- fastlane: Appfile/Fastfile/Gemfile with deploy_play lane (AAB -> Play internal track) - CI: tag-gated build:android (signed AAB/APK from CI secrets) + deploy:play jobs - F-Droid: fdroiddata build recipe at docs/fdroid/org.comunes.tane.yml - Play compliance: Data Safety / content-rating answer sheet (docs/legal/internal) - docs/release.md: automated tag-triggered flow, dedicated tane-upload keystore - pubspec: description now mentions the market, not just the inventory
145 lines
4.8 KiB
YAML
145 lines
4.8 KiB
YAML
# CI for Tane. Mirrors the local verification gate (analyze + test +
|
|
# coverage) from docs/design/testing.md. Adapt to GitHub Actions if the
|
|
# canonical remote changes; the commands are the same.
|
|
#
|
|
# Uses the official Flutter Docker image. Pin the version to match the
|
|
# developer toolchain (Flutter 3.41.x / Dart 3.11.x).
|
|
image: ghcr.io/cirruslabs/flutter:3.41.9
|
|
|
|
stages:
|
|
- analyze
|
|
- test
|
|
- build
|
|
- deploy
|
|
|
|
variables:
|
|
PUB_CACHE: "$CI_PROJECT_DIR/.pub-cache"
|
|
|
|
cache:
|
|
key: "$CI_COMMIT_REF_SLUG"
|
|
paths:
|
|
- .pub-cache/
|
|
|
|
before_script:
|
|
# SQLCipher so the "no plaintext at rest" security test actually runs (it
|
|
# skips where the library is absent). The -dev package ships the unversioned
|
|
# libsqlcipher.so symlink, which package:sqlite3 loads reliably.
|
|
- apt-get update -qq && apt-get install -y -qq libsqlcipher-dev
|
|
- flutter --version
|
|
- flutter pub get
|
|
|
|
analyze:
|
|
stage: analyze
|
|
script:
|
|
- dart format --output=none --set-exit-if-changed .
|
|
- flutter analyze
|
|
|
|
test:commons_core:
|
|
stage: test
|
|
script:
|
|
- cd packages/commons_core
|
|
- dart test
|
|
|
|
# Windows desktop build. Needs a Windows runner: on gitlab.com the SaaS
|
|
# `saas-windows-medium-amd64` shared runners (Windows Server 2022 with Visual
|
|
# Studio 2022 Build Tools — the C++ workload Flutter requires). Manual +
|
|
# allow_failure until the canonical remote actually has Windows runners.
|
|
build:windows:
|
|
stage: build
|
|
tags:
|
|
- saas-windows-medium-amd64
|
|
rules:
|
|
- when: manual
|
|
allow_failure: true
|
|
# The global Linux image is ignored on Windows shell runners; override the
|
|
# global before_script (apt-get) — this job runs in PowerShell.
|
|
before_script:
|
|
- git clone --depth 1 -b stable https://github.com/flutter/flutter.git "$env:CI_PROJECT_DIR\.flutter"
|
|
- $env:PATH = "$env:CI_PROJECT_DIR\.flutter\bin;$env:PATH"
|
|
- flutter --version
|
|
- flutter pub get
|
|
script:
|
|
- cd apps\app_seeds
|
|
- dart run slang
|
|
- dart run build_runner build --delete-conflicting-outputs
|
|
- flutter build windows --release
|
|
artifacts:
|
|
paths:
|
|
- apps/app_seeds/build/windows/x64/runner/Release/
|
|
|
|
test:app_seeds:
|
|
stage: test
|
|
script:
|
|
- cd apps/app_seeds
|
|
# slang is generated via its CLI (disabled in build_runner); Drift via build_runner.
|
|
- dart run slang
|
|
- dart run build_runner build --delete-conflicting-outputs
|
|
- flutter test --coverage
|
|
coverage: '/lines\.*: \d+\.\d+\%/'
|
|
artifacts:
|
|
paths:
|
|
- apps/app_seeds/coverage/lcov.info
|
|
reports:
|
|
coverage_report:
|
|
coverage_format: cobertura
|
|
path: apps/app_seeds/coverage/cobertura.xml
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Release automation. Runs ONLY on tags, so it never touches the per-push gate.
|
|
# Password-free: signing + Play credentials come from masked+protected CI vars.
|
|
# Required CI variables (Settings > CI/CD > Variables), set once:
|
|
# TANE_KEYSTORE_BASE64 base64 of the dedicated Tane upload keystore (.jks)
|
|
# TANE_KEYSTORE_PASSWORD store password
|
|
# TANE_KEY_ALIAS key alias (tane-upload)
|
|
# TANE_KEY_PASSWORD key password
|
|
# SUPPLY_JSON_KEY_DATA Google Play service-account JSON (raw file contents)
|
|
# Tag a commit (e.g. `git tag v0.1.0 && git push --tags`) to build + publish.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# Build the signed release artifacts (AAB for Play, APK for sideload/QA).
|
|
build:android:
|
|
stage: build
|
|
rules:
|
|
- if: '$CI_COMMIT_TAG'
|
|
script:
|
|
- cd apps/app_seeds
|
|
- dart run slang
|
|
- dart run build_runner build --delete-conflicting-outputs
|
|
# Materialize the signing material from CI secrets (never in the repo).
|
|
- echo "$TANE_KEYSTORE_BASE64" | base64 -d > "$CI_PROJECT_DIR/tane-upload.jks"
|
|
- |
|
|
cat > android/key.properties <<EOF
|
|
storeFile=$CI_PROJECT_DIR/tane-upload.jks
|
|
storePassword=$TANE_KEYSTORE_PASSWORD
|
|
keyAlias=$TANE_KEY_ALIAS
|
|
keyPassword=$TANE_KEY_PASSWORD
|
|
EOF
|
|
- flutter build appbundle --release
|
|
- flutter build apk --release
|
|
# Don't leave signing material in the workspace/cache.
|
|
- rm -f android/key.properties "$CI_PROJECT_DIR/tane-upload.jks"
|
|
artifacts:
|
|
paths:
|
|
- apps/app_seeds/build/app/outputs/bundle/release/app-release.aab
|
|
- apps/app_seeds/build/app/outputs/flutter-apk/app-release.apk
|
|
expire_in: 90 days
|
|
|
|
# Upload the AAB + store listing to Google Play (internal track) via fastlane.
|
|
# Needs a Ruby image, not the Flutter one, so it overrides the global setup.
|
|
deploy:play:
|
|
stage: deploy
|
|
image: ruby:3.2
|
|
needs:
|
|
- job: build:android
|
|
artifacts: true
|
|
rules:
|
|
- if: '$CI_COMMIT_TAG'
|
|
before_script:
|
|
- cd apps/app_seeds
|
|
- bundle install --path vendor/bundle
|
|
script:
|
|
- bundle exec fastlane deploy_play
|
|
cache:
|
|
key: "fastlane-gems"
|
|
paths:
|
|
- apps/app_seeds/vendor/bundle/
|