Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ jobs:
env:
BASE: ${{ github.event.pull_request.base.sha || github.event.before }}
run: |
build=$(hack/touches "$BASE" alpine e2fsprogs ubuntu mkosi -- \
build=$(hack/touches "$BASE" alpine e2fsprogs ubuntu mkosi task git-lfs buildkit -- \
image e2fsprogs versions go.mod .github/workflows/image.yml)
echo "build=${build}" | tee -a "$GITHUB_OUTPUT"

Expand Down
12 changes: 12 additions & 0 deletions image/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,18 @@ RUN --mount=type=cache,sharing=locked,id=image-mkosi-src,target=/var/cache/mkosi
# Asks the binary just installed which version it is, rather than trusting the tag.
test "$(mkosi --version)" = "mkosi ${MKOSI_VERSION}"

# What install-dev-tools.sh downloads into the image, by content. It runs inside mkosi's tree,
# which sees only what mkosi.conf's Environment= passes through, so each is an ENV here.
ARG TASK_VERSION
ARG TASK_SHA256
ARG GIT_LFS_VERSION
ARG GIT_LFS_SHA256
ARG BUILDKIT_VERSION
ARG BUILDKIT_SHA256
ENV TASK_VERSION=${TASK_VERSION} TASK_SHA256=${TASK_SHA256} \
GIT_LFS_VERSION=${GIT_LFS_VERSION} GIT_LFS_SHA256=${GIT_LFS_SHA256} \
BUILDKIT_VERSION=${BUILDKIT_VERSION} BUILDKIT_SHA256=${BUILDKIT_SHA256}

COPY image/mkosi.conf image/mkosi.postinst.chroot /work/
COPY image/mkosi.extra /work/mkosi.extra
COPY image/build.sh /usr/local/bin/build-base-image
Expand Down
2 changes: 1 addition & 1 deletion image/Taskfile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ tasks:
--platform linux/amd64 \
--cache-from {{.IMAGE_CACHE_FROM}} \
{{.IMAGE_CACHE_TO}} \
$({{.VERSIONS}} args ubuntu mkosi) \
$({{.VERSIONS}} args ubuntu mkosi task git-lfs buildkit) \
--tag {{.IMAGE_BUILDER_TAG}} \
--load \
.
2 changes: 2 additions & 0 deletions image/mkosi.conf
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,8 @@ MinimumVersion=27.1
Incremental=yes
CacheDirectory=/cache
WithNetwork=yes
# From image/Dockerfile, which has them from versions.yaml: what install-dev-tools.sh downloads.
Environment=TASK_VERSION TASK_SHA256 GIT_LFS_VERSION GIT_LFS_SHA256 BUILDKIT_VERSION BUILDKIT_SHA256

[Distribution]
Distribution=ubuntu
Expand Down
41 changes: 14 additions & 27 deletions image/mkosi.extra/usr/local/lib/spin-base/install-dev-tools.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,38 +3,26 @@ set -euo pipefail

echo "Installing development tools..."

# -------------------------------------------------
# Version configuration
# -------------------------------------------------
TASK_VERSION="${TASK_VERSION:-3.45.5}"
GIT_LFS_VERSION="${GIT_LFS_VERSION:-3.7.0}"
BUILDKIT_VERSION="${BUILDKIT_VERSION:-0.26.2}"

# -------------------------------------------------
# Helper functions
# -------------------------------------------------
download_and_verify() {
local url="$1"
local output="$2"
local expected_sha256="$3"
# Versions and sha256s from versions.yaml, through image/Dockerfile and mkosi.conf's Environment=.
: "${TASK_VERSION:?}" "${TASK_SHA256:?}"
: "${GIT_LFS_VERSION:?}" "${GIT_LFS_SHA256:?}"
: "${BUILDKIT_VERSION:?}" "${BUILDKIT_SHA256:?}"

download() {
local url="$1" output="$2" sha256="$3"
echo "Downloading ${url}..."
curl -fsSL "${url}" -o "${output}"

if [ -n "${expected_sha256}" ]; then
echo "Verifying checksum..."
echo "${expected_sha256} ${output}" | sha256sum -c -
fi
echo "${sha256} ${output}" | sha256sum -c -
}

# -------------------------------------------------
# Install Task (Taskfile runner)
# -------------------------------------------------
echo "Installing Task v${TASK_VERSION}..."
download_and_verify \
download \
"https://github.com/go-task/task/releases/download/v${TASK_VERSION}/task_linux_amd64.tar.gz" \
"/tmp/task.tar.gz" \
""
"${TASK_SHA256}"

tar -xzf /tmp/task.tar.gz -C /tmp
install -m 755 /tmp/task /usr/local/bin/task
Expand All @@ -44,10 +32,10 @@ task --version
# Install Git LFS
# -------------------------------------------------
echo "Installing Git LFS v${GIT_LFS_VERSION}..."
download_and_verify \
download \
"https://github.com/git-lfs/git-lfs/releases/download/v${GIT_LFS_VERSION}/git-lfs-linux-amd64-v${GIT_LFS_VERSION}.tar.gz" \
"/tmp/git-lfs.tar.gz" \
""
"${GIT_LFS_SHA256}"

tar -xzf /tmp/git-lfs.tar.gz -C /tmp
install -m 755 "/tmp/git-lfs-${GIT_LFS_VERSION}/git-lfs" /usr/local/bin/git-lfs
Expand All @@ -57,10 +45,10 @@ git-lfs version
# Install BuildKit
# -------------------------------------------------
echo "Installing BuildKit v${BUILDKIT_VERSION}..."
download_and_verify \
download \
"https://github.com/moby/buildkit/releases/download/v${BUILDKIT_VERSION}/buildkit-v${BUILDKIT_VERSION}.linux-amd64.tar.gz" \
"/tmp/buildkit.tar.gz" \
""
"${BUILDKIT_SHA256}"

tar -xzf /tmp/buildkit.tar.gz -C /usr/local
# Remove QEMU binaries we don't need
Expand All @@ -87,8 +75,7 @@ apt-get install -y \
docker-ce-cli \
containerd.io \
docker-buildx-plugin \
docker-compose-plugin \
isal pigz
docker-compose-plugin

# -------------------------------------------------
# Cleanup
Expand Down
32 changes: 32 additions & 0 deletions versions.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,38 @@
`task image:build`, then `task shell` and `task boot:bench`: a new mkosi can change the
tree without failing the build.

- name: task
kind: download
source: https://github.com/go-task/task/releases/download/v{version}/task_linux_amd64.tar.gz
version: 3.45.5
pin: e547ea2a47f5240657fdc89ea776baa90d628a1f2748242eaa7478fd92bffd40
track: tags https://github.com/go-task/task.git
note: >-
image/Dockerfile hands it to install-dev-tools.sh, which puts it in the base image's
/usr/local/bin for whoever works inside a guest. The pin can be checked against
task_checksums.txt beside the tarball. After the bump: `task image:build`.

- name: git-lfs
kind: download
source: https://github.com/git-lfs/git-lfs/releases/download/v{version}/git-lfs-linux-amd64-v{version}.tar.gz
version: 3.7.0
pin: e7ebba491af8a54e560be3a00666fa97e4cf2bbbb223178a0934b8ef74cf9bed
track: tags https://github.com/git-lfs/git-lfs.git
note: >-
image/Dockerfile hands it to install-dev-tools.sh, as task. The pin can be checked against
sha256sums.asc beside the tarball. After the bump: `task image:build`.

- name: buildkit
kind: download
source: https://github.com/moby/buildkit/releases/download/v{version}/buildkit-v{version}.linux-amd64.tar.gz
version: 0.26.2
pin: 1ef7c888f808e7f3f49d9aeeca11f661afe5c0880a4b114cc31c56dee86acd35
track: tags https://github.com/moby/buildkit.git
note: >-
image/Dockerfile hands it to install-dev-tools.sh, as task: buildctl and buildkitd. The
release publishes no checksums, only a provenance attestation beside the tarball. After the
bump: `task image:build`.

- name: qboot
kind: git
source: https://github.com/bonzini/qboot.git
Expand Down