* feat(5): F-Droid CI pipeline — self-hosted repo via GitHub Pages - New publish-fdroid.yml workflow: builds APK, generates F-Droid repo index via fdroidserver, deploys to gh-pages/fdroid/repo - gitignore: add __pycache__/ and *.pyc - Generated F-Droid repo signing keystore + stored as GH secrets - GitHub Pages enabled for gh-pages branch Closes #5 * fix(5): review findings — pin fdroidserver, add index verification, clean perms - Pin fdroidserver to 2.4.4 (verified version) - Add post-update index.xml existence check - Remove unnecessary pages:write + id-token:write perms * docs(5): add test report and review artifacts
2.9 KiB
2.9 KiB
Problem / Goal / Success Metric
(carry over from Phase 2)
Current State
build.ymlbuilds APK and attaches to GitHub releases (works for v0.3.1+)publish-play-store.ymlbuilds AAB + publishes to Play Store (blocked: app not created yet)publish-app-store.ymlpublishes to TestFlight (blocked: Apple enrollment pending)- No F-Droid distribution at all
distribution/fdroid-submission/metadata.ymlprepared for mainline F-Droid (manual MR)- GitHub Pages NOT enabled on repo
Proposed Design
New CI workflow .github/workflows/publish-fdroid.yml:
- Trigger: on tag push (v*) OR workflow_dispatch
- Build APK: reuse same steps as
build.yml— npm install, expo prebuild, gradle assembleRelease with production signing - Generate F-Droid repo: install
fdroidserver, restore repo signing keystore from secret, runfdroid update --create-metadatato produce signed repo index - Deploy: push
fdroid/directory togh-pagesbranch viapeaceiris/actions-gh-pages
One-time setup outside CI:
- Generate F-Droid repo signing keystore → store as GitHub secret
FDROID_REPO_KEYSTORE_B64+FDROID_REPO_KEYSTORE_PASS+FDROID_REPO_KEY_ALIAS+FDROID_REPO_KEY_PASS - Enable GitHub Pages on repo (via Settings → Pages → source:
gh-pagesbranch,/root)
Repo URL: https://dzianisv.github.io/opencode-mobile/fdroid/repo
The existing APK signing key (production-release.jks) signs the APK. The F-Droid repo needs a SEPARATE keystore for signing the repo index (index.xml). These are different keys for different purposes.
Alternatives Considered
- Skip fdroidserver, manually craft index.xml — rejected: fragile, violates F-Droid spec, no icon generation, no archive management
- Use IzzyOnDroid only — rejected: IzzyOnDroid auto-delists when mainline F-Droid accepts the app; we want our own repo that persists regardless
- Wait for mainline F-Droid — rejected: blocked on Play Store; self-hosted repo works today
- Deploy via S3/Cloudflare R2 instead of gh-pages — rejected: gh-pages is free, zero infra, fits the existing GitHub-centric toolchain
Risks & Open Questions
| Risk | Mitigation |
|---|---|
| fdroidserver pip package may have missing deps in CI runner | Pin version, test via workflow_dispatch first |
| F-Droid repo keystore must be stable across CI runs | Generate once, store in secrets; if lost, repo URL changes |
| GitHub Pages not enabled | API call to enable via gh api -X POST repos/:owner/:repo/pages — one-time setup in the workflow |
| APK signature vs repo signature confusion | Document clearly in comments: two different keys |
| fdroidserver requires Java for apksigner | Already have JDK 17 in CI from android build steps |
Touched Surface
- NEW:
.github/workflows/publish-fdroid.yml— the workflow - MODIFIED:
.gitignore— add.pycentries - ONE-TIME: repo keystore generation (done during implementation)
- ONE-TIME: GitHub Pages enable (done via API)