Grilling: Lock channel + toolchain #38

Closed
opened 2026-09-02 18:31:22 +00:00 by xavierk · 1 comment
Owner

Parent map: Fenris deb + rpm release plan

Question

Given the research findings, lock the distribution channel (Gitea Debian/RPM registry vs OBS vs both) and the packaging toolchain per format. Decide the single-source-of-truth build layout (shared version + file lists) and the artifact promotion flow (tag → build → publish → attach to release).

Parent map: [Fenris deb + rpm release plan](https://git.bongbetic.com/xavierk/Fenris/issues/33) ## Question Given the research findings, lock the distribution channel (Gitea Debian/RPM registry vs OBS vs both) and the packaging toolchain per format. Decide the single-source-of-truth build layout (shared version + file lists) and the artifact promotion flow (tag → build → publish → attach to release).
xavierk added this to the Wayfinder: Fenris deb + rpm release plan milestone 2026-09-02 18:31:22 +00:00
xavierk added the wayfinder:grilling label 2026-09-02 18:31:22 +00:00
xavierk added a new dependency 2026-09-02 18:34:06 +00:00
xavierk added a new dependency 2026-09-02 18:34:06 +00:00
xavierk added a new dependency 2026-09-02 18:34:07 +00:00
xavierk added a new dependency 2026-09-02 18:34:07 +00:00
xavierk added a new dependency 2026-09-02 18:34:08 +00:00
xavierk added a new dependency 2026-09-02 18:34:09 +00:00
xavierk self-assigned this 2026-09-02 19:35:42 +00:00
Author
Owner

Resolution

All nine sub-decisions locked (user accepted recommendations Q1–Q9):

Channel: Gitea 1.27.1 self-hosted Debian/RPM registry, single channel, OBS permanently off the route (ratifies #36).

Toolchain: nfpm for both deb and rpm, single packaging/nfpm.yaml with overrides: per format; fpm dropped entirely (not even a documented fallback); no hand rpm spec (ratifies #34).

Artifacts/dists: one deb (bundled venv → no distro deps) PUT to each dist pool by codename: bookworm, jammy, noble. One rpm, single group fenris, serving Fedora 40+.

Build layout (single source of truth): packaging/nfpm.yaml in repo; version injected from pyproject.toml; file lists generated by a staging script (venv --copies → /opt/fenris tree) which the nfpm config references — no hand-maintained file lists; entry point make package producing deb + rpm.

Version scheme: <pyproject-version>-1 both formats; revision bump (-2, -3, …) on rebuild of same upstream version; never re-PUT the same filename (registry 409s duplicates).

Promotion flow: tag → make release (manual: build + PUT upload + attach assets); release assets = .deb, .rpm, SHA256SUMS. Dormant .gitea/workflows/release.yml committed now — on: push: tags: ['v*'], single job, host-mode runner assumed; queueing-until-runner is acceptable since manual flow remains the fallback.

Writing nfpm.yaml / staging script / workflow file is execution — deliberately out of this map's scope.

Downstream tickets Grilling: Signing + key policy and Grilling: Package ownership + ADR 0004 amendment are now unblocked.

## Resolution All nine sub-decisions locked (user accepted recommendations Q1–Q9): **Channel**: Gitea 1.27.1 self-hosted Debian/RPM registry, single channel, OBS permanently off the route (ratifies #36). **Toolchain**: nfpm for both deb and rpm, single `packaging/nfpm.yaml` with `overrides:` per format; fpm dropped entirely (not even a documented fallback); no hand rpm spec (ratifies #34). **Artifacts/dists**: one deb (bundled venv → no distro deps) PUT to each dist pool by **codename**: `bookworm`, `jammy`, `noble`. One rpm, single group `fenris`, serving Fedora 40+. **Build layout (single source of truth)**: `packaging/nfpm.yaml` in repo; version injected from `pyproject.toml`; file lists generated by a staging script (venv `--copies` → `/opt/fenris` tree) which the nfpm config references — no hand-maintained file lists; entry point `make package` producing deb + rpm. **Version scheme**: `<pyproject-version>-1` both formats; revision bump (`-2`, `-3`, …) on rebuild of same upstream version; never re-PUT the same filename (registry 409s duplicates). **Promotion flow**: tag → `make release` (manual: build + PUT upload + attach assets); release assets = `.deb`, `.rpm`, `SHA256SUMS`. Dormant `.gitea/workflows/release.yml` committed now — `on: push: tags: ['v*']`, single job, host-mode runner assumed; queueing-until-runner is acceptable since manual flow remains the fallback. Writing `nfpm.yaml` / staging script / workflow file is execution — deliberately out of this map's scope. Downstream tickets [Grilling: Signing + key policy](https://git.bongbetic.com/xavierk/Fenris/issues/39) and [Grilling: Package ownership + ADR 0004 amendment](https://git.bongbetic.com/xavierk/Fenris/issues/40) are now unblocked.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#38