Requires updated repo secrets KEYSTORE_B64, KEYSTORE_PASSWORD, KEY_PASSWORD. Until they are set, CI release builds fail instead of shipping an APK signed with the old key that Obtainium would reject. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YE5FmDZmFnWxH6RXCZLcjj
126 lines
5.3 KiB
YAML
126 lines
5.3 KiB
YAML
name: Build & Release APK
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
check:
|
|
# Fast fail: lockfile sync, types, lint — catches in ~2 min what would
|
|
# otherwise kill the APK build twenty minutes in.
|
|
runs-on: desktop
|
|
container:
|
|
image: node:22
|
|
steps:
|
|
- name: Checkout
|
|
run: |
|
|
git init -q .
|
|
git fetch -q --depth 1 "https://git.rehbock.xyz/${{ github.repository }}.git" "${{ github.sha }}"
|
|
git checkout -q FETCH_HEAD
|
|
- name: Lockfile + typecheck + lint
|
|
run: |
|
|
cd app
|
|
npm ci --no-audit --no-fund
|
|
npx tsc --noEmit
|
|
npx eslint .
|
|
- name: Notify failure
|
|
if: failure()
|
|
env:
|
|
NTFY_TOKEN: ${{ secrets.NTFY_TOKEN }}
|
|
run: |
|
|
[ -n "$NTFY_TOKEN" ] || { echo "NTFY_TOKEN not set — skipping notification"; exit 0; }
|
|
curl -s -H "Authorization: Bearer $NTFY_TOKEN" -H "Title: gtd CI: check failed" -H "Priority: high" \
|
|
-d "typecheck/lint/lockfile failed at ${{ github.sha }} — https://git.rehbock.xyz/marcus/gtd/actions" \
|
|
https://ntfy.rehbock.xyz/gtd-ci
|
|
|
|
build:
|
|
needs: check
|
|
# RN/NDK builds starve the 4-core VPS — run on the desktop runner
|
|
# (marcusDesktop). Jobs queue while the desktop is off and start when it
|
|
# comes online; switch back to ubuntu-latest to build on the VPS.
|
|
runs-on: desktop
|
|
container:
|
|
image: eclipse-temurin:21-jdk
|
|
steps:
|
|
# actions/checkout needs node, which this container lacks — clone directly
|
|
- name: Checkout
|
|
run: |
|
|
apt-get update -qq && apt-get install -y -qq git unzip curl >/dev/null
|
|
git init -q .
|
|
git fetch -q --depth 1 "https://git.rehbock.xyz/${{ github.repository }}.git" "${{ github.sha }}"
|
|
git checkout -q FETCH_HEAD
|
|
|
|
- name: Install Node.js
|
|
run: |
|
|
curl -fsSL https://deb.nodesource.com/setup_22.x | bash - >/dev/null 2>&1
|
|
apt-get install -y -qq nodejs >/dev/null
|
|
node --version
|
|
|
|
- name: Install Android SDK
|
|
# $HOME/android-sdk is a persistent runner volume — skip when warm.
|
|
run: |
|
|
if [ ! -d "$HOME/android-sdk/platforms/android-36" ]; then
|
|
mkdir -p "$HOME/android-sdk/cmdline-tools"
|
|
curl -sLo /tmp/ct.zip https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
|
|
unzip -q /tmp/ct.zip -d /tmp
|
|
mv /tmp/cmdline-tools "$HOME/android-sdk/cmdline-tools/latest"
|
|
yes | "$HOME/android-sdk/cmdline-tools/latest/bin/sdkmanager" --sdk_root="$HOME/android-sdk" --licenses >/dev/null 2>&1 || true
|
|
"$HOME/android-sdk/cmdline-tools/latest/bin/sdkmanager" --sdk_root="$HOME/android-sdk" \
|
|
"platform-tools" "platforms;android-36" "build-tools;36.0.0" >/dev/null
|
|
else
|
|
echo "SDK cache warm — skipping install"
|
|
fi
|
|
|
|
- name: Install app dependencies
|
|
run: cd app && npm ci --no-audit --no-fund
|
|
|
|
- name: Decode signing keystore
|
|
env:
|
|
KEYSTORE_B64: ${{ secrets.KEYSTORE_B64 }}
|
|
run: echo "$KEYSTORE_B64" | base64 -d > /tmp/release.jks
|
|
|
|
- name: Build signed release APK
|
|
env:
|
|
KEYSTORE_FILE: /tmp/release.jks
|
|
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
|
|
# EAS-managed keystore (since v1.16) — alias is EAS-generated, and the
|
|
# key password can differ from the store password.
|
|
KEY_ALIAS: a5ff13aa8571055bcaecbaca29a548ae
|
|
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
|
|
VERSION_CODE: ${{ github.run_number }}
|
|
VERSION_NAME: 1.${{ github.run_number }}
|
|
run: |
|
|
export ANDROID_HOME="$HOME/android-sdk"
|
|
cd app/android
|
|
echo "sdk.dir=$ANDROID_HOME" > local.properties
|
|
./gradlew assembleRelease --no-daemon --console=plain
|
|
|
|
- name: Publish Gitea release with APK
|
|
env:
|
|
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
API="https://git.rehbock.xyz/api/v1/repos/${{ github.repository }}"
|
|
TAG="v1.${{ github.run_number }}"
|
|
APK=app/android/app/build/outputs/apk/release/app-release.apk
|
|
test -f "$APK"
|
|
curl -sf -X POST "$API/releases" \
|
|
-H "Authorization: token $TOKEN" -H "Content-Type: application/json" \
|
|
-d "{\"tag_name\":\"$TAG\",\"name\":\"$TAG\",\"body\":\"Automated build of commit ${{ github.sha }}\",\"target_commitish\":\"${{ github.sha }}\"}" \
|
|
> /tmp/release.json
|
|
RID=$(grep -o '"id":[0-9]*' /tmp/release.json | head -1 | cut -d: -f2)
|
|
echo "release id: $RID"
|
|
curl -sf -X POST "$API/releases/$RID/assets?name=gtd-$TAG.apk" \
|
|
-H "Authorization: token $TOKEN" \
|
|
-F "attachment=@$APK;type=application/vnd.android.package-archive" >/dev/null
|
|
echo "published $TAG"
|
|
|
|
- name: Notify failure
|
|
if: failure()
|
|
env:
|
|
NTFY_TOKEN: ${{ secrets.NTFY_TOKEN }}
|
|
run: |
|
|
[ -n "$NTFY_TOKEN" ] || { echo "NTFY_TOKEN not set — skipping notification"; exit 0; }
|
|
curl -s -H "Authorization: Bearer $NTFY_TOKEN" -H "Title: gtd CI: APK build failed" -H "Priority: high" \
|
|
-d "release build failed at ${{ github.sha }} — https://git.rehbock.xyz/marcus/gtd/actions" \
|
|
https://ntfy.rehbock.xyz/gtd-ci
|