name: Build & Release APK on: push: branches: [main] jobs: check: # Fast fail: lockfile sync, types, lint — catches in ~2 min what would # otherwise kill the APK build twenty minutes in. runs-on: macbook steps: - name: Checkout run: | git init -q . git fetch -q --depth 1 "https://git.rehbock.xyz/${{ github.repository }}.git" "${{ github.sha }}" git checkout -q -f FETCH_HEAD git clean -qfd - name: Lockfile + typecheck + lint run: | export PATH="$HOME/.hermes/node/bin:$PATH" cd app npm ci --no-audit --no-fund npx tsc --noEmit npx eslint . - name: Notify failure if: failure() env: NTFY_TOKEN: ${{ secrets.NTFY_TOKEN }} run: | [ -n "$NTFY_TOKEN" ] || { echo "NTFY_TOKEN not set — skipping notification"; exit 0; } curl -s -H "Authorization: Bearer $NTFY_TOKEN" -H "Title: gtd CI: check failed" -H "Priority: high" \ -d "typecheck/lint/lockfile failed at ${{ github.sha }} — https://git.rehbock.xyz/marcus/gtd/actions" \ https://ntfy.rehbock.xyz/gtd-ci build: needs: check # Runs natively on the MacBook Air (gitea-runner in host mode, label # "macbook"): Java 21 from Homebrew, the Android SDK from Android Studio, # node 22 from ~/.hermes. No container, no SDK download. runs-on: macbook env: ANDROID_HOME: /Users/marcus/Library/Android/sdk JAVA_HOME: /opt/homebrew/opt/openjdk@21/libexec/openjdk.jdk/Contents/Home steps: - name: Checkout run: | git init -q . git fetch -q --depth 1 "https://git.rehbock.xyz/${{ github.repository }}.git" "${{ github.sha }}" git checkout -q -f FETCH_HEAD git clean -qfd - name: Toolchain run: | export PATH="$HOME/.hermes/node/bin:$PATH" node --version "$JAVA_HOME/bin/java" -version test -d "$ANDROID_HOME/platforms/android-36" test -d "$ANDROID_HOME/build-tools/36.0.0" - name: Install app dependencies run: | export PATH="$HOME/.hermes/node/bin:$PATH" cd app && npm ci --no-audit --no-fund - name: Decode signing keystore env: KEYSTORE_B64: ${{ secrets.KEYSTORE_B64 }} run: echo "$KEYSTORE_B64" | base64 --decode > /tmp/release.jks - name: Build signed release APK env: KEYSTORE_FILE: /tmp/release.jks KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }} # EAS-managed keystore (since v1.16) — alias is EAS-generated, and the # key password can differ from the store password. KEY_ALIAS: a5ff13aa8571055bcaecbaca29a548ae KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }} VERSION_CODE: ${{ github.run_number }} VERSION_NAME: 1.${{ github.run_number }} run: | export PATH="$HOME/.hermes/node/bin:$PATH" cd app/android echo "sdk.dir=$ANDROID_HOME" > local.properties ./gradlew assembleRelease --no-daemon --console=plain - name: Publish Gitea release with APK env: TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | API="https://git.rehbock.xyz/api/v1/repos/${{ github.repository }}" TAG="v1.${{ github.run_number }}" APK=app/android/app/build/outputs/apk/release/app-release.apk test -f "$APK" curl -sf -X POST "$API/releases" \ -H "Authorization: token $TOKEN" -H "Content-Type: application/json" \ -d "{\"tag_name\":\"$TAG\",\"name\":\"$TAG\",\"body\":\"Automated build of commit ${{ github.sha }}\",\"target_commitish\":\"${{ github.sha }}\"}" \ > /tmp/release.json RID=$(grep -o '"id":[0-9]*' /tmp/release.json | head -1 | cut -d: -f2) echo "release id: $RID" curl -sf -X POST "$API/releases/$RID/assets?name=gtd-$TAG.apk" \ -H "Authorization: token $TOKEN" \ -F "attachment=@$APK;type=application/vnd.android.package-archive" >/dev/null echo "published $TAG" - name: Notify failure if: failure() env: NTFY_TOKEN: ${{ secrets.NTFY_TOKEN }} run: | [ -n "$NTFY_TOKEN" ] || { echo "NTFY_TOKEN not set — skipping notification"; exit 0; } curl -s -H "Authorization: Bearer $NTFY_TOKEN" -H "Title: gtd CI: APK build failed" -H "Priority: high" \ -d "release build failed at ${{ github.sha }} — https://git.rehbock.xyz/marcus/gtd/actions" \ https://ntfy.rehbock.xyz/gtd-ci