forked from heavy-duty/stoke
The package depends on nodejs (>= 22.12), but Debian 13 ships Node 20 and Ubuntu 24.04 ships Node 18, so a fresh container failed apt-get install with an unmet dependency. install-apt.sh now checks whether any configured apt source can satisfy the requirement and, if not, adds the NodeSource Node 22 repository before installing. README documents the behaviour and the manual equivalent. Verified on fresh debian:13 and ubuntu:24.04 containers: one-line setup, apt-get install stoke, stoke --version all succeed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
90 lines
3.5 KiB
Bash
Executable file
90 lines
3.5 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
#
|
|
# One-time setup to install stoke via apt on Debian/Ubuntu.
|
|
#
|
|
# Adds the heavy-duty Forgejo Debian registry as an APT source (with its
|
|
# signing key) and installs the stoke package. Safe to re-run; afterwards
|
|
# stoke upgrades through regular `apt-get upgrade`.
|
|
#
|
|
# Usage:
|
|
# ./scripts/install-apt.sh
|
|
# FORGE_URL=... OWNER=... ./scripts/install-apt.sh # non-default instance
|
|
#
|
|
# Run as root or as a user with sudo.
|
|
|
|
set -euo pipefail
|
|
|
|
FORGE_URL="${FORGE_URL:-https://forgejo.heavyduty.builders}"
|
|
OWNER="${OWNER:-heavy-duty}"
|
|
DISTRIBUTION="${DISTRIBUTION:-stable}"
|
|
COMPONENT="${COMPONENT:-main}"
|
|
|
|
KEYRING="/etc/apt/keyrings/forgejo-$OWNER.asc"
|
|
LIST="/etc/apt/sources.list.d/forgejo-$OWNER.list"
|
|
|
|
SUDO=""
|
|
if [ "$(id -u)" -ne 0 ]; then
|
|
command -v sudo >/dev/null 2>&1 || { echo "error: run as root or install sudo" >&2; exit 1; }
|
|
SUDO="sudo"
|
|
fi
|
|
|
|
update_only_source() {
|
|
$SUDO apt-get update \
|
|
-o Dir::Etc::sourcelist="$1" \
|
|
-o Dir::Etc::sourceparts=/dev/null \
|
|
-o APT::Get::List-Cleanup=0
|
|
}
|
|
|
|
# stoke needs Node.js >= 22.12 (commander 15), but the distro archives of
|
|
# Debian 13 (nodejs 20.x) and Ubuntu 24.04 (nodejs 18.x) cannot satisfy
|
|
# that, which would make `apt-get install stoke` fail with an unmet
|
|
# dependency. When no configured source offers a new-enough nodejs, add the
|
|
# NodeSource repository for Node 22 so the dependency resolves.
|
|
NODE_MIN="22.12"
|
|
node_candidate_ok() {
|
|
local candidate
|
|
candidate="$(apt-cache policy nodejs 2>/dev/null | sed -n 's/^ Candidate: //p')"
|
|
[ -n "$candidate" ] && [ "$candidate" != "(none)" ] || return 1
|
|
dpkg --compare-versions "${candidate#*:}" ge "$NODE_MIN"
|
|
}
|
|
|
|
ensure_nodejs_source() {
|
|
node_candidate_ok && return 0
|
|
echo "No apt source provides nodejs >= $NODE_MIN; adding NodeSource (Node 22) ..."
|
|
local ns_keyring="/etc/apt/keyrings/nodesource.asc"
|
|
local ns_list="/etc/apt/sources.list.d/nodesource.list"
|
|
curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | $SUDO tee "$ns_keyring" >/dev/null
|
|
echo "deb [signed-by=$ns_keyring] https://deb.nodesource.com/node_22.x nodistro main" \
|
|
| $SUDO tee "$ns_list" >/dev/null
|
|
update_only_source "$ns_list"
|
|
node_candidate_ok || { echo "error: still no nodejs >= $NODE_MIN available after adding NodeSource" >&2; exit 1; }
|
|
}
|
|
|
|
echo "Adding APT source for $FORGE_URL/$OWNER ..."
|
|
$SUDO install -d -m 0755 /etc/apt/keyrings
|
|
curl -fsSL "$FORGE_URL/api/packages/$OWNER/debian/repository.key" | $SUDO tee "$KEYRING" >/dev/null
|
|
echo "deb [signed-by=$KEYRING] $FORGE_URL/api/packages/$OWNER/debian $DISTRIBUTION $COMPONENT" \
|
|
| $SUDO tee "$LIST" >/dev/null
|
|
|
|
# Newer apt verifies with sqv (Sequoia), which rejects the signature Forgejo
|
|
# currently produces for its Debian registry (malformed Ed25519 MPI encoding
|
|
# in the upstream signing library). Try the properly signed source first so
|
|
# this heals automatically once the forge is fixed; otherwise fall back to
|
|
# [trusted=yes] — package integrity then relies on HTTPS to our own forge.
|
|
if ! update_only_source "$LIST"; then
|
|
echo
|
|
echo "WARNING: signature verification failed (known Forgejo registry issue" >&2
|
|
echo "with sqv-based apt). Falling back to [trusted=yes]; transport" >&2
|
|
echo "security is provided by HTTPS to $FORGE_URL." >&2
|
|
echo
|
|
echo "deb [trusted=yes] $FORGE_URL/api/packages/$OWNER/debian $DISTRIBUTION $COMPONENT" \
|
|
| $SUDO tee "$LIST" >/dev/null
|
|
update_only_source "$LIST"
|
|
fi
|
|
|
|
ensure_nodejs_source
|
|
|
|
$SUDO apt-get install -y stoke
|
|
|
|
echo
|
|
stoke --version >/dev/null && echo "stoke $(stoke --version) installed. Run: stoke auth login"
|