Commit b44b537
authored
docs(self-hosting): correct what a server change clears, and the cert requirement (#7158)
* docs(self-hosting): correct what a server change clears, and the cert requirement
The page said the built-in browser's profile survives a server change. It does
not — the teardown clears the browser's saved sessions and the agent's folder
grants along with the saved route, because those are capabilities granted to a
specific deployment. The page now lists what is cleared and what is kept, says
why, and notes that a change which cannot complete is refused rather than
half-applied.
Adds two things a self-hoster hits in practice. Certificate errors are rejected
outright with no "continue anyway", so a private CA that is not in the system
trust store will not load however correct the URL is — worth saying, since a
private CA is a normal self-host setup. And packaging your own shell needs
Xcode 26 or newer, which otherwise fails with an opaque actool error.
Also notes that the CLI asks which deployment you mean when a machine has more
than one configuration, and states signing/notarization for a self-built shell
as a requirement rather than predicting what happens without credentials.
* docs(self-hosting): point custom builds at package:mac, not package:share
package:share is the "send someone a build to try" path. It passes
-c.mac.timestamp=none to skip the per-file round trip to Apple's timestamp
authority, and its own docstring notes distribution builds need those
timestamps. Apple's notary service requires a secure timestamp, so a build made
that way cannot be notarized however many credentials the operator supplies —
which is exactly what the section was telling them to do.
package:mac inherits notarize and hardenedRuntime from electron-builder.yml and
leaves timestamps on, and bun run build honours SIM_DESKTOP_DEFAULT_ORIGIN the
same way, so the baked-origin instruction is unchanged. Its artifact path and
name differ from the share script's per-channel overrides, so those are
corrected too, and the two stacked warnings are merged into one.
* docs(self-hosting): spell out that APPLE_API_KEY is a path to the .p8
The variable holds an absolute filesystem path to the App Store Connect key
file, not the key material, and @electron/notarize reads it through Node fs so
a leading ~ is not expanded — the release workflow carries a comment saying
exactly that. Listed alongside the other credentials with no explanation, it
reads like somewhere to paste the key, and notarization then fails while every
variable looks set.1 parent a3705a7 commit b44b537
1 file changed
Lines changed: 29 additions & 6 deletions
Lines changed: 29 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
43 | 45 | | |
44 | 46 | | |
45 | 47 | | |
| |||
61 | 63 | | |
62 | 64 | | |
63 | 65 | | |
64 | | - | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
65 | 78 | | |
66 | 79 | | |
67 | 80 | | |
| |||
81 | 94 | | |
82 | 95 | | |
83 | 96 | | |
84 | | - | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
85 | 102 | | |
86 | 103 | | |
87 | 104 | | |
88 | 105 | | |
89 | 106 | | |
| 107 | + | |
| 108 | + | |
90 | 109 | | |
91 | 110 | | |
92 | | - | |
| 111 | + | |
93 | 112 | | |
94 | 113 | | |
95 | | - | |
| 114 | + | |
96 | 115 | | |
97 | 116 | | |
98 | | - | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
99 | 122 | | |
0 commit comments