Repository navigation
ci: publish Debian packages through frostyard/apt-publisher - #6
Merged
Merged
Conversation
The release job ran repogen's publish-to-r2 pinned to v0.4.1, the last release that still accepts package-type deb. Every push to stable therefore kept writing incus into the frozen legacy suite (dists/stable), as 7.4 did on 2026-09-16. Core ADR-0055 makes frostyard/apt-publisher the only Debian writer, and signed stable must stay unchanged. A build of stable now: - checks that the artifact holds exactly one Debian 13 amd64 build of incus, incus-base, incus-client, incus-extra and incus-ui-canonical, because apt-publisher publishes every .deb in the release; - attests the .deb files' build provenance; - creates a GitHub release holding only those .deb files, tagged with the package version minus its epoch (e.g. 7.5.1-debian13-202610031200); - sends publish-deb to frostyard/apt-publisher with APT_PUBLISH_TOKEN, for trixie only and not continue-on-error, from a job with no GITHUB_TOKEN permissions. Builds of any other branch or tag stop after the build job. Before, the release job ran for every branch push. Removed: the repogen step with its R2, Cloudflare and signing secrets, and the "Kickoff snosi" dispatch, which could never fire: it required the default branch, daily, where this workflow does not exist. apt-publisher now dispatches build to snosi after the packages are live (ADR-0056). The build job's checkout and upload-artifact are pinned to the commits their v4 tags point at (ADR-0021), and the checkout no longer keeps the token in .git/config. All of it is generated by sync-docker-build.py, so regenerating the workflow during an upstream sync keeps it. [skip ci] keeps the push of this branch from starting the build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 task done
1 task done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Frostyard's incus builds stop writing the APT repository themselves.
stableattaches its Debian 13 packages to a GitHub release.https://repository.frostyard.org/debian/trixie.buildto frostyard/snosi once the packages are installable (ADR-0056).This also stops writes to the frozen legacy
stablesuite.publish-to-r2@v0.4.1. v0.4.1 is the last repogen release without the deb refusal; 6f85328 pinned it on 2026-09-16 to get around that refusal.stablestill writesdists/stable. Incus 7.4 did at 15:18 UTC on 2026-09-16, after the freeze, and core's stable drift alarm has failed since.stablemust stay unchanged through 2027-09-30 (ADR-0055).stable, in particular the Incus 7.5.1 sync, Merge upstream/stable (Incus 7.5.1) into frostyard stable #7. That PR contains this commit so it can't land without it.What changes
Everything is in
sync-docker-build.py, which generatesbuilds-docker.yml, so an upstream sync's regeneration keeps it. The workflow is regenerated: before this change the generator reproduced the committed file byte for byte.releasejob, only forfrostyard/incusonrefs/heads/stable(push or manual dispatch).incus,incus-base,incus-client,incus-extraandincus-ui-canonical, allamd64.1:<x.y[.z]>-debian13-<12-digit UTC time>, and each must be under GitHub's 2 GiB asset limit..debin a release. This keeps any other OS build, architecture or partial set out of it..buildinfoand.changesfiles are never uploaded..debfiles' build provenance (actions/attest-build-provenancev4.2.2)..debfiles.7.5.1-debian13-202610031200.request-publicationjob (permissions: {}).publish-debrepository_dispatchto frostyard/apt-publisher withAPT_PUBLISH_TOKEN. The payload carriesrepo,tagand"codenames": ["trixie"].continue-on-error.R2_*,CLOUDFLARE_*andREPOGEN_GPG_KEY;ORG_PAT). It could never fire: it was guarded to the default branch,daily, where this workflow doesn't exist;actions/checkoutandactions/upload-artifactare pinned to the commits theirv4tags point at today, so nothing that runs changes;persist-credentials: false.Otherwise the build job is unchanged, and other branches and tags still build as CI.
Codename and version
1:<incus>-debian13-<UTC minute>.-debian13-isn't a~debNNmarker, so apt-publisher registers incus fortrixieonly (frostyard/apt-publisher#7). This workflow also requeststrixieexplicitly.1:7.5.1-debian13-…, whichdpkg --compare-versionssorts above trixie's current1:7.4-debian13-202609161516.~deb13/~deb14to the version, which needs no apt-publisher change (…-debian13-…~deb13<…-debian14-…~deb14, checked); or-debianNN-counts as a marker.Attestation
The
.debfiles are attested, but apt-publisher can't use that yet.refs/heads/stable, while apt-publisher verifies--source-ref refs/tags/<tag>. incus is therefore registeredattested=no.gh attestation verify incus_<version>_amd64.deb --repo frostyard/incus --source-ref refs/heads/stable.attested=yes:Risk classification
.github/workflows/**, the workflow-and-permissions boundary; it publishes packages that snosi's incus sysext installs)Threat analysis
stablebuild → frostyard/apt-publisher, through a cross-repositoryrepository_dispatch.ORG_PAT.APT_PUBLISH_TOKENhas Contents read/write on frostyard/apt-publisher only, whichrepository_dispatchrequires.mainis protected by the "Protect main" ruleset: pull request required, no force-push or deletion, no bypass.maincan use theapt-repositoryenvironment, which holds the signing key and R2 credentials.publish-debfor any registered producer and tag. apt-publisher accepts only registered producers, and only their registered package names, codenames and architectures. For incus that means the five names,trixie, amd64/arm64/all.contents: write.stablehas no protection, and a push to it published through repogen.stableand the attestation follow-up above would narrow it.${{ }}insiderun:; values reach scripts throughenv:.tagis validated by the check step's regex (digits, dots,-debian13-, 12 digits) before it's used, andrepoisgithub.repository.contents: read;releasejob:contents,attestationsandid-tokenwrite;request-publication: noGITHUB_TOKENpermissions.request-publication.Rollback
@v0.4.1, which writes the frozenstablesuite.frostyard/incusfrom apt-publisher'sconfig/producers.tsv(its publish runs then refuse), or disable this workflow.trixie, package, version) for each of the five packages.repo=frostyard/incusand the tag.Merge order and first publication
APT_PUBLISH_TOKEN. The org-secrets API already lists it for this repository; confirm it.stableand skip the build. A merge commit's message is "Merge pull request …" plus the title, so thestablebuild runs.cancel-in-progressonstable), so 7.5.1 is the first publication.After the merge:
stable: about 35 minutes, thenreleaseandrequest-publication.gh release view <tag> -R frostyard/incus.scripts/apt-canary.sh trixie amd64 incus=1:<version>.snosi still reads the frozen
stablesuite until Plan 0009 Phase 5. Until snosi moves to/debian/trixie, its images keep incus 7.4 even after apt-publisher dispatches the rebuild.Verification
builds-docker.ymlbyte for byte before the change. Regenerating after it is idempotent..debfiles:.buildinfo/.changes, giving tag7.5.1-debian13-202610031200.~deb13version.Other findings
zabbly-stableandfix/incus-pkgos-trixie-depsstill havebuilds-docker.ymlwithon: push,workflow_dispatchand repogenpublish-to-r2@main(package-type: deb).@mainrefuses deb today, but it's a mutable ref, and any push or dispatch on those branches runs it.stable.sync-upstream.ymlnever runs. Schedules only fire from the default branch,daily, where it doesn't exist, and GitHub doesn't list it as a workflow. Upstream syncs are manual merges.🤖 Generated with Claude Code