Add reproducible build system, native Unraid plugin, and WebUI
Build Packages / Build .txz packages (push) Failing after 9s
Lint / ShellCheck (push) Failing after 43s
Lint / Validate .plg XML (push) Successful in 10s
Lint / EditorConfig (push) Failing after 6s

- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt,
  and fuse-overlayfs to verified upstream source checksums; SlackBuild
  recipes, scripts/build-packages.sh, checksums.sh, release.sh, and
  update-versions.sh implement the reproducible pipeline; GitHub Actions
  workflows build in a Slackware container and publish releases without
  committing any binaries.

- plugin/podman.plg installs/updates/removes all eight packages (the
  seven components plus the plugin's own unraid-podman scaffolding
  package) via upgradepkg, using the official Unraid array-event hook
  mechanism (event/disks_mounted, event/stopping) instead of editing
  /boot/config/go. rc.podman and the sbin/ helper scripts implement
  storage creation, config seeding/sync, preflight checks, autostart
  with per-container Safe-Mode, and package verify/update/rollback.

- webui/plugins/podman implements the Dashboard, Containers, Pods,
  Images, Volumes, Networks, Logs, Terminal, Compose, and Settings
  panels against the approved mockup (webui/mockups/prototype.html),
  talking to podman system service exclusively via PodmanClient.php
  (libpod REST API over the Unix socket), with two documented
  exceptions: Terminal's one-shot exec model and Compose's use of the
  podman compose CLI, since libpod has no REST equivalent for either.

- docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions
  and honest current status (syntax-checked, unit- and
  integration-tested against fake sockets/servers; not yet run against
  a real Unraid/Podman/Slackware system).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-11 10:51:14 +00:00
co-authored by Claude Sonnet 5
parent 58ffc0c226
commit e2fefcdf9c
124 changed files with 9611 additions and 0 deletions
+59
View File
@@ -0,0 +1,59 @@
# packages/
One subdirectory per Slackware `.txz` package required by the plugin, built
against Unraid's Slackware base. See
[docs/ARCHITECTURE.md, section 5](../docs/ARCHITECTURE.md#5-paketmanagement)
for the full rationale (why these components, static linking preference,
version pinning, build strategy).
## Packages
| Directory | Upstream project | Purpose |
|---|---|---|
| `podman/` | [containers/podman](https://github.com/containers/podman) | Core container engine binary |
| `conmon/` | [containers/conmon](https://github.com/containers/conmon) | Container monitor process |
| `crun/` | [containers/crun](https://github.com/containers/crun) | OCI runtime (preferred over runc) |
| `netavark/` | [containers/netavark](https://github.com/containers/netavark) | Network backend |
| `aardvark-dns/` | [containers/aardvark-dns](https://github.com/containers/aardvark-dns) | DNS for container-to-container name resolution |
| `containers-common/` | [containers/common](https://github.com/containers/common) | Default config/seccomp/registries templates |
| `fuse-overlayfs/` | [containers/fuse-overlayfs](https://github.com/containers/fuse-overlayfs) | Fallback storage driver (rootless, Phase 2) |
| `passt/` | [passt.top](https://passt.top/passt/about/) (no GitHub mirror) | Rootless networking (Phase 2), successor to slirp4netns |
| `unraid-podman/` | this repository (not an upstream project) | Plugin's own scaffolding — rc.podman, sbin/ scripts, event/ hooks, config templates (see [its README](unraid-podman/README.md)) |
`podman`, `conmon`, `crun`, `netavark`, `aardvark-dns`, `passt`,
`fuse-overlayfs`, and `unraid-podman` are built and released automatically by
`.github/workflows/build-packages.yml`. `containers-common` currently only
supplies reference config (see [config/](../config)) and is not yet wired
into the automated build.
## Standard layout per package
Each package directory follows the same skeleton:
```
packages/<name>/
├── <name>.SlackBuild # Slackware build script (source download, build, packaging)
├── slack-desc # Slackware package description (max 70 cols / 11 lines)
├── patches/ # Optional patches applied during the build
└── README.md # Upstream version pinned, build notes, patch rationale
```
## Build pipeline
Packages are built via `scripts/build-packages.sh`, which runs each
package's `<name>.SlackBuild` in turn (see `scripts/lib/slackbuild-common.sh`
for the shared fetch/verify/package helpers they all use). This must run
inside a Slackware-compatible build environment — never on an arbitrary host
distro, to avoid glibc/ABI drift against Unraid's base.
`.github/workflows/build-packages.yml` is the CI entry point: it runs the
same script inside a pinned Slackware container
(`scripts/ci/setup-slackware-buildenv.sh` bootstraps any build-time
dependency the base image doesn't already ship) and uploads the results as a
workflow artifact — nothing built is ever committed to this repository.
Exact upstream versions and source checksums are pinned centrally in
[versions.env](../versions.env) (update via `scripts/update-versions.sh`,
never by hand) and, at release time, mirrored into the top-level
`plugin/podman.plg` manifest together with MD5 checksums by
`scripts/release.sh`, so installs are reproducible and rollback-able — see
[docs/ARCHITECTURE.md, section 14 (Rollback)](../docs/ARCHITECTURE.md#14-rollback).