Update Helm chart paths in workflows and documentation to avoid ambiguity in Gitea's package registry
CI / lint (push) Failing after 3s
CI / smoke-test (push) Failing after 5s
Release chart / release (push) Successful in 6s

This commit is contained in:
2026-08-12 13:23:07 +02:00
parent 103ad311b7
commit 5af33e9128
5 changed files with 25 additions and 18 deletions
+2 -2
View File
@@ -82,10 +82,10 @@ jobs:
- name: Package and push a throwaway chart version
run: |
helm package charts/aptly --version 0.0.0-preflight --app-version preflight
helm push aptly-0.0.0-preflight.tgz oci://git.morlana.online/f.weber
helm push aptly-0.0.0-preflight.tgz oci://git.morlana.online/f.weber/charts
- name: Verify it is pullable
run: |
helm show chart oci://git.morlana.online/f.weber/aptly --version 0.0.0-preflight
helm show chart oci://git.morlana.online/f.weber/charts/aptly --version 0.0.0-preflight
issues-api:
runs-on: ubuntu-22.04
+9 -3
View File
@@ -8,6 +8,12 @@ name: Release chart
# metadata bookstack-chart uses: Helm rewrites `+` to `_` on OCI push (and
# back on pull), which breaks listing in some third-party tooling (e.g.
# Rancher). The aptly version lives in appVersion instead.
#
# The chart is pushed under f.weber/charts/aptly, NOT f.weber/aptly: Gitea's
# package registry stores both container images and Helm OCI charts as
# generic OCI artifacts, and a chart sharing the exact repository path with
# the container image of the same name makes the package listing/type
# ambiguous. A distinct `charts/` path keeps the two package kinds apart.
on:
push:
tags:
@@ -43,7 +49,7 @@ jobs:
- name: Idempotency check — refuse to overwrite an existing chart version
run: |
if helm show chart "oci://git.morlana.online/f.weber/aptly" --version "${{ steps.version.outputs.version }}" >/dev/null 2>&1; then
if helm show chart "oci://git.morlana.online/f.weber/charts/aptly" --version "${{ steps.version.outputs.version }}" >/dev/null 2>&1; then
echo "::error::chart version ${{ steps.version.outputs.version }} already exists in the registry. Bump the version and re-tag — this workflow never overwrites a published chart."
exit 1
fi
@@ -80,7 +86,7 @@ jobs:
run: |
echo "${{ secrets.REGISTRY_TOKEN }}" | helm registry login git.morlana.online \
--username "${{ secrets.REGISTRY_USER }}" --password-stdin
helm push "aptly-${{ steps.version.outputs.version }}.tgz" oci://git.morlana.online/f.weber
helm push "aptly-${{ steps.version.outputs.version }}.tgz" oci://git.morlana.online/f.weber/charts
- name: Create Gitea release with chart artifacts
uses: softprops/action-gh-release@v2
@@ -88,7 +94,7 @@ jobs:
tag_name: ${{ gitea.ref_name }}
name: "aptly chart ${{ steps.version.outputs.version }}"
body: |
`helm pull oci://git.morlana.online/f.weber/aptly --version ${{ steps.version.outputs.version }}`
`helm pull oci://git.morlana.online/f.weber/charts/aptly --version ${{ steps.version.outputs.version }}`
files: |
aptly-${{ steps.version.outputs.version }}.tgz
aptly-${{ steps.version.outputs.version }}.tgz.prov
+1 -1
View File
@@ -27,7 +27,7 @@ curl http://localhost:8080/api/ready
Details and the production path: [docs/quickstart-compose.md](docs/quickstart-compose.md).
```bash
helm install aptly oci://git.morlana.online/f.weber/aptly --version <version>
helm install aptly oci://git.morlana.online/f.weber/charts/aptly --version <version>
```
Details: [docs/quickstart-helm.md](docs/quickstart-helm.md).
+2 -2
View File
@@ -8,7 +8,7 @@ no library-chart dependency, no concepts to learn beyond aptly's and Kubernetes'
## TL;DR
```bash
helm install my-aptly oci://git.morlana.online/f.weber/aptly --version <version>
helm install my-aptly oci://git.morlana.online/f.weber/charts/aptly --version <version>
```
## Introduction
@@ -45,7 +45,7 @@ Three things this chart is built around:
## Installing the chart
```bash
helm install my-aptly oci://git.morlana.online/f.weber/aptly --version <version> \
helm install my-aptly oci://git.morlana.online/f.weber/charts/aptly --version <version> \
--set ingress.enabled=true \
--set ingress.repo.host=apt.example.com
```
+11 -10
View File
@@ -1,11 +1,13 @@
# Public keys
## Chart signing key (needed, not yet set up)
## Chart signing key
`.gitea/workflows/release-chart.yaml` runs `helm package --sign` to produce a
`.tgz.prov` file for every chart release, and `charts/aptly/Chart.yaml` is meant to
carry an `artifacthub.io/signKey` annotation pointing at the public half of that
key (both are currently commented out / referencing a placeholder — see below).
`.tgz.prov` file for every chart release, and `charts/aptly/Chart.yaml` carries an
`artifacthub.io/signKey` annotation pointing at `chart-signing.asc` in this
directory (fingerprint `FC35C0FAA26605C4C21C7BBFBF43884145E5AA94`). The matching
private key is stored as the `GPG_PRIVATE_KEY`/`GPG_PASSPHRASE`/`GPG_KEY_ID`
secrets in this repo's Gitea settings.
**This key must NOT be Ed25519/EdDSA.** Helm's chart signing is built on the
deprecated `golang.org/x/crypto/openpgp` library, which cannot read Ed25519 keys at
@@ -25,7 +27,7 @@ Ed25519 — see [docs/packaging.md](../docs/packaging.md#gpg) — just not for
`helm package --sign`. This repo therefore needs its own, separate, RSA key
dedicated to chart-package signing.
### Generating it
### Generating a replacement (e.g. on rotation)
Run this yourself (locally, not in CI) so the private key material never has to
pass through anything but your own machine and the Gitea secrets store:
@@ -44,16 +46,15 @@ gpg --armor --export <key-id> > pubkeys/chart-signing.asc
gpg --armor --export-secret-keys <key-id> # -> paste as GPG_PRIVATE_KEY
```
Then, in the repo's Gitea settings:
Then, in the repo's Gitea settings, update:
- Secret **`GPG_PRIVATE_KEY`** — the armored output of the last command above
- Secret **`GPG_PASSPHRASE`** — whatever passphrase you set (empty string if none)
- Secret **`GPG_KEY_ID`** — the key ID or fingerprint from `gpg --list-secret-keys`
Commit `pubkeys/chart-signing.asc`, then uncomment the `artifacthub.io/signKey`
block in `charts/aptly/Chart.yaml` with the real fingerprint, and uncomment
`pubkeys/chart-signing.asc` in `release-chart.yaml`'s release-assets step.
Commit the new `pubkeys/chart-signing.asc` over the old one, and update the
fingerprint in the `artifacthub.io/signKey` annotation in `charts/aptly/Chart.yaml`.
### Verifying a downloaded chart (once the key exists)
### Verifying a downloaded chart
```bash
gpg --import pubkeys/chart-signing.asc