- release.yml android job: build APK + AAB (bundleRelease/bundleDebug) - androidApp: versionCode overridable via -PappVersionCode (Play requires an incrementing versionCode per upload) - make_release_keystore.sh: PKCS12 has no separate key password (keytool ignores -keypass) — print the store password for ANDROID_KEY_PASSWORD
40 lines
1.4 KiB
Bash
Executable File
40 lines
1.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# One-time setup: create the Android release keystore and print the values to
|
|
# paste into Gitea (repo -> Settings -> Actions -> Secrets).
|
|
#
|
|
# Usage: scripts/make_release_keystore.sh [output-file]
|
|
# (default: ~/iris-release.keystore)
|
|
#
|
|
# WARNING: back up the keystore file immediately. If it is lost, the app can
|
|
# never be updated on users' phones (a new key = a brand-new app as far as
|
|
# Android is concerned).
|
|
set -euo pipefail
|
|
|
|
OUT="${1:-$HOME/iris-release.keystore}"
|
|
if [ -e "$OUT" ]; then
|
|
echo "Refusing to overwrite existing file: $OUT" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# PKCS12 keystores do not support a separate key password (keytool ignores
|
|
# -keypass), so one password covers both the store and the key.
|
|
STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
|
|
|
|
keytool -genkeypair -v \
|
|
-keystore "$OUT" -storetype PKCS12 \
|
|
-alias iris -keyalg RSA -keysize 2048 -validity 10000 \
|
|
-storepass "$STORE_PASS" \
|
|
-dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE"
|
|
|
|
echo
|
|
echo "Keystore written to: $OUT"
|
|
echo ">>> Back it up NOW (password manager / cloud storage). <<<"
|
|
echo
|
|
echo "Add these four secrets in Gitea (repo -> Settings -> Actions -> Secrets):"
|
|
echo
|
|
echo " ANDROID_KEYSTORE_BASE64 = $(base64 -w0 "$OUT")"
|
|
echo
|
|
echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS"
|
|
echo " ANDROID_KEY_ALIAS = iris"
|
|
echo " ANDROID_KEY_PASSWORD = $STORE_PASS # same: PKCS12 has no separate key password"
|