To ease the development of Wolfi OS, you can use the sdk Chainguard Image that already includes both apko and melange.
To start a development environment, do
make dev-containerWhat it does is start the chainguard-images/sdk image and mount the current working directory into it.
Now, the Makefile script assume that there're melange folder & melange binary the upper level dir (../melange). I change it locally to the following because it's where they are in chainguard-image/sdk.
MELANGE_DIR ?= /usr/share/melange
MELANGE ?= $(shell which melange)
Wolfi packages are built using melange. If you want to learn how packages are built, you can see all the details in the ci-build workflow and in the Makefile.
Start by cloning this repository and create a YAML file named <your-package-name>.yaml in its root directory. If you have any patches, create a folder with the same name and put them there.
Add a new entry for your package in the Makefile like this
$(eval $(call build-package,<your-package-name>,<version>-r<epoch>))
Once you're done writing the new package configuration file, you can test it by triggering a build with make packages/<your-package-name>.
-
When bumping version of a package, you will need to update the version, epoch & shasum (sha256 or sha512) in package YAML file. The version and epoch also need to be bumped in Makefile.
-
epochneeds to be bump when package version remains the same but something else changes.epochneeds to be reset to 0 when it's a new version of the package. -
melangeCLI has a commandbumpto make it easier. More details are available here.
-
melange has a few built-in pipelines. You can see their source code in the melange repository.
-
You don't need to add
environment.contents.repositoriesandenvironment.contents.keyring. Those are added automatically in theci-build.yamlscript during CI. -
For patching CVEs, you can follow the documentation here.
-
If you don't want to build all the packages locally, you can install
gsutiland use it to sync the prebuilt packages fromgs://wolfi-production-registry-destination/os/bucket:
gsutil -m rsync -r gs://wolfi-production-registry-destination/os/ ./packages- If you dont want to install
gsutillocally, you can use this imagegcr.io/google.com/cloudsdktool/google-cloud-cli:slimwhich is the official SDK image from GCP and already includegsutilin there.