chore(release): self-hosted updater on update.netralax.cloud
Switches the Tauri updater endpoint from GitHub Releases to a static host. New Ed25519 pubkey (old private key was lost); existing 0.10.x installs need one manual reinstall to pick up the new updater identity. Release flow is now pnpm release <version> <notes> which bumps, builds + signs locally, scps artifacts to the server, commits, tags. GitHub workflow stays as workflow_dispatch backup (Windows only). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,35 +1,27 @@
|
||||
name: Release desktop app
|
||||
name: Release desktop app (manual backup)
|
||||
|
||||
# Tag a version to trigger a release:
|
||||
# git tag v0.1.0 && git push --tags
|
||||
#
|
||||
# Produces signed Tauri bundles for macOS (arm + intel), Windows, and Linux,
|
||||
# uploads them to a GitHub Release, and publishes `latest.json` for the
|
||||
# updater plugin to discover.
|
||||
# Self-hosted updates run from scripts/release.mjs on Dennis's Windows box.
|
||||
# This workflow is kept as a manual backup — trigger it from the Actions tab
|
||||
# if the local build host is unavailable.
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- "v*"
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
description: "Tag to build (e.g. v0.10.2) — must already exist"
|
||||
required: true
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
build:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- platform: macos-14 # universal binary covers both Intel + Apple Silicon
|
||||
args: "--target universal-apple-darwin --bundles app,updater"
|
||||
- platform: windows-latest
|
||||
args: ""
|
||||
|
||||
runs-on: ${{ matrix.platform }}
|
||||
runs-on: windows-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ inputs.tag }}
|
||||
|
||||
- name: Install pnpm
|
||||
uses: pnpm/action-setup@v4
|
||||
@@ -42,8 +34,6 @@ jobs:
|
||||
|
||||
- name: Setup Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
with:
|
||||
targets: ${{ matrix.platform == 'macos-14' && 'aarch64-apple-darwin,x86_64-apple-darwin' || '' }}
|
||||
|
||||
- name: Install JS deps
|
||||
run: pnpm install --frozen-lockfile
|
||||
@@ -54,18 +44,16 @@ jobs:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
|
||||
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
|
||||
# Client-side env vars baked into the bundle — paste your prod values
|
||||
# into the repo's Actions → Secrets so releases point at prod.
|
||||
VITE_SUPABASE_URL: ${{ secrets.VITE_SUPABASE_URL }}
|
||||
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
|
||||
VITE_AUTH_REDIRECT_URL: ${{ secrets.VITE_AUTH_REDIRECT_URL }}
|
||||
VITE_LIVEKIT_URL: ${{ secrets.VITE_LIVEKIT_URL }}
|
||||
with:
|
||||
projectPath: apps/desktop
|
||||
tagName: ${{ github.ref_name }}
|
||||
releaseName: "ChatApp ${{ github.ref_name }}"
|
||||
releaseBody: "See the assets below to download this version."
|
||||
tagName: ${{ inputs.tag }}
|
||||
releaseName: "ChatApp ${{ inputs.tag }}"
|
||||
releaseBody: "Manual build — copy .nsis.zip/.sig/latest.json to the update host."
|
||||
releaseDraft: true
|
||||
prerelease: false
|
||||
tauriScript: pnpm exec tauri
|
||||
args: ${{ matrix.args }}
|
||||
args: "--bundles nsis"
|
||||
|
||||
Reference in New Issue
Block a user