From 7031576f63d26fce51b4dca3e284fc8aacc9dd9f Mon Sep 17 00:00:00 2001 From: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Date: Fri, 12 Jun 2020 12:02:20 +0200 Subject: [PATCH] Create a Krill DEB package via GH actions: - Assumes that the target system has ca-certificates installed already. - Vendor OpenSSL to support Ubuntu 16.04 which only has OpenSSL 1.0.0. - Use an Ubuntu 16.04 compatible version of libgcc1 (don't use cargo-deb $auto depends as the GH 16.04 runner has a much newer libgcc1 package than stock Ubuntu 16.04). - Use GH caching to avoid repeat compilation of unchanging cargo deb and krill dependencies. - Sanity check the created DEB in targeted O/S versions. --- .github/workflows/ci.yml | 6 ++- .github/workflows/e2e.yml | 2 + .github/workflows/pkg.yml | 93 +++++++++++++++++++++++++++++++++++++++ Cargo.lock | 10 +++++ Cargo.toml | 18 +++++++- 5 files changed, 127 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/pkg.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 413bf728..f1f660e8 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,6 +4,8 @@ on: paths-ignore: - '.dockerignore' - '.github/workflow/e2e.yml' + - '.github/workflow/pkg.yml' + - '.github/workflow/e2e test cache rebuild.yml' - 'Changelog.md' - 'Dockerfile' - 'doc/**' @@ -16,6 +18,8 @@ on: paths-ignore: - '.dockerignore' - '.github/workflow/e2e.yml' + - '.github/workflow/pkg.yml' + - '.github/workflow/e2e test cache rebuild.yml' - 'Changelog.md' - 'Dockerfile' - 'doc/**' @@ -39,4 +43,4 @@ jobs: with: rust-version: ${{ matrix.rust }} - run: cargo build --verbose - - run: cargo test --verbose + - run: cargo test --verbose \ No newline at end of file diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 12b62efa..39b89968 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -24,6 +24,8 @@ on: paths: - '**' - '!.github/workflows/ci.yml' + - '!.github/workflows/e2e test cache rebuild.yml' + - '!.github/workflows/pkg.yml' - '!Changelog.md' - '!doc/**' - '!LICENSE' diff --git a/.github/workflows/pkg.yml b/.github/workflows/pkg.yml new file mode 100644 index 00000000..a0f89de0 --- /dev/null +++ b/.github/workflows/pkg.yml @@ -0,0 +1,93 @@ +name: Packaging +on: + push: + paths-ignore: + - '.dockerignore' + - '.github/workflow/pkg.yml' + - 'Changelog.md' + - 'Dockerfile' + - 'doc/**' + - 'docker/**' + - 'LICENSE' + - 'README.md' + - 'tests/e2e/**' + # Hmm, annoying, do we really have to duplicate this? + pull_request: + paths-ignore: + - '.dockerignore' + - '.github/workflow/pkg.yml' + - 'Changelog.md' + - 'Dockerfile' + - 'doc/**' + - 'docker/**' + - 'LICENSE' + - 'README.md' + - 'tests/e2e/**' + +jobs: + deb-pkg: + env: + CARGO_DEB_VER: 1.23.1 + name: deb-pkg + runs-on: [ubuntu-16.04] + steps: + - name: Checkout repository + uses: actions/checkout@v1 + + - name: Install Rust + uses: hecrj/setup-rust-action@v1 + with: + rust-version: stable + + - name: Cache Dot Cargo + uses: actions/cache@v2 + with: + path: | + ~/.cargo/registry + ~/.cargo/git + target + key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }} + + - name: Cache Cargo Deb binary + id: cache-cargo-deb + uses: actions/cache@v2 + with: + path: ~/.cargo/bin/cargo-deb + key: ${{ runner.os }}-${{ env.CARGO_DEB_VER }}-cargo-deb + + - name: Install Cargo Deb + if: steps.cache-cargo-deb.outputs.cache-hit != 'true' + run: | + cargo install cargo-deb --version=$CARGO_DEB_VER + + - name: Create the package + run: | + cargo deb --verbose + + - name: Upload artifacts + uses: actions/upload-artifact@v2 + with: + name: debian-package + path: target/debian/*.deb + + deb-pkg-test: + name: test + needs: deb-pkg + runs-on: ${{ matrix.os }} + strategy: + matrix: + os: [ubuntu-16.04, ubuntu-18.04, ubuntu-20.04] + steps: + - name: Download DEB package + uses: actions/download-artifact@v2 + + - name: Install DEB package + run: | + sudo apt-get -y install ./debian-package/*.deb + shell: bash + + - name: Test installed binaries + run: | + krillc --version + krill --version + shell: bash \ No newline at end of file diff --git a/Cargo.lock b/Cargo.lock index f8ee4aeb..368adefd 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -896,6 +896,15 @@ version = "0.1.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "77af24da69f9d9341038eba93a073b1fdaaa1b788221b00a69bce9e762cb32de" +[[package]] +name = "openssl-src" +version = "111.10.0+1.1.1g" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "47cd4a96d49c3abf4cac8e8a80cba998a030c75608f158fb1c5f609772f265e6" +dependencies = [ + "cc", +] + [[package]] name = "openssl-sys" version = "0.9.54" @@ -905,6 +914,7 @@ dependencies = [ "autocfg 1.0.0", "cc", "libc", + "openssl-src", "pkg-config", "vcpkg", ] diff --git a/Cargo.toml b/Cargo.toml index 7b8d64e1..5bb3c5c4 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -4,6 +4,7 @@ version = "0.6.3" edition = "2018" authors = [ "The NLnet Labs RPKI team " ] description = "Resource Public Key Infrastructure (RPKI) daemon" +homepage = "https://www.nlnetlabs.nl/projects/rpki/krill/" repository = "https://github.com/NLnetLabs/krill" keywords = ["rpki", "routing-security", "bgp"] readme = "README.md" @@ -45,7 +46,22 @@ syslog = "^4.0" [build-dependencies] ignore = "^0.4" - [features] default = [] extra-debug = [ "rpki/extra-debug" ] +deb-pkg = [ "openssl/vendored" ] + +[package.metadata.deb] +features = [ "deb-pkg" ] +priority = "extra" +section = "net" +depends = "libc6 (>= 2.23), libgcc1 (>= 1:6.0.1)" +extended-description = """\ +Krill is a free, open source RPKI Certificate Authority that lets you run +delegated RPKI under one or multiple Regional Internet Registries (RIRs). +Through its built-in publication server, Krill can publish Route Origin +Authorisations (ROAs) on your own servers or with a third party. + +This package contains the krill daemon and krillc CLI binaries. + +For more information visit https://rpki.readthedocs.io/en/latest/krill/."""