#!/usr/bin/env bash # One-time setup: create the Android release keystore and print the values to # paste into Gitea (repo -> Settings -> Actions -> Secrets). # # Usage: scripts/make_release_keystore.sh [output-file] # (default: ~/iris-release.keystore) # # WARNING: back up the keystore file immediately. If it is lost, the app can # never be updated on users' phones (a new key = a brand-new app as far as # Android is concerned). set -euo pipefail OUT="${1:-$HOME/iris-release.keystore}" if [ -e "$OUT" ]; then echo "Refusing to overwrite existing file: $OUT" >&2 exit 1 fi # PKCS12 keystores do not support a separate key password (keytool ignores # -keypass), so one password covers both the store and the key. STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')" keytool -genkeypair -v \ -keystore "$OUT" -storetype PKCS12 \ -alias iris -keyalg RSA -keysize 2048 -validity 10000 \ -storepass "$STORE_PASS" \ -dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE" echo echo "Keystore written to: $OUT" echo ">>> Back it up NOW (password manager / cloud storage). <<<" echo echo "Add these four secrets in Gitea (repo -> Settings -> Actions -> Secrets):" echo echo " ANDROID_KEYSTORE_BASE64 = $(base64 -w0 "$OUT")" echo echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS" echo " ANDROID_KEY_ALIAS = iris" echo " ANDROID_KEY_PASSWORD = $STORE_PASS # same: PKCS12 has no separate key password"