|
| 1 | +# GitHub Actions Workflow for Kotlin Multi-Platform Application Deployment |
| 2 | +# |
| 3 | +# OVERVIEW: |
| 4 | +# This workflow supports building and publishing applications across multiple platforms: |
| 5 | +# - Android (APK/AAB) |
| 6 | +# - iOS (IPA) |
| 7 | +# - Desktop (EXE, MSI, DMG, DEB) |
| 8 | +# - Web (GitHub Pages) |
| 9 | +# |
| 10 | +# PREREQUISITES: |
| 11 | +# Ensure your project is configured with: |
| 12 | +# - Gradle build system |
| 13 | +# - Kotlin Multiplatform Project with Android, iOS, Desktop, and Web modules |
| 14 | +# - Fastlane for deployment automation |
| 15 | +# - Separate modules/package names for each platform |
| 16 | +# |
| 17 | +# REQUIRED SECRETS: |
| 18 | +# Configure the following secrets in GitHub repository settings: |
| 19 | +# - ORIGINAL_KEYSTORE_FILE: Base64 encoded Android release keystore |
| 20 | +# - ORIGINAL_KEYSTORE_FILE_PASSWORD: Keystore password |
| 21 | +# - ORIGINAL_KEYSTORE_ALIAS: Keystore alias |
| 22 | +# - ORIGINAL_KEYSTORE_ALIAS_PASSWORD: Keystore alias password |
| 23 | + |
| 24 | +# - UPLOAD_KEYSTORE_FILE: Base64 encoded Android release keystore |
| 25 | +# - UPLOAD_KEYSTORE_FILE_PASSWORD: Keystore password |
| 26 | +# - UPLOAD_KEYSTORE_ALIAS: Keystore alias |
| 27 | +# - UPLOAD_KEYSTORE_ALIAS_PASSWORD: Keystore alias password |
| 28 | + |
| 29 | +# - GOOGLESERVICES: Google Services configuration JSON |
| 30 | +# - PLAYSTORECREDS: Play Store service account credentials |
| 31 | +# - FIREBASECREDS: Firebase distribution credentials |
| 32 | + |
| 33 | +# - NOTARIZATION_APPLE_ID: Apple ID for macOS app notarization |
| 34 | +# - NOTARIZATION_PASSWORD: Notarization password |
| 35 | +# - NOTARIZATION_TEAM_ID: Apple developer team ID |
| 36 | + |
| 37 | +# WORKFLOW INPUTS: |
| 38 | +# - release_type: 'internal' (default) or 'beta' |
| 39 | +# - target_branch: Branch to use for release (default: 'dev') |
| 40 | +# - android_package_name: Name of Android module |
| 41 | +# - ios_package_name: Name of iOS module |
| 42 | +# - desktop_package_name: Name of desktop module |
| 43 | +# - web_package_name: Name of web module |
| 44 | +# - publish_android: Enable/disable Android Play Store publishing |
| 45 | +# - build_ios: Enable/disable iOS build |
| 46 | +# - publish_ios: Enable/disable iOS App Store publishing |
| 47 | + |
| 48 | +# USAGE: |
| 49 | +# 1. Ensure all required secrets are configured |
| 50 | +# 2. Customize package names in workflow inputs |
| 51 | +# 3. Toggle platform-specific publishing flags |
| 52 | +# 4. Trigger workflow manually or via GitHub Actions UI |
| 53 | + |
| 54 | +# https://github.com/openMF/mifos-x-actionhub/blob/main/.github/workflows/multi-platform-build-and-publish.yaml |
| 55 | + |
| 56 | +# ############################################################################## |
| 57 | +# DON'T EDIT THIS FILE UNLESS NECESSARY # |
| 58 | +# ############################################################################## |
| 59 | +name: Multi-Platform Build and Publish |
| 60 | + |
| 61 | +on: |
| 62 | + workflow_dispatch: |
| 63 | + inputs: |
| 64 | + release_type: |
| 65 | + type: choice |
| 66 | + options: |
| 67 | + - internal |
| 68 | + - beta |
| 69 | + default: internal |
| 70 | + description: Release Type |
| 71 | + |
| 72 | + target_branch: |
| 73 | + type: string |
| 74 | + default: 'dev' |
| 75 | + description: 'Target branch for release' |
| 76 | + |
| 77 | + distribute_ios_firebase: |
| 78 | + type: boolean |
| 79 | + default: false |
| 80 | + description: Distribute iOS App via Firebase App Distribution |
| 81 | + |
| 82 | + distribute_ios_testflight: |
| 83 | + type: boolean |
| 84 | + default: false |
| 85 | + description: Distribute iOS App via TestFlight (App Store Connect) |
| 86 | + |
| 87 | + distribute_ios_appstore: |
| 88 | + type: boolean |
| 89 | + default: false |
| 90 | + description: Distribute iOS App to Appstore |
| 91 | + |
| 92 | +permissions: |
| 93 | + contents: write |
| 94 | + id-token: write |
| 95 | + pages: write |
| 96 | + |
| 97 | +concurrency: |
| 98 | + group: "reusable" |
| 99 | + cancel-in-progress: false |
| 100 | + |
| 101 | +jobs: |
| 102 | + multi_platform_build_and_publish: |
| 103 | + name: Multi-Platform Build and Publish |
| 104 | + uses: openMF/mifos-x-actionhub/.github/workflows/multi-platform-build-and-publish.yaml@v1.0.11 |
| 105 | + with: |
| 106 | + release_type: ${{ inputs.release_type }} |
| 107 | + target_branch: ${{ inputs.target_branch }} |
| 108 | + android_package_name: 'cmp-android' |
| 109 | + ios_package_name: 'cmp-ios' |
| 110 | + desktop_package_name: 'cmp-desktop' |
| 111 | + web_package_name: 'cmp-web' |
| 112 | + metadata_path: './fastlane/metadata' |
| 113 | + use_cocoapods: true |
| 114 | + shared_module: ':cmp-shared' |
| 115 | + distribute_ios_firebase: ${{ inputs.distribute_ios_firebase }} |
| 116 | + # When App Store is enabled, skip TestFlight — deliver() already uploads |
| 117 | + # the IPA to App Store Connect which makes the build available in TestFlight. |
| 118 | + # Running both in parallel causes version conflicts since the upstream |
| 119 | + # reusable workflow has no job dependency between the two. |
| 120 | + distribute_ios_testflight: ${{ inputs.distribute_ios_testflight && !inputs.distribute_ios_appstore }} |
| 121 | + distribute_ios_appstore: ${{ inputs.distribute_ios_appstore }} |
| 122 | + secrets: |
| 123 | + original_keystore_file: ${{ secrets.ORIGINAL_KEYSTORE_FILE }} |
| 124 | + original_keystore_file_password: ${{ secrets.ORIGINAL_KEYSTORE_FILE_PASSWORD }} |
| 125 | + original_keystore_alias: ${{ secrets.ORIGINAL_KEYSTORE_ALIAS }} |
| 126 | + original_keystore_alias_password: ${{ secrets.ORIGINAL_KEYSTORE_ALIAS_PASSWORD }} |
| 127 | + |
| 128 | + upload_keystore_file: ${{ secrets.UPLOAD_KEYSTORE_FILE }} |
| 129 | + upload_keystore_file_password: ${{ secrets.UPLOAD_KEYSTORE_FILE_PASSWORD }} |
| 130 | + upload_keystore_alias: ${{ secrets.UPLOAD_KEYSTORE_ALIAS }} |
| 131 | + upload_keystore_alias_password: ${{ secrets.UPLOAD_KEYSTORE_ALIAS_PASSWORD }} |
| 132 | + |
| 133 | + notarization_apple_id: ${{ secrets.NOTARIZATION_APPLE_ID }} |
| 134 | + notarization_password: ${{ secrets.NOTARIZATION_PASSWORD }} |
| 135 | + notarization_team_id: ${{ secrets.NOTARIZATION_TEAM_ID }} |
| 136 | + appstore_key_id: ${{ secrets.APPSTORE_KEY_ID }} |
| 137 | + appstore_issuer_id: ${{ secrets.APPSTORE_ISSUER_ID }} |
| 138 | + appstore_auth_key: ${{ secrets.APPSTORE_AUTH_KEY }} |
| 139 | + match_password: ${{ secrets.MATCH_PASSWORD }} |
| 140 | + match_ssh_private_key: ${{ secrets.MATCH_SSH_PRIVATE_KEY }} |
| 141 | + |
| 142 | + windows_signing_key: ${{ secrets.WINDOWS_SIGNING_KEY }} |
| 143 | + windows_signing_password: ${{ secrets.WINDOWS_SIGNING_PASSWORD }} |
| 144 | + windows_signing_certificate: ${{ secrets.WINDOWS_SIGNING_CERTIFICATE }} |
| 145 | + |
| 146 | + macos_signing_key: ${{ secrets.MACOS_SIGNING_KEY }} |
| 147 | + macos_signing_password: ${{ secrets.MACOS_SIGNING_PASSWORD }} |
| 148 | + macos_signing_certificate: ${{ secrets.MACOS_SIGNING_CERTIFICATE }} |
| 149 | + |
| 150 | + linux_signing_key: ${{ secrets.LINUX_SIGNING_KEY }} |
| 151 | + linux_signing_password: ${{ secrets.LINUX_SIGNING_PASSWORD }} |
| 152 | + linux_signing_certificate: ${{ secrets.LINUX_SIGNING_CERTIFICATE }} |
| 153 | + |
| 154 | + keychain_password: ${{ secrets.KEYCHAIN_PASSWORD }} |
| 155 | + certificates_password: ${{ secrets.CERTIFICATES_PASSWORD }} |
| 156 | + mac_app_distribution_certificate_b64: ${{ secrets.MAC_APP_DISTRIBUTION_CERTIFICATE_B64 }} |
| 157 | + mac_installer_distribution_certificate_b64: ${{ secrets.MAC_INSTALLER_DISTRIBUTION_CERTIFICATE_B64 }} |
| 158 | + mac_embedded_provision_b64: ${{ secrets.MAC_EMBEDDED_PROVISION_B64 }} |
| 159 | + mac_runtime_provision_b64: ${{ secrets.MAC_RUNTIME_PROVISION_B64 }} |
| 160 | + |
| 161 | + google_services: ${{ secrets.GOOGLESERVICES }} |
| 162 | + firebase_creds: ${{ secrets.FIREBASECREDS }} |
| 163 | + playstore_creds: ${{ secrets.PLAYSTORECREDS }} |
| 164 | + token: ${{ secrets.GITHUB_TOKEN }} |
| 165 | + supabase_creds: ${{ secrets.SUPABASECREDS }} |
0 commit comments