.github/.github/workflows/cd-mobile-ios.yaml
Adam Moussa 4a6cbfd362
Some checks failed
ci / ci / ci (push) Has been cancelled
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
ci(workflows): pin remaining GitHub Actions to SHA (#139)
Mutable tags and the dependency-review v5 branch executed inside every consumer, including OIDC deploy jobs. SHA pins with version comments match the policy scanner and let Renovate advance them.
2026-08-26 18:25:53 -04:00

103 lines
3.4 KiB
YAML

name: CD — Mobile iOS (TestFlight)
on:
workflow_call:
inputs:
node-version:
description: "Node.js version to use"
type: string
default: "24"
ruby-version:
description: "Ruby version for Fastlane"
type: string
default: "3.3"
working-directory:
description: "Directory containing the mobile project"
type: string
default: "."
cache-dependency-path:
description: "Path to package-lock.json for npm cache"
type: string
default: "package-lock.json"
fastlane-lane:
description: "Fastlane lane to run"
type: string
default: "ios beta"
region:
description: "AWS region (for match S3 storage)"
type: string
default: "us-east-1"
timeout-minutes:
description: "Job timeout in minutes"
type: number
default: 45
secrets:
deploy-role-arn:
description: "OIDC deploy role ARN (for match S3 access)"
required: true
match-password:
description: "Encryption passphrase for match certificates"
required: true
asc-key-id:
description: "App Store Connect API key ID"
required: true
asc-issuer-id:
description: "App Store Connect API issuer ID"
required: true
asc-key-content:
description: "Base64-encoded App Store Connect API key (.p8)"
required: true
permissions:
id-token: write
contents: read
jobs:
deploy-ios:
runs-on: macos-26
timeout-minutes: ${{ inputs.timeout-minutes }}
# Serialise per app + lane so two pushes cannot upload over each other.
# There is no app-identifier input: the target is whatever Fastfile lives in
# working-directory, so that plus the lane is what identifies the deploy.
# Both always default ("." and "ios beta"), so the group is never empty.
# cancel-in-progress is FALSE on purpose: unlike CI, aborting midway can
# leave a half-uploaded TestFlight build.
concurrency:
group: cd-mobile-ios-${{ inputs.working-directory }}-${{ inputs.fastlane-lane }}
cancel-in-progress: false
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with:
role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }}
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ inputs.node-version }}
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true
working-directory: ${{ inputs.working-directory }}
- name: Install JS dependencies
run: npm ci
- name: Install CocoaPods
run: bundle exec pod install --project-directory=ios
- name: Build and upload
run: bundle exec fastlane ${{ inputs.fastlane-lane }}
env:
MATCH_PASSWORD: ${{ secrets.match-password }}
ASC_KEY_ID: ${{ secrets.asc-key-id }}
ASC_ISSUER_ID: ${{ secrets.asc-issuer-id }}
ASC_KEY_CONTENT: ${{ secrets.asc-key-content }}