fix(release): retain XBPS key through publication
The optional XBPS publisher signs repository metadata after package signing. Remove the runner key only after publication and release asset upload.
This commit is contained in:
@@ -58,6 +58,20 @@ gpg --batch --yes --delete-keys packaging@bongbetic.com
|
||||
The committed `fenris-packaging.asc` must contain the real public key (replace
|
||||
the placeholder comments).
|
||||
|
||||
## XBPS signing key
|
||||
|
||||
XBPS uses a separate RSA 3072 key. Its private half is stored as the Gitea
|
||||
repository Actions secret `XBPS_SIGNING_KEY`. The corresponding public key is
|
||||
published at
|
||||
`https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/keys/fenris-xbps-signing.pub`,
|
||||
with fingerprint `SHA256:AvPMRlKMikPg75u0iKr8AUkxlfU/Ad4k/S4o2M9W4/w`.
|
||||
The secret must match that public key.
|
||||
|
||||
The release workflow writes the key to `~/.ssh/id_xbps` to sign the XBPS
|
||||
package. A requested XBPS publication also uses the key to sign repository
|
||||
metadata. A final `always()` cleanup removes the runner copy after publication
|
||||
and release asset upload, including when an earlier step fails.
|
||||
|
||||
## Per-release signing flow
|
||||
|
||||
Each tagged release performs: **import → verify → sign → delete** on the
|
||||
@@ -76,14 +90,16 @@ git push origin v<version>
|
||||
|
||||
The release workflow imports `GPG_PRIVATE_KEY`, checks it against
|
||||
`packaging/keys/fenris-packaging.asc`, builds packages, signs the RPM and
|
||||
clearsigned checksum manifest, validates both, and publishes the release.
|
||||
XBPS publication is separate and requires its signing key and host acceptance.
|
||||
clearsigned checksum manifest, validates both, and publishes the release. The
|
||||
workflow imports `XBPS_SIGNING_KEY` separately and signs the XBPS package.
|
||||
XBPS publication is optional and also signs repository metadata; it requires
|
||||
host acceptance and explicit selection during workflow dispatch.
|
||||
|
||||
### Step 3: Verify runner cleanup
|
||||
|
||||
The workflow's `always()` cleanup removes the imported key from the runner's
|
||||
keyring, including after a failed job. Confirm no packaging secret key remains
|
||||
on the runner after the release job.
|
||||
The workflow's `always()` cleanup removes the GPG key from the runner's keyring
|
||||
and deletes `~/.ssh/id_xbps`, including after a failed job. Confirm no signing
|
||||
key remains on the runner after the release job.
|
||||
|
||||
The Gitea Actions secret remains the approved signing source. Do not copy it to
|
||||
the runner or repository outside the workflow.
|
||||
|
||||
Reference in New Issue
Block a user