# A Flatpak built from the .deb this release already produces. # # Why this exists: on RHEL 8 and its rebuilds — AlmaLinux 8, Rocky 8 — none of # the other Linux artifacts can run, and not for a packaging reason. # # * the .rpm and .deb require `libwebkit2gtk-4.1.so.0`; RHEL 8 ships # `webkit2gtk3`, which provides `libwebkit2gtk-4.0.so.37`, and there is no # 4.1 package for it at all; # * the AppImage bundles webkit 4.1, but the binary needs `GLIBC_2.39` and # RHEL 8 has 2.28. An AppImage does not carry a libc. # # The GNOME runtime carries both: a glibc new enough, and WebKitGTK 4.1 built # against the runtime's own GTK, glib, wayland and Mesa. Only the binary comes # from the release — the .deb's, as Tauri's own Flatpak guide takes it, since # the AppImage's copy has RUNPATH $ORIGIN/../lib pointing back into a library # directory this bundle no longer fills. 50 because 47–49 are end-of-life on # Flathub and 50 is what the Tauri apps there run on. # # Not the AppImage's libraries. Up to 4.19.0 this bundle ran on the bare # freedesktop runtime and copied the AppImage's whole usr/lib into /app/lib — # Ubuntu 24.04's WebKit, GTK, glib, epoxy, gstreamer, ssl, wayland and ~90 # more, each first on the path ahead of the runtime's own. The runtime's Mesa # EGL driver then loaded Ubuntu's older libwayland-client, which lacks a # symbol that driver binds at load, so EGL had no driver at all and WebKit's # web process aborted on "Could not create default EGL display: # EGL_BAD_PARAMETER" — a white window on every launch. No environment # variable changed that; CI tried five. # # This is a **bundle**, published as a release asset, not a Flathub # submission. Flathub forbids prebuilt binaries and builds offline, which is # where a bun project runs out of road; none of that applies to a bundle the # reader installs with `flatpak install ./Rubick.flatpak`. app-id: com.k8s_gui.app runtime: org.gnome.Platform runtime-version: '50' sdk: org.gnome.Sdk command: Rubick separate-locales: false finish-args: - --share=network - --share=ipc # x11, because GDK_BACKEND below forces it: the Wayland backend crashes # (tauri-apps/tauri#8541). - --socket=x11 - --device=dri # The kubeconfig, the caches, and the helpers under $HOME: krew, asdf, # ~/.local/bin. The ones in /usr/bin need host-os below. - --filesystem=home # A sandbox's /usr is the runtime's, so an EKS context whose exec block # names /usr/local/bin/aws cannot connect at all. This puts the host tree # under /run/host, where the path resolver now looks. - --filesystem=host-os:ro - --talk-name=org.freedesktop.secrets # notify-rust talks to this name directly, not through the portal, and a # denied call is swallowed: notify() reports delivered for nothing shown. - --talk-name=org.freedesktop.Notifications # single-instance asks to own tauri.conf.json's hyphenated identifier plus # .SingleInstance, which this app-id does not prefix; the refusal is # swallowed, and every rubick:// link then opens a second window. - --own-name=com.k8s-gui.app.SingleInstance - --env=GDK_BACKEND=x11 modules: - name: rubick buildsystem: simple build-commands: - ar x rubick.deb && tar -xf data.tar.* - install -Dm755 usr/bin/Rubick /app/bin/Rubick # Everything the binary links has to come from the runtime — asked of # the linker rather than listed by hand, so a dependency the next Tauri # adds fails the build here instead of a launch on somebody's desktop. - | missing=$(ldd /app/bin/Rubick | awk '/=> not found/ { print $1 }' | sort -u) for lib in $missing; do # The .deb carries no libraries, so a gap here is a gap in the # runtime — said out loud rather than filled from somewhere else. echo "the runtime does not provide $lib" >&2 exit 1 done # And nothing in /app/lib at all: a library of ours first on the path # is the whole of the bug this manifest was rewritten for. if [ -n "$(ls -A /app/lib 2>/dev/null)" ]; then echo "the bundle carries libraries; it must carry none" >&2 ls -la /app/lib >&2 exit 1 fi - install -Dm644 usr/share/applications/Rubick.desktop /app/share/applications/com.k8s_gui.app.desktop - desktop-file-edit --set-key=Icon --set-value=com.k8s_gui.app /app/share/applications/com.k8s_gui.app.desktop # Exec decides what the exported launcher runs: flatpak turns its first # word into `--command=`. `%u` is how a `rubick://` link is handed over; # the desktop file declares the scheme and passed nothing. - desktop-file-edit --set-key=Exec --set-value='Rubick %u' /app/share/applications/com.k8s_gui.app.desktop # The three sizes the .deb carries, named as hicolor names them. # No `if -f`: an icon that stopped shipping must break the build. - for d in 32x32 128x128 256x256@2; do install -Dm644 "usr/share/icons/hicolor/$d/apps/Rubick.png" "/app/share/icons/hicolor/$d/apps/com.k8s_gui.app.png"; done sources: - type: file path: rubick.deb