CI: dispatch-only cold-build reproducibility workflow

Proves a fresh clone builds the release image on a hosted runner
(sibling checkouts for meta-openglow and the kernel-module externalsrc,
rm_work to fit the disk budget) and publishes artifact checksums for
comparison against locally built releases. Never produces release
artifacts - releases are built and signed on the maintainer's host.
This commit is contained in:
ScottW514
2026-08-08 13:32:00 -04:00
parent fcf183eefd
commit a2f1b8e9e8
2 changed files with 93 additions and 0 deletions
+16
View File
@@ -0,0 +1,16 @@
# CI overlay for the cold-build reproducibility workflow: merge after the
# main config (kas build kas/forgefirm-glowforge.yml:kas/ci.yml).
# rm_work keeps the build inside a hosted runner's disk budget; the
# release image alone is built (the dev image adds nothing to the
# reproducibility question).
header:
version: 14
target: forgefirm-image
local_conf_header:
ci: |
INHERIT += "rm_work"
BB_NUMBER_THREADS = "4"
PARALLEL_MAKE = "-j 4"