Unify coreos build - #85
madhu-pillai wants to merge 1 commit into
Conversation
| #kbc_image := "quay.io/trusted-execution-clusters/trustee-attester:fedora-b13fd8a" | ||
| #clevis_pin_trustee_image := "quay.io/trusted-execution-clusters/clevis-pin-trustee:fedora-75015a5" | ||
| #ignition_image := "quay.io/trusted-execution-clusters/ignition:fedora-af7bcce09" | ||
| tec_config := env("TEC_CONFIG", "../../fedora-coreos-tec-config") |
There was a problem hiding this comment.
where are you fetching those configuration? I think it require the remote github repository
| #kbc_image := "quay.io/trusted-execution-clusters/trustee-attester:fedora-b13fd8a" | ||
| #clevis_pin_trustee_image := "quay.io/trusted-execution-clusters/clevis-pin-trustee:fedora-75015a5" | ||
| #ignition_image := "quay.io/trusted-execution-clusters/ignition:fedora-af7bcce09" |
There was a problem hiding this comment.
I think those variable are still necessary, we have no defaults in https://github.com/trusted-execution-clusters/fedora-coreos-tec-config/blob/main/Containerfile#L6-L9
| ##@echo "kbc_image {{kbc_image}}" | ||
| #@echo "clevis_pin_trustee_image {{clevis_pin_trustee_image}}" |
| podman build --no-cache \ | ||
| --build-arg BASE={{base}} \ | ||
| --build-arg KBC_IMG="${KBC_IMG}" \ | ||
| --build-arg CLEVIS_PIN_IMG="${CLEVIS_PIN_IMG}" \ | ||
| --build-arg IGNITION_IMG="${IGNITION_IMG}" \ | ||
| --build-arg NAME={{os_name}} \ | ||
| --build-arg ID={{os}} \ | ||
| --build-arg VERSION="${VERSION}" \ | ||
| --build-arg STREAM="${STREAM}" \ | ||
| --build-arg DESCRIPTION="{{os_name}} for trusted execution clusters" \ | ||
| -t {{image}} -f {{tec_config}}/Containerfile {{tec_config}} |
There was a problem hiding this comment.
is it possible to use cosa init and cose build instead of building directly with podman
|
Could you please sign the commit and add a short description in the commit body? |
d93d607 to
6f9b598
Compare
|
@alicefr , Able to boot the coreos image using attestation (testing). |
Jakob-Naucke
left a comment
There was a problem hiding this comment.
thanks @madhu-pillai, could you commit under an author email associated with the same GH account and take a look at the CI failure?
I also still want to test the KubeVirt image
| cd cache | ||
| cosa init --force {{config}} | ||
| cosa import oci-archive:/srv/{{archive}} | ||
| # 1. Init with upstream config (provides osbuild, platforms.yaml, BUILDER_IMG) |
There was a problem hiding this comment.
nit: remove numeral steps, requires shifting every time we change them
Jakob-Naucke
left a comment
There was a problem hiding this comment.
it does, but I'd probably want to bump the components in the fedora config repo before we merge this
dce4ea0 to
5515bd2
Compare
Replace the two-phase podman build + cosa import workflow with a unified cosa build approach that works across fcos, scos, and rhcos. Previous approach: 1. podman build --build-arg BASE=<img> -f Containerfile 2. skopeo copy → oci-archive 3. cosa init --force <upstream-config> 4. cosa import oci-archive 5. cosa osbuild qemu New approach: 1. cosa init --force <base_config> (upstream osbuild infra) 2. git clone <tec_config> + overlay (TEC files on top) 3. cosa build (buildah multi-stage) 4. cosa osbuild qemu Key changes: - Split config variable into base_config (upstream osbuild infra) and tec_config (TEC Containerfile, build-args, dracut modules) - Remove podman build, oci-archive, init targets — replaced by unified build target with overlay logic - Fix cosa function: replace sudo podman run -u 0 with podman run --userns=keep-id:uid=1000,gid=1000 matching upstream - Add BUILDER_IMG save/restore across TEC overlay (TEC build-args.conf doesn't carry BUILDER_IMG needed for osbuild buildroot python3) - Add base_img override: SCOS shares RHCOS TEC config which has restricted Red Hat base — override with public OKD scos-content - Make component images (KBC_IMG, CLEVIS_PIN_IMG, IGNITION_IMG) and OS_VERSION overridable via environment variables - Add usage header and step-numbered comments in build target - Add podman rm -f cosa before targets to handle stale containers - Add changes in CI .github/workflows/build-fcos-images.yml Signed-off-by: Madhu Pillai <mapillai@redhat.com>
Looks like my redhat github account |
| # Apply env overrides if set | ||
| [ -n "{{kbc_image}}" ] && sed -i "s|^KBC_IMG=.*|KBC_IMG={{kbc_image}}|" src/config/build-args.conf | ||
| [ -n "{{clevis_pin_trustee_image}}" ] && sed -i "s|^CLEVIS_PIN_IMG=.*|CLEVIS_PIN_IMG={{clevis_pin_trustee_image}}|" src/config/build-args.conf | ||
| [ -n "{{ignition_image}}" ] && sed -i "s|^IGNITION_IMG=.*|IGNITION_IMG={{ignition_image}}|" src/config/build-args.conf |
There was a problem hiding this comment.
I understand that before we were overwriting the variables, but maybe we shouldn't. If somebody wants to try a local build they need to modify the fedora/rhcos config directly. This scripts has become too complex imo
There was a problem hiding this comment.
If we do not requires overrides then i'll remove it.
| # Override the os version | ||
| [ -n "{{os_version}}" ] && sed -i "s|^VERSION=.*|VERSION={{os_version}}|" src/config/build-args.conf | ||
|
|
||
| cp /tmp/tec-overlay/manifest.yaml src/config/ | ||
| cp /tmp/tec-overlay/versionary src/config/ | ||
| cp -rL /tmp/tec-overlay/usr src/config/ | ||
| rm -rf /tmp/tec-overlay | ||
| echo "!/usr/" >> src/config/.containerignore |
There was a problem hiding this comment.
Why is this necessary? Won't this be already correctly set based on the configuration we take?
There was a problem hiding this comment.
112 and 113, will remove.
what i am trying to achieve here was using cosa instead of manually running the podman cosa init <upstream config> then copy the necessary tec config to /src/config then build the image. So any changes user requires can directly apply from tec config.
However, I tried with only the cosa init <tec config> the build works, but when we create image just build-qemu it fails in error says following. Looks like it does not have the builder-img.
I did not try the cosa
Building FCOS buildroot container
[1/2] STEP 1/3: FROM overridden AS builder
Error: creating build container: short-name resolution enforced but cannot prompt without a TTY
failed to execute cmd-buildextend-qemu: exit status 125
+ rc=125
+ set +x
| cp "$BUILD_ARGS" src/config/build-args.conf | ||
| [ -n "{{base_img}}" ] && sed -i "s|^BASE=.*|BASE={{base_img}}|" src/config/build-args.conf |
There was a problem hiding this comment.
As I commented below, the script is too complex. I think we should set the default in the configuration and rely on those. If the users want to build a different version, they can always fork and change the configuration in their repository
There was a problem hiding this comment.
for clarification: we do want to keep the option to override guest components images, right? that I see myself using a lot and forking and switching branches in l. 100 is really a lot more clumsy
|
|
||
| # Clone TEC config and overlay (Containerfile, build-args, manifest, versionary, usr/) | ||
| rm -rf /tmp/tec-overlay | ||
| git clone --depth=1 --recurse-submodules {{tec_config}} /tmp/tec-overlay |
There was a problem hiding this comment.
I barely dare ask this, but regardless of env support, do we need to support branches here?
There was a problem hiding this comment.
I think it is better to have branch support too. Its easier for testing.
hi,
Removed the
/usr , Containerfile and modified justfileto pull the images default fromfedora-coreos-tec-configThanks
Madhu