Release: create app signing keystore and add publishing secrets to CI #141

Open
opened 2026-07-02 15:55:05 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-02 15:55:05 +00:00 (Migrated from github.com)

Manual prerequisite for publishing to Google Play and Samsung Galaxy Store, and for the automated release workflow (#19), which is gated on these secrets existing. F-Droid signs its own builds from source, so this does not apply there.

Steps (human)

  • Generate a release upload keystore (keytool); store the keystore file + passwords in a password manager, never in the repo. Record the SHA-256 fingerprint.
  • Choose the signing strategy: for Google Play, enroll in Play App Signing (Google holds the app signing key; you upload with the upload key — losing the upload key is recoverable, so prefer this). For Galaxy Store, you sign the AAB/APK yourself with the release key.
  • Add the signing material to GitHub Actions secrets used by the release workflow (#19): base64-encoded keystore, keystore password, key alias, key password. The exact secret names the workflow reads are documented in docs/release.md (from #19).
  • Confirm app/build.gradle.kts release signingConfig reads these from env/secrets (wired in #19) and that local/debug builds still work with them absent.
  • Establish a real version scheme and bump versionCode/versionName for the first release — #16 found tags v0.1.0 and v0.2.0 both map to versionCode 1, which must be fixed before any store submission.

Notes

  • Never commit the keystore or passwords. Losing the Play upload key is recoverable via Play support; losing a self-managed app signing key is not — another reason to use Play App Signing.

Dependencies

Unblocks the Google Play and Galaxy Store publication tickets and the #19 automated-publish workflow.

Manual prerequisite for publishing to Google Play and Samsung Galaxy Store, and for the automated release workflow (#19), which is gated on these secrets existing. F-Droid signs its own builds from source, so this does not apply there. ## Steps (human) - [ ] Generate a release **upload keystore** (`keytool`); store the keystore file + passwords in a password manager, never in the repo. Record the SHA-256 fingerprint. - [ ] Choose the signing strategy: for **Google Play**, enroll in **Play App Signing** (Google holds the app signing key; you upload with the upload key — losing the upload key is recoverable, so prefer this). For **Galaxy Store**, you sign the AAB/APK yourself with the release key. - [ ] Add the signing material to **GitHub Actions secrets** used by the release workflow (#19): base64-encoded keystore, keystore password, key alias, key password. The exact secret names the workflow reads are documented in `docs/release.md` (from #19). - [ ] Confirm `app/build.gradle.kts` release `signingConfig` reads these from env/secrets (wired in #19) and that local/debug builds still work with them absent. - [ ] Establish a real version scheme and bump `versionCode`/`versionName` for the first release — #16 found tags `v0.1.0` and `v0.2.0` both map to `versionCode 1`, which must be fixed before any store submission. ## Notes - Never commit the keystore or passwords. Losing the Play **upload** key is recoverable via Play support; losing a self-managed **app signing** key is not — another reason to use Play App Signing. ## Dependencies Unblocks the Google Play and Galaxy Store publication tickets and the #19 automated-publish workflow.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#141