Skip to content

Release signing and publishing pipeline in CI (GitHub Environments, SOPS boundary) #49

Description

@altaywtf

Part of #14 (W0 → release infrastructure). Blocked by #46 (credentials in custody) and #16 (CI base). Feeds #31 and #35.

Outcome

Release signing and publishing work in GitHub Actions within the workspace CI boundary: GitHub Environment secrets or OIDC, SOPS-routed payloads, no 1Password at runtime. Apply the workspace release supply-chain checklist.

Scope

  • Signing config wired for release builds of both flavors (keystore injected from CI secrets, never committed; signingConfigs currently absent entirely)
  • Play publishing step (internal/beta tracks) using the service account from Release credentials custody: Play Console access, signing lineage, Sentry DSN (owner: Altay) #46
  • Fire TV S3 sideload artifact step (replaces the legacy fastlane upload_to_s3 lane)
  • versionCode strategy implemented (>91 family, form-factor scheme from the one-package decision)
  • Release checklist doc in the repo per the workspace release-security routing

Acceptance criteria

  • A tagged run produces signed, Play-uploadable artifacts for both flavors from CI alone
  • DoD: CI run linked as proof; a signed artifact installed on the harness with a screenshot

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions