From 5af33e9128598ecc5f5cec8eb328f34c464b47f7 Mon Sep 17 00:00:00 2001 From: Florian Weber Date: Wed, 12 Aug 2026 13:23:07 +0200 Subject: [PATCH] Update Helm chart paths in workflows and documentation to avoid ambiguity in Gitea's package registry --- .gitea/workflows/preflight.yaml | 4 ++-- .gitea/workflows/release-chart.yaml | 12 +++++++++--- README.md | 2 +- charts/aptly/README.md | 4 ++-- pubkeys/README.md | 21 +++++++++++---------- 5 files changed, 25 insertions(+), 18 deletions(-) diff --git a/.gitea/workflows/preflight.yaml b/.gitea/workflows/preflight.yaml index 19dae2b..856490b 100644 --- a/.gitea/workflows/preflight.yaml +++ b/.gitea/workflows/preflight.yaml @@ -82,10 +82,10 @@ jobs: - name: Package and push a throwaway chart version run: | helm package charts/aptly --version 0.0.0-preflight --app-version preflight - helm push aptly-0.0.0-preflight.tgz oci://git.morlana.online/f.weber + helm push aptly-0.0.0-preflight.tgz oci://git.morlana.online/f.weber/charts - name: Verify it is pullable run: | - helm show chart oci://git.morlana.online/f.weber/aptly --version 0.0.0-preflight + helm show chart oci://git.morlana.online/f.weber/charts/aptly --version 0.0.0-preflight issues-api: runs-on: ubuntu-22.04 diff --git a/.gitea/workflows/release-chart.yaml b/.gitea/workflows/release-chart.yaml index 387a3dd..062fb42 100644 --- a/.gitea/workflows/release-chart.yaml +++ b/.gitea/workflows/release-chart.yaml @@ -8,6 +8,12 @@ name: Release chart # metadata bookstack-chart uses: Helm rewrites `+` to `_` on OCI push (and # back on pull), which breaks listing in some third-party tooling (e.g. # Rancher). The aptly version lives in appVersion instead. +# +# The chart is pushed under f.weber/charts/aptly, NOT f.weber/aptly: Gitea's +# package registry stores both container images and Helm OCI charts as +# generic OCI artifacts, and a chart sharing the exact repository path with +# the container image of the same name makes the package listing/type +# ambiguous. A distinct `charts/` path keeps the two package kinds apart. on: push: tags: @@ -43,7 +49,7 @@ jobs: - name: Idempotency check — refuse to overwrite an existing chart version run: | - if helm show chart "oci://git.morlana.online/f.weber/aptly" --version "${{ steps.version.outputs.version }}" >/dev/null 2>&1; then + if helm show chart "oci://git.morlana.online/f.weber/charts/aptly" --version "${{ steps.version.outputs.version }}" >/dev/null 2>&1; then echo "::error::chart version ${{ steps.version.outputs.version }} already exists in the registry. Bump the version and re-tag — this workflow never overwrites a published chart." exit 1 fi @@ -80,7 +86,7 @@ jobs: run: | echo "${{ secrets.REGISTRY_TOKEN }}" | helm registry login git.morlana.online \ --username "${{ secrets.REGISTRY_USER }}" --password-stdin - helm push "aptly-${{ steps.version.outputs.version }}.tgz" oci://git.morlana.online/f.weber + helm push "aptly-${{ steps.version.outputs.version }}.tgz" oci://git.morlana.online/f.weber/charts - name: Create Gitea release with chart artifacts uses: softprops/action-gh-release@v2 @@ -88,7 +94,7 @@ jobs: tag_name: ${{ gitea.ref_name }} name: "aptly chart ${{ steps.version.outputs.version }}" body: | - `helm pull oci://git.morlana.online/f.weber/aptly --version ${{ steps.version.outputs.version }}` + `helm pull oci://git.morlana.online/f.weber/charts/aptly --version ${{ steps.version.outputs.version }}` files: | aptly-${{ steps.version.outputs.version }}.tgz aptly-${{ steps.version.outputs.version }}.tgz.prov diff --git a/README.md b/README.md index 46d4759..1061dd0 100644 --- a/README.md +++ b/README.md @@ -27,7 +27,7 @@ curl http://localhost:8080/api/ready Details and the production path: [docs/quickstart-compose.md](docs/quickstart-compose.md). ```bash -helm install aptly oci://git.morlana.online/f.weber/aptly --version +helm install aptly oci://git.morlana.online/f.weber/charts/aptly --version ``` Details: [docs/quickstart-helm.md](docs/quickstart-helm.md). diff --git a/charts/aptly/README.md b/charts/aptly/README.md index e650ab5..56ac8f5 100644 --- a/charts/aptly/README.md +++ b/charts/aptly/README.md @@ -8,7 +8,7 @@ no library-chart dependency, no concepts to learn beyond aptly's and Kubernetes' ## TL;DR ```bash -helm install my-aptly oci://git.morlana.online/f.weber/aptly --version +helm install my-aptly oci://git.morlana.online/f.weber/charts/aptly --version ``` ## Introduction @@ -45,7 +45,7 @@ Three things this chart is built around: ## Installing the chart ```bash -helm install my-aptly oci://git.morlana.online/f.weber/aptly --version \ +helm install my-aptly oci://git.morlana.online/f.weber/charts/aptly --version \ --set ingress.enabled=true \ --set ingress.repo.host=apt.example.com ``` diff --git a/pubkeys/README.md b/pubkeys/README.md index 4be4a30..ba2737c 100644 --- a/pubkeys/README.md +++ b/pubkeys/README.md @@ -1,11 +1,13 @@ # Public keys -## Chart signing key (needed, not yet set up) +## Chart signing key `.gitea/workflows/release-chart.yaml` runs `helm package --sign` to produce a -`.tgz.prov` file for every chart release, and `charts/aptly/Chart.yaml` is meant to -carry an `artifacthub.io/signKey` annotation pointing at the public half of that -key (both are currently commented out / referencing a placeholder — see below). +`.tgz.prov` file for every chart release, and `charts/aptly/Chart.yaml` carries an +`artifacthub.io/signKey` annotation pointing at `chart-signing.asc` in this +directory (fingerprint `FC35C0FAA26605C4C21C7BBFBF43884145E5AA94`). The matching +private key is stored as the `GPG_PRIVATE_KEY`/`GPG_PASSPHRASE`/`GPG_KEY_ID` +secrets in this repo's Gitea settings. **This key must NOT be Ed25519/EdDSA.** Helm's chart signing is built on the deprecated `golang.org/x/crypto/openpgp` library, which cannot read Ed25519 keys at @@ -25,7 +27,7 @@ Ed25519 — see [docs/packaging.md](../docs/packaging.md#gpg) — just not for `helm package --sign`. This repo therefore needs its own, separate, RSA key dedicated to chart-package signing. -### Generating it +### Generating a replacement (e.g. on rotation) Run this yourself (locally, not in CI) so the private key material never has to pass through anything but your own machine and the Gitea secrets store: @@ -44,16 +46,15 @@ gpg --armor --export > pubkeys/chart-signing.asc gpg --armor --export-secret-keys # -> paste as GPG_PRIVATE_KEY ``` -Then, in the repo's Gitea settings: +Then, in the repo's Gitea settings, update: - Secret **`GPG_PRIVATE_KEY`** — the armored output of the last command above - Secret **`GPG_PASSPHRASE`** — whatever passphrase you set (empty string if none) - Secret **`GPG_KEY_ID`** — the key ID or fingerprint from `gpg --list-secret-keys` -Commit `pubkeys/chart-signing.asc`, then uncomment the `artifacthub.io/signKey` -block in `charts/aptly/Chart.yaml` with the real fingerprint, and uncomment -`pubkeys/chart-signing.asc` in `release-chart.yaml`'s release-assets step. +Commit the new `pubkeys/chart-signing.asc` over the old one, and update the +fingerprint in the `artifacthub.io/signKey` annotation in `charts/aptly/Chart.yaml`. -### Verifying a downloaded chart (once the key exists) +### Verifying a downloaded chart ```bash gpg --import pubkeys/chart-signing.asc