diff --git a/.claude/context/standards.md b/.claude/context/standards.md index 18d3836..dc8b0b3 100644 --- a/.claude/context/standards.md +++ b/.claude/context/standards.md @@ -113,9 +113,11 @@ in this order: a local `android/key.properties` (gitignored — points at a gitignored keystore file, e.g. `android/app/release-keystore.jks`), then CI env vars (`RELEASE_KEYSTORE_PATH`/`_PASSWORD`, `RELEASE_KEY_ALIAS`/ `_PASSWORD`, set from the same repo secrets by both `.gitea/workflows/ -build.yml`, triggered by `RC*` tags and producing a sideloadable APK, and -`.gitea/workflows/release.yml`, triggered by `Release-*` tags and producing -the `.aab` Play Console wants), then falls back to the debug key if neither +build.yml`, triggered by `RC-Android-*` tags and producing a sideloadable +APK, and `.gitea/workflows/release.yml`, triggered by `Release-*` tags and +producing the `.aab` Play Console wants; `.gitea/workflows/ios.yml` builds +and uploads the signed iOS app to TestFlight on `RC-iOS-*` and `Release-*` +tags, on a self-hosted macOS runner), then falls back to the debug key if neither is configured. As long as the same dedicated release keystore backs both `key.properties` locally and the Gitea secrets, local release builds and CI-built release APKs share one signature, so `adb install -r` works diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml index 8e7a8e8..e55836b 100644 --- a/.gitea/workflows/build.yml +++ b/.gitea/workflows/build.yml @@ -1,12 +1,13 @@ name: Build APK -# Deliberately not "on every push" - only when a release-candidate tag -# (RC1, RC2, RC2026.1, ...) is pushed. Tag the commit you want built: -# git tag RC1 && git push origin RC1 +# Deliberately not "on every push" - only when an Android release-candidate +# tag (RC-Android-1, RC-Android-2, ...) is pushed. Tag the commit you want built: +# git tag RC-Android-1 && git push origin RC-Android-1 +# iOS has its own RC-iOS-* tags (ios.yml); Release-* builds both platforms. on: push: tags: - - "RC*" + - "RC-Android-*" jobs: build: @@ -72,7 +73,7 @@ jobs: # talks to this same Gitea instance automatically via the # `github.token`/`github.server_url` context Gitea Actions # provides for compatibility. Release is named/tagged after - # whatever tag triggered this run (e.g. "RC1"). + # whatever tag triggered this run (e.g. "RC-Android-1"). uses: akkuman/gitea-release-action@v1 with: files: ${{ env.APK_PATH }} diff --git a/.gitea/workflows/ios.yml b/.gitea/workflows/ios.yml index 3caed23..d455de1 100644 --- a/.gitea/workflows/ios.yml +++ b/.gitea/workflows/ios.yml @@ -1,14 +1,18 @@ name: Build iOS -# Same trigger as the Play Store bundle (release.yml): a real release tag. -# git tag Release-1.0.0 && git push origin Release-1.0.0 -# Builds a signed .ipa, attaches it to the Gitea release, and uploads it to -# TestFlight. Needs a Mac runner registered with the `macos` label (act_runner -# in host mode) with Xcode installed; Linux runners cannot build iOS. +# Tag scheme (shared with the Android workflows): +# Release- -> release.yml (Play bundle) AND this workflow +# RC-Android- -> build.yml (APK) only +# RC-iOS- -> this workflow only +# git tag RC-iOS-1 && git push origin RC-iOS-1 +# Builds a signed .ipa and uploads it to TestFlight. Needs a Mac runner +# registered with the `macos` label (gitea-runner in host mode) with Xcode +# installed; Linux runners cannot build iOS. on: push: tags: - "Release-*" + - "RC-iOS-*" jobs: build: @@ -23,6 +27,8 @@ jobs: channel: stable - name: Check tag matches pubspec version + # Only Release-* tags carry a version; RC-iOS-* tags are free-form. + if: startsWith(github.ref_name, 'Release-') run: | VERSION=$(grep '^version:' pubspec.yaml | sed 's/version: //' | cut -d'+' -f1) if [ "${GITHUB_REF_NAME}" != "Release-${VERSION}" ]; then diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 12646e4..28e4799 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -3,7 +3,7 @@ name: Build App Bundle # Deliberately not "on every push" - only when a real release tag (Release-1.0.0, # Release-1.2.3, ...) is pushed. Tag the commit you want built: # git tag Release-1.0.0 && git push origin Release-1.0.0 -# Unlike the RC* flow (build.yml), this builds the .aab Play Console wants, +# Unlike the RC-Android-* flow (build.yml), this builds the .aab Play Console wants, # not a sideloadable .apk. on: push: @@ -56,7 +56,7 @@ jobs: run: flutter analyze - name: Decode release keystore - # Same key as the RC* APK builds, so a Play Store upload's signature + # Same key as the RC-Android-* APK builds, so a Play Store upload's signature # matches anything sideloaded from a release build. See # android/app/build.gradle.kts. run: echo "$RELEASE_KEYSTORE_BASE64" | base64 -d > "${{ runner.temp }}/release-keystore.jks"