Slight restructure
This commit is contained in:
parent
361e4a1f1e
commit
5523a823e0
2
.gitignore
vendored
2
.gitignore
vendored
@ -1,2 +1,2 @@
|
|||||||
artifacts/
|
build/artifacts/
|
||||||
secrets/
|
secrets/
|
@ -3,6 +3,14 @@
|
|||||||
set -euxo pipefail
|
set -euxo pipefail
|
||||||
|
|
||||||
mkdir -p /artifacts/dist
|
mkdir -p /artifacts/dist
|
||||||
export EPREFIX="/artifacts/dist"
|
export EPREFIX="/build/artifacts/dist"
|
||||||
|
|
||||||
emerge --sync --quiet
|
rm -f /var/db/repos/gentoo/metadata/timestamp.chk
|
||||||
|
emerge --sync --quiet
|
||||||
|
eselect profile list | grep hardened
|
||||||
|
eselect profile set default/linux/amd64/23.0/musl/hardened/selinux
|
||||||
|
|
||||||
|
mkdir -p /etc/portage/sets
|
||||||
|
cp /build/packages.txt /etc/portage/sets/halogenos
|
||||||
|
|
||||||
|
emerge @halogenos
|
1
build/packages.txt
Normal file
1
build/packages.txt
Normal file
@ -0,0 +1 @@
|
|||||||
|
app-shells/bash
|
@ -3,7 +3,6 @@ services:
|
|||||||
image: docker.io/gentoo/stage3
|
image: docker.io/gentoo/stage3
|
||||||
command: /build/build-image.sh
|
command: /build/build-image.sh
|
||||||
volumes:
|
volumes:
|
||||||
- ./artifacts:/artifacts
|
|
||||||
- ./build:/build
|
- ./build:/build
|
||||||
sign:
|
sign:
|
||||||
image: docker.io/vladgh/gpg
|
image: docker.io/vladgh/gpg
|
||||||
@ -13,11 +12,11 @@ services:
|
|||||||
- signing_key_private
|
- signing_key_private
|
||||||
- signing_key_public
|
- signing_key_public
|
||||||
volumes:
|
volumes:
|
||||||
- ./artifacts:/artifacts
|
- ./build/artifacts:/artifacts
|
||||||
serve:
|
serve:
|
||||||
image: docker.io/halverneus/static-file-server
|
image: docker.io/halverneus/static-file-server
|
||||||
volumes:
|
volumes:
|
||||||
- ./artifacts:/artifacts
|
- ./build/artifacts:/artifacts
|
||||||
|
|
||||||
secrets:
|
secrets:
|
||||||
signing_key_password:
|
signing_key_password:
|
||||||
|
Loading…
Reference in New Issue
Block a user