PKGBUILDs and Concourse pipelines for building Arch Linux packages
  • Shell 53.3%
  • JavaScript 46.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-27 21:12:26 +00:00
1password Update dependency 1password to v8.12.36 2026-09-09 19:39:19 +00:00
1password-cli Update dependency 1password-cli to v2.39.0 2026-08-14 23:39:18 +00:00
archon-lite-bin Update dependency RPGLogs/Uploaders-archon-lite to v9.6.80 2026-09-16 17:38:50 +00:00
claude-code Update dependency anthropics/claude-code to v2.1.283 2026-09-25 23:43:45 +00:00
pi-coding-agent Update dependency earendil-works/pi to v0.87.1 2026-09-22 21:39:26 +00:00
pipelines Make build-package.sh executable and invoke it via bash 2026-08-08 23:03:08 +00:00
scripts Retry registry upload on transient 5xx 2026-08-08 23:14:15 +00:00
xivlauncher-rb Update dependency rankynbass/XIVLauncher.Core to v1.4.0.12 2026-09-05 17:39:22 +00:00
README.md Split pipeline into one per package with a set_pipeline manager 2026-08-08 22:56:58 +00:00
renovate.json Track 1password and 1password-cli via the official 1Password RSS feeds 2026-08-08 22:44:58 +00:00

coop/arch

Arch Linux packaging for the coop org: PKGBUILDs and the Concourse pipeline that builds them and publishes the resulting packages to the Forgejo Arch package registry, which acts as a full pacman mirror (Forgejo maintains the package database and signs packages with the coop owner key).

Layout

Path What it is
pi-coding-agent/ PKGBUILD for pi-coding-agent (the Pi coding agent)
xivlauncher-rb/ PKGBUILD for xivlauncher-rb (the XIVLauncher fork with RB patches)
1password/ PKGBUILD for 1password (the 1Password desktop app)
1password-cli/ PKGBUILD for 1password-cli (the 1Password CLI, op)
claude-code/ PKGBUILD for claude-code (Anthropic's Claude Code CLI)
archon-lite-bin/ PKGBUILD for archon-lite-bin (Archon Lite Uploader — pre-built AppImage)
pipelines/manager.yaml Concourse manager pipeline (arch): set_pipelines every per-package pipeline on each push
pipelines/<package>.yaml One Concourse pipeline per package (arch-<package>); builds and uploads that package
scripts/build-package.sh Shared build + publish logic used by every per-package pipeline

Consuming the repo on an Arch machine

Add the registry as a pacman repository (one-time setup):

# 1. Import and trust the coop signing key.
wget -O /tmp/coop.gpg https://git.sams.wtf/api/packages/coop/arch/repository.key
pacman-key --add /tmp/coop.gpg
# The key's uid is coop@noreply.git.sams.wtf — verify with:
#   gpg --show-keys /tmp/coop.gpg
pacman-key --lsign-key coop@noreply.git.sams.wtf
# 2. Append to /etc/pacman.conf
[arch]
SigLevel = Required
Server = https://git.sams.wtf/api/packages/coop/arch/arch/$arch
# 3. Install
pacman -Sy
pacman -S pi-coding-agent       # or: xivlauncher-rb, 1password, 1password-cli, claude-code, archon-lite-bin

Building locally

cd pi-coding-agent       # or: xivlauncher-rb, 1password, 1password-cli, claude-code, archon-lite-bin
makepkg -si              # build + install; or just `makepkg` to build

Pipeline

The repo is split into one Concourse pipeline per package so a change to one package doesn't rebuild all of them. Each per-package pipeline (arch-<package>, defined in pipelines/<package>.yaml) builds its PKGBUILD in an archlinux:base-devel container and uploads the resulting .pkg.tar.zst to the registry. Its git resource has a paths filter for the package's directory, so it only triggers on commits that touch that package. Existing uploads of the same version are deleted first, because the registry refuses duplicate files (HTTP 409).

The manager pipeline (named arch) runs on every push to main and re-sets each per-package pipeline with set_pipeline, so pipeline changes are applied automatically and the definitions in pipelines/ are the source of truth. It only runs native set_pipeline steps — no containers, no builds.

Set it up (first time only):

fly -t coop set-pipeline -p arch -c pipelines/manager.yaml -n
fly -t coop unpause-pipeline -p arch
# the manager's first run creates the per-package pipelines paused;
# unpause them once (the manager keeps them unpaused afterwards):
fly -t coop unpause-pipeline -p arch-1password
fly -t coop unpause-pipeline -p arch-1password-cli
fly -t coop unpause-pipeline -p arch-archon-lite-bin
fly -t coop unpause-pipeline -p arch-claude-code
fly -t coop unpause-pipeline -p arch-pi-coding-agent
fly -t coop unpause-pipeline -p arch-xivlauncher-rb

The ((coop-forgejo.token)) credential (hermes PAT, write:package scope) comes from the Concourse credential manager — the same secret used by coop/hermes-image.

Adding a new package

  1. Create PKGBUILD in a new directory (mirror an existing one).
  2. Create pipelines/<name>.yaml (copy an existing package pipeline, change the paths filter and PKGBUILD_DIR; add PGP_KEY_FPS / EXTRA_PACKAGES params if the build needs them).
  3. Add a set_pipeline: arch-<name> step to pipelines/manager.yaml.
  4. Push — the manager re-sets the new pipeline on the next check. Unpause it once (fly -t coop unpause-pipeline -p arch-<name>), then it's self-maintaining.

Update process

The PKGBUILD is pinned to a specific upstream release. To bump it manually: update pkgver, fetch the new checksums from the release's SHA256SUMS asset, and update the sha256sums_* arrays (in both PKGBUILD and .SRCINFO). Then push — the pipeline rebuilds and republishes automatically.

Renovate

renovate.json automates this: the regex manager tracks pkgver (in PKGBUILD and .SRCINFO) against upstream GitHub releases of earendil-works/pi, and a postUpgradeTask runs scripts/update-pkgsums.js to recompute the sha256sums_* lines from the release's SHA256SUMS asset. Renovate opens a PR with the version bump + fresh checksums; merging it triggers the Concourse build, which verifies the checksums with makepkg before publishing.