Skip to content

build: KEEL_APT_TRACK picks the Keel track; the plan drops tklbam, hubdns and the release meta package - #32

Merged
marcos-mendez merged 2 commits into
19.xfrom
feat/keel-apt-track
Oct 2, 2026
Merged

marcos-mendez merged 2 commits into
19.xfrom
feat/keel-apt-track

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Summary

  • The bootstrap gets the Keel archive. Since fix: images take packages from Debian and the Keel repository only #30 a Keel image installs from Debian and the Keel archive only, but the bootstrap had no Keel source, so the plan could not install keel-archive-keyring, inithooks and the other Keel packages from it. conf/bootstrap_apt now writes keel.sources into the bootstrap, naming the armored public key mk/turnkey.mk copies in from the new keys/keel-archive-keyring.asc (the key the archive publishes at its root). The package later installs the same key as .gpg and the overlay replaces the file; the conf script removes the bootstrap's copy.
  • KEEL_APT_TRACK (conf variable, default stable): testing enables trixie-testing in the bootstrap, so the build installs from the testing track, and conf/turnkey.d/keel-apt makes the image follow it (the overlay's stanza turned on). Any other value stops the build. This is what step 4 of the attended release needs: images built from trixie-testing.
  • Plan: tklbam, hubdns, webmin-tklbam leave plans/turnkey/base (Keel Backup, decision 0040; Keel Cloud); that also drops turnkey-pypy2 and py3curl-wrapper, which nothing else wanted (checked with apt-cache rdepends against TurnKey's archive).
  • No release meta package: mk/turnkey.mk no longer runs make-release-deb.py (turnkey-<app>-<version>); keel-core is the meta package (decision 0047). /etc/turnkey_version is still written (decision 0014). Note common#5 (/etc/keel_version) is still open.

Tests

tests/apt-sources.bats: 44 pass locally. New: the bootstrap writes keel.sources (stable on, testing off, key path, and the key in keys/ is AD0964BE…3180); the track decision for unset/stable/testing/other; the conf script on the default track (file untouched, key copy removed), on testing (only the stanza's Enabled changes, apt would fetch both suites), and its refusals; the plan has none of the five packages and the makefile no make-release-deb.

For the maintainer

  • An image built with KEEL_APT_TRACK=testing follows the testing track once installed. Say if a testing-channel image should rather stay on stable.
  • keys/keel-archive-keyring.asc is the public key only, the same file the archive serves.

navigator added 2 commits October 2, 2026 18:14
…backup and DNS

A Keel image installs from Debian and the Keel archive alone since #30,
but the bootstrap had no Keel source, so the plan could not install
keel-archive-keyring, inithooks and the rest from it. conf/bootstrap_apt
now writes keel.sources into the bootstrap too, naming the armored public
key mk/turnkey.mk copies in from keys/ (the key the archive publishes at
its root; the package installs the same one as a binary keyring, and the
overlay replaces the file). KEEL_APT_TRACK, a conf variable, says which
track the build installs from: stable (default) reads trixie alone,
testing also enables trixie-testing, where every package lands first, for
an image of the testing channel (handbook decision 0043). The conf script
keel-apt makes such an image follow the testing track and removes the
bootstrap's key copy; any other value stops the build in both places.

plans/turnkey/base no longer installs tklbam, hubdns and webmin-tklbam
(backup is Keel Backup, decision 0040; DNS registration is Keel Cloud),
which also drops turnkey-pypy2 and py3curl-wrapper, wanted by nothing
else. mk/turnkey.mk no longer builds fab's release meta package
(turnkey-<app>-<version>): keel-core is the meta package (decision 0047);
/etc/turnkey_version is still written (decision 0014).

tests/apt-sources.bats: the bootstrap's keel.sources, the track decision
for each value, the conf script on each track, and the plan.
@marcos-mendez
marcos-mendez merged commit ee5be5b into 19.x Oct 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant