Bug 14482 - Document how to set up the Yocto Project for production work
Summary: Document how to set up the Yocto Project for production work
Status: RESOLVED MOVED
Alias: None
Product: General Docs
Classification: Documentation
Component: docs-general (show other bugs)
Version: 3.3
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: Future
Assignee: Michael Opdenacker
QA Contact:
URL:
Whiteboard:
: 6437 (view as bug list)
Depends on:
Blocks:
 
Reported: 2021-07-15 09:32 UTC by Michael Opdenacker
Modified: 2021-07-30 15:45 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Yes (doc changes required)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Opdenacker 2021-07-15 09:32:26 UTC
This is an attempt to help address bug #6437 (https://bugzilla.yoctoproject.org/show_bug.cgi?id=6437), starting from a clean state, as it becomes unmanageable, carrying too much history, making it difficult to grasp.

I'm just keeping the information that is still useful, that is a comment from Robert Berger, summarized and expanded by this mind mapping attachement: https://bugzilla.yoctoproject.org/attachment.cgi?id=4793

A developer workflow for production should be mentioned:

*) SDK for developer/bitbake for production build and Yocto/OE person
*) devtool for developer/devtool for Yocto/OE person

SW update solutions[1] should be mentioned for production, since people are reinventing all the time what's already there.

The following can be used
*) for "hardening" the production image
*) to be able to see what meta-layers/branch/commit-id were used to build the image and whether something was modified without being checked in
*) what packages are in the rootfs (without a package manager)

- cve-check.bbclass
- buildhistory.bbclass
- image-buildinfo.bbclass
- static code checks: https://github.com/priv-kweihmann/meta-sca
- I use this[2] to write /etc/image-manifest (all packages) into my rootfs

you can see here[3] how the output of image-buildinfo.bbclass and image-manifestinfo.bbclass looks like.

Something like the oss-review toolkit[4] could be used to help with license compliance. I am not sure yet whether this should be outside of the YP or integrated with it. 

[1] https://wiki.yoctoproject.org/wiki/System_Update

[2] https://gitlab.com/meta-layers/meta-resy/-/blob/dunfell/classes/image-manifestinfo.bbclass

[3] https://hub.docker.com/r/yoctotrainer/app-container-tensorflow-oci

[4] https://github.com/tsteenbe/ort
Comment 1 Michael Opdenacker 2021-07-15 09:33:24 UTC
Some additional inputs from Randy MacLeod:

- local source mirrors
- strategies for handling the git cloned repos 
    (use local branches and rebase vs bbappend )
Comment 2 Michael Opdenacker 2021-07-15 09:36:07 UTC
Setting the target milestone to "Future". This enhancement is too broad to be quickly addressed anyway. This will take time, but it's worth keeping the good ideas in mind when improving the documentation.
Comment 3 Michael Opdenacker 2021-07-15 09:39:45 UTC
*** Bug 6437 has been marked as a duplicate of this bug. ***
Comment 4 Robert Berger 2021-07-29 19:55:31 UTC
Is this here the place to collect ideas?
Comment 5 Michael Opdenacker 2021-07-30 10:17:55 UTC
Actually, we discussed this during the bug triage meeting and it turns out that these too wide bugs last forever and can never be fixed.

I slept on it and realize using the wiki for collecting such ideas is probably the best idea.

Let me propose something.
Comment 6 Michael Opdenacker 2021-07-30 15:45:03 UTC
Moved ideas to https://wiki.yoctoproject.org/wiki/Documentation_Production_Workflow

Please contribute to this wiki page from now on
(and send doc contribution patches too!)

Closing this bug