From 7f51458d54d9082529720f1fe2e7ed6333bf21d9 Mon Sep 17 00:00:00 2001 From: kmk1971 Date: Sun, 2 Aug 2026 17:08:51 +0400 Subject: [PATCH] Add GitHub Actions ISO builder (host kernel blocks osbuild mounts); uploads ISO back to Forgejo Co-Authored-By: Claude Fable 5 --- .github/workflows/kamos-iso.yml | 67 +++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 .github/workflows/kamos-iso.yml diff --git a/.github/workflows/kamos-iso.yml b/.github/workflows/kamos-iso.yml new file mode 100644 index 0000000..9f7eb6f --- /dev/null +++ b/.github/workflows/kamos-iso.yml @@ -0,0 +1,67 @@ +name: Build KAMOS ISO + +# Builds the KAMOS installer ISO on a runner whose kernel permits the +# mounts osbuild needs. It only *pulls* the finished KAMOS image from +# fcs.tgsad.ae — all source, image builds and the registry stay self-hosted. + +on: + workflow_dispatch: + inputs: + variant: + description: "Which KAMOS variant" + required: true + default: "kamos" + type: choice + options: + - kamos + - kamos-nvidia + +jobs: + iso: + runs-on: ubuntu-latest + steps: + - name: Free disk space (ISO needs ~30 GB) + uses: jlumbroso/free-disk-space@v1.3.1 + with: + tool-cache: true + android: true + dotnet: true + haskell: true + large-packages: true + docker-images: true + swap-storage: true + + - name: Allow container mounts (Ubuntu userns hardening) + run: | + sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 || true + + - name: Pull KAMOS image from self-hosted registry + run: | + sudo podman pull "fcs.tgsad.ae/mkm1971_admin/${{ inputs.variant }}:stable" + + - name: Build installer ISO + run: | + mkdir -p output + sudo podman run --rm --privileged \ + -v "$PWD/output:/output" \ + -v /var/lib/containers/storage:/var/lib/containers/storage \ + quay.io/centos-bootc/bootc-image-builder:latest \ + --type anaconda-iso \ + --rootfs btrfs \ + "fcs.tgsad.ae/mkm1971_admin/${{ inputs.variant }}:stable" + sudo mv output/bootiso/install.iso "output/${{ inputs.variant }}-$(date +%Y%m%d).iso" + ls -lh output/ + + - name: Upload ISO to your Forgejo package registry + run: | + RUSER="$(printf "%s" "${{ secrets.REGISTRY_USER }}" | tr -d ' \r\n')" + RTOKEN="$(printf "%s" "${{ secrets.REGISTRY_TOKEN }}" | tr -d ' \r\n')" + ISO=$(ls output/*.iso) + NAME=$(basename "$ISO") + DATE_TAG=$(date +%Y%m%d) + sudo chmod a+r "$ISO" + curl --fail --progress-bar -u "${RUSER}:${RTOKEN}" \ + --upload-file "$ISO" \ + "https://fcs.tgsad.ae/api/packages/mkm1971_admin/generic/kamos-iso/${DATE_TAG}/${NAME}" \ + -o /dev/null + echo "Done: https://fcs.tgsad.ae/mkm1971_admin/-/packages/generic/kamos-iso/${DATE_TAG}"