Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/build-and-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ jobs:
arch: arm64
runs-on: ${{ matrix.runner }}
timeout-minutes: 30
env:
APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/

steps:
- name: Checkout repository
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/build-oci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ jobs:
runs-on: ${{ matrix.runner }}
# NOTE: 90 min covers the qemu lanes; native lanes finish well under 30.
timeout-minutes: 90
env:
APT_MIRROR: http://azure.archive.ubuntu.com/ubuntu/

steps:
- name: Checkout repository
Expand All @@ -58,7 +60,7 @@ jobs:
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: images-out/
key: images-${{ matrix.arch }}-${{ hashFiles('images/Dockerfile.*', 'hack/bread-warning.sh', 'hack/banner.txt', 'hack/lazy-apt.sh', 'hack/build_image.sh', '.stamp/binaries') }}
key: images-${{ matrix.arch }}-${{ hashFiles('images/Dockerfile.*', 'hack/bread-warning.sh', 'hack/banner.txt', 'hack/lazy-apt.sh', 'hack/apt-mirror.sh', 'hack/build_image.sh', '.stamp/binaries') }}

- name: Set up qemu (emulated arches only)
if: matrix.qemu && steps.images-cache.outputs.cache-hit != 'true'
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,7 @@ spread-bread/
check_base.sh # detect upstream ubuntu base digest drift; rewrite @sha256 pins
inline_scripts.rb # splice scripts/*.sh into yaml templates
tar-shim.sh # image /bin/tar; routes extraction to bsdtar where gnu tar is broken
apt-mirror.sh # build-time apt mirror override, bind-mounted into image builds by ci
scripts/ # allocate / discard scripts, one pair per flavour
images/ # one Dockerfile per (flavour, ubuntu version)
templates/ # yaml templates with `source scripts/...` markers
Expand Down
30 changes: 30 additions & 0 deletions hack/apt-mirror.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
#!/bin/sh -e
# bread-apt-mirror: build-time apt mirror override for docker build, which
# otherwise pulls from archive.ubuntu.com; on ci that is the slow path, while
# the runner itself uses the azure mirror. Same mirror, same failover shape:
# https://github.com/actions/runner-images/blob/main/images/ubuntu/scripts/build/configure-apt-sources.sh
# https://manpages.ubuntu.com/manpages/noble/en/man1/apt-transport-mirror.1.html
#
# Writes into the scratch dir $1 copies of the apt sources with the archive
# uris pointed at a mirrorlist ($APT_MIRROR first, archive.ubuntu.com second)
# plus an apt.conf that makes apt read those copies; the build exports
# APT_CONFIG=<dir>/apt.conf. The image's own /etc/apt is never touched.
# Without APT_MIRROR the apt.conf is empty and apt behaves as stock.
#
# Usage: bread-apt-mirror <scratch-dir>

dir="${1:?scratch dir required}"
mkdir -p "$dir/sources.list.d"
: > "$dir/apt.conf"
[ -n "${APT_MIRROR:-}" ] || exit 0

list="$dir/mirrors.txt"
printf '%s\tpriority:1\nhttp://archive.ubuntu.com/ubuntu/\tpriority:2\n' "$APT_MIRROR" > "$list"

: > "$dir/sources.list"
for f in /etc/apt/sources.list /etc/apt/sources.list.d/*.list /etc/apt/sources.list.d/*.sources; do
[ -f "$f" ] || continue
sed "s|http://archive\.ubuntu\.com/ubuntu/|mirror+file:$list|g" "$f" > "$dir/${f#/etc/apt/}"
done

printf 'Dir::Etc::sourcelist "%s/sources.list";\nDir::Etc::sourceparts "%s/sources.list.d";\n' "$dir" "$dir" > "$dir/apt.conf"
2 changes: 2 additions & 0 deletions hack/build_image.sh
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ case "$flavour" in
bread)
docker build \
--tag "bread:$ver-$arch" \
--build-arg "APT_MIRROR=${APT_MIRROR:-}" \
--file "images/Dockerfile.bread-$ver" \
--platform "linux/$arch" \
.
Expand All @@ -38,6 +39,7 @@ case "$flavour" in
docker build \
--tag "bread-chisel-releases:$ver-$arch" \
--build-arg "BASE_TAG=$ver-$arch" \
--build-arg "APT_MIRROR=${APT_MIRROR:-}" \
--build-arg "BUILD_ARCH=$arch" \
--file "images/Dockerfile.bread-chisel-releases-$ver" \
--platform "linux/$arch" \
Expand Down
2 changes: 2 additions & 0 deletions hack/hash_inputs.sh
Original file line number Diff line number Diff line change
Expand Up @@ -40,12 +40,14 @@ case "$flavour" in
"hack/bread-warning.sh"
"hack/banner.txt"
"hack/tar-shim.sh"
"hack/apt-mirror.sh"
)
;;
bread-chisel-releases)
inputs=(
"images/Dockerfile.bread-chisel-releases-$ver"
"hack/lazy-apt.sh"
"hack/apt-mirror.sh"
".stamp/bread-$ver-$arch"
".stamp/binaries"
)
Expand Down
9 changes: 7 additions & 2 deletions images/Dockerfile.bread-22.04
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,19 @@

FROM docker.io/library/ubuntu:22.04@sha256:829f6df217bcbae2b371026e81711d1a787c61b2967ad09d015063663ebafbf7

ARG APT_MIRROR=

# Skip man/doc/info install for every subsequent package -- dpkg's man-db
# trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in
# the image fs, so the bread-chisel-releases install inherits the exclusion.
RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
> /etc/dpkg/dpkg.cfg.d/01-nodoc && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \
mkdir /var/run/sshd || true && \
mkdir -p /var/run/sshd && \
echo 'root:bread' | chpasswd && \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
Expand Down
9 changes: 7 additions & 2 deletions images/Dockerfile.bread-24.04
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,19 @@

FROM docker.io/library/ubuntu:24.04@sha256:224a1869083a311ef3f13648a154ba79832fbef6364d31493642ca03082da254

ARG APT_MIRROR=

# Skip man/doc/info install for every subsequent package -- dpkg's man-db
# trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in
# the image fs, so the bread-chisel-releases install inherits the exclusion.
RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
> /etc/dpkg/dpkg.cfg.d/01-nodoc && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \
mkdir /var/run/sshd || true && \
mkdir -p /var/run/sshd && \
echo 'root:bread' | chpasswd && \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
Expand Down
9 changes: 7 additions & 2 deletions images/Dockerfile.bread-25.10
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,19 @@

FROM docker.io/library/ubuntu:25.10@sha256:7cc5e35f6567ee8c66d2abb4aab0fd866669e6207c237c3a8f0947a5c7f17092

ARG APT_MIRROR=

# Skip man/doc/info install for every subsequent package -- dpkg's man-db
# trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in
# the image fs, so the bread-chisel-releases install inherits the exclusion.
RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
> /etc/dpkg/dpkg.cfg.d/01-nodoc && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \
mkdir /var/run/sshd || true && \
mkdir -p /var/run/sshd && \
echo 'root:bread' | chpasswd && \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
Expand Down
9 changes: 7 additions & 2 deletions images/Dockerfile.bread-26.04
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,19 @@

FROM docker.io/library/ubuntu:26.04@sha256:513c074113a871b51a8d16ab445c88779d6452d937a164fb5cc479f32668a41d

ARG APT_MIRROR=

# Skip man/doc/info install for every subsequent package -- dpkg's man-db
# trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in
# the image fs, so the bread-chisel-releases install inherits the exclusion.
RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
> /etc/dpkg/dpkg.cfg.d/01-nodoc && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \
mkdir /var/run/sshd || true && \
mkdir -p /var/run/sshd && \
echo 'root:bread' | chpasswd && \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
Expand Down
9 changes: 7 additions & 2 deletions images/Dockerfile.bread-26.10
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,19 @@

FROM docker.io/library/ubuntu:26.10@sha256:49077a16b772f8bc6e6f160ad2bfc218919f3455037387ed19a8309174328603

ARG APT_MIRROR=

# Skip man/doc/info install for every subsequent package -- dpkg's man-db
# trigger is a major cost under qemu emulation (s390x / ppc64le). Persists in
# the image fs, so the bread-chisel-releases install inherits the exclusion.
RUN printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
printf 'path-exclude /usr/share/man/*\npath-exclude /usr/share/doc/*\npath-exclude /usr/share/info/*\n' \
> /etc/dpkg/dpkg.cfg.d/01-nodoc && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends openssh-server libarchive-tools && \
mkdir /var/run/sshd || true && \
mkdir -p /var/run/sshd && \
echo 'root:bread' | chpasswd && \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config && \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
Expand Down
6 changes: 5 additions & 1 deletion images/Dockerfile.bread-chisel-releases-22.04
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,12 @@ ARG BASE_TAG=22.04-amd64
ARG BUILD_ARCH=amd64
FROM bread:${BASE_TAG}
ARG BUILD_ARCH
ARG APT_MIRROR=

RUN apt-get update && \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
curl wget git jq file sudo tree \
skopeo iproute2 && \
Expand Down
6 changes: 5 additions & 1 deletion images/Dockerfile.bread-chisel-releases-24.04
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,12 @@ ARG BASE_TAG=24.04-amd64
ARG BUILD_ARCH=amd64
FROM bread:${BASE_TAG}
ARG BUILD_ARCH
ARG APT_MIRROR=

RUN apt-get update && \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
curl wget git jq file sudo tree \
skopeo iproute2 && \
Expand Down
6 changes: 5 additions & 1 deletion images/Dockerfile.bread-chisel-releases-25.10
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,12 @@ ARG BASE_TAG=25.10-amd64
ARG BUILD_ARCH=amd64
FROM bread:${BASE_TAG}
ARG BUILD_ARCH
ARG APT_MIRROR=

RUN apt-get update && \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
curl wget git jq file sudo tree \
skopeo iproute2 && \
Expand Down
6 changes: 5 additions & 1 deletion images/Dockerfile.bread-chisel-releases-26.04
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,12 @@ ARG BASE_TAG=26.04-amd64
ARG BUILD_ARCH=amd64
FROM bread:${BASE_TAG}
ARG BUILD_ARCH
ARG APT_MIRROR=

RUN apt-get update && \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
curl wget git jq file sudo tree \
skopeo iproute2 && \
Expand Down
6 changes: 5 additions & 1 deletion images/Dockerfile.bread-chisel-releases-26.10
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,12 @@ ARG BASE_TAG=26.10-amd64
ARG BUILD_ARCH=amd64
FROM bread:${BASE_TAG}
ARG BUILD_ARCH
ARG APT_MIRROR=

RUN apt-get update && \
RUN --mount=type=bind,source=hack/apt-mirror.sh,target=/usr/local/bin/bread-apt-mirror \
--mount=type=tmpfs,target=/run/apt-mirror \
export APT_CONFIG=/run/apt-mirror/apt.conf && bread-apt-mirror /run/apt-mirror && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
curl wget git jq file sudo tree \
skopeo iproute2 && \
Expand Down