Captures the proven release flow (bump+changelog -> tag -> internal -> promote) and documents that CI publishes to internal ONLY by design: the service account lacks production scope, so a track=production workflow_dispatch fails with 'The caller does not have permission' after building. Records both the recommended Console promotion (add-from-library, no rebuild) and the optional path to fully-automated prod releases (grant the SA production permission first). Learned the hard way when v0.4.8's production dispatch failed post-build. Claude-Session: https://claude.ai/code/session_01T12AhSnQVrSxNnvwfCx2z6 Co-authored-by: engineer <engineer@macbookpro.lan> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
3.0 KiB
3.0 KiB
Publishing to Google Play Store
Required GitHub Secrets
Configure these in Settings > Secrets and variables > Actions:
| Secret | Description |
|---|---|
PLAY_STORE_SERVICE_ACCOUNT_JSON |
Google Play Console service account JSON key (full JSON content) |
KEYSTORE_BASE64 |
Base64-encoded release keystore (base64 -w0 release.keystore) |
KEYSTORE_PASSWORD |
Keystore password |
KEY_ALIAS |
Key alias in the keystore |
KEY_PASSWORD |
Key password |
Setup Steps
1. Create a release keystore
keytool -genkeypair -v -storetype PKCS12 \
-keystore release.keystore -alias release \
-keyalg RSA -keysize 2048 -validity 10000
Encode it for GitHub secrets:
base64 -w0 release.keystore
2. Create a Google Play service account
- Go to Google Cloud Console > IAM > Service Accounts
- Create a service account and download the JSON key
- In Google Play Console > Settings > API access, link the service account
- Grant it release management permissions for your app
3. Workflow triggers
The publish workflow runs on:
- GitHub Release publish events
- Tag pushes matching
v*
It builds an AAB (Android App Bundle), signs it with the release keystore, and uploads to the internal track. Promote to production via Play Console.
Releasing (proven runbook)
- Bump
versioninpackage.jsonandapp.json, andandroid.versionCodeinapp.json(must be higher than the current Play build). Add a changelog atfastlane/metadata/android/en-US/changelogs/<versionCode>.txt. Merge tomain. - Tag the release:
git tag -a vX.Y.Z <sha> -m "..." && git push origin vX.Y.Z. This triggers the publish workflow → internal track. - Verify the publish run is green, then confirm the build on the internal track.
- Promote to production (see below).
Promoting to production
Production is not published by CI by default — the service account is scoped to the internal track only, which is intentional (a human gate before a build reaches all users).
- Recommended — Play Console: Production → Create release → Add from library → select the
versionCodealready uploaded to internal → review → roll out. No rebuild. - Fully automated (optional): grant the CI service account "Release to production" for this app in Play Console → Users & permissions, then run the workflow's
workflow_dispatchwithtrack=production,status=completed. Without that permission the production dispatch fails withThe caller does not have permissionafter building — so don't dispatchtrack=productionuntil the service account has been granted production access.
Fastlane (Alternative)
A Fastlane setup is included for local publishing:
bundle install
bundle exec fastlane android deploy
Set environment variables: SUPPLY_JSON_KEY, RELEASE_STORE_FILE, RELEASE_STORE_PASSWORD, RELEASE_KEY_ALIAS, RELEASE_KEY_PASSWORD.