Repository navigation
chore(personal): signed desktop releases for every Mac, plus a runbook - #31
Merged
Merged
Conversation
Local desktop builds were ad-hoc signed, so every new build was a new app to macOS privacy grants, keychain ACLs and Little Snitch, and each Mac re-prompted for everything. Installs were also hand-rolled per Mac, and matebook lost its app to one of them. scripts/personal/ now holds the whole desktop flow: - t3-alpha-build: aligns package versions (so the server reports the release version too), builds the zip, re-signs it with a stable identity - t3-alpha-install: the installer, moved from ~/.local/bin; refuses unsigned zips, checks the bundle version, prunes old backups - t3-alpha-deploy: installs a zip on every Mac over SSH, studio last release-pipeline.md becomes the single runbook: machines, upstream sync, desktop deploy, mobile build/submit, one-time setup.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Local desktop builds were ad-hoc signed. macOS privacy grants, keychain access and Little Snitch rules are tied to an app's signature, so every new build counted as a new app and each Mac re-prompted for everything. Installs were also done by hand per Mac, and matebook lost its app to one of them.
How:
scripts/personal/t3-alpha-build <version>: aligns every package.json to the version (so the server reports it too, not the stale 0.0.42), builds the macOS arm64 zip, and re-signs it with the Apple Development identity on studio. Only the version-bumped manifests are restored afterwards.scripts/personal/t3-alpha-install: moved from~/.local/bin. It now refuses zips that aren't signed by the team and checks the installed bundle's version. The old sources were wrong: LaunchServices lags one install behind, and the server version was never bumped. It also keeps only the newest backup and cleans up its staging folder on every exit.scripts/personal/t3-alpha-deploy <zip> [host...]: copies the zip and this checkout's installer to matebook and sm-em over SSH, waits for each result, and installs studio last.docs/personal/release-pipeline.mdis rewritten as the single runbook: machines, upstream sync via PR, desktop deploy, mobile build/submit (with the EAS identity values), one-time setup.Verified: built 0.0.46 with
t3-alpha-build, then deployed it to matebook and sm-em witht3-alpha-deploy. Both now report server version 0.0.46 with the stable signing ruleidentifier "com.t3tools.t3code" and anchor apple generic and certificate leaf[subject.CN] = "Apple Development: Emanuel Franzen (T4J48V44Q2)".