Skip to content

Merge pull request #194 from appdevforall/release/ADFA-4677-v0.5.1-beta #26

Merge pull request #194 from appdevforall/release/ADFA-4677-v0.5.1-beta

Merge pull request #194 from appdevforall/release/ADFA-4677-v0.5.1-beta #26

name: Build and Release IIAB APKs
on:
push:
# Only triggers automatically when a release tag is pushed (e.g., v1.0.0)
tags:
- 'v*'
workflow_dispatch:
jobs:
build-and-release:
name: Build Release APKs & Upload to R2
runs-on: ubuntu-latest
defaults:
run:
working-directory: ./controller
steps:
- name: Checkout Code
uses: actions/checkout@v5
with:
submodules: recursive
# TODO (Future): Add a Jira step here to verify if the version exists in Jira
# or to extract release notes directly from a Jira board.
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: 'zulu'
java-version: '17'
cache: 'gradle'
- name: Grant execute permission for gradlew
run: chmod +x gradlew
# ADFA-4466: the google-services plugin needs google-services.json at build time;
# inject it from the dedicated K2Go analytics secret so the build compiles.
- name: Create google-services.json
env:
GOOGLE_SERVICES_JSON_K2GO_ANALYTICS: ${{ secrets.GOOGLE_SERVICES_JSON_K2GO_ANALYTICS }}
run: echo "$GOOGLE_SERVICES_JSON_K2GO_ANALYTICS" > app/google-services.json
- name: Decode Keystore
env:
ENCODED_STRING: ${{ secrets.KEYSTORE_BASE64 }}
run: |
echo "$ENCODED_STRING" | base64 -d > keystore.jks
# --- VERSION AUDIT ---
- name: Log Pinned Binary Version
run: |
echo "=========================================="
echo "Compiling with native binaries pinned to:"
cat binary_version.txt
echo ""
echo "=========================================="
# --- BUILD AND SIGNING ---
- name: Build and Sign Release APKs
env:
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
KEY_ALIAS: ${{ secrets.KEY_ALIAS }}
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
# ADFA-4533: GlitchTip DSN for release builds
SENTRY_DSN_RELEASE: ${{ secrets.SENTRY_DSN_RELEASE }}
run: |
./gradlew assembleRelease \
-Pandroid.injected.signing.store.file=$(pwd)/keystore.jks \
-Pandroid.injected.signing.store.password=$KEYSTORE_PASSWORD \
-Pandroid.injected.signing.key.alias=$KEY_ALIAS \
-Pandroid.injected.signing.key.password=$KEY_PASSWORD
- name: Upload APK Artifacts
uses: actions/upload-artifact@v6
with:
name: iiab-apks-release
path: controller/**/build/outputs/apk/release/*.apk
retention-days: 7
# --- GITHUB RELEASES ---
- name: Create GitHub Release
if: startsWith(github.ref, 'refs/tags/v')
uses: softprops/action-gh-release@v3
with:
# Automatically marks as Pre-release if the tag ends in "-beta" or "-rc"
prerelease: ${{ contains(github.ref, '-beta') || contains(github.ref, '-rc') }}
files: controller/**/build/outputs/apk/release/*.apk
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# --- CLOUDFLARE R2 UPLOAD ---
- name: Upload to Cloudflare R2
if: startsWith(github.ref, 'refs/tags/v')
env:
AWS_ACCESS_KEY_ID: ${{ vars.CLOUDFLARE_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: auto
R2_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
BUCKET_NAME: "iiaboa-apk-repo"
run: |
# Loop through all generated APKs (universal, arm64, armeabi) and upload them
for apk in $(find . -path "*/build/outputs/apk/release/*.apk"); do
filename=$(basename "$apk")
echo "Uploading $filename to Cloudflare R2 ($BUCKET_NAME)..."
# Use aws-cli configured to point to Cloudflare's S3-compatible API
aws s3 cp "$apk" "s3://$BUCKET_NAME/$filename" \
--endpoint-url "https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com" \
--content-type "application/vnd.android.package-archive"
done
# TODO (Future): Add Jira finalization step here to automatically mark
# the Jira version as "Released" and close the corresponding tickets.
# TODO (Future): Add a Slack notification step to announce the official release
# with links to the GitHub Release page and direct Cloudflare downloads.
# --- SECURITY CLEANUP ---
- name: Cleanup Keystore
if: always()
run: rm -f keystore.jks