Builds Debian (trixie) packages for ostree
and bootc, released here and published
to the Frostyard APT repository (https://repository.frostyard.org/debian/,
trixie) by frostyard/apt-publisher.
It produces:
libostree-1-1— OSTree library and toolsbootc— boot and upgrade via container images
Upstream versions are pinned in download/checksums.json
(version, release-tarball URL, sha256). build.sh downloads and
verifies the tarballs, builds ostree, then builds bootc against it (offline,
using upstream's vendored crates and a pinned Rust toolchain), and packages
both as .debs. This mirrors the in-image build in
frostyard/snosi
(shared/bootc/build/bootc.chroot) so both build paths stay identical.
Versions are <upstream>-frostyard<UTC minute>~deb13, for example
1.16.8-frostyard202610040130~deb13. The timestamp makes every rebuild sort
newer. ~deb13 names the Debian release the packages were built against:
apt-publisher publishes a ~debNN version only to the codename for Debian NN
(core ADR-0055),
so a later forky build (~deb14) can sit beside it.
Workflows:
- Build (
build.yml) — on push tomainand on PRs: builds the packages only. - Releasing — a manual run of Build on
main(workflow_dispatch) also:- checks that the build is exactly
bootcandlibostree-1-1, amd64,~deb13, from one build; - attests their build provenance;
- creates a GitHub release tagged
bootc-<version>-ostree-<version>-<UTC minute>with the two.debfiles (GitHub lists them with.deb13in place of~deb13); - sends a
publish-debrequest to frostyard/apt-publisher. apt-publisher publishes the release totrixie, then dispatches a frostyard/snosi image build.
- checks that the build is exactly
- Check Upstream Versions (
check-dependencies.yml) — weekly: checks for new ostree/bootc releases and opens a PR updatingdownload/checksums.json. Merging that PR triggers a build; releasing needs a manual run.
docker run --rm -v "$PWD":/src -w /src debian:trixie bash build.shPackages land in dist/. build.sh refuses to run on anything but trixie.
Edit download/checksums.json (or run the Check Upstream Versions workflow
via workflow_dispatch). On a bootc bump, check whether RUST_VERSION in
build.sh needs a bump — a new bootc release may require a newer rustc to
build.