Operating system and container binary deployment and upgrades
Go to file
Philip Withnall 8c148eb7e1 lib/repo-finder: Emit gpg-verify-summary=false in dynamic remote config
When returning results from finding repos, set gpg-verify-summary=false
in their configs, since any pulls from such remotes will necessarily
involve collection IDs, and hence should be using the unsigned summary
support. In the intended deployment mode for P2P transmission of OSTree
refs, summaries *cannot* be signed, so setting gpg-verify-summary=true
would cause all the pulls to fail.

The unsigned summary support is the move of repository metadata from
the summary file (not spliceable) to the well-known ostree-metadata ref
(spliceable, as it can exist for multiple collection IDs in the same
repository).

Signed-off-by: Philip Withnall <withnall@endlessm.com>

Closes: #1066
Approved by: cgwalters
2017-08-08 18:08:05 +00:00
apidoc lib/repo-refs: Add ostree_repo_remote_list_collection_refs() API 2017-08-08 13:59:58 +00:00
bsdiff@1edf9f6568 bsdiff: change submodule location 2015-03-26 23:33:07 +01:00
build-aux Add infrastructure for "make syntax-check" 2015-01-30 15:27:36 +01:00
buildutil build: Use AM_TESTS_ENVIRONMENT rather than TESTS_ENVIRONMENT 2017-05-23 17:51:27 +00:00
ci ci: Enable libcurl by default on Fedora 2017-07-26 20:54:35 +00:00
coccinelle tree-wide: Add+run spatch to use glnx_throw() 2017-05-26 19:27:11 +00:00
docs tree-wide: Replace various uses of archive-z2archive 2017-06-29 16:00:13 +00:00
libglnx@ea6df95f22 Update libglnx, port some uses to newer APIs 2017-07-24 18:43:57 +00:00
man man: The min-free-space-percent item goes in [core] section 2017-08-08 12:56:47 +00:00
manual-tests repo+tests: Add [core]disable-xattrs=true, use it on overlayfs 2017-03-24 22:16:43 +00:00
rust rust: Support make dist -> cargo vendor 2017-02-07 16:50:37 +00:00
src lib/repo-finder: Emit gpg-verify-summary=false in dynamic remote config 2017-08-08 18:08:05 +00:00
tests lib/deploy: Use a FIFREEZE/FITHAW cycle for /boot 2017-08-08 16:09:04 +00:00
.dir-locals.el .dir-locals.el: Standard Emacs indentation config 2017-01-12 16:09:34 +00:00
.gitmodules bsdiff: change submodule location 2015-03-26 23:33:07 +01:00
.papr.yml ci: Enable libcurl by default on Fedora 2017-07-26 20:54:35 +00:00
.travis.yml ci: Move travis scripts from tests/ → ci/ 2017-05-09 18:25:13 +00:00
autogen.sh autogen.sh: Fix running out of tree 2017-08-08 12:44:17 +00:00
cfg.mk tests: add a syntax-check rule for glnx_prefix_error() 2017-06-26 15:09:12 +00:00
configure.ac main: Fix subcommand usage output 2017-08-05 00:55:36 +00:00
CONTRIBUTING.md Rewrite manual in mkdocs 2016-01-28 09:31:37 -05:00
COPYING COPYING: Update to latest FSF with current address 2014-01-16 10:22:30 -05:00
git.mk Use git.mk 2016-04-07 12:49:40 +00:00
GNUmakefile Add infrastructure for "make syntax-check" 2015-01-30 15:27:36 +01:00
maint.mk tests/installed: New installed, privileged tests using Fedora AH 2017-04-25 15:15:06 +00:00
Makefile-boot.am Move ostree-* executables to /usr/lib/ostree 2016-08-11 14:04:59 +00:00
Makefile-decls.am build-sys: Minor makefile tweaks 2017-01-04 16:32:11 +00:00
Makefile-libostree-defines.am lib/repo-finder: Add Avahi based OstreeRepoFinder implementation 2017-06-26 15:56:07 +00:00
Makefile-libostree.am Move the include directive to the enum template 2017-07-17 15:14:44 +00:00
Makefile-man.am build: Don't distribute generated man pages 2017-07-18 21:51:43 +00:00
Makefile-ostree.am find-remotes: Add a find-remotes built-in command 2017-06-26 15:56:07 +00:00
Makefile-otutil.am libutil: Delete unused threadpool wrapper 2017-03-30 13:14:43 +00:00
Makefile-switchroot.am Switch to using a systemd generator for /var 2017-05-16 16:13:05 +00:00
Makefile-tests.am tests: More fixes for gjs tests 2017-07-21 15:45:27 +00:00
Makefile.am lib/repo-finder: Add mount based OstreeRepoFinder implementation 2017-06-26 15:56:07 +00:00
mkdocs.yml docs: Add a section on repository management 2016-03-29 14:10:24 +00:00
ostree.doap doap category infrastructure 2014-07-31 11:26:32 +02:00
README-historical.md README: Just link to wiki, move most of it to README-historical.md 2014-01-20 18:00:09 -05:00
README.md Documentation: README: Remove deprecated wiki link 2017-08-03 13:00:26 +00:00
TODO Fix repeated words. 2015-01-30 15:27:36 +01:00

libOSTree

New! See the docs online at Read The Docs (OSTree)


This project is now known as "libOSTree", renamed from "OSTree"; the focus is on the shared library. However, in most of the rest of the documentation, we will use the term "OSTree", since it's slightly shorter, and changing all documentation at once is impractical. We expect to transition to the new name over time.

libOSTree is a library and suite of command line tools that combines a "git-like" model for committing and downloading bootable filesystem trees, along with a layer for deploying them and managing the bootloader configuration.

The core OSTree model is like git in that it checksums individual files and has a content-addressed-object store. It's unlike git in that it "checks out" the files via hardlinks, and they should thus be immutable. Therefore, another way to think of OSTree is that it's just a more polished version of Linux VServer hardlinks.

Features:

  • Atomic upgrades and rollback for the system
  • Replicating content incrementally over HTTP via GPG signatures and "pinned TLS" support
  • Support for parallel installing more than just 2 bootable roots
  • Binary history on the server side (and client)
  • Introspectable shared library API for build and deployment systems

This last point is important - you should think of the OSTree command line as effectively a "demo" for the shared library. The intent is that package managers, system upgrade tools, container build tools and the like use OSTree as a "deduplicating hardlink store".

Projects using OSTree

meta-updater is a layer available for OpenEmbedded systems.

QtOTA is Qt's over-the-air update framework which uses libostree.

rpm-ostree is a next-generation hybrid package/image system for Fedora and CentOS, used by the Atomic Host project. By default it uses libostree to atomically replicate a base OS (all dependency resolution is done on the server), but it supports "package layering", where additional RPMs can be layered on top of the base. This brings a "best of both worlds"" model for image and package systems.

flatpak uses libostree for desktop application containers. Unlike most of the other systems here, flatpak does not use the "libostree host system" aspects (e.g. bootloader management), just the "git-like hardlink dedup". For example, flatpak supports a per-user OSTree repository.

Endless OS uses libostree for their host system as well as flatpak. See their eos-updater and deb-ostree-builder projects.

GNOME Continuous is where OSTree was born - as a high performance continuous delivery/testing system for GNOME.

Building

Releases are available as GPG signed git tags, and most recent versions support extended validation using git-evtag.

However, in order to build from a git clone, you must update the submodules. If you're packaging OSTree and want a tarball, I recommend using a "recursive git archive" script. There are several available online; this code in OSTree is an example.

Once you have a git clone or recursive archive, building is the same as almost every autotools project:

env NOCONFIGURE=1 ./autogen.sh
./configure --prefix=...
make
make install DESTDIR=/path/to/dest

More documentation

New! See the docs online at Read The Docs (OSTree)

Contributing

See Contributing.