mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
Mutable tags and the dependency-review v5 branch executed inside every consumer, including OIDC deploy jobs. SHA pins with version comments match the policy scanner and let Renovate advance them.
103 lines
3.4 KiB
YAML
103 lines
3.4 KiB
YAML
name: CD — Mobile iOS (TestFlight)
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
node-version:
|
|
description: "Node.js version to use"
|
|
type: string
|
|
default: "24"
|
|
ruby-version:
|
|
description: "Ruby version for Fastlane"
|
|
type: string
|
|
default: "3.3"
|
|
working-directory:
|
|
description: "Directory containing the mobile project"
|
|
type: string
|
|
default: "."
|
|
cache-dependency-path:
|
|
description: "Path to package-lock.json for npm cache"
|
|
type: string
|
|
default: "package-lock.json"
|
|
fastlane-lane:
|
|
description: "Fastlane lane to run"
|
|
type: string
|
|
default: "ios beta"
|
|
region:
|
|
description: "AWS region (for match S3 storage)"
|
|
type: string
|
|
default: "us-east-1"
|
|
timeout-minutes:
|
|
description: "Job timeout in minutes"
|
|
type: number
|
|
default: 45
|
|
secrets:
|
|
deploy-role-arn:
|
|
description: "OIDC deploy role ARN (for match S3 access)"
|
|
required: true
|
|
match-password:
|
|
description: "Encryption passphrase for match certificates"
|
|
required: true
|
|
asc-key-id:
|
|
description: "App Store Connect API key ID"
|
|
required: true
|
|
asc-issuer-id:
|
|
description: "App Store Connect API issuer ID"
|
|
required: true
|
|
asc-key-content:
|
|
description: "Base64-encoded App Store Connect API key (.p8)"
|
|
required: true
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy-ios:
|
|
runs-on: macos-26
|
|
timeout-minutes: ${{ inputs.timeout-minutes }}
|
|
# Serialise per app + lane so two pushes cannot upload over each other.
|
|
# There is no app-identifier input: the target is whatever Fastfile lives in
|
|
# working-directory, so that plus the lane is what identifies the deploy.
|
|
# Both always default ("." and "ios beta"), so the group is never empty.
|
|
# cancel-in-progress is FALSE on purpose: unlike CI, aborting midway can
|
|
# leave a half-uploaded TestFlight build.
|
|
concurrency:
|
|
group: cd-mobile-ios-${{ inputs.working-directory }}-${{ inputs.fastlane-lane }}
|
|
cancel-in-progress: false
|
|
defaults:
|
|
run:
|
|
working-directory: ${{ inputs.working-directory }}
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
|
|
with:
|
|
role-to-assume: ${{ secrets.deploy-role-arn }}
|
|
aws-region: ${{ inputs.region }}
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: ${{ inputs.node-version }}
|
|
cache: npm
|
|
cache-dependency-path: ${{ inputs.cache-dependency-path }}
|
|
|
|
- uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
|
|
with:
|
|
ruby-version: ${{ inputs.ruby-version }}
|
|
bundler-cache: true
|
|
working-directory: ${{ inputs.working-directory }}
|
|
|
|
- name: Install JS dependencies
|
|
run: npm ci
|
|
|
|
- name: Install CocoaPods
|
|
run: bundle exec pod install --project-directory=ios
|
|
|
|
- name: Build and upload
|
|
run: bundle exec fastlane ${{ inputs.fastlane-lane }}
|
|
env:
|
|
MATCH_PASSWORD: ${{ secrets.match-password }}
|
|
ASC_KEY_ID: ${{ secrets.asc-key-id }}
|
|
ASC_ISSUER_ID: ${{ secrets.asc-issuer-id }}
|
|
ASC_KEY_CONTENT: ${{ secrets.asc-key-content }}
|