Initial commit: FlatKontrol, a Kirigami Flatpak permissions manager

A KDE/Qt application to review and edit the permissions of installed
Flatpak applications, editing the same override files as Flatpak itself.
Covers shared subsystems, sockets, devices, features, filesystem access,
persistent paths, environment variables, D-Bus policies and portals.

Includes a Flatpak manifest and a CI workflow that publishes a bundle and
a hosted Flatpak repository on tagged releases.
This commit is contained in:
2026-06-30 19:31:10 -05:00
commit 3b639115c8
26 changed files with 4086 additions and 0 deletions
+103
View File
@@ -0,0 +1,103 @@
# SPDX-License-Identifier: GPL-3.0-or-later
name: Build and Publish Flatpak
on:
push:
tags:
- 'v*'
workflow_dispatch: {}
permissions:
contents: write # create releases / upload the bundle
pages: write # deploy the hosted Flatpak repo
id-token: write # required by actions/deploy-pages
concurrency:
group: pages
cancel-in-progress: false
jobs:
build:
name: Build Flatpak
runs-on: ubuntu-latest
container:
# Ships the KDE Platform/Sdk + flatpak-builder. Bump the tag to match
# runtime-version in the manifest.
image: ghcr.io/flathub-infra/flatpak-github-actions:kde-6.10
options: --privileged
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Build from the checked-out commit
run: |
python3 - <<'PY'
import re
p = "io.github.toservetheking.FlatKontrol.yml"
s = open(p).read()
s = re.sub(r" sources:.*\Z",
" sources:\n - type: dir\n path: .\n",
s, flags=re.S)
open(p, "w").write(s)
print(s)
PY
- name: Build repo and bundle
run: |
flatpak-builder --user --disable-rofiles-fuse --force-clean \
--default-branch=stable --repo=repo \
builddir io.github.toservetheking.FlatKontrol.yml
flatpak build-update-repo repo --generate-static-deltas
flatpak build-bundle repo \
io.github.toservetheking.FlatKontrol.flatpak \
io.github.toservetheking.FlatKontrol stable
- name: Add repo landing page and .flatpakrepo
run: |
cat > repo/flatkontrol.flatpakrepo <<'EOF'
[Flatpak Repo]
Title=FlatKontrol
Url=https://toservetheking.github.io/FlatKontrol/
Homepage=https://github.com/toservetheking/FlatKontrol
Description=Manage Flatpak permissions
EOF
cat > repo/index.html <<'EOF'
<!doctype html>
<meta charset="utf-8">
<title>FlatKontrol Flatpak repository</title>
<h1>FlatKontrol</h1>
<p>Add the repository and install:</p>
<pre>flatpak remote-add --if-not-exists --user flatkontrol https://toservetheking.github.io/FlatKontrol/flatkontrol.flatpakrepo
flatpak install --user flatkontrol io.github.toservetheking.FlatKontrol</pre>
<p>Or download the single-file bundle from the
<a href="https://github.com/toservetheking/FlatKontrol/releases">Releases page</a>.</p>
EOF
- name: Upload bundle artifact
uses: actions/upload-artifact@v4
with:
name: flatpak-bundle
path: io.github.toservetheking.FlatKontrol.flatpak
- name: Attach bundle to release
if: startsWith(github.ref, 'refs/tags/')
uses: softprops/action-gh-release@v2
with:
files: io.github.toservetheking.FlatKontrol.flatpak
- name: Upload Pages artifact
uses: actions/upload-pages-artifact@v3
with:
path: repo
deploy-pages:
name: Deploy hosted repo to Pages
needs: build
runs-on: ubuntu-latest
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Deploy
id: deployment
uses: actions/deploy-pages@v4