From 858a104d352698249abdd6155000bdf8b21d5a12 Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Tue, 7 Jul 2026 11:33:30 +0200 Subject: [PATCH 1/8] license: replace MIT with Apache-2.0 The LICENSE file contained MIT text, but pyproject.toml declared Apache-2.0. Apache-2.0 is the standard license for Red Hat's OpenShift ecosystem projects, providing explicit patent protection for enterprise use. Assisted-by: Claude Code --- LICENSE | 222 ++++++++++++++++++++++++++++++++++++++++++++++++++------ 1 file changed, 201 insertions(+), 21 deletions(-) diff --git a/LICENSE b/LICENSE index 55c2576d..b62caed5 100644 --- a/LICENSE +++ b/LICENSE @@ -1,21 +1,201 @@ -MIT License - -Copyright (c) 2026 Red Hat - -Permission is hereby granted, free of charge, to any person obtaining a copy -of this software and associated documentation files (the "Software"), to deal -in the Software without restriction, including without limitation the rights -to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -copies of the Software, and to permit persons to whom the Software is -furnished to do so, subject to the following conditions: - -The above copyright notice and this permission notice shall be included in all -copies or substantial portions of the Software. - -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -SOFTWARE. + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright 2026 Red Hat + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. From 58d3d609f8be18a2338af1d0126ab0e943c44bc6 Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Tue, 7 Jul 2026 11:35:47 +0200 Subject: [PATCH 2/8] rpm: add spec file for enclave package MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit noarch RPM that installs enclave to /opt/enclave. Runtime dependencies mirror setup_env.sh. Post-install copies config examples to active names. No network activity during install — user runs 'make setup' afterward. Assisted-by: Claude Code --- hack/rpm/enclave.spec | 106 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 106 insertions(+) create mode 100644 hack/rpm/enclave.spec diff --git a/hack/rpm/enclave.spec b/hack/rpm/enclave.spec new file mode 100644 index 00000000..1a91a13f --- /dev/null +++ b/hack/rpm/enclave.spec @@ -0,0 +1,106 @@ +Name: enclave +Version: %{enclave_version} +Release: 1%{?dist} +Summary: Red Hat Sovereign Enclave — deployment platform for OpenShift on bare metal +License: Apache-2.0 +URL: https://github.com/rh-ecosystem-edge/enclave +BuildArch: noarch + +Source0: enclave-%{enclave_version}.tar.gz + +Requires: bind-utils +Requires: curl +Requires: git-core +Requires: httpd +Requires: ipcalc +Requires: jq +Requires: lsof +Requires: make +Requires: nmstate +Requires: openssl +Requires: podman +Requires: python3 +Requires: rsync +Requires: skopeo +Requires: tar +Requires: unzip + +%description +Red Hat Sovereign Enclave (RHSE) is an optionally disconnected infrastructure +platform that delivers a cloud-like experience based on OpenShift. It provisions +and maintains OpenShift clusters on bare metal hardware, supports a local +management plane (ACM, Quay), and controls software ingress into air-gapped +environments. + +This package installs the enclave distribution to /opt/enclave with playbooks, +scripts, schemas, plugins, and the Python CLI source. After installing, run +'make setup' from /opt/enclave to bootstrap the Python and Ansible environment. + +%prep +%setup -q -n enclave-%{enclave_version} + +%build +%dnl Nothing to build — interpreted code only (Python, Ansible, Bash, Jinja2) + +%install +mkdir -p %{buildroot}/opt/enclave +cp -a . %{buildroot}/opt/enclave + +# Remove dev-only files that must not ship +rm -rf %{buildroot}/opt/enclave/.github +rm -rf %{buildroot}/opt/enclave/.githooks +rm -rf %{buildroot}/opt/enclave/.claude +rm -rf %{buildroot}/opt/enclave/.ruff_cache +rm -rf %{buildroot}/opt/enclave/.pytest_cache +rm -rf %{buildroot}/opt/enclave/scripts +rm -rf %{buildroot}/opt/enclave/src/tests +rm -rf %{buildroot}/opt/enclave/test-fixtures +rm -rf %{buildroot}/opt/enclave/hack +rm -rf %{buildroot}/opt/enclave/out +rm -rf %{buildroot}/opt/enclave/artifacts +rm -rf %{buildroot}/opt/enclave/docs/superpowers +rm -f %{buildroot}/opt/enclave/.coderabbit.yaml +rm -f %{buildroot}/opt/enclave/.ansible-lint +rm -f %{buildroot}/opt/enclave/.yamllint.yml +rm -f %{buildroot}/opt/enclave/.gitignore +rm -f %{buildroot}/opt/enclave/.python-version +rm -f %{buildroot}/opt/enclave/.coverage +rm -f %{buildroot}/opt/enclave/Makefile.ci +rm -f %{buildroot}/opt/enclave/CLAUDE.md +rm -f %{buildroot}/opt/enclave/AGENTS.md +rm -f %{buildroot}/opt/enclave/CONTRIBUTING.md +find %{buildroot}/opt/enclave/plugins -type d -name test-fixtures -exec rm -rf {} + 2>/dev/null || : + +%post +for f in /opt/enclave/config/*.example.yaml; do + [ -f "$f" ] || continue + target="${f%.example.yaml}.yaml" + [ -f "$target" ] || cp "$f" "$target" +done +for f in /opt/enclave/config/plugins/*.example.yaml; do + [ -f "$f" ] || continue + target="${f%.example.yaml}.yaml" + [ -f "$target" ] || cp "$f" "$target" +done + +%postun +if [ $1 -eq 0 ]; then + rm -f /opt/enclave/config/global.yaml + rm -f /opt/enclave/config/certificates.yaml + rm -f /opt/enclave/config/cloud_infra.yaml + rm -f /opt/enclave/config/plugins/lvms.yaml + rm -f /opt/enclave/config/plugins/odf.yaml + rm -f /opt/enclave/config/plugins/osac.yaml + rm -f /opt/enclave/config/plugins/rhbk.yaml + rm -f /opt/enclave/config/plugins/vast-csi.yaml + rm -rf /opt/enclave/.local + rm -rf /opt/enclave/.cache + rm -rf /opt/enclave/collections +fi + +%files +/opt/enclave + +%changelog +* Mon Jul 07 2026 Ricardo Piccoli - 0.1.0-1 +- Initial RPM packaging with Mock-based build system From cb728d504c8a6923126da3ac64125c99264c887c Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Tue, 7 Jul 2026 11:36:13 +0200 Subject: [PATCH 3/8] rpm: add build script using Mock inside podman Creates source tarball via git archive, then runs Mock inside a Fedora 42 podman container targeting centos-stream-10-x86_64. Outputs RPMs, SRPM, and SHA256 checksums to out/. No host dependencies beyond podman. Assisted-by: Claude Code --- hack/rpm/build-rpm.sh | 84 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 84 insertions(+) create mode 100755 hack/rpm/build-rpm.sh diff --git a/hack/rpm/build-rpm.sh b/hack/rpm/build-rpm.sh new file mode 100755 index 00000000..f95bba12 --- /dev/null +++ b/hack/rpm/build-rpm.sh @@ -0,0 +1,84 @@ +#!/usr/bin/env bash +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +REPO_DIR="$(cd "${SCRIPT_DIR}/../.." && pwd)" +OUT_DIR="${REPO_DIR}/out" +SPEC_FILE="${SCRIPT_DIR}/enclave.spec" + +VERSION=$(grep '^version' "${REPO_DIR}/pyproject.toml" | sed 's/version = "\(.*\)"/\1/') +if [[ -z "${VERSION}" ]]; then + echo "ERROR: Could not extract version from pyproject.toml" + exit 1 +fi + +echo "=== Building Enclave RPM ===" +echo " Version: ${VERSION}" +echo "" + +WORK_DIR=$(mktemp -d) +cleanup() { rm -rf "${WORK_DIR}"; } +trap cleanup EXIT + +# --- Step 1: Create source tarball --- +echo "[1/3] Creating source tarball..." +git -C "${REPO_DIR}" archive \ + --format=tar.gz \ + --prefix="enclave-${VERSION}/" \ + --output="${WORK_DIR}/enclave-${VERSION}.tar.gz" \ + HEAD + +# --- Step 2: Build RPM with Mock inside podman --- +echo "[2/3] Building RPM (Mock inside podman)..." +mkdir -p "${OUT_DIR}" + +podman run --rm --privileged \ + -v "${WORK_DIR}:/work:z" \ + -v "${SCRIPT_DIR}:/specs:z" \ + -v "${OUT_DIR}:/out:z" \ + registry.fedoraproject.org/fedora:42 \ + bash -c " + set -euo pipefail + + echo ' Installing mock and rpm-build...' + dnf install -y mock rpm-build 2>/dev/null >/dev/null + + # Mock needs a non-root user + useradd -m mockbuilder + usermod -aG mock mockbuilder + + RPMBUILD_DIR=\$(mktemp -d) + mkdir -p \${RPMBUILD_DIR}/{SOURCES,SPECS,RPMS,BUILD,SRPMS} + cp /work/enclave-${VERSION}.tar.gz \${RPMBUILD_DIR}/SOURCES/ + cp /specs/enclave.spec \${RPMBUILD_DIR}/SPECS/ + + # Build SRPM first + echo ' Building SRPM...' + rpmbuild -bs \\ + --define \"_topdir \${RPMBUILD_DIR}\" \\ + --define \"enclave_version ${VERSION}\" \\ + \${RPMBUILD_DIR}/SPECS/enclave.spec + + SRPM=\$(find \${RPMBUILD_DIR}/SRPMS -name '*.src.rpm' | head -1) + echo \" SRPM: \$(basename \${SRPM})\" + + # Rebuild with Mock + echo ' Building RPM with Mock (centos-stream-10-x86_64)...' + su - mockbuilder -c \"mock -r centos-stream-10-x86_64 \\ + --define 'enclave_version ${VERSION}' \\ + --rebuild \${SRPM} \\ + --resultdir /out\" + + echo ' Build complete.' + " + +# --- Step 3: Generate checksums --- +echo "[3/3] Generating checksums..." +for rpm in "${OUT_DIR}/"enclave-*.rpm; do + [[ -f "${rpm}" ]] || continue + sha256sum "${rpm}" > "${rpm}.sha256" +done + +echo "" +echo "Build complete. Artifacts in ${OUT_DIR}/:" +ls -lh "${OUT_DIR}/"enclave-* 2>/dev/null || echo " (no artifacts found)" From c310e3d2db94f8a2eb71e8f00ada3b4f969170ef Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Tue, 7 Jul 2026 11:37:11 +0200 Subject: [PATCH 4/8] rpm: add build-rpm Makefile target MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Wraps hack/rpm/build-rpm.sh for building the enclave RPM. Uses Mock inside podman — only prerequisite is podman. Assisted-by: Claude Code --- Makefile | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/Makefile b/Makefile index 4f9d9258..89fff9b5 100644 --- a/Makefile +++ b/Makefile @@ -6,7 +6,7 @@ deploy-cluster-pre-install-validate \ deploy-cluster-install deploy-cluster-post-install deploy-cluster-operators \ deploy-cluster-day2 deploy-cluster-discovery deploy-cluster-connected \ - deploy-plugin mirror-plugin bootstrap sync + deploy-plugin mirror-plugin bootstrap sync build-rpm # Configuration WORKING_DIR ?= $(HOME) @@ -50,6 +50,9 @@ help: @echo " make bootstrap - Bootstrap the Landing Zone" @echo " make sync - Sync configuration to the Landing Zone" @echo "" + @echo "Packaging targets:" + @echo " make build-rpm - Build enclave RPM for RHEL 10 / CentOS Stream 10" + @echo "" @echo "Development targets:" @echo " make dev-env - Install all Python dependencies (uv sync)" @echo " make python-format - Format and lint reconcile/ with ruff" @@ -141,6 +144,10 @@ bootstrap: sync: @bash ./sync.sh +# Packaging +build-rpm: + @bash ./hack/rpm/build-rpm.sh + python-format: @uv run ruff format src/ @uv run ruff check src/ From 89a05641743fef065a5e5d253b4d77249ccc7a85 Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Tue, 7 Jul 2026 11:51:39 +0200 Subject: [PATCH 5/8] rpm: fix build issues found during testing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Fix changelog date: July 7, 2026 is Tuesday, not Monday - Switch from Mock inside podman to rpmbuild inside CentOS Stream 10 container — Mock's nested chroot inside podman caused permission issues with bind mounts. The CentOS container provides equivalent isolation while building natively on the target platform. - Build produces both SRPM and binary RPM Tested: build, install, uninstall all pass on CentOS Stream 10. Assisted-by: Claude Code --- hack/rpm/build-rpm.sh | 33 ++++++++++++++++----------------- hack/rpm/enclave.spec | 2 +- 2 files changed, 17 insertions(+), 18 deletions(-) diff --git a/hack/rpm/build-rpm.sh b/hack/rpm/build-rpm.sh index f95bba12..c0791115 100755 --- a/hack/rpm/build-rpm.sh +++ b/hack/rpm/build-rpm.sh @@ -28,31 +28,27 @@ git -C "${REPO_DIR}" archive \ --output="${WORK_DIR}/enclave-${VERSION}.tar.gz" \ HEAD -# --- Step 2: Build RPM with Mock inside podman --- -echo "[2/3] Building RPM (Mock inside podman)..." +# --- Step 2: Build RPM inside CentOS Stream 10 container --- +echo "[2/3] Building RPM in CentOS Stream 10 container..." mkdir -p "${OUT_DIR}" -podman run --rm --privileged \ +podman run --rm \ -v "${WORK_DIR}:/work:z" \ -v "${SCRIPT_DIR}:/specs:z" \ -v "${OUT_DIR}:/out:z" \ - registry.fedoraproject.org/fedora:42 \ + quay.io/centos/centos:stream10 \ bash -c " set -euo pipefail - echo ' Installing mock and rpm-build...' - dnf install -y mock rpm-build 2>/dev/null >/dev/null - - # Mock needs a non-root user - useradd -m mockbuilder - usermod -aG mock mockbuilder + echo ' Installing rpm-build...' + dnf install -y rpm-build 2>/dev/null >/dev/null RPMBUILD_DIR=\$(mktemp -d) mkdir -p \${RPMBUILD_DIR}/{SOURCES,SPECS,RPMS,BUILD,SRPMS} cp /work/enclave-${VERSION}.tar.gz \${RPMBUILD_DIR}/SOURCES/ cp /specs/enclave.spec \${RPMBUILD_DIR}/SPECS/ - # Build SRPM first + # Build SRPM echo ' Building SRPM...' rpmbuild -bs \\ --define \"_topdir \${RPMBUILD_DIR}\" \\ @@ -61,13 +57,16 @@ podman run --rm --privileged \ SRPM=\$(find \${RPMBUILD_DIR}/SRPMS -name '*.src.rpm' | head -1) echo \" SRPM: \$(basename \${SRPM})\" + cp \${SRPM} /out/ + + # Build binary RPM + echo ' Building binary RPM...' + rpmbuild -bb \\ + --define \"_topdir \${RPMBUILD_DIR}\" \\ + --define \"enclave_version ${VERSION}\" \\ + \${RPMBUILD_DIR}/SPECS/enclave.spec - # Rebuild with Mock - echo ' Building RPM with Mock (centos-stream-10-x86_64)...' - su - mockbuilder -c \"mock -r centos-stream-10-x86_64 \\ - --define 'enclave_version ${VERSION}' \\ - --rebuild \${SRPM} \\ - --resultdir /out\" + cp \${RPMBUILD_DIR}/RPMS/*/*.rpm /out/ echo ' Build complete.' " diff --git a/hack/rpm/enclave.spec b/hack/rpm/enclave.spec index 1a91a13f..aa7c5c65 100644 --- a/hack/rpm/enclave.spec +++ b/hack/rpm/enclave.spec @@ -102,5 +102,5 @@ fi /opt/enclave %changelog -* Mon Jul 07 2026 Ricardo Piccoli - 0.1.0-1 +* Tue Jul 07 2026 Ricardo Piccoli - 0.1.0-1 - Initial RPM packaging with Mock-based build system From 3f349421039d626d9781d0ae70eb49c4767f5a83 Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Fri, 31 Jul 2026 11:31:49 +0200 Subject: [PATCH 6/8] address review comments: move to scripts/, improve spec, add CI workflow - Move RPM build files from hack/rpm/ to scripts/rpm/ so they are excluded from the release tarball (scripts/ is already in the tarball exclude list) - Add %license LICENSE and %doc README.md to the spec - Guard all %post and %postun scriptlet commands with || : for safety - Add rmdir cleanup in %postun to remove /opt/enclave on full uninstall - Remove stale hack/ exclusion from %install - Add GitHub Actions workflow (build-rpm.yml) that builds the RPM in a CentOS Stream 10 container on PRs/pushes and attaches to releases on tags Assisted-by: Claude Code Signed-off-by: Riccardo Piccoli --- .github/workflows/build-rpm.yml | 115 +++++++++++++++++++++++++++++ Makefile | 2 +- {hack => scripts}/rpm/build-rpm.sh | 0 {hack => scripts}/rpm/enclave.spec | 42 ++++++----- 4 files changed, 141 insertions(+), 18 deletions(-) create mode 100644 .github/workflows/build-rpm.yml rename {hack => scripts}/rpm/build-rpm.sh (100%) rename {hack => scripts}/rpm/enclave.spec (72%) diff --git a/.github/workflows/build-rpm.yml b/.github/workflows/build-rpm.yml new file mode 100644 index 00000000..24a1c946 --- /dev/null +++ b/.github/workflows/build-rpm.yml @@ -0,0 +1,115 @@ +name: Build RPM + +on: + workflow_dispatch: + push: + branches: + - main + tags: + - '*' + pull_request: + types: [opened, synchronize, reopened] + merge_group: + types: [checks_requested] + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + build-rpm: + name: Build RPM + runs-on: [self-hosted, pr-validation] + container: + image: quay.io/centos/centos:stream10 + options: --user root + timeout-minutes: 15 + outputs: + version: ${{ steps.meta.outputs.version }} + defaults: + run: + shell: bash + + steps: + - name: Install build tools + run: dnf install -y rpm-build git-core + + - name: Checkout code + uses: actions/checkout@v4 + + - name: Extract version + id: meta + run: | + VERSION=$(grep '^version' pyproject.toml | sed 's/version = "\(.*\)"/\1/') + echo "version=${VERSION}" >> "$GITHUB_OUTPUT" + + - name: Create source tarball + run: | + git archive \ + --format=tar.gz \ + --prefix="enclave-${{ steps.meta.outputs.version }}/" \ + --output="/tmp/enclave-${{ steps.meta.outputs.version }}.tar.gz" \ + HEAD + + - name: Build RPM + run: | + RPMBUILD_DIR=$(mktemp -d) + mkdir -p "${RPMBUILD_DIR}"/{SOURCES,SPECS,RPMS,BUILD,SRPMS} + cp "/tmp/enclave-${{ steps.meta.outputs.version }}.tar.gz" "${RPMBUILD_DIR}/SOURCES/" + cp scripts/rpm/enclave.spec "${RPMBUILD_DIR}/SPECS/" + + rpmbuild -bs \ + --define "_topdir ${RPMBUILD_DIR}" \ + --define "enclave_version ${{ steps.meta.outputs.version }}" \ + "${RPMBUILD_DIR}/SPECS/enclave.spec" + + rpmbuild -bb \ + --define "_topdir ${RPMBUILD_DIR}" \ + --define "enclave_version ${{ steps.meta.outputs.version }}" \ + "${RPMBUILD_DIR}/SPECS/enclave.spec" + + mkdir -p out + cp "${RPMBUILD_DIR}"/SRPMS/*.src.rpm out/ + cp "${RPMBUILD_DIR}"/RPMS/*/*.rpm out/ + + echo "## RPM Build" >> "$GITHUB_STEP_SUMMARY" + echo "" >> "$GITHUB_STEP_SUMMARY" + echo "### Artifacts" >> "$GITHUB_STEP_SUMMARY" + echo '```' >> "$GITHUB_STEP_SUMMARY" + ls -lh out/*.rpm >> "$GITHUB_STEP_SUMMARY" + echo '```' >> "$GITHUB_STEP_SUMMARY" + + - name: Upload RPM artifacts + uses: actions/upload-artifact@v4 + with: + name: enclave-rpm-${{ steps.meta.outputs.version }} + path: out/*.rpm + retention-days: 7 + + attach-to-release: + name: Attach RPM to Release + needs: build-rpm + if: startsWith(github.ref, 'refs/tags/') + runs-on: [self-hosted, pr-validation] + permissions: + contents: write + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Download RPM artifacts + uses: actions/download-artifact@v4 + with: + name: enclave-rpm-${{ needs.build-rpm.outputs.version }} + path: rpms + + - name: Upload to release + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + for rpm in rpms/*.rpm; do + gh release upload "${{ github.ref_name }}" "${rpm}" --repo "${{ github.repository }}" + done diff --git a/Makefile b/Makefile index 89fff9b5..740fb3ec 100644 --- a/Makefile +++ b/Makefile @@ -146,7 +146,7 @@ sync: # Packaging build-rpm: - @bash ./hack/rpm/build-rpm.sh + @bash ./scripts/rpm/build-rpm.sh python-format: @uv run ruff format src/ diff --git a/hack/rpm/build-rpm.sh b/scripts/rpm/build-rpm.sh similarity index 100% rename from hack/rpm/build-rpm.sh rename to scripts/rpm/build-rpm.sh diff --git a/hack/rpm/enclave.spec b/scripts/rpm/enclave.spec similarity index 72% rename from hack/rpm/enclave.spec rename to scripts/rpm/enclave.spec index aa7c5c65..85b7891c 100644 --- a/hack/rpm/enclave.spec +++ b/scripts/rpm/enclave.spec @@ -55,7 +55,6 @@ rm -rf %{buildroot}/opt/enclave/.pytest_cache rm -rf %{buildroot}/opt/enclave/scripts rm -rf %{buildroot}/opt/enclave/src/tests rm -rf %{buildroot}/opt/enclave/test-fixtures -rm -rf %{buildroot}/opt/enclave/hack rm -rf %{buildroot}/opt/enclave/out rm -rf %{buildroot}/opt/enclave/artifacts rm -rf %{buildroot}/opt/enclave/docs/superpowers @@ -74,33 +73,42 @@ find %{buildroot}/opt/enclave/plugins -type d -name test-fixtures -exec rm -rf { %post for f in /opt/enclave/config/*.example.yaml; do [ -f "$f" ] || continue - target="${f%.example.yaml}.yaml" - [ -f "$target" ] || cp "$f" "$target" + target="${f%%.example.yaml}.yaml" + [ -f "$target" ] || cp "$f" "$target" || : done for f in /opt/enclave/config/plugins/*.example.yaml; do [ -f "$f" ] || continue - target="${f%.example.yaml}.yaml" - [ -f "$target" ] || cp "$f" "$target" + target="${f%%.example.yaml}.yaml" + [ -f "$target" ] || cp "$f" "$target" || : done %postun if [ $1 -eq 0 ]; then - rm -f /opt/enclave/config/global.yaml - rm -f /opt/enclave/config/certificates.yaml - rm -f /opt/enclave/config/cloud_infra.yaml - rm -f /opt/enclave/config/plugins/lvms.yaml - rm -f /opt/enclave/config/plugins/odf.yaml - rm -f /opt/enclave/config/plugins/osac.yaml - rm -f /opt/enclave/config/plugins/rhbk.yaml - rm -f /opt/enclave/config/plugins/vast-csi.yaml - rm -rf /opt/enclave/.local - rm -rf /opt/enclave/.cache - rm -rf /opt/enclave/collections + rm -f /opt/enclave/config/global.yaml || : + rm -f /opt/enclave/config/certificates.yaml || : + rm -f /opt/enclave/config/cloud_infra.yaml || : + rm -f /opt/enclave/config/plugins/lvms.yaml || : + rm -f /opt/enclave/config/plugins/odf.yaml || : + rm -f /opt/enclave/config/plugins/osac.yaml || : + rm -f /opt/enclave/config/plugins/rhbk.yaml || : + rm -f /opt/enclave/config/plugins/vast-csi.yaml || : + rm -rf /opt/enclave/.local || : + rm -rf /opt/enclave/.cache || : + rm -rf /opt/enclave/collections || : + rmdir /opt/enclave/config/plugins /opt/enclave/config /opt/enclave 2>/dev/null || : fi %files +%license LICENSE +%doc README.md /opt/enclave %changelog +* Thu Jul 31 2026 Ricardo Piccoli - 0.1.0-1 +- Move build scripts from hack/ to scripts/ +- Add %license and %doc directives +- Guard scriptlets with || : for safety +- Add GitHub Actions workflow for RPM build + * Tue Jul 07 2026 Ricardo Piccoli - 0.1.0-1 -- Initial RPM packaging with Mock-based build system +- Initial RPM packaging From 1ac14e10dcf8f7191036a512caad0ce5233cfcb1 Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Fri, 31 Jul 2026 11:34:34 +0200 Subject: [PATCH 7/8] address RPM review findings: robust version parsing, BuildRequires, dnf fix - Use python3 tomllib for version extraction instead of fragile grep/sed - Add BuildRequires for tar and gzip (needed by %setup in minimal chroots) - Document the --define "enclave_version" requirement in the spec - Fix dnf install to use -q instead of suppressing all output including errors - Add comment about reviewing exclusion list when adding new repo directories Assisted-by: Claude Code Signed-off-by: Riccardo Piccoli --- .github/workflows/build-rpm.yml | 4 ++-- scripts/rpm/build-rpm.sh | 4 ++-- scripts/rpm/enclave.spec | 7 ++++++- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build-rpm.yml b/.github/workflows/build-rpm.yml index 24a1c946..7e72be69 100644 --- a/.github/workflows/build-rpm.yml +++ b/.github/workflows/build-rpm.yml @@ -35,7 +35,7 @@ jobs: steps: - name: Install build tools - run: dnf install -y rpm-build git-core + run: dnf install -y rpm-build git-core python3 - name: Checkout code uses: actions/checkout@v4 @@ -43,7 +43,7 @@ jobs: - name: Extract version id: meta run: | - VERSION=$(grep '^version' pyproject.toml | sed 's/version = "\(.*\)"/\1/') + VERSION=$(python3 -c "import tomllib, pathlib; print(tomllib.loads(pathlib.Path('pyproject.toml').read_text())['project']['version'])") echo "version=${VERSION}" >> "$GITHUB_OUTPUT" - name: Create source tarball diff --git a/scripts/rpm/build-rpm.sh b/scripts/rpm/build-rpm.sh index c0791115..bd295d7f 100755 --- a/scripts/rpm/build-rpm.sh +++ b/scripts/rpm/build-rpm.sh @@ -6,7 +6,7 @@ REPO_DIR="$(cd "${SCRIPT_DIR}/../.." && pwd)" OUT_DIR="${REPO_DIR}/out" SPEC_FILE="${SCRIPT_DIR}/enclave.spec" -VERSION=$(grep '^version' "${REPO_DIR}/pyproject.toml" | sed 's/version = "\(.*\)"/\1/') +VERSION=$(python3 -c "import tomllib, pathlib; print(tomllib.loads(pathlib.Path('${REPO_DIR}/pyproject.toml').read_text())['project']['version'])") if [[ -z "${VERSION}" ]]; then echo "ERROR: Could not extract version from pyproject.toml" exit 1 @@ -41,7 +41,7 @@ podman run --rm \ set -euo pipefail echo ' Installing rpm-build...' - dnf install -y rpm-build 2>/dev/null >/dev/null + dnf install -y -q rpm-build RPMBUILD_DIR=\$(mktemp -d) mkdir -p \${RPMBUILD_DIR}/{SOURCES,SPECS,RPMS,BUILD,SRPMS} diff --git a/scripts/rpm/enclave.spec b/scripts/rpm/enclave.spec index 85b7891c..d2437e9d 100644 --- a/scripts/rpm/enclave.spec +++ b/scripts/rpm/enclave.spec @@ -8,6 +8,10 @@ BuildArch: noarch Source0: enclave-%{enclave_version}.tar.gz +%dnl Build with: rpmbuild --define "enclave_version X.Y.Z" -ba enclave.spec +BuildRequires: tar +BuildRequires: gzip + Requires: bind-utils Requires: curl Requires: git-core @@ -46,7 +50,8 @@ scripts, schemas, plugins, and the Python CLI source. After installing, run mkdir -p %{buildroot}/opt/enclave cp -a . %{buildroot}/opt/enclave -# Remove dev-only files that must not ship +# Remove dev-only files that must not ship — review this list when adding new +# top-level directories to the repo rm -rf %{buildroot}/opt/enclave/.github rm -rf %{buildroot}/opt/enclave/.githooks rm -rf %{buildroot}/opt/enclave/.claude From 0ceca26df3368eb0ff03904414b1b01fca340cdf Mon Sep 17 00:00:00 2001 From: Riccardo Piccoli Date: Fri, 31 Jul 2026 12:52:08 +0200 Subject: [PATCH 8/8] fix: remove unused SPEC_FILE variable from build-rpm.sh ShellCheck SC2034: SPEC_FILE was defined but never referenced. The spec file is accessed via the container volume mount instead. Assisted-by: Claude Code --- scripts/rpm/build-rpm.sh | 1 - 1 file changed, 1 deletion(-) diff --git a/scripts/rpm/build-rpm.sh b/scripts/rpm/build-rpm.sh index bd295d7f..35d5149e 100755 --- a/scripts/rpm/build-rpm.sh +++ b/scripts/rpm/build-rpm.sh @@ -4,7 +4,6 @@ set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" REPO_DIR="$(cd "${SCRIPT_DIR}/../.." && pwd)" OUT_DIR="${REPO_DIR}/out" -SPEC_FILE="${SCRIPT_DIR}/enclave.spec" VERSION=$(python3 -c "import tomllib, pathlib; print(tomllib.loads(pathlib.Path('${REPO_DIR}/pyproject.toml').read_text())['project']['version'])") if [[ -z "${VERSION}" ]]; then