• Sources: supakeen's weblog, HN 49046525
  • Summary: The post traces a package from a packager's commit to a composed release and names the tool at each stage. Source definitions live in per-package Git repositories at src.fedoraproject.org, with large tarballs kept in a separate lookaside cache, and fedpkg build hands Koji a URL pointing at a specific commit so the build is reproducible from that hash. Koji is hub-and-spoke, a passive XML-RPC server over PostgreSQL with builder daemons that create a fresh Mock chroot per build, organized around tags that support multiple inheritance. Bodhi gates updates through pending, testing and stable using karma, holds critical path packages 14 days instead of 7, and moves builds between Koji tags rather than copying artifacts. Pungi orchestrates the compose and freezes the package set from a Koji tag in its Pkgset phase, so a build submitted mid-compose cannot slip in. Downstream, lorax produces boot.iso, Kiwi builds cloud and live images, Image Builder handles ostree and bootc artifacts on osbuild with 176 stages running in bubblewrap sandboxes, rpm-ostree composes the Atomic Desktops, productmd writes the compose metadata that Anaconda and openQA consume, and the Changes process routes system-wide modifications through FESCo. The author notes the document is still living because Fedora 45 is unreleased and change proposals affecting boot.iso production are in flight.
  • Why it matters: The pipeline detail usually spread across a dozen wiki pages is in one place, including the compose-time package set freeze that makes a Fedora compose auditable back to a commit hash.

send feedback on this story