Release: also build AAB; fix keystore key-password guidance
- release.yml android job: build APK + AAB (bundleRelease/bundleDebug) - androidApp: versionCode overridable via -PappVersionCode (Play requires an incrementing versionCode per upload) - make_release_keystore.sh: PKCS12 has no separate key password (keytool ignores -keypass) — print the store password for ANDROID_KEY_PASSWORD
This commit is contained in:
1 parent
7309158e12
commit
1f182a7e7e
3 files changed
+18
-8
No files matched your search
@@ -113,24 +113,31 @@ jobs:
|
|||||||
echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)"
|
echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Build APK
|
- name: Build APK + AAB
|
||||||
run: |
|
run: |
|
||||||
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
|
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
|
||||||
cd app
|
cd app
|
||||||
if [ -n "$ANDROID_KEYSTORE_FILE" ]; then
|
if [ -n "$ANDROID_KEYSTORE_FILE" ]; then
|
||||||
./gradlew :androidApp:assembleRelease -PappVersion="$VERSION"
|
# APK for direct sideloading, AAB for Play Store uploads.
|
||||||
|
./gradlew :androidApp:assembleRelease :androidApp:bundleRelease -PappVersion="$VERSION"
|
||||||
cp androidApp/build/outputs/apk/release/androidApp-release.apk \
|
cp androidApp/build/outputs/apk/release/androidApp-release.apk \
|
||||||
"$GITHUB_WORKSPACE/iris-android-v$VERSION.apk"
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION.apk"
|
||||||
|
cp androidApp/build/outputs/bundle/release/androidApp-release.aab \
|
||||||
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION.aab"
|
||||||
else
|
else
|
||||||
./gradlew :androidApp:assembleDebug -PappVersion="$VERSION"
|
./gradlew :androidApp:assembleDebug :androidApp:bundleDebug -PappVersion="$VERSION"
|
||||||
cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \
|
cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \
|
||||||
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk"
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk"
|
||||||
|
cp androidApp/build/outputs/bundle/debug/androidApp-debug.aab \
|
||||||
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.aab"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
- uses: actions/upload-artifact@v4
|
- uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: android
|
name: android
|
||||||
path: iris-android-*.apk
|
path: |
|
||||||
|
iris-android-*.apk
|
||||||
|
iris-android-*.aab
|
||||||
|
|
||||||
desktop:
|
desktop:
|
||||||
name: Build desktop (Linux, jpackage)
|
name: Build desktop (Linux, jpackage)
|
||||||
|
|||||||
@@ -13,7 +13,9 @@ android {
|
|||||||
applicationId = "dev.iris.app"
|
applicationId = "dev.iris.app"
|
||||||
minSdk = 29
|
minSdk = 29
|
||||||
targetSdk = 34
|
targetSdk = 34
|
||||||
versionCode = 1
|
// Play Store requires an incrementing versionCode per upload; CI can
|
||||||
|
// pass -PappVersionCode=<n>. Local builds keep the default.
|
||||||
|
versionCode = (project.findProperty("appVersionCode")?.toString()?.toIntOrNull()) ?: 1
|
||||||
// CI passes -PappVersion=<version> (release workflow); local builds
|
// CI passes -PappVersion=<version> (release workflow); local builds
|
||||||
// keep the default.
|
// keep the default.
|
||||||
versionName = (project.findProperty("appVersion") as? String) ?: "0.1.0"
|
versionName = (project.findProperty("appVersion") as? String) ?: "0.1.0"
|
||||||
|
|||||||
@@ -16,13 +16,14 @@ if [ -e "$OUT" ]; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# PKCS12 keystores do not support a separate key password (keytool ignores
|
||||||
|
# -keypass), so one password covers both the store and the key.
|
||||||
STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
|
STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
|
||||||
KEY_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
|
|
||||||
|
|
||||||
keytool -genkeypair -v \
|
keytool -genkeypair -v \
|
||||||
-keystore "$OUT" -storetype PKCS12 \
|
-keystore "$OUT" -storetype PKCS12 \
|
||||||
-alias iris -keyalg RSA -keysize 2048 -validity 10000 \
|
-alias iris -keyalg RSA -keysize 2048 -validity 10000 \
|
||||||
-storepass "$STORE_PASS" -keypass "$KEY_PASS" \
|
-storepass "$STORE_PASS" \
|
||||||
-dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE"
|
-dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE"
|
||||||
|
|
||||||
echo
|
echo
|
||||||
@@ -35,4 +36,4 @@ echo " ANDROID_KEYSTORE_BASE64 = $(base64 -w0 "$OUT")"
|
|||||||
echo
|
echo
|
||||||
echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS"
|
echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS"
|
||||||
echo " ANDROID_KEY_ALIAS = iris"
|
echo " ANDROID_KEY_ALIAS = iris"
|
||||||
echo " ANDROID_KEY_PASSWORD = $KEY_PASS"
|
echo " ANDROID_KEY_PASSWORD = $STORE_PASS # same: PKCS12 has no separate key password"
|
||||||
Reference in new issue
Block a user