Skip to content

Migrate to mkosi + sysupdate - #809

Open
jumpyvi wants to merge 109 commits into
elementary:mainfrom
jumpyvi:sysupdate
Open

Migrate to mkosi + sysupdate#809
jumpyvi wants to merge 109 commits into
elementary:mainfrom
jumpyvi:sysupdate

Conversation

@jumpyvi

@jumpyvi jumpyvi commented Jul 22, 2026

Copy link
Copy Markdown

Migrate to mkosi and sysupdate

I got basic boot, missing a few package update to be able to check the full experience with Resolute.

Fixes elementary/settings-daemon#167
Fixes #717
Fixes #724

@danirabbit danirabbit added this to OS 9 Jul 22, 2026
@danirabbit danirabbit moved this to In progress in OS 9 Jul 22, 2026
@nikodunk

nikodunk commented Jul 22, 2026

Copy link
Copy Markdown

This is more elegant than #808, and builds out the mkosi/sysupdate method from #793 that fully supports ubuntu already. In comparison to my bootc suggestion, this:

  • Build: mkosi build --profile=sysupdate Create disk image (currently .raw but could be a fake .iso).
  • Install: rsync mkosi.output/elementary.raw https://r2.cloudflarestorage.com/installer/x86.iso Copy the image to the download link, so users can download it and write to a USB drive. Live boot session would need to copy this image to disk. Installer would need to be adapted.
  • Update: rsync mkosi.output/* https://r2.cloudflarestorage.com/updates Push image to any static host so all existing ElementaryOS installs can run updatectl update (settings app would need to be adapted). This checks a static folder at ie. updates.elementary.io (currently set to 10.0.2.2:7676 for testing), downloads anything newer than the currently-booted IMAGE_VERSION, drops it into the inactive A/B slot, and reboots into it on next boot. Even over major versions like 8=>9=>10.

@nikodunk

nikodunk commented Jul 23, 2026

Copy link
Copy Markdown

@danirabbit what's the best way to land this? This PR currently replaces the old stuff, but I'm guessing some the 8.1 stable jobs might be run in parallel with the 9.0 sysupdate jobs until 8.1 reaches EOL?

Edit: My proposal, not speaking for @jumpyvi here:

  • When ready to merge, make current os/main branch into archive and keep running the 8.1 stable jobs off of that archive branch.
  • This becomes main, and starts building the sysupdate isos and updates.

@danirabbit

This comment was marked as resolved.

@danirabbit

This comment was marked as resolved.

@jumpyvi

This comment was marked as outdated.

@nikodunk

nikodunk commented Jul 23, 2026

Copy link
Copy Markdown

OK so going back on my above suggestions, how about we keep sysupdate on a branch, and add a 4th job on a sysupdate branch then:

  • daily-8.1 (main branch)
  • daily-9.0 (main branch)
  • stable-8.1 (main branch)
  • image-9.0 (sysupdate branch this can be a manual kick-off, and not advertised until there's delta updates?)

@jumpyvi

jumpyvi commented Jul 23, 2026

Copy link
Copy Markdown
Author
* image-9.0 (sysupdate branch this can be a manual kick-off, and not advertised until there's delta updates?)

We don't know when/if systemd will choose to implement this.

idk if there is any other solutions

systemd/systemd#28227

@nikodunk

This comment was marked as resolved.

@danirabbit

This comment was marked as resolved.

@lewisgoddard

Copy link
Copy Markdown
Member

For S3 compatible storage I would recommend Cloudflare R2. We already use Cloudflare and there is no bandwidth billing there, only storage and action costs.

@nikodunk

nikodunk commented Jul 24, 2026

Copy link
Copy Markdown

Thank you! Looks like we were holding it wrong: cost won’t be a problem at $0.60 for 10,000 users downloading a 4gb image once a week on Cloudflare R2 (50 gb, 4 writes per mo, 70% egress, 40,000 reads per mo) - thank you @lewisgoddard .

OK so maybe @jumpyvi we don't optimize for transmission size yet for now then, and optimize for deltas later as sysupdate matures - other projects will have this problem too.

JumpyVi and others added 3 commits July 24, 2026 14:17
* re-add sysupdate jobs

* make only monthly image.

* make monthly

* update scripts

* done

* merge

* revert

* fix typo, PR feedback on build

* add date to raw

* better update file matching

* update sha

* update upload.py for cloudflare R2
@nikodunk

nikodunk commented Jul 25, 2026

Copy link
Copy Markdown

@jumpyvi got updates working (hosted on a temporary CDN), @jumpyvi has also booted the .raw off of a usb stick (I don't have one that's big enough).

Screenshot_20260724_113227

Finally, an initial job has been added @danirabbit - edited upload.py to upload to Cloudflare R2

@nikodunk

This comment was marked as outdated.

@danirabbit

This comment was marked as outdated.

@danirabbit danirabbit left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I'm happy to move this to testing. Just waiting on re-review from @ryonakano I think :)

@ryonakano

Copy link
Copy Markdown
Member

Sorry for my late review, I will take a look at this again when getting back home today.

@ryonakano ryonakano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm sorry for my late review. Leaving a few nitpicking comments and questions, otherwise LGTM.

Comment thread mkosi.images/base/mkosi.extra/usr/lib/systemd/system/apparmor-firstboot.service Outdated
Comment thread mkosi.images/base/mkosi.extra/usr/lib/tmpfiles.d/etc.conf Outdated
Comment thread mkosi.images/base/mkosi.extra/usr/lib/tmpfiles.d/etc.conf Outdated
Comment thread mkosi.images/liveiso/mkosi.extra/iso_root/.disk/info Outdated
Comment thread .github/workflows/daily-9.0.yml
Comment thread .github/workflows/daily-9.0.yml Outdated

@ryonakano ryonakano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix, leaving tiny EOF comments.

Comment thread mkosi.images/liveiso/mkosi.profiles/aarch64/mkosi.conf Outdated
Comment thread mkosi.images/liveiso/mkosi.profiles/x86-64/mkosi.conf Outdated
Comment thread mkosi.profiles/aarch64/mkosi.conf Outdated
Comment thread mkosi.profiles/x86-64/mkosi.conf Outdated
@jumpyvi
jumpyvi requested a review from ryonakano September 9, 2026 23:24

@ryonakano ryonakano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I have some additional comments.

name: Extension release ${{ steps.get_date.outputs.RELEASE_DATE }} (${{ inputs.build_type }}) for ${ARCH}
files: |
mkosi.output/ext/ext-*.raw.zst
mkosi.output/ext/SHA256SUMS No newline at end of file

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing EOF newline

uses: ./.github/workflows/reusable-release.yml
with:
build_type: daily
secrets: inherit No newline at end of file

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing EOF newline

uses: ./.github/workflows/reusable-release.yml
with:
build_type: stable
secrets: inherit No newline at end of file

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing EOF newline

@@ -0,0 +1 @@
#placeholder for real public key No newline at end of file

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing EOF newline

Comment thread README.md
Configure the channel (stable, daily) in the configuration file (`etc/terraform-amd64.conf` or `etc/terraform-arm64.conf` based on your host architecture), then run:
```bash
just genkey
just do-release

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
just do-release
just do-daily

Comment thread README.md
More information about the concepts behind `live-build` and the technical decisions made to arrive at this set of tools to build an .iso can be found [on the wiki](https://github.com/elementary/os/wiki/Building-iso-Images).
## Minimum specs
- UEFI
- ~8gb usb stick

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- ~8gb usb stick
- 8 GB of USB flash drive

Comment thread README.md
## Minimum specs
- UEFI
- ~8gb usb stick
- Gnome Boxes >=51 (for VM only)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Gnome Boxes >=51 (for VM only)
- GNOME Boxes >=51 (for VM only)

Comment thread README.md
- UEFI
- ~8gb usb stick
- Gnome Boxes >=51 (for VM only)
- 70gb destination disk, 4gb ram (less should be possible, but not tested)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- 70gb destination disk, 4gb ram (less should be possible, but not tested)
- 64 GB of destination disk
- 4 GB of system memory (RAM)

I can install with 64 GB.

Comment thread README.md
just genkey
just do-release
```
Create install media with [Fedora Media Writer](https://flathub.org/en/apps/org.fedoraproject.MediaWriter) or [Impression](flathub.org/en/apps/io.gitlab.adhami3310.Impression), or boot with Gnome Boxes (>=51). Then, in demo mode, install via script:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Create install media with [Fedora Media Writer](https://flathub.org/en/apps/org.fedoraproject.MediaWriter) or [Impression](flathub.org/en/apps/io.gitlab.adhami3310.Impression), or boot with Gnome Boxes (>=51). Then, in demo mode, install via script:
Create install media with [Fedora Media Writer](https://flathub.org/en/apps/org.fedoraproject.MediaWriter) or [Impression](flathub.org/en/apps/io.gitlab.adhami3310.Impression), or boot with GNOME Boxes (>=51). Then, in demo mode, install via script:

Comment thread README.md

More information about the concepts behind `live-build` and the technical decisions made to arrive at this set of tools to build an .iso can be found [on the wiki](https://github.com/elementary/os/wiki/Building-iso-Images).
## Minimum specs
- UEFI

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- UEFI
- UEFI with secure boot disabled

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Needs Review

Development

Successfully merging this pull request may close these issues.

Build systemd-sysupdate compatible images There isn't a way to upgrade between OS releases Switch to SystemD Boot

6 participants