Downstream of registry.gitlab.com/fdroid/docker-executable-fdroidserver:master,
patched for publishing F-Droid repos over IPFS:
- install Debian ipfs-cid so fdroidserver populates ipfsCIDv1 on every
package file (APKs, icons, screenshots), which fdroidclient with an
IPFS-gateway mirror routes via CID natively
- rehash.py wrapper that adds ipfsCIDv1 to entry["index"], renames the
index to a content-addressed filename, and re-signs entry.jar after
`fdroid update` — closes the cache-busting gap on the index file itself
- entrypoint.sh chains rehash automatically after any `fdroid update`,
so existing fdroid-via-docker wrappers need no changes
See SPEC.md for the rationale and Change 2's algorithm; README.md for
end-user usage.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.3 KiB
fdroidserver-ipfs
Downstream of registry.gitlab.com/fdroid/docker-executable-fdroidserver:master,
patched for publishing F-Droid repos over IPFS. See SPEC.md for the why.
Usage
Drop-in replacement for the upstream image. Run fdroid update exactly as
before — the image's entrypoint chains fdroidserver-ipfs-rehash after any
successful update, so you never have to remember the second step:
docker run --rm -v "$PWD:/repo" your-image-tag update
# ↑ runs `fdroid update`, then automatically renames index, adds ipfsCIDv1,
# re-signs entry.jar (and regenerates entry.json.asc if GPG was in the loop).
Every other subcommand (build, publish, gpgsign, …) passes straight
through to fdroid unchanged.
Running the rehash standalone
If you want to invoke the rehash directly (e.g. on an already-published repo):
docker run --rm -v "$PWD:/repo" \
--entrypoint fdroidserver-ipfs-rehash \
your-image-tag
fdroidserver-ipfs-rehash discovers repo/ (and archive/ if configured)
from config.yml. If GPG signing was already part of your pipeline (i.e.
entry.json.asc exists), it invokes fdroid gpgsign itself to regenerate
the invalidated signatures. Pass repodirs explicitly to override discovery:
fdroidserver-ipfs-rehash repo archive