From 3fe71a790e5db527e025caa41a196e4efeb6b7c8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20ROBERT?= Date: Thu, 1 Oct 2026 05:57:10 +0200 Subject: [PATCH] =?UTF-8?q?fix(appliance):=20nommer=20les=20images=20d'apr?= =?UTF-8?q?=C3=A8s=20le=20tag=20vis=C3=A9,=20pas=20la=20branche?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Les images de la 0.3.0 se sont appelées `dsoxlab-appliance-main.ova`. Le nom venait de `GITHUB_REF_NAME`, c'est-à-dire de la ref qui porte le build : sur un `push` de tag les deux coïncident, mais sur un `workflow_dispatch` — précisément la façon de rattraper un build manqué — le job tourne sur `main`. Le pire est qu'elles s'attachaient à la BONNE Release : la version était juste partout sauf dans le nom du fichier, si bien que la documentation annonçait `dsoxlab-appliance-0.3.0.ova` et que personne ne pouvait le trouver. L'étape d'attachement employait déjà `inputs.tag || github.ref_name`. C'est maintenant la seule source du nom, posée une fois en `env:` du job et employée aux trois endroits qui nommaient l'image. actionlint, zizmor et poutine sont propres. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/appliance.yml | 13 ++++++++++--- CHANGELOG.fr.md | 6 ++++++ CHANGELOG.md | 7 +++++++ 3 files changed, 23 insertions(+), 3 deletions(-) diff --git a/.github/workflows/appliance.yml b/.github/workflows/appliance.yml index 44d3473..ffbf1bd 100644 --- a/.github/workflows/appliance.yml +++ b/.github/workflows/appliance.yml @@ -55,6 +55,13 @@ jobs: # `/` has ~14 GB free on a runner, `/mnt` has ~70. Building anywhere else # dies on disk space, twenty minutes in. BUILD_DIR: /mnt/appliance + # Le nom des images vient du TAG VISÉ, et non de la ref qui porte le build. + # Sur un `push` de tag les deux coïncident ; sur un `workflow_dispatch` — + # celui qui sert à rattraper un build manqué — le job tourne sur `main`, et + # les images s'appelaient alors `dsoxlab-appliance-main.ova`. Elles + # s'attachaient pourtant à la bonne Release, si bien que la documentation + # annonçait un fichier que personne ne pouvait trouver. Vécu sur la 0.3.0. + IMAGE_REF: ${{ inputs.tag || github.ref_name }} steps: - name: Harden the runner @@ -152,7 +159,7 @@ jobs: set -euo pipefail packer init . packer validate \ - -var "image_version=${GITHUB_REF_NAME#v}" \ + -var "image_version=${IMAGE_REF#v}" \ -var "iso_url=${ISO_URL}" \ -var "iso_checksum=sha256:${ISO_SUM}" \ -var "output_directory=${BUILD_DIR}/out" . @@ -172,7 +179,7 @@ jobs: export PACKER_LOG=1 export PACKER_LOG_PATH="${BUILD_DIR}/packer.log" if ! packer build \ - -var "image_version=${GITHUB_REF_NAME#v}" \ + -var "image_version=${IMAGE_REF#v}" \ -var "iso_url=${ISO_URL}" \ -var "iso_checksum=sha256:${ISO_SUM}" \ -var "output_directory=${BUILD_DIR}/out" . ; then @@ -191,7 +198,7 @@ jobs: # Verified locally before this workflow existed: the resulting OVA imports # into VirtualBox 7.0 ("Successfully imported the appliance"), and the disk # comes back byte-identical after the conversion. - run: bash packer/faire-ova.sh "${GITHUB_REF_NAME#v}" "${BUILD_DIR}/out" + run: bash packer/faire-ova.sh "${IMAGE_REF#v}" "${BUILD_DIR}/out" - name: The OVF must validate against the DMTF schema # VirtualBox imports almost anything; VMware checks. Since the same OVA diff --git a/CHANGELOG.fr.md b/CHANGELOG.fr.md index 31ddde4..60e7c88 100644 --- a/CHANGELOG.fr.md +++ b/CHANGELOG.fr.md @@ -11,6 +11,12 @@ et le projet suit le [versionnage sémantique](https://semver.org/lang/fr/). ### Corrigé +- **Les images de l'appliance étaient nommées d'après la branche et non la + version** (build de cette release). Un `workflow_dispatch` — la façon de + rattraper un build manqué — tourne sur `main`, et les images s'appelaient donc + `dsoxlab-appliance-main.ova`. Elles s'attachaient pourtant à la bonne Release, + si bien que la documentation annonçait un fichier introuvable. Le nom vient + désormais du **tag visé**, ce que l'étape d'attachement employait déjà. - **La fabrique de l'appliance refusait au lieu de nettoyer** (build de cette release même). Debian a publié un noyau entre l'ISO et le build : l'installateur pose le sien **explicitement**, donc `apt-get autoremove` n'y touche jamais, et diff --git a/CHANGELOG.md b/CHANGELOG.md index f9e87c4..0cfc1ea 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed +- **The appliance images were named after the branch, not the version** (build of + this release). A `workflow_dispatch` — the way a missed build is caught up — + runs on `main`, and the images were therefore called + `dsoxlab-appliance-main.ova`. They attached to the right Release all the same, + so the documentation announced a file nobody could find. The name now comes + from the **tag being targeted**, which is also what the attach step already + used. - **The appliance build refused instead of cleaning up** (build of this very release). Debian published a kernel between the ISO and the build: the installer lays down its own **explicitly**, so `apt-get autoremove` never