fix(release): retain XBPS key through publication

The optional XBPS publisher signs repository metadata after package signing. Remove the runner key only after publication and release asset upload.
This commit is contained in:
xavierk
2026-09-29 04:06:45 +05:30
parent a5b84f7566
commit 3f2dd6a5a1
3 changed files with 26 additions and 6 deletions
+21 -5
View File
@@ -58,6 +58,20 @@ gpg --batch --yes --delete-keys packaging@bongbetic.com
The committed `fenris-packaging.asc` must contain the real public key (replace
the placeholder comments).
## XBPS signing key
XBPS uses a separate RSA 3072 key. Its private half is stored as the Gitea
repository Actions secret `XBPS_SIGNING_KEY`. The corresponding public key is
published at
`https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/keys/fenris-xbps-signing.pub`,
with fingerprint `SHA256:AvPMRlKMikPg75u0iKr8AUkxlfU/Ad4k/S4o2M9W4/w`.
The secret must match that public key.
The release workflow writes the key to `~/.ssh/id_xbps` to sign the XBPS
package. A requested XBPS publication also uses the key to sign repository
metadata. A final `always()` cleanup removes the runner copy after publication
and release asset upload, including when an earlier step fails.
## Per-release signing flow
Each tagged release performs: **import → verify → sign → delete** on the
@@ -76,14 +90,16 @@ git push origin v<version>
The release workflow imports `GPG_PRIVATE_KEY`, checks it against
`packaging/keys/fenris-packaging.asc`, builds packages, signs the RPM and
clearsigned checksum manifest, validates both, and publishes the release.
XBPS publication is separate and requires its signing key and host acceptance.
clearsigned checksum manifest, validates both, and publishes the release. The
workflow imports `XBPS_SIGNING_KEY` separately and signs the XBPS package.
XBPS publication is optional and also signs repository metadata; it requires
host acceptance and explicit selection during workflow dispatch.
### Step 3: Verify runner cleanup
The workflow's `always()` cleanup removes the imported key from the runner's
keyring, including after a failed job. Confirm no packaging secret key remains
on the runner after the release job.
The workflow's `always()` cleanup removes the GPG key from the runner's keyring
and deletes `~/.ssh/id_xbps`, including after a failed job. Confirm no signing
key remains on the runner after the release job.
The Gitea Actions secret remains the approved signing source. Do not copy it to
the runner or repository outside the workflow.