Skip to content

fix(infrastructure): rpk, Confluent and librdkafka from vendor repos - #104

Merged
catinspace-au merged 2 commits into
mainfrom
fix/vendor-repo-moves
Oct 6, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/vendor-repo-moves

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

rpk, the Confluent CLI and librdkafka now come from their vendors' signed repos, so a normal apt or dnf upgrade keeps them current.

  • rpk installs redpanda-rpk from Redpanda's repo (rpk alone, not the broker). The old GitHub zip copy in /usr/local/bin goes once the package is in.
  • The Confluent CLI moves to its dedicated repo (4.78.0). The old Confluent Platform repo was picked by a lexical version sort and pinned a CP minor whose 8.3.2 build wrapped CLI 4.72. The swap is one transaction, so the old CLI only goes when the new one lands.
  • librdkafka for the Rust role now comes from Confluent's clients repo (2.15.1), the same source scalo-rs builds against. The distro builds lag: 2.3.0 on Ubuntu 24.04, 2.13.0 on 26.04, 2.14.1 on Fedora.
    • On Fedora, a box with a package that requires librdkafka by name (python3-confluent-kafka) keeps Fedora's build and gets a warning, rather than having that package erased.
  • ClickHouse's rpms are unsigned, but the repo metadata is now signature-checked.
  • Every key is staged, checked for exactly one primary key matching the pin, and only then trusted. A failed check removes that vendor's repo so later apt runs are not broken, and the trusted keys are left alone.

Tested in ubuntu:24.04, ubuntu:26.04, fedora:43 and fedora:44: fresh installs, hosts migrated from the old setup (one copy of each tool afterwards), second converges changed=0, wrong fingerprints fail closed, and check mode on a fresh host raises no spurious warnings. All six pins were re-derived from signed metadata.

Done when rpk, confluent and librdkafka update with the host and nothing else installs them.

rpk now comes from Redpanda's package repo as redpanda-rpk, the CLI alone, instead of a GitHub zip in /usr/local/bin that nothing ever updated. The old binary is removed once the package is in.

The Confluent CLI moves to its own unversioned repo. The Confluent Platform repo it came from was picked by a lexical sort of version strings, and it carries a confluent-cli numbered by the platform release (8.3.2) that wraps an older CLI (4.72) and outranks the real one on version. The old repo and key are removed, and a confluent-cli the CLI repo does not carry is replaced.

librdkafka for the rdkafka crate comes from Confluent's clients repo on Ubuntu and Fedora, matching what scalo-rs images ship, instead of the distro builds (2.3.0 on noble). An apt pin keeps Confluent's build ahead of Ubuntu's same-named packages, and on Fedora a dnf swap replaces the differently named distro package in one transaction.

Every new repo key is downloaded to an untrusted path, checked to hold exactly one primary key with the pinned fingerprint, and only then trusted, with failures recorded as deploy warnings. The ClickHouse repo on Fedora now checks its signed metadata; its rpms are unsigned, so package gpgcheck stays off.
The Fedora librdkafka swap no longer passes --allowerasing, which silently removed python3-confluent-kafka (it requires librdkafka by name, which Confluent's librdkafka1 does not provide) along with its python dependants. A host with such a package now keeps Fedora's librdkafka, the Confluent clients repo stays off it so dnf upgrade does not hit the file conflict, and the run records a warning naming the package. Later converges repeat the same check without changing anything.

A confluent-cli from the Confluent Platform repo is now replaced in one transaction, a downgrade to the CLI repo's newest build, instead of a remove then install that left no CLI when the download failed. On Fedora the repo query passes -y so the new repo's key is imported on first use. The Platform repo definition is removed, and on Ubuntu its key; on Fedora its key stays in the rpm database, because it is the same key that signs the Confluent clients repo librdkafka now comes from.

When a pinned fingerprint check fails, that vendor repo is removed so the apt module's cache refresh does not fail for the rest of the run, and the previously trusted key is left in place. The Ubuntu repo is removed as a file because deb822_repository state=absent also deletes the keyring of the same name. In check mode on a fresh host the key read, verify and install steps and the package installs are skipped instead of failing into a deploy warning.

The install docs list the Confluent CLI in the data group and librdkafka under the Confluent clients repo. The data_tools.yml header is ASCII and the stale macOS rpk fallback note is gone.
@catinspace-au
catinspace-au merged commit ed5b5d0 into main Oct 6, 2026
18 checks passed
@catinspace-au
catinspace-au deleted the fix/vendor-repo-moves branch October 6, 2026 03:08
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant