CI: split release tags - RC-Android-* (APK), RC-iOS-* (iOS), Release-* (both)
Build iOS / build (push) Failing after 1m55s

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Ayushya Amitabh
2026-10-07 19:15:29 -04:00
co-authored by Claude Sonnet 5.5
parent ca4afb2ed7
commit 0ea98363de
4 changed files with 24 additions and 15 deletions
+5 -3
View File
@@ -113,9 +113,11 @@ in this order: a local `android/key.properties` (gitignored — points at a
gitignored keystore file, e.g. `android/app/release-keystore.jks`), then gitignored keystore file, e.g. `android/app/release-keystore.jks`), then
CI env vars (`RELEASE_KEYSTORE_PATH`/`_PASSWORD`, `RELEASE_KEY_ALIAS`/ CI env vars (`RELEASE_KEYSTORE_PATH`/`_PASSWORD`, `RELEASE_KEY_ALIAS`/
`_PASSWORD`, set from the same repo secrets by both `.gitea/workflows/ `_PASSWORD`, set from the same repo secrets by both `.gitea/workflows/
build.yml`, triggered by `RC*` tags and producing a sideloadable APK, and build.yml`, triggered by `RC-Android-*` tags and producing a sideloadable
`.gitea/workflows/release.yml`, triggered by `Release-*` tags and producing APK, and `.gitea/workflows/release.yml`, triggered by `Release-*` tags and
the `.aab` Play Console wants), then falls back to the debug key if neither producing the `.aab` Play Console wants; `.gitea/workflows/ios.yml` builds
and uploads the signed iOS app to TestFlight on `RC-iOS-*` and `Release-*`
tags, on a self-hosted macOS runner), then falls back to the debug key if neither
is configured. As long as the same dedicated release keystore backs both is configured. As long as the same dedicated release keystore backs both
`key.properties` locally and the Gitea secrets, local release builds and `key.properties` locally and the Gitea secrets, local release builds and
CI-built release APKs share one signature, so `adb install -r` works CI-built release APKs share one signature, so `adb install -r` works
+6 -5
View File
@@ -1,12 +1,13 @@
name: Build APK name: Build APK
# Deliberately not "on every push" - only when a release-candidate tag # Deliberately not "on every push" - only when an Android release-candidate
# (RC1, RC2, RC2026.1, ...) is pushed. Tag the commit you want built: # tag (RC-Android-1, RC-Android-2, ...) is pushed. Tag the commit you want built:
# git tag RC1 && git push origin RC1 # git tag RC-Android-1 && git push origin RC-Android-1
# iOS has its own RC-iOS-* tags (ios.yml); Release-* builds both platforms.
on: on:
push: push:
tags: tags:
- "RC*" - "RC-Android-*"
jobs: jobs:
build: build:
@@ -72,7 +73,7 @@ jobs:
# talks to this same Gitea instance automatically via the # talks to this same Gitea instance automatically via the
# `github.token`/`github.server_url` context Gitea Actions # `github.token`/`github.server_url` context Gitea Actions
# provides for compatibility. Release is named/tagged after # provides for compatibility. Release is named/tagged after
# whatever tag triggered this run (e.g. "RC1"). # whatever tag triggered this run (e.g. "RC-Android-1").
uses: akkuman/gitea-release-action@v1 uses: akkuman/gitea-release-action@v1
with: with:
files: ${{ env.APK_PATH }} files: ${{ env.APK_PATH }}
+11 -5
View File
@@ -1,14 +1,18 @@
name: Build iOS name: Build iOS
# Same trigger as the Play Store bundle (release.yml): a real release tag. # Tag scheme (shared with the Android workflows):
# git tag Release-1.0.0 && git push origin Release-1.0.0 # Release-<version> -> release.yml (Play bundle) AND this workflow
# Builds a signed .ipa, attaches it to the Gitea release, and uploads it to # RC-Android-<n> -> build.yml (APK) only
# TestFlight. Needs a Mac runner registered with the `macos` label (act_runner # RC-iOS-<n> -> this workflow only
# in host mode) with Xcode installed; Linux runners cannot build iOS. # git tag RC-iOS-1 && git push origin RC-iOS-1
# Builds a signed .ipa and uploads it to TestFlight. Needs a Mac runner
# registered with the `macos` label (gitea-runner in host mode) with Xcode
# installed; Linux runners cannot build iOS.
on: on:
push: push:
tags: tags:
- "Release-*" - "Release-*"
- "RC-iOS-*"
jobs: jobs:
build: build:
@@ -23,6 +27,8 @@ jobs:
channel: stable channel: stable
- name: Check tag matches pubspec version - name: Check tag matches pubspec version
# Only Release-* tags carry a version; RC-iOS-* tags are free-form.
if: startsWith(github.ref_name, 'Release-')
run: | run: |
VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1) VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1)
if [ "${GITHUB_REF_NAME}" != "Release-${VERSION}" ]; then if [ "${GITHUB_REF_NAME}" != "Release-${VERSION}" ]; then
+2 -2
View File
@@ -3,7 +3,7 @@ name: Build App Bundle
# Deliberately not "on every push" - only when a real release tag (Release-1.0.0, # Deliberately not "on every push" - only when a real release tag (Release-1.0.0,
# Release-1.2.3, ...) is pushed. Tag the commit you want built: # Release-1.2.3, ...) is pushed. Tag the commit you want built:
# git tag Release-1.0.0 && git push origin Release-1.0.0 # git tag Release-1.0.0 && git push origin Release-1.0.0
# Unlike the RC* flow (build.yml), this builds the .aab Play Console wants, # Unlike the RC-Android-* flow (build.yml), this builds the .aab Play Console wants,
# not a sideloadable .apk. # not a sideloadable .apk.
on: on:
push: push:
@@ -56,7 +56,7 @@ jobs:
run: flutter analyze run: flutter analyze
- name: Decode release keystore - name: Decode release keystore
# Same key as the RC* APK builds, so a Play Store upload's signature # Same key as the RC-Android-* APK builds, so a Play Store upload's signature
# matches anything sideloaded from a release build. See # matches anything sideloaded from a release build. See
# android/app/build.gradle.kts. # android/app/build.gradle.kts.
run: echo "$RELEASE_KEYSTORE_BASE64" | base64 -d > "${{ runner.temp }}/release-keystore.jks" run: echo "$RELEASE_KEYSTORE_BASE64" | base64 -d > "${{ runner.temp }}/release-keystore.jks"