 xavierkandCommandCodeBot
|
d8fa6df072
|
signing: rpm payload signing, key publication, consumer repo setup for #51
Implement the signing and consumer-repo trust infrastructure:
- Makefile: add generate-test-key, sign-rpm, checksums, clearsign targets;
make release now automates the full build→sign→checksum→clearsign flow
- Key ceremony: document the import→sign→delete lifecycle, key rotation
outline, and private-key-in-password-manager policy
- Public key: update placeholder with raw URL, algorithm, and ceremony ref
- Consumer docs: README now covers apt signed-by keyring flow, dnf repo
file setup, signature verification commands, and migration runbook link
- Release spec: updated to reference ceremony doc and rpmsign workflow
- Tests: 36 structural signing tests (nfpm config, Makefile targets,
repo file, key publication, ceremony doc, consumer docs, spec refs)
plus throwaway-key RPM signature and clearsign mechanics; no network
or real key required
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
|
2026-09-03 14:14:55 +05:30 |
|
xavierk
|
b005049733
|
docs: release & packaging spec + ADR 0007 amending 0004 (map #33, task #42)
- docs/spec/release-packaging.md: decision-complete spec — compat matrix,
Gitea 1.27.1 registry channel, nfpm toolchain, signing/key policy,
release mechanics, package layout/ownership, maintainer-script
contracts, initial config, make-install migration runbook.
- docs/adr/0007: package delivery amends ADR 0004 (delivery/ownership
only; runtime semantics inherited verbatim). 0004 status updated.
- docs/research/: toolchain, gitea-registry, obs findings merged from
research branches (assets of map tickets #34/#35/#36).
- CONTEXT.md: Release + Rollback glossary terms (ticket #43).
|
2026-09-03 01:44:37 +05:30 |
|