
0daaefd
Update to 1877.16.1
toanju Apr 30, 2026
b8bb1ba
Update to 1877.17.1
toanju May 9, 2026
7559857
sci: Set nfs max_session_slots=512
fwiesel Mar 5, 2026
40dde77
Add EU funding logo to README
toanju May 19, 2026
36a9edc
Merge pull request #224 from gardenlinux/update-readme
toanju May 19, 2026
25ac752
Merge pull request #223 from gardenlinux/backport-nfs-session-slots
toanju May 19, 2026
03f7e91
Upgrade packages cloud hypervisor and libvirt
toanju May 19, 2026
cbee99a
Merge pull request #225 from gardenlinux/update-packages-1877
toanju May 19, 2026
35d5647
Update to 1877.17.2
toanju May 19, 2026
ed40b18
Update to 1877.19
toanju May 29, 2026
6f52ae0
Merge pull request #227 from gardenlinux/update-to-1877-19
toanju May 29, 2026
504f702
add chost _pxe flavor
toanju May 29, 2026
6ea9b23
Merge pull request #231 from gardenlinux/add-flavor-1877
toanju May 29, 2026
96c3b93
Update to 1877.19.2
toanju May 29, 2026
bb9a0e6
fix(pxe): use - for stdin for sha256 check
toanju Jun 2, 2026
364be63
Merge pull request #233 from gardenlinux/fixup-pxe-1877
toanju Jun 3, 2026
28cb693
Update to 1877.19.3
toanju Jun 3, 2026
b21411a
Renaming of the repository
toanju Jun 11, 2026
4af4d5f
chore: add renovate.json for base branch config merge
anokfireball Jun 11, 2026
d0f6208
Merge pull request #241 from gardenlinux/fix/renovate-json-rel-1877-dev
toanju Jun 11, 2026
84a05a2
Merge pull request #240 from gardenlinux/renaming-1877
toanju Jun 11, 2026
b8cdccf
Pin dependencies (#249)
renovate[bot] Jun 15, 2026
1961e0e
Update sigstore/cosign-installer action to v4 (#254)
renovate[bot] Jun 16, 2026
35f1bb0
Update actions/checkout action to v6 (#252)
renovate[bot] Jun 16, 2026
428e89a
Update oras-project/setup-oras action to v2 (#253)
renovate[bot] Jun 16, 2026
1f14f13
Update cri-tools version to 1.35 (#250) (#261)
toanju Jun 16, 2026
1b8a4b2
Update to 1877.19.4
toanju Jun 16, 2026
5d53f18
renovate: automate SCI package updates for rel-1877-dev (#264)
anokfireball Jun 18, 2026
046987c
Update actions/checkout action to v7 (#268)
renovate[bot] Jun 22, 2026
afdd9c9
Remove packageRules from renovate.json (#275)
toanju Jun 22, 2026
9f148aa
Update SCI custom packages (#272)
renovate[bot] Jun 22, 2026
55baf7b
Update to 1877.19.5
toanju Jun 22, 2026
9626c9c
Update SCI custom packages (#287)
renovate[bot] Jun 30, 2026
3587572
Update to 1877.19.6
toanju Jun 30, 2026
8a34aae
Update SCI custom packages (#289)
renovate[bot] Jul 6, 2026
926147a
Prepare 1877.20 (#293)
toanju Jul 7, 2026
2c008b8
Update to 1877.20.0
toanju Jul 7, 2026
030ca71
Improve sci exec.config (#297)
toanju Jul 13, 2026
6d4723f
Update oras-project/setup-oras digest to 1d808f7 (#295)
renovate[bot] Jul 14, 2026
3538866
Update SCI custom packages (#300)
renovate[bot] Jul 14, 2026
a8ab0b5
Apply systemd presets (#299) (#303)
toanju Jul 15, 2026
5bad46c
Update version to 1877.20.1 (#304)
toanju Jul 15, 2026
fc81a7d
fix(ci): try to improve performance
anokfireball Jul 16, 2026
3f57b12
Update Group GitHub Actions (#310)
renovate[bot] Aug 11, 2026
cba5e75
Bump to 1877.21.0 (#314)
toanju Aug 11, 2026
54f8e89
Add modified gardenlinux-update tool for in-place update testing (#315)
toanju Aug 12, 2026
00b27b0
Rename UKI in persist script (#316)
toanju Aug 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 15 additions & 6 deletions .github/actions/test/integration/build/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ runs:
- name: Set ENV
shell: bash
env:
REPO: ghcr.io/gardenlinux/gardenlinux-ccloud
REPO: ghcr.io/gardenlinux/gardenlinux-sci
TAG: ${{ inputs.image_tag }}
ESP_SIZE: 2 # GiB
DISK_SIZE: 8 # GiB
Expand Down Expand Up @@ -99,12 +99,21 @@ runs:
chmod 600 /opt/ssh_host_ed25519_key
SSH_KEY=$(cat /opt/ssh_host_ed25519_key.pub)
echo "SSH_KEY=$SSH_KEY" >> $GITHUB_ENV
sed -i "s|SSH_KEY_GOES_HERE|$SSH_KEY|g" ./.github/actions/test/integration/build/dev-user-butane.yaml
cp ./.github/actions/test/integration/build/dev-user-butane.yaml ./.github/actions/test/integration/build/dev-user-butane-hv1.yaml
yq '.storage.files += load("./.github/actions/test/integration/build/root-hints.yaml")' ./.github/actions/test/integration/build/dev-user-butane.yaml > ./.github/actions/test/integration/build/dev-user-butane-hv2.yaml

sed -i "s|SSH_KEY_GOES_HERE|$SSH_KEY|g" ./.github/actions/test/integration/build/dev-user-butane-hv1.yaml
sed -i "s|SSH_KEY_GOES_HERE|$SSH_KEY|g" ./.github/actions/test/integration/build/dev-user-butane-hv2.yaml

PASSWORD=$(openssl passwd "password")
echo "PASSWORD=$PASSWORD" >> $GITHUB_ENV
sed -i "s|PASSWORD_GOES_HERE|$PASSWORD|g" ./.github/actions/test/integration/build/dev-user-butane.yaml
sed -i "s|TAG_GOES_HERE|${{ inputs.image_tag }}|g" ./.github/actions/test/integration/build/dev-user-butane.yaml
butane --pretty --strict ./.github/actions/test/integration/build/dev-user-butane.yaml > "/opt/${TAG}.ign"
sed -i "s|PASSWORD_GOES_HERE|$PASSWORD|g" ./.github/actions/test/integration/build/dev-user-butane-hv1.yaml
sed -i "s|PASSWORD_GOES_HERE|$PASSWORD|g" ./.github/actions/test/integration/build/dev-user-butane-hv2.yaml
sed -i "s|TAG_GOES_HERE|${{ inputs.image_tag }}|g" ./.github/actions/test/integration/build/dev-user-butane-hv1.yaml
sed -i "s|TAG_GOES_HERE|${{ inputs.image_tag }}|g" ./.github/actions/test/integration/build/dev-user-butane-hv2.yaml

butane --pretty --strict ./.github/actions/test/integration/build/dev-user-butane-hv1.yaml > "/opt/${TAG}-hv1.ign"
butane --pretty --strict ./.github/actions/test/integration/build/dev-user-butane-hv2.yaml > "/opt/${TAG}-hv2.ign"

- name: Download ubuntu cloud image
shell: bash
Expand All @@ -126,7 +135,7 @@ runs:
# - name: Upload artifacts
# uses: actions/upload-artifact@v4
# with:
# name: gardenlinux-ccloud-${{ inputs.image_tag }}
# name: gardenlinux-sci-${{ inputs.image_tag }}
# path: /opt/${{ inputs.image_tag }}.*
# retention-days: 1
# overwrite: true
17 changes: 9 additions & 8 deletions .github/actions/test/integration/build/dev-user-butane.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
variant: fcos
version: 1.3.0
version: 1.7.0
passwd:
users:
- name: root
Expand Down Expand Up @@ -37,12 +37,6 @@ storage:
# custom
192.168.122.2 hv1
192.168.122.3 hv2
- path: /opt/persist/root-hints.yaml
mode: 0644
contents:
inline: |
hints:
- size: lt 500G
# turn off hugepages, not required for this test
# also SIGNIFICANTLY reduces test runtime
- path: /opt/persist/hugepages.env
Expand All @@ -55,7 +49,7 @@ storage:
contents:
inline: |
# pull the image from GHCR instead of keppel
OCI_REPO=ghcr.io/gardenlinux/gardenlinux-ccloud
OCI_REPO=ghcr.io/gardenlinux/gardenlinux-sci
# point to a custom tag to download for the persist step
OCI_TAG=TAG_GOES_HERE
# Enable unlimited core dumps for all systemd services
Expand Down Expand Up @@ -85,3 +79,10 @@ storage:
kernel.core_pattern=|/usr/lib/systemd/systemd-coredump %P %u %g %s %t %c %h
kernel.core_pipe_limit=16
fs.suid_dumpable=2
# Disable libvirt sockets not required for CI tests
systemd:
units:
- name: libvirtd-tls.socket
mask: true
- name: libvirtd-tcp.socket
mask: true
6 changes: 6 additions & 0 deletions .github/actions/test/integration/build/root-hints.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
- path: /opt/persist/root-hints.yaml
mode: 0644
contents:
inline: |
hints:
- size: lt 500G
2 changes: 1 addition & 1 deletion .github/actions/test/integration/dependencies/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ runs:
- name: butane
shell: bash
run: |
BUTANE_VERSION="0.24.0"
BUTANE_VERSION="0.27.0"
curl -LO "https://github.com/coreos/butane/releases/download/v${BUTANE_VERSION}/butane-x86_64-unknown-linux-gnu"
chmod +x "butane-x86_64-unknown-linux-gnu"
sudo mv "butane-x86_64-unknown-linux-gnu" /usr/local/bin/butane
3 changes: 2 additions & 1 deletion .github/actions/test/integration/setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,8 @@ runs:
- name: Copy ignition file
shell: bash
run: |
sudo cp "/opt/${TAG}.ign" /var/lib/libvirt/images/hv.ign
sudo cp "/opt/${TAG}-hv1.ign" /var/lib/libvirt/images/HV1.ign
sudo cp "/opt/${TAG}-hv2.ign" /var/lib/libvirt/images/HV2.ign

- name: Create HyperVisor 1
shell: bash
Expand Down
4 changes: 2 additions & 2 deletions .github/actions/test/integration/setup/hv.xml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
<disk type='file' device='disk'>
<driver name='qemu' type='qcow2' />
<source file='/var/lib/libvirt/images/HV_NAME_GOES_HERE.qcow2' />
<target dev='hda' bus='ide' />
<target dev='vda' bus='virtio' />
</disk>
<interface type='network'>
<mac address='MAC_GOES_HERE' />
Expand All @@ -32,6 +32,6 @@
</devices>
<qemu:commandline>
<qemu:arg value='-fw_cfg' />
<qemu:arg value='name=opt/com.coreos/config,file=/var/lib/libvirt/images/hv.ign' />
<qemu:arg value='name=opt/com.coreos/config,file=/var/lib/libvirt/images/HV_NAME_GOES_HERE.ign' />
</qemu:commandline>
</domain>
6 changes: 3 additions & 3 deletions .github/actions/test/integration/test/qemu/vm.xml
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,12 @@
<disk type='file' device='disk'>
<driver name='qemu' type='qcow2' />
<source file='/var/lib/libvirt/images/ubuntu.qcow2' />
<target dev='hda' bus='ide' />
<target dev='vda' bus='virtio' />
</disk>
<disk type='file' device='cdrom'>
<disk type='file' device='disk'>
<driver name='qemu' type='raw' />
<source file='/var/lib/libvirt/images/ubuntu-cloud-init-ds.iso' />
<target dev='hdb' bus='ide' />
<target dev='vdb' bus='virtio' />
<readonly />
</disk>
<interface type='network'>
Expand Down
45 changes: 45 additions & 0 deletions .github/scripts/compute-image-tag.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
#!/bin/bash
# Computes the OCI image tag for Garden Linux ccloud images
#
# This script centralizes the image tag format computation to ensure consistency
# across all workflows (nightly, dev, upload_oci).
#
# Usage:
# ./compute-image-tag.sh <version> [flavor]
#
# Arguments:
# version - The version for the tag (e.g., "1877.10.1", "pr-123")
# flavor - The image flavor (e.g., "metal-sci-usi-amd64"). Defaults to "metal-sci-usi-amd64".
#
# Environment:
# GITHUB_SHA - Git commit SHA (required, set automatically by GitHub Actions)
#
# Output:
# Prints the computed image tag to stdout
#
# Tag format:
# {version}-{flavor}-{dashed_version}-{commit_sha_short}
#
# Examples:
# ./compute-image-tag.sh "1877.10.1"
# # Output: 1877.10.1-metal-sci-usi-amd64-1877-10-1-abcd1234
#
# ./compute-image-tag.sh "pr-123" "metal-capi-amd64"
# # Output: pr-123-metal-capi-amd64-pr-123-abcd1234

set -euo pipefail

VERSION="${1:?Error: VERSION argument required}"
FLAVOR="${2:-metal-sci-usi-amd64}"

if [ -z "${GITHUB_SHA:-}" ]; then
echo "Error: GITHUB_SHA environment variable is required" >&2
exit 1
fi

COMMIT_SHA="${GITHUB_SHA::8}"
DASHED_VERSION="${VERSION//./-}"

IMAGE_TAG="${VERSION}-${FLAVOR}-${DASHED_VERSION}-${COMMIT_SHA}"

echo "$IMAGE_TAG"
35 changes: 20 additions & 15 deletions .github/workflows/dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ on:
push:
branches:
- main
- rel-1877-dev
paths-ignore:
- "**/README.md"
- "docs/**"
Expand All @@ -11,6 +12,13 @@ on:
paths-ignore:
- "**/README.md"
- "docs/**"

# Cancel any in-progress PR workflow runs when PR is closed
# Used to ensure cleanup runs after any PR build are uploaded (or aborts before the upload)
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event.action == 'closed' }}

jobs:
set_version:
if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }}
Expand All @@ -19,30 +27,25 @@ jobs:
VERSION: ${{ steps.version.outputs.VERSION }}
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: recursive

- name: use VERSION file to support dev build on rel-branch
id: version
run: |
if [ "${{ github.event_name }}" = "pull_request" ]; then
echo "VERSION=today" >> $GITHUB_OUTPUT
else
echo "VERSION=$(cat VERSION)" >> $GITHUB_OUTPUT
fi
echo "VERSION=$(cat VERSION)" >> $GITHUB_OUTPUT

build:
needs: [set_version]
if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }}
uses: gardenlinux/gardenlinux/.github/workflows/build.yml@40e7dfa820cb8bd5e0317779f818d31464c18c63
uses: gardenlinux/gardenlinux/.github/workflows/build.yml@409e9b640087ade203321a8d63bd1651f4677205
with:
version: ${{ needs.set_version.outputs.VERSION }}
# to set target to "release" or "nightly" we need proper KMS secrets
# have a look at gardenlinux/.github/workflows/github.mjs
target: dev
fail_fast: true
platform_test_build: false
# secrets:
# aws_region: ${{ secrets.AWS_REGION }}
# aws_kms_role: ${{ secrets.KMS_SIGNING_IAM_ROLE }}
Expand All @@ -55,16 +58,18 @@ jobs:
runs-on: ubuntu-latest
outputs:
UPLOAD_VERSION: ${{ steps.meta.outputs.upload_version }}
COMMIT_SHA: ${{ steps.meta.outputs.sha }}
image_tag: ${{ steps.meta.outputs.image_tag }}
steps:
- name: Derive image version
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Compute image metadata
id: meta
run: |
PR_NUMBER=${{ github.event.pull_request.number }}
UPLOAD_VERSION="pr-${PR_NUMBER}"
echo "upload_version=${UPLOAD_VERSION}" >> $GITHUB_OUTPUT
SHA="${GITHUB_SHA::8}"
echo "sha=${SHA}" >> $GITHUB_OUTPUT
IMAGE_TAG=$(.github/scripts/compute-image-tag.sh "${UPLOAD_VERSION}")
echo "image_tag=${IMAGE_TAG}" >> $GITHUB_OUTPUT

upload:
name: Upload PR image to OCI
Expand All @@ -83,7 +88,7 @@ jobs:
if: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.action != 'closed' }}
uses: ./.github/workflows/test.yml
with:
image_tag: "${{ needs.meta.outputs.UPLOAD_VERSION }}-metal-sci-usi-amd64-${{ needs.meta.outputs.UPLOAD_VERSION }}-${{ needs.meta.outputs.COMMIT_SHA }}"
image_tag: ${{ needs.meta.outputs.image_tag }}

cleanup_images:
name: Cleanup PR images
Expand All @@ -104,7 +109,7 @@ jobs:
response=$(curl -s -H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" \
-H "Accept: application/vnd.github+json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
"https://api.github.com/orgs/gardenlinux/packages/container/gardenlinux-ccloud/versions?per_page=$page_size&page=$page")
"https://api.github.com/orgs/gardenlinux/packages/container/gardenlinux-sci/versions?per_page=$page_size&page=$page")

page_ids=$(echo "$response" | jq -r --arg prefix "${UPLOAD_VERSION}" '
.[] | select(.metadata.container.tags[]? | test("^" + $prefix + "(-.*)?$")) | .id
Expand Down Expand Up @@ -133,7 +138,7 @@ jobs:
-H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" \
-H "Accept: application/vnd.github+json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
"https://api.github.com/orgs/gardenlinux/packages/container/gardenlinux-ccloud/versions/$version_id")
"https://api.github.com/orgs/gardenlinux/packages/container/gardenlinux-sci/versions/$version_id")
if [ "$http_code" != "204" ]; then
echo "Failed to delete version $version_id (HTTP $http_code)"
fi
Expand Down
30 changes: 25 additions & 5 deletions .github/workflows/nightly.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,29 +14,49 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: recursive
build:
needs: [checkout]
uses: gardenlinux/gardenlinux/.github/workflows/build.yml@40e7dfa820cb8bd5e0317779f818d31464c18c63
uses: gardenlinux/gardenlinux/.github/workflows/build.yml@409e9b640087ade203321a8d63bd1651f4677205
with:
version: ${{ inputs.version || 'now' }}
# to set target to "release" or "nightly" we need proper KMS secrets
# have a look at gardenlinux/.github/workflows/github.mjs
# have a look at gardenlinux/.github/workflows/github.mjs
target: dev
fail_fast: true
platform_test_build: false
#platform_test_build: false
# secrets:
# aws_region: ${{ secrets.AWS_REGION }}
# aws_kms_role: ${{ secrets.KMS_SIGNING_IAM_ROLE }}
# aws_oidc_session: ${{ secrets.AWS_OIDC_SESSION }}
# secureboot_db_kms_arn: ${{ secrets.SECUREBOOT_DB_KMS_ARN }}
meta:
name: Compute image metadata
needs: [build]
runs-on: ubuntu-latest
outputs:
image_tag: ${{ steps.meta.outputs.image_tag }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Compute image tag
id: meta
run: |
IMAGE_TAG=$(.github/scripts/compute-image-tag.sh "${{ needs.build.outputs.version }}")
echo "image_tag=${IMAGE_TAG}" >> $GITHUB_OUTPUT
upload_oci:
name: Run glcli to publish to OCI
needs: [build]
# use custom upload_oci.yml as we do not sign the images
# uses: gardenlinux/gardenlinux/.github/workflows/upload_oci.yml@40e7dfa820cb8bd5e0317779f818d31464c18c63
# uses: gardenlinux/gardenlinux/.github/workflows/upload_oci.yml@409e9b640087ade203321a8d63bd1651f4677205
uses: ./.github/workflows/upload_oci.yml
with:
version: ${{ needs.build.outputs.version }}
test:
name: Test nightly image
needs: [meta, upload_oci]
uses: ./.github/workflows/test.yml
with:
image_tag: ${{ needs.meta.outputs.image_tag }}
Loading
Loading