# Release automation for git.comunes.org (Forgejo Actions). # # Pushing a tag `v*` runs two independent jobs: # play - build the signed AAB and ship it to Google Play (internal). # fdroid_reference- build the per-ABI reference APKs the SAME way F-Droid will # (fdroid build inside the fdroidserver buildserver image), # sign them with the tane-upload key, and attach them to the # Forgejo release. F-Droid re-runs `fdroid build` on the same # commit+recipe+image, gets byte-identical output, verifies our # signature (AllowedAPKSigningKeys) and publishes OUR APK — so # F-Droid and Play share the same signing key. # # All credentials come from repo secrets (Settings > Actions > Secrets): # TANE_KEYSTORE_BASE64 base64 of the dedicated tane-upload.jks # TANE_KEYSTORE_PASSWORD store password # TANE_KEY_ALIAS tane-upload # TANE_KEY_PASSWORD key password # SUPPLY_JSON_KEY_DATA Google Play service-account JSON # # NOTE: `runs-on` must match a label your Forgejo runner registered with. # The fdroid_reference job pulls a large image (~2 GB) and builds tesseract from # source, so it is slow (~20-40 min); the play job is independent and unaffected. name: release on: push: tags: - 'v*' jobs: play: runs-on: docker container: image: ghcr.io/cirruslabs/flutter:3.41.9 steps: # Manual git checkout (no Node): the flutter image has no node, so JS # actions like actions/checkout@v4 fail with "exec: node: not found". - name: Checkout env: TOKEN: ${{ github.token }} run: | git config --global --add safe.directory '*' git init -q . git remote add origin "http://x-access-token:${TOKEN}@forgejo:3000/${GITHUB_REPOSITORY}.git" git fetch -q --depth 1 origin "${GITHUB_SHA}" git checkout -q FETCH_HEAD - name: Generate code (i18n + Drift) working-directory: apps/app_seeds run: | flutter pub get dart run slang dart run build_runner build --delete-conflicting-outputs - name: Materialize signing material from secrets working-directory: apps/app_seeds env: TANE_KEYSTORE_BASE64: ${{ secrets.TANE_KEYSTORE_BASE64 }} TANE_KEYSTORE_PASSWORD: ${{ secrets.TANE_KEYSTORE_PASSWORD }} TANE_KEY_ALIAS: ${{ secrets.TANE_KEY_ALIAS }} TANE_KEY_PASSWORD: ${{ secrets.TANE_KEY_PASSWORD }} run: | echo "$TANE_KEYSTORE_BASE64" | base64 -d > "$GITHUB_WORKSPACE/tane-upload.jks" cat > android/key.properties < /tmp/ks.jks api="http://forgejo:3000/api/v1/repos/${GITHUB_REPOSITORY}" tag="${GITHUB_REF_NAME}" curl -sf -X POST "$api/releases" \ -H "Authorization: token ${TOKEN}" -H 'Content-Type: application/json' \ -d "{\"tag_name\":\"${tag}\",\"name\":\"${tag}\"}" >/dev/null || true rid=$(curl -sf -H "Authorization: token ${TOKEN}" "$api/releases/tags/${tag}" \ | python3 -c 'import sys,json;print(json.load(sys.stdin)["id"])') for f in unsigned/org.comunes.tane_*.apk; do vc=$(echo "$f" | sed -E 's/.*_([0-9]+)\.apk/\1/') case $((vc % 10)) in 1) abi=armeabi-v7a ;; 2) abi=arm64-v8a ;; 3) abi=x86_64 ;; *) echo "unexpected versionCode $vc"; exit 1 ;; esac out="/tmp/app-${abi}-release.apk" "$apksigner" sign --ks /tmp/ks.jks --ks-key-alias "$TANE_KEY_ALIAS" \ --ks-pass "pass:$TANE_KEYSTORE_PASSWORD" --key-pass "pass:$TANE_KEY_PASSWORD" \ --out "$out" "$f" curl -sf -X POST "$api/releases/${rid}/assets?name=app-${abi}-release.apk" \ -H "Authorization: token ${TOKEN}" \ -F "attachment=@${out};type=application/vnd.android.package-archive" echo "uploaded app-${abi}-release.apk (from ${f##*/})" done rm -f /tmp/ks.jks