-
Notifications
You must be signed in to change notification settings - Fork 1.8k
packaging: add support for Opensuse Leap 15.6 and SLES 15.7 #10978
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
WalkthroughAdds OpenSUSE Leap 15.6 and SLES 15.7 packaging support: new Dockerfiles for multi-arch builds, build config targets, zypper-based repo update script, test script path for zypper, installer branch for OpenSUSE/SLES, updated repo routing, and docs table update. Minor build script tweak to derive a builder stage name from distro/version. Changes
Sequence Diagram(s)sequenceDiagram
autonumber
actor User
participant InstallScript as install.sh
participant OS as OpenSUSE/SLES Host
participant Repo as Fluent Bit Repo
User->>InstallScript: Run with RELEASE_VERSION/params
InstallScript->>OS: Detect distro (opensuse-leap|sles)
InstallScript->>OS: Import GPG key
InstallScript->>OS: Write fluent-bit.repo (baseurl,gpgkey)
InstallScript->>OS: zypper refresh
InstallScript->>Repo: Fetch metadata/RPMs
Repo-->>InstallScript: Packages/repodata
InstallScript->>OS: zypper install fluent-bit[=ZYPPER_VERSION]
OS-->>User: Installation result/version
sequenceDiagram
autonumber
participant Updater as packaging/update-repos.sh
participant ZypperUpdater as update-zypper-repo.sh
participant YumUpdater as update-yum-repo.sh
participant S3 as AWS S3
Updater->>Updater: For each RPM_REPO_PATH
alt opensuse/* or sles/*
Updater->>ZypperUpdater: Update repo (sign RPMs, createrepo_c)
opt AWS_S3_BUCKET set
ZypperUpdater->>S3: Write .repo file (baseurl,gpgkey)
end
else other RPM repos
Updater->>YumUpdater: Update repo (existing path)
end
Estimated code review effort🎯 4 (Complex) | ⏱️ ~60 minutes Suggested reviewers
Poem
Pre-merge checks and finishing touches✅ Passed checks (5 passed)
✨ Finishing touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (8)
packaging/README.md
(1 hunks)packaging/build-config.json
(1 hunks)packaging/distros/opensuse/15.6.arm64v8/Dockerfile
(1 hunks)packaging/distros/opensuse/15.6/Dockerfile
(1 hunks)packaging/distros/opensuse/Dockerfile
(1 hunks)packaging/distros/sles/Dockerfile
(1 hunks)packaging/test-release-packages.sh
(1 hunks)packaging/update-repos.sh
(1 hunks)
🔇 Additional comments (3)
packaging/distros/opensuse/15.6.arm64v8/Dockerfile (1)
12-24
: Confirm availability ofcmake3-full
.On Leap 15.x the package is usually
cmake
/cmake-full
;cmake3-full
may not exist and would break the build. Please confirm the package name and adjust if necessary (likelycmake-full
).packaging/distros/opensuse/15.6/Dockerfile (1)
7-19
: Verify thecmake3-full
dependency.Same concern as the arm64 Dockerfile: ensure
cmake3-full
exists on Leap 15.6; otherwise switch tocmake-full
to avoid install failures.packaging/distros/opensuse/Dockerfile (1)
16-28
: Please double-check thecmake3-full
install.For the generic OpenSUSE builder we also request confirmation that
cmake3-full
is present on the chosen Leap image; if not, use the availablecmake-full
package instead.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
🧹 Nitpick comments (4)
packaging/README.md (1)
40-43
: Docs update looks good; minor style nitEntries are correct. Consider dropping bold on “SLES” to match the table’s neutral style used for other distros.
packaging/test-release-packages.sh (1)
123-141
: Harden zypper invocations to avoid key promptsAdd --gpg-auto-import-keys to refresh/install to eliminate potential non-interactive key prompts on fresh images.
- sh -c "zypper --non-interactive refresh && zypper --non-interactive install gpg curl; $INSTALL_CMD && /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE" + sh -c "zypper --non-interactive --gpg-auto-import-keys refresh && zypper --non-interactive --gpg-auto-import-keys install gpg curl; $INSTALL_CMD && /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE"install.sh (2)
158-172
: Avoid non-interactive key prompts on repo refresh/installAdd --gpg-auto-import-keys to the zypper commands to ensure fully non-interactive runs across images.
- zypper --non-interactive refresh - $INSTALL_CMD_PREFIX zypper --non-interactive $ZYPPER_PARAMETERS install $INSTALL_PACKAGE_NAME$ZYPPER_VERSION + zypper --non-interactive --gpg-auto-import-keys refresh + $INSTALL_CMD_PREFIX zypper --non-interactive --gpg-auto-import-keys $ZYPPER_PARAMETERS install $INSTALL_PACKAGE_NAME$ZYPPER_VERSION
161-169
: Optional repo metadata fieldsConsider adding type=rpm-md and autorefresh=1 for clarity and default behavior parity with common SUSE repo snippets. Not required.
[fluent-bit] name = Fluent Bit baseurl = $RELEASE_URL/$SUSE_OS/$SUSE_VER gpgcheck=1 repo_gpgcheck=1 gpgkey=$RELEASE_KEY enabled=1 +type=rpm-md +autorefresh=1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (3)
install.sh
(3 hunks)packaging/README.md
(1 hunks)packaging/test-release-packages.sh
(2 hunks)
🔇 Additional comments (4)
packaging/test-release-packages.sh (1)
63-66
: Good targetsCorrect images for openSUSE Leap and SLES (BCI base). Nice fix separating Zypper-based distros.
install.sh (3)
17-17
: Env parameter passthrough looks goodZYPPER_PARAMETERS addition mirrors APT/YUM patterns. No issues.
52-57
: Version pinning parityZYPPER_VERSION addition aligns with YUM_VERSION format. Good for consistent pinning.
151-172
: Consistency check passed: packaging/update-repos.sh and packaging/build-config.json already include opensuse/15.6 and sles/15.7.
@illescad can you raise and link a docs PR as well? Also just tweak the commits and PR title to include |
75c6d92
to
f52823d
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 2
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (9)
install.sh
(3 hunks)packaging/README.md
(1 hunks)packaging/build-config.json
(1 hunks)packaging/distros/opensuse/15.6.arm64v8/Dockerfile
(1 hunks)packaging/distros/opensuse/15.6/Dockerfile
(1 hunks)packaging/distros/opensuse/Dockerfile
(1 hunks)packaging/distros/sles/Dockerfile
(1 hunks)packaging/test-release-packages.sh
(2 hunks)packaging/update-repos.sh
(1 hunks)
🚧 Files skipped from review as they are similar to previous changes (7)
- packaging/README.md
- packaging/distros/sles/Dockerfile
- install.sh
- packaging/distros/opensuse/15.6/Dockerfile
- packaging/build-config.json
- packaging/distros/opensuse/Dockerfile
- packaging/update-repos.sh
RUN zypper up -y && \ | ||
zypper install -y --no-recommends \ | ||
rpm-build \ | ||
curl ca-certificates wget unzip flex bison \ | ||
gcc gcc-c++ \ | ||
cmake3-full \ | ||
make \ | ||
bash \ | ||
systemd-devel \ | ||
postgresql postgresql-devel postgresql-server \ | ||
cyrus-sasl cyrus-sasl-devel \ | ||
libopenssl3 libopenssl-3-devel \ | ||
libyaml-devel && \ | ||
zypper clean -a && rm -rf /var/cache/zypp/* |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
cmake3-full
doesn’t exist in Leap 15.x repos
zypper install … cmake3-full
will fail because the package name in Leap/SLES is cmake
(with the optional cmake-full
pattern), not cmake3-full
. The Docker build will therefore break before we even reach CMake configure. Please swap in the correct package name (typically cmake
or cmake-full
) so the image can install successfully.
🤖 Prompt for AI Agents
In packaging/distros/opensuse/15.6.arm64v8/Dockerfile around lines 11-24, the
Dockerfile attempts to install a non-existent package named cmake3-full on Leap
15.x; replace cmake3-full with the correct package name (typically cmake or the
cmake-full pattern) in the zypper install line so the install succeeds, then
rebuild the image to verify CMake is available.
packaging/test-release-packages.sh
Outdated
sh -c "zypper --non-interactive --gpg-auto-import-keys refresh \ | ||
zypper --non-interactive --gpg-auto-import-keys install gpg curl; \ | ||
$INSTALL_CMD /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fix command chaining in the zypper loop
The escaped newline glues both zypper
invocations into a single command (zypper … refresh zypper … install …
), which fails, and $INSTALL_CMD /opt/…
treats the version check as arguments to the installer, so /opt/fluent-bit/bin/fluent-bit --version
never runs. Use explicit &&
separators just like the YUM/APT blocks.
- sh -c "zypper --non-interactive --gpg-auto-import-keys refresh \
- zypper --non-interactive --gpg-auto-import-keys install gpg curl; \
- $INSTALL_CMD /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE"
+ sh -c "zypper --non-interactive --gpg-auto-import-keys refresh && \
+ zypper --non-interactive --gpg-auto-import-keys install gpg curl && \
+ $INSTALL_CMD && /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE"
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
sh -c "zypper --non-interactive --gpg-auto-import-keys refresh \ | |
zypper --non-interactive --gpg-auto-import-keys install gpg curl; \ | |
$INSTALL_CMD /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE" | |
sh -c "zypper --non-interactive --gpg-auto-import-keys refresh && \ | |
zypper --non-interactive --gpg-auto-import-keys install gpg curl && \ | |
$INSTALL_CMD && /opt/fluent-bit/bin/fluent-bit --version" | tee "$LOG_FILE" |
🤖 Prompt for AI Agents
In packaging/test-release-packages.sh around lines 139 to 141, the zypper
commands are joined by an escaped newline which concatenates them into a single
invalid command and causes the version check to be passed as arguments to the
installer; change the chaining to use explicit && between commands (e.g. zypper
... refresh && zypper ... install gpg curl && $INSTALL_CMD
/opt/fluent-bit/bin/fluent-bit --version) so each zypper invocation runs
sequentially and the --version check executes as a separate command.
f52823d
to
f15e9e4
Compare
@illescad if you can sort the DCO and docs PR that would be great so we can merge? Plus just check the CodeRabbit comments and resolve/fix as needed. |
…is not working. Currently testing ./build.sh -d opensuse/leap:15.6 Signed-off-by: Dan Illescas <[email protected]>
Signed-off-by: Dan Illescas <[email protected]>
…upport suse Signed-off-by: Dan Illescas <[email protected]>
Signed-off-by: Dan Illescas <[email protected]>
…n test-release-packages.sh Signed-off-by: Dan Illescas <[email protected]>
c6c3a76
to
3389284
Compare
@patrick-stephens working through the the docs PR today and any coderabbit fixes |
Thanks mate, let me know when you're done and I'll re-approve for merge. Looks good to me and I'll probably take it downstream to our repo straightaway anyway! |
Signed-off-by: Dan Illescas <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 2
🧹 Nitpick comments (7)
packaging/update-zypper-repo.sh (7)
2-2
: Harden shell optionsAdd pipefail to catch errors in pipelines; optionally gate xtrace with a DEBUG flag.
-set -eux +set -euo pipefail +${DEBUG:+set -x}
36-41
: realpath flags portability; add fallback
realpath -sm
may not be available on all images. Provide a fallback toreadlink -f
or drop-s
.-REPO_DIR=$(realpath -sm "$BASE_PATH/$RPM_REPO") +if command -v realpath >/dev/null 2>&1; then + REPO_DIR=$(realpath -m "$BASE_PATH/$RPM_REPO") +elif command -v readlink >/dev/null 2>&1; then + REPO_DIR=$(readlink -f "$BASE_PATH/$RPM_REPO") +else + REPO_DIR=$(cd "$BASE_PATH/$RPM_REPO" && pwd -P) +fiPlease confirm
realpath -s
exists on your target SUSE/Leap images.
42-46
: RPM signing: robustness and batching
- Use null-delimited paths and batch to reduce process spawn and handle odd filenames.
- Ensure we only target regular files.
- find "$REPO_DIR" -name "*-bit-*.rpm" -exec rpm --define "_gpg_name $GPG_KEY" --addsign {} \; + find "$REPO_DIR" -type f -name "*-bit-*.rpm" -print0 | \ + xargs -0 -r rpm --define "_gpg_name $GPG_KEY" --addsign
50-66
: Align metadata signing with zypper checksYou sign
repomd.xml
, but the generated .repo lacksrepo_gpgcheck=1
. Either add it (recommended) or skip metadata signing.baseurl=https://$AWS_S3_BUCKET.s3.amazonaws.com/$RPM_REPO/ enabled=1 gpgkey=https://$AWS_S3_BUCKET.s3.amazonaws.com/fluentbit.key gpgcheck=1 +repo_gpgcheck=1 autorefresh=1
If you prefer not to enforce repo metadata verification, remove the repomd signatures to avoid confusion.
Also applies to: 68-76
60-63
: Allow overriding base URL (CDN/region)Hardcoding the S3 endpoint can be limiting. Support
REPO_BASEURL
override while keeping current default.-baseurl=https://$AWS_S3_BUCKET.s3.amazonaws.com/$RPM_REPO/ +baseurl=${REPO_BASEURL:-https://$AWS_S3_BUCKET.s3.amazonaws.com/$RPM_REPO/}
29-31
: Package name hintOn SUSE, the package providing
createrepo
is typicallycreaterepo_c
. Adjust helper text.-echo "ERROR: 'createrepo' command not found. Please install it, e.g., 'zypper install createrepo'." +echo "ERROR: 'createrepo' command not found. Install it, e.g., 'zypper install createrepo_c'."
1-3
: Set a sane umask for repo filesEnsure world-readable artifacts.
#!/bin/bash -set -euo pipefail +umask 022 +set -euo pipefail
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think you need this as it should be part of the opensuse/Dockerfile?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I had an issue with docker finding the correct base image when trying to set the specific leap versions. So if using the opensuse/Dockerfile
and setting the target to something like
./packaging/build.sh -d opensuse/leap:15.6
Then the build.sh
will add a -base
to the image name, opensuse/leap:15.6-base
, which does not exist for opensuse. The standard naming convention is opensuse/leap:15.6
which is already the minimal image.
I wasnt sure how to correctly get around this, I can also add a check in build.sh
if DISTRO is opensuse to not append the -base
. Or maybe there is another way I am not understanding
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think you need this as it should be part of the opensuse/Dockerfile?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think i discovered the problem i had on why i thought i needed multiple Dockerfiles. The build.sh
needs to be updated to replace :
with -
if i want to call ./build.sh -d opensuse/leap:15.6
. I'll push an update to remove the extra Dockerfiles.
Is there a preference on the name we will pass the target distro to build.sh?
./build.sh -d opensuse/leap:15.6
or
./build.sh -d opensuse/leap-15.6
or
./build.sh -d opensuse/15.6
opensuse/leap:15.6
makes sense to me and I can make a change to build.sh
to replace :
with -
to make sure its a valid stage name.
FROM multiarch/qemu-user-static:x86_64-aarch64 AS multiarch-aarch64 | ||
|
||
# opensuse/leap base image | ||
FROM registry.suse.com/bci/bci-base:15.7 AS sles-15.7-base |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What's the main deltas between opensuse and sles? Just want to make sure we capture which one people should use for their targets.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah i think I caused some confusion, I need to update that comment to say its the SLES base container image not # opensuse/leap base image
. But its just building from SLES image vs the community os opensuse, and people would want to target the os they are building for.
@jhansonhpe do you have a better explanation for main deltas?
…ome coderabbit concerns Signed-off-by: Dan Illescas <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (5)
packaging/README.md (1)
40-43
: Docs addition looks consistent; consider noting Tumbleweed unsupportedTargets and “Target Option” values align with build.sh and repo paths. Optional: add a short note that openSUSE Tumbleweed isn’t supported via install.sh to avoid confusion.
packaging/update-zypper-repo.sh (2)
28-39
: Honor CREATE_REPO_CMD in availability check and messageYou define CREATE_REPO_CMD but check for a hardcoded createrepo. Use the variable for consistency and overrides.
-# Check for createrepo -if ! command -v createrepo &> /dev/null; then - echo "ERROR: 'createrepo' command not found. Please install it, e.g., 'zypper install createrepo'." +# Check for createrepo-compatible command +if ! command -v "$CREATE_REPO_CMD" &> /dev/null; then + echo "ERROR: '$CREATE_REPO_CMD' not found. Install it, e.g., 'zypper install createrepo'." exit 1 fi
49-53
: Robust signing: handle spaces and show failuresMinor hardening: use -print0 with xargs and fail the script if any signing fails.
-if [[ "$DISABLE_SIGNING" != "true" ]]; then - # Sign all RPMs created for this target, cover both fluent-bit and legacy packages - find "$REPO_DIR" -name "*-bit-*.rpm" -exec rpm --define "_gpg_name $GPG_KEY" --addsign {} \; -fi +if [[ "$DISABLE_SIGNING" != "true" ]]; then + # Sign all RPMs (fluent-bit and legacy td-agent-bit) + find "$REPO_DIR" -name "*-bit-*.rpm" -print0 | xargs -0 -r -n1 \ + rpm --define "_gpg_name $GPG_KEY" --addsign +fipackaging/update-repos.sh (1)
61-68
: Pass BASE_PATH explicitly to child scripts to reduce env couplingupdate-zypper-repo.sh expects BASE_PATH via env or $1. Pass it to be explicit and resilient.
- "opensuse/"* | "sles/"*) - /bin/bash -eux "$SCRIPT_DIR/update-zypper-repo.sh" + "opensuse/"* | "sles/"*) + /bin/bash -eux "$SCRIPT_DIR/update-zypper-repo.sh" "$BASE_PATH" ;; *) - /bin/bash -eux "$SCRIPT_DIR/update-yum-repo.sh" + /bin/bash -eux "$SCRIPT_DIR/update-yum-repo.sh" "$BASE_PATH" ;;packaging/distros/sles/Dockerfile (1)
63-71
: CMake flags: remove unused FLB_OUT_KAFKA arg or wire it throughYou define FLB_OUT_KAFKA but pass FLB_KAFKA to CMake. Either drop FLB_OUT_KAFKA or add the corresponding -DFLB_OUT_KAFKA flag if intended.
-ARG FLB_OUT_KAFKA=On ... - -DFLB_KAFKA="$FLB_KAFKA" \ + -DFLB_KAFKA="$FLB_KAFKA" \ + # If separate output toggle exists, include: + # -DFLB_OUT_KAFKA="$FLB_OUT_KAFKA" \
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (8)
install.sh
(3 hunks)packaging/README.md
(1 hunks)packaging/build-config.json
(1 hunks)packaging/build.sh
(1 hunks)packaging/distros/opensuse/Dockerfile
(1 hunks)packaging/distros/sles/Dockerfile
(1 hunks)packaging/update-repos.sh
(2 hunks)packaging/update-zypper-repo.sh
(1 hunks)
🚧 Files skipped from review as they are similar to previous changes (2)
- packaging/distros/opensuse/Dockerfile
- packaging/build-config.json
🔇 Additional comments (5)
install.sh (2)
151-169
: openSUSE Leap zypper branch LGTMRepo stanza, key import, refresh, and install flow look correct for Leap using VERSION_ID.
171-188
: Verify zypper’s $releasever expansion on SLES 15.7
Test on a SLES 15.7 instance to confirm$releasever
is correctly expanded in the repo URL; if it isn’t, replace with$VERSION_ID
(or a sanitized SLES version):- baseurl = $RELEASE_URL/sles/\$releasever + baseurl = $RELEASE_URL/sles/$VERSION_IDpackaging/update-repos.sh (1)
46-48
: Repo list update LGTMNew SUSE paths present: opensuse/leap/15.6 and sles/15.7.
packaging/build.sh (1)
63-71
: Stage name derivation matches versioned base stagesConstructing BASE_BUILDER as "-<cleaned_version>-base" aligns with SLES stage names (e.g., sles-15.7-base) and likely the opensuse/leap:15.6 Dockerfile. Good.
If opensuse’s Dockerfile uses unversioned base stage names, update it to include the version or adjust this derivation accordingly.
packaging/distros/sles/Dockerfile (1)
9-20
: Base images and tooling look correct for SLES 15.7Multi-arch bases, qemu setup, zypper install set, and cleanup steps are appropriate.
Providing support for SLES and Opensuse
Resolves #10875 by adding SLES v15.7 and Opensuse Leap 15.6 packaging. Opensuse repo images are minimal so adding -base to the target will case errors. To get around this multiple Dockerfiles were created for distro/opensuse/15.6*
Testing
Before we can approve your change; please submit the following in a comment:
[N/A] Example configuration file for the change
[N/A] Debug log output from testing the change
[N/A] Attached Valgrind output that shows no leaks or memory corruption was found
If this is a change to packaging of containers or native binaries then please confirm it works for all targets.
ok-package-test
label to test for all targets (requires maintainer to do).Documentation
Backporting
Fluent Bit is licensed under Apache 2.0, by submitting this pull request I understand that this code will be released under the terms of that license.
Summary by CodeRabbit
New Features
Documentation
Tests
Chores