mirror of
https://github.com/R0m1k3/xtremobile.git
synced 2026-10-11 17:29:26 +02:00
fix(android): sign release APK with a stable keystore in CI
Release builds were signed with the debug keystore. On the GitHub runner
that keystore is generated fresh on every build, so each CI APK carried a
different signature and Android refused to install it over an existing
version ("App not installed").
- build.gradle.kts: read android/key.properties when present and use it
as the release signing config; fall back to debug otherwise so local
`flutter run --release` keeps working.
- build-apk.yml: decode the keystore from ANDROID_KEYSTORE_* secrets into
android/key.properties before building, and fail early if any secret
is missing instead of silently signing with a throwaway key.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3E5JovvDaQQ19D4UR258o
This commit is contained in:
1 parent
05ca6f85be
commit
c096532fec
2 files changed
+54
-3
No files matched your search
@@ -37,6 +37,30 @@ jobs:
|
|||||||
|
|
||||||
- run: flutter pub get
|
- run: flutter pub get
|
||||||
|
|
||||||
|
# Keystore fixe injecté via secrets : sans lui, Gradle signerait avec une
|
||||||
|
# clé debug générée sur le runner (différente à chaque build) et l'APK ne
|
||||||
|
# s'installerait pas par-dessus une version déjà présente sur l'appareil.
|
||||||
|
- name: Set up release signing
|
||||||
|
env:
|
||||||
|
KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
|
||||||
|
KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
|
||||||
|
KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
|
||||||
|
KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
|
||||||
|
run: |
|
||||||
|
for v in KEYSTORE_BASE64 KEYSTORE_PASSWORD KEY_ALIAS KEY_PASSWORD; do
|
||||||
|
if [ -z "${!v}" ]; then
|
||||||
|
echo "::error::Secret ANDROID_$v manquant — impossible de signer l'APK avec une clé stable."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
echo "$KEYSTORE_BASE64" | base64 -d > android/app/release.jks
|
||||||
|
{
|
||||||
|
echo "storeFile=release.jks"
|
||||||
|
echo "storePassword=$KEYSTORE_PASSWORD"
|
||||||
|
echo "keyAlias=$KEY_ALIAS"
|
||||||
|
echo "keyPassword=$KEY_PASSWORD"
|
||||||
|
} > android/key.properties
|
||||||
|
|
||||||
- name: Build release APK
|
- name: Build release APK
|
||||||
run: flutter build apk --release
|
run: flutter build apk --release
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
import java.util.Properties
|
||||||
|
|
||||||
plugins {
|
plugins {
|
||||||
id("com.android.application")
|
id("com.android.application")
|
||||||
id("kotlin-android")
|
id("kotlin-android")
|
||||||
@@ -5,6 +7,18 @@ plugins {
|
|||||||
id("dev.flutter.flutter-gradle-plugin")
|
id("dev.flutter.flutter-gradle-plugin")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Signature release stable : android/key.properties (ignoré par git) pointe vers
|
||||||
|
// un keystore fixe. Sans ce fichier, on retombe sur la clé debug locale pour que
|
||||||
|
// `flutter run --release` continue de marcher. La CI DOIT fournir key.properties,
|
||||||
|
// sinon chaque build serait signé avec une clé debug aléatoire et l'APK ne
|
||||||
|
// s'installerait pas par-dessus une version existante.
|
||||||
|
val keystoreProperties = Properties()
|
||||||
|
val keystorePropertiesFile = rootProject.file("key.properties")
|
||||||
|
val hasReleaseKeystore = keystorePropertiesFile.exists()
|
||||||
|
if (hasReleaseKeystore) {
|
||||||
|
keystorePropertiesFile.inputStream().use { keystoreProperties.load(it) }
|
||||||
|
}
|
||||||
|
|
||||||
android {
|
android {
|
||||||
namespace = "com.example.xtremflow"
|
namespace = "com.example.xtremflow"
|
||||||
compileSdk = flutter.compileSdkVersion
|
compileSdk = flutter.compileSdkVersion
|
||||||
@@ -30,11 +44,24 @@ android {
|
|||||||
versionName = flutter.versionName
|
versionName = flutter.versionName
|
||||||
}
|
}
|
||||||
|
|
||||||
|
signingConfigs {
|
||||||
|
if (hasReleaseKeystore) {
|
||||||
|
create("release") {
|
||||||
|
storeFile = file(keystoreProperties.getProperty("storeFile"))
|
||||||
|
storePassword = keystoreProperties.getProperty("storePassword")
|
||||||
|
keyAlias = keystoreProperties.getProperty("keyAlias")
|
||||||
|
keyPassword = keystoreProperties.getProperty("keyPassword")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
buildTypes {
|
buildTypes {
|
||||||
release {
|
release {
|
||||||
// TODO: Add your own signing config for the release build.
|
signingConfig = if (hasReleaseKeystore) {
|
||||||
// Signing with the debug keys for now, so `flutter run --release` works.
|
signingConfigs.getByName("release")
|
||||||
signingConfig = signingConfigs.getByName("debug")
|
} else {
|
||||||
|
signingConfigs.getByName("debug")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in new issue
Block a user