diff --git a/.gitignore b/.gitignore index dab163e..ea7aebf 100644 --- a/.gitignore +++ b/.gitignore @@ -67,3 +67,14 @@ windows/ # Release artifacts stashed by fastlane /dist/ + +# Credentials -- repo-wide backstop. +# The per-platform rules in android/.gitignore and ios/.gitignore cover the +# exact paths in use; these cover the whole class, including the .env.default +# and .env. files fastlane also loads, and a .p8 downloaded +# anywhere other than ios/fastlane/. +*.p8 +*.pem +.env +.env.* +!.env.example diff --git a/RELEASING.md b/RELEASING.md index 7d0538f..ded24e6 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -1,5 +1,12 @@ # Releasing Coves +> **This is for maintainers publishing the official Coves builds.** You do not +> need any of it to build or run Coves from source -- see the README for that. +> Every step below requires access to the project's own store accounts and +> signing identity. A fork that wants to publish its own builds needs its own +> Apple and Google Play accounts, its own signing keys, and its own bundle +> identifier; the automation here is reusable, the credentials are not. + Release automation lives in `android/fastlane` and `ios/fastlane`, driven by [fastlane](https://fastlane.tools) (installed via Homebrew; verified against 2.231.1). Both platforms share `tool/fastlane_flutter.rb`. @@ -31,9 +38,11 @@ Then in Play Console, at the **account** level (not inside an app): 5. **Users and permissions > Invite new users**, paste the service account email (`...@.iam.gserviceaccount.com`). -6. Grant **Admin (all permissions)**, or the narrower set: *Release to - production, exclude devices, and use Play App Signing* + *Release apps to - testing tracks* + *View app information*. +6. Grant only what the upload lanes need: *Release to production, exclude + devices, and use Play App Signing* + *Release apps to testing tracks* + + *View app information*. **Admin (all permissions)** also works and is what + most guides suggest, but it hands a CI-shaped credential far more authority + than uploading a build requires. Verify with `cd android && fastlane run validate_play_store_json_key`. diff --git a/android/fastlane/Fastfile b/android/fastlane/Fastfile index 73eb7ff..5e9ff77 100644 --- a/android/fastlane/Fastfile +++ b/android/fastlane/Fastfile @@ -3,7 +3,8 @@ # Credentials required (not in git): # android/fastlane/play-store-key.json Play service account JSON, # or set PLAY_STORE_JSON_KEY. -# android/key.properties Upload keystore config (already set up). +# android/key.properties Upload keystore config. Maintainer +# provided -- see RELEASING.md. # # Usage: # cd android && fastlane build # signed AAB only, no upload