소스 정보
- 저장소
- coreos/coreos-installer
- 최근 소스 활동
- 2026년 5월 15일 18:37
- 감지된 SKILL.md 언어
- 영어
- 스타
- 244
- 포크
- 104
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/coreos/coreos-installer --skill signing-key-rotation명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | signing-key-rotation |
| description | Add a new Fedora signing key and drop the oldest one in coreos-installer |
src/signing-keys.ascdocs/release-notes.md with the additionsigning-keys: add Fedora {N} keysrc/signing-keys.ascdocs/release-notes.md with the removalsigning-keys: drop Fedora {N-3} keycoreos-installersrc/signing-keys.asc exists with current signing keysdocs/release-notes.md exists with an unreleased section at the top# Rotate keys for a new Fedora version
/signing-key-rotation 46
# Specify a custom old version to drop (default: NEW - 3)
/signing-key-rotation 46 --drop 43
# Include a tracker issue reference for the drop commit
/signing-key-rotation 46 --tracker https://github.com/coreos/fedora-coreos-tracker/issues/XXXX
Extract the new Fedora version number from the user's invocation. If not provided, ask for it.
NEW_VERSION = (from user input)
OLD_VERSION = NEW_VERSION - 3 (unless --drop is specified)
TRACKER_URL = (from --tracker, optional)
Run these validation checks:
# Verify signing-keys.asc exists
ls src/signing-keys.asc
# Check what keys are currently present
grep "Comment:" src/signing-keys.asc
# Verify the old key exists
grep "RPM-GPG-KEY-fedora-${OLD_VERSION}-primary" src/signing-keys.asc
# Verify the new key does NOT already exist
grep "RPM-GPG-KEY-fedora-${NEW_VERSION}-primary" src/signing-keys.asc
If the new key already exists, STOP and inform the user. If the old key does not exist, STOP and inform the user.
Fetch the key from Fedora's package sources:
URL: https://src.fedoraproject.org/rpms/fedora-repos/blob/rawhide/f/RPM-GPG-KEY-fedora-{NEW_VERSION}-primary
Use the WebFetch tool to download the page, then extract the raw PGP key block between -----BEGIN PGP PUBLIC KEY BLOCK----- and -----END PGP PUBLIC KEY BLOCK----- (inclusive).
If the page is not found or doesn't contain a PGP key block, STOP and inform the user that the key may not exist yet.
src/signing-keys.ascUsing the Edit tool, append to the end of src/signing-keys.asc:
-----END PGP PUBLIC KEY BLOCK----------BEGIN PGP PUBLIC KEY BLOCK----- through -----END PGP PUBLIC KEY BLOCK-----)Make sure the file ends with a newline.
Using the Edit tool on docs/release-notes.md, find the first "Major changes:" section (the unreleased version at the top) and add:
- Add Fedora {NEW_VERSION} signing key
The entry goes right after the "Major changes:" line. If there are already entries there, add it as the first bullet point. If the section is empty (just blank lines between "Major changes:" and the next heading), add it on the blank line.
Do NOT commit unless the user has asked you to commit. If they have, create the commit:
git add src/signing-keys.asc docs/release-notes.md
git commit -m "signing-keys: add Fedora {NEW_VERSION} key
Fedora {NEW_VERSION - 1} branched from rawhide, so rawhide is now F{NEW_VERSION}.
Ref: https://src.fedoraproject.org/rpms/fedora-repos/blob/rawhide/f/RPM-GPG-KEY-fedora-{NEW_VERSION}-primary"
src/signing-keys.ascUsing the Edit tool, find and remove the entire PGP key block that contains:
Comment: RPM-GPG-KEY-fedora-{OLD_VERSION}-primary
Remove from the blank line before -----BEGIN PGP PUBLIC KEY BLOCK----- through the -----END PGP PUBLIC KEY BLOCK----- line (inclusive). Also remove any trailing blank line that was part of the separator between key blocks.
Using the Edit tool on docs/release-notes.md, change:
- Add Fedora {NEW_VERSION} signing key
to:
- Add Fedora {NEW_VERSION} signing key; drop Fedora {OLD_VERSION} signing key
Do NOT commit unless the user has asked you to commit. If they have:
If a tracker URL was provided:
git add src/signing-keys.asc docs/release-notes.md
git commit -m "signing-keys: drop Fedora {OLD_VERSION} key
Ref: {TRACKER_URL}"
If no tracker URL:
git add src/signing-keys.asc docs/release-notes.md
git commit -m "signing-keys: drop Fedora {OLD_VERSION} key"
Run verification checks:
# Confirm exactly 4 key blocks (1 RHEL + 3 Fedora)
grep "Comment:" src/signing-keys.asc
# Verify the new key is present
grep "RPM-GPG-KEY-fedora-${NEW_VERSION}-primary" src/signing-keys.asc
# Verify the old key is gone
grep "RPM-GPG-KEY-fedora-${OLD_VERSION}-primary" src/signing-keys.asc
# (should return no match)
# Show the git log
git log --oneline -2
Optionally run cargo check to verify the build still works.
Present the user with a summary:
Signing key rotation complete:
Added: Fedora {NEW_VERSION} signing key
Dropped: Fedora {OLD_VERSION} signing key
Current keys in src/signing-keys.asc:
- RPM-GPG-KEY-redhat-release
- RPM-GPG-KEY-fedora-{OLD_VERSION + 1}-primary
- RPM-GPG-KEY-fedora-{OLD_VERSION + 2}-primary
- RPM-GPG-KEY-fedora-{NEW_VERSION}-primary
Commits created:
1. signing-keys: add Fedora {NEW_VERSION} key
2. signing-keys: drop Fedora {OLD_VERSION} key
Files modified:
- src/signing-keys.asc
- docs/release-notes.md
Next steps:
1. Push to a branch and open a PR
2. Get review and merge
This skill automates the following from the manual process:
src/signing-keys.ascsrc/signing-keys.ascdocs/release-notes.mdcargo test) - only cargo check is optionally run$ /signing-key-rotation 46
Validating inputs...
NEW_VERSION: 46
OLD_VERSION: 43 (46 - 3)
Current keys: redhat-release, fedora-43, fedora-44, fedora-45
Downloading Fedora 46 key from src.fedoraproject.org...
Found PGP key block (31 lines)
Adding Fedora 46 key to src/signing-keys.asc...
Appended key block to end of file
Updating docs/release-notes.md...
Added "Add Fedora 46 signing key" to Major changes
Created commit: signing-keys: add Fedora 46 key
Removing Fedora 43 key from src/signing-keys.asc...
Removed key block with Comment: RPM-GPG-KEY-fedora-43-primary
Updating docs/release-notes.md...
Updated to "Add Fedora 46 signing key; drop Fedora 43 signing key"
Created commit: signing-keys: drop Fedora 43 key
Verification:
Keys present: redhat-release, fedora-44, fedora-45, fedora-46
Key count: 4 (correct)
cargo check: passed
Signing key rotation complete!
.opencode/skills/signing-key-rotation/DESIGN.md.opencode/skills/signing-key-rotation/examples/example-1-add-f45-drop-f42.md.opencode/skills/signing-key-rotation/examples/example-2-add-f43-drop-f40.mdhttps://src.fedoraproject.org/rpms/fedora-repos/blob/rawhide/f/RPM-GPG-KEY-fedora-{N}-primaryhttps://github.com/coreos/fedora-coreos-tracker/issues