-
Notifications
You must be signed in to change notification settings - Fork 0
197 lines (168 loc) · 7.41 KB
/
Copy pathcd.yml
File metadata and controls
197 lines (168 loc) · 7.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
name: CD
on:
push:
branches: [develop]
workflow_dispatch:
inputs:
deploy_firebase:
description: "Firebase App Distribution 배포 여부 (수동 실행 전용 — push 트리거는 항상 배포)"
type: boolean
default: true
concurrency:
group: cd-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
# QA/기능 테스트용. `internal` buildType 은 debug 서명 + 온디바이스 모델을 APK 에 그대로 번들해서
# (PAD 미사용) 테스터가 설치하자마자 모든 기능을 바로 쓸 수 있다 — data/build.gradle.kts,
# fastlane/Fastfile 의 `distribute` lane 참고. release 서명 키스토어는 필요 없다.
#
# push(develop)는 항상 배포하고, workflow_dispatch(수동 실행)만 deploy_firebase 입력으로 건너뛸 수
# 있다 — 예: release AAB만 다시 뽑아서 확인하고 싶을 때 테스터에게 알림이 가는 걸 막는 용도.
firebase-distribution:
if: ${{ github.event_name != 'workflow_dispatch' || inputs.deploy_firebase }}
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
# 레포에는 LFS 로도 들어 있지만, 매 실행마다 LFS 에서 받으면 대역폭 예산이 소진되므로 Release
# 자산에서 받습니다. 모델을 교체할 때는 양쪽을 함께 갱신해야 합니다.
- name: Download on-device models
env:
GH_TOKEN: ${{ github.token }}
run: ./scripts/fetch-models.sh
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: '17'
- name: Set up Gradle
uses: gradle/actions/setup-gradle@v4
with:
validate-wrappers: true
- name: Set up Ruby
uses: ruby/setup-ruby@v1
with:
ruby-version: '3.3'
bundler-cache: true
- name: Prepare secret directories
run: mkdir -p fastlane/config keystore
- name: Write google-services.json
run: echo "${{ secrets.GOOGLE_SERVICES_JSON }}" | base64 -d > app/google-services.json
- name: Write local.properties
shell: bash
env:
DEV_BASE_URL: ${{ secrets.DEV_BASE_URL }}
PROD_BASE_URL: ${{ secrets.PROD_BASE_URL }}
run: |
: "${DEV_BASE_URL:?DEV_BASE_URL secret is not configured}"
: "${PROD_BASE_URL:?PROD_BASE_URL secret is not configured}"
printf 'DEV_BASE_URL=%s\n' "$DEV_BASE_URL" > local.properties
printf 'PROD_BASE_URL=%s\n' "$PROD_BASE_URL" >> local.properties
- name: Write release keystore
run: echo "${{ secrets.RELEASE_KEYSTORE }}" | base64 -d > keystore/release.jks
- name: Write Firebase service account key
run: echo "${{ secrets.FIREBASE_SERVICE_ACCOUNT_JSON }}" | base64 -d > fastlane/config/gamss-key.json
- name: Compute CI version
run: |
echo "VERSION_CODE=$((100000 + GITHUB_RUN_NUMBER))" >> "$GITHUB_ENV"
- name: Distribute to Firebase App Distribution
env:
FIREBASE_SERVICE_CREDENTIALS_FILE: ${{ github.workspace }}/fastlane/config/gamss-key.json
FIREBASE_APP_ID: ${{ secrets.FIREBASE_APP_ID }}
FIREBASE_TESTER_GROUPS: inner-tester
RELEASE_KEYSTORE_PATH: ${{ github.workspace }}/keystore/release.jks
RELEASE_KEYSTORE_PASSWORD: ${{ secrets.RELEASE_KEYSTORE_PASSWORD }}
RELEASE_KEY_ALIAS: ${{ secrets.RELEASE_KEY_ALIAS }}
RELEASE_KEY_PASSWORD: ${{ secrets.RELEASE_KEY_PASSWORD }}
run: bundle exec fastlane android distribute
- name: Upload reports
if: failure()
uses: actions/upload-artifact@v4
with:
name: firebase-distribution-reports
path: |
**/build/reports/**
if-no-files-found: ignore
retention-days: 7
# Play Console 에 올릴 서명된 운영용 AAB 를 만들어 워크플로 아티팩트로 남긴다. `release` buildType
# 그대로라 기존 PAD 정책(emotion=fast-follow, summary=on-demand)이 유지되고, internal 배포용 설정이
# 여기 섞이지 않는다.
#
# Play Console 로 자동 업로드(upload_to_play_store)는 아직 안 한다 — 서비스 계정 JSON secret
# (PLAY_STORE_SERVICE_ACCOUNT_JSON)이 리포지토리에 아직 없어서 지금 붙이면 이 job 이 매번 실패한다.
# 그래서 지금은 서명된 AAB 를 여기까지만 만들고, Actions 탭에서 아티팩트를 받아 Play Console에
# 수동으로 올린다. secret 이 준비되면 fastlane/Fastfile 의 build_play_release_aab lane 주석대로
# upload_to_play_store 호출을 다시 붙이면 된다.
play-release-aab:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
# 레포에는 LFS 로도 들어 있지만, 매 실행마다 LFS 에서 받으면 대역폭 예산이 소진되므로 Release
# 자산에서 받습니다. 모델을 교체할 때는 양쪽을 함께 갱신해야 합니다.
- name: Download on-device models
env:
GH_TOKEN: ${{ github.token }}
run: ./scripts/fetch-models.sh
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: '17'
- name: Set up Gradle
uses: gradle/actions/setup-gradle@v4
with:
validate-wrappers: true
- name: Set up Ruby
uses: ruby/setup-ruby@v1
with:
ruby-version: '3.3'
bundler-cache: true
- name: Prepare secret directories
run: mkdir -p keystore
- name: Write google-services.json
run: echo "${{ secrets.GOOGLE_SERVICES_JSON }}" | base64 -d > app/google-services.json
- name: Write local.properties
shell: bash
env:
DEV_BASE_URL: ${{ secrets.DEV_BASE_URL }}
PROD_BASE_URL: ${{ secrets.PROD_BASE_URL }}
run: |
: "${DEV_BASE_URL:?DEV_BASE_URL secret is not configured}"
: "${PROD_BASE_URL:?PROD_BASE_URL secret is not configured}"
printf 'DEV_BASE_URL=%s\n' "$DEV_BASE_URL" > local.properties
printf 'PROD_BASE_URL=%s\n' "$PROD_BASE_URL" >> local.properties
- name: Write release keystore
run: echo "${{ secrets.RELEASE_KEYSTORE }}" | base64 -d > keystore/release.jks
- name: Compute CI version
run: |
echo "VERSION_CODE=$((100000 + GITHUB_RUN_NUMBER))" >> "$GITHUB_ENV"
- name: Build signed release AAB
env:
RELEASE_KEYSTORE_PATH: ${{ github.workspace }}/keystore/release.jks
RELEASE_KEYSTORE_PASSWORD: ${{ secrets.RELEASE_KEYSTORE_PASSWORD }}
RELEASE_KEY_ALIAS: ${{ secrets.RELEASE_KEY_ALIAS }}
RELEASE_KEY_PASSWORD: ${{ secrets.RELEASE_KEY_PASSWORD }}
run: bundle exec fastlane android build_play_release_aab
- name: Upload release AAB artifact
uses: actions/upload-artifact@v4
with:
name: app-release-aab
path: app/build/outputs/bundle/release/*.aab
if-no-files-found: error
retention-days: 7
- name: Upload reports
if: failure()
uses: actions/upload-artifact@v4
with:
name: play-release-aab-reports
path: |
**/build/reports/**
if-no-files-found: ignore
retention-days: 7