Skip to content

nightswatcher: add /sign-apks endpoint - #184

Closed
Frenzie wants to merge 1 commit into
koreader:masterfrom
Frenzie:apk-signing
Closed

Frenzie wants to merge 1 commit into
koreader:masterfrom
Frenzie:apk-signing

Conversation

@Frenzie

@Frenzie Frenzie commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Cf. discussion in koreader/koreader#15902 (comment). Perhaps it's better completely separately, but for this poc I figured I'd reuse everything that was already there.

In the meantime I intend to apply it to a little automated release I've set up on GitLab.

https://gitlab.com/koreader/nightly-builds/-/releases/nightly-20260920-09-2865086386

The CI side of things would look something like this:

diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
index edc3716..4d6b51f 100644
--- a/.gitlab-ci.yml
+++ b/.gitlab-ci.yml
@@ -10,6 +10,7 @@ workflow:
 
 stages:
   - build
+  - sign
   - release
 
 variables:
@@ -149,6 +150,44 @@ build_android_x86:
     - bash build_release.sh android-x86
 
 
+sign_android:
+  stage: sign
+  image: alpine:3.24
+  after_script: []
+  when: always
+  dependencies:
+    - build_android
+    - build_android_aarch64
+    - build_android_x86
+  script:
+    - |
+      set -eu
+      apk add --no-cache curl unzip zip
+      : "${APK_SIGNING_URL:?Set APK_SIGNING_URL to the signing endpoint}"
+      : "${APK_SIGNING_TOKEN:?Set APK_SIGNING_TOKEN as a masked CI/CD variable}"
+
+      find . -type f -name 'koreader-*.apk' -print | sort > apk-files.txt
+      test -s apk-files.txt
+      zip -j unsigned-apks.zip $(cat apk-files.txt)
+
+      curl --fail-with-body \
+        --header "X-APK-SIGNING-TOKEN: $APK_SIGNING_TOKEN" \
+        --header 'Content-Type: application/zip' \
+        --data-binary @unsigned-apks.zip \
+        --output signed-apks.zip \
+        "$APK_SIGNING_URL"
+
+      mkdir signed-apks
+      unzip -o signed-apks.zip -d signed-apks
+      find . -type f -name 'koreader-android-fdroid-latest' -exec cp {} signed-apks/ \;
+      find signed-apks -type f -name '*.apk' -print | sort > signed-apk-files.txt
+      test -s signed-apk-files.txt
+  artifacts:
+    paths:
+      - signed-apks/koreader-*.apk
+      - signed-apks/koreader-android-fdroid-latest
+
+
 publish_daily_release:
   stage: release
   image: alpine:3.24
@@ -169,9 +208,7 @@ publish_daily_release:
     - build_linux_x86_64
     - build_linux_aarch64
     - build_linux_armhf
-    - build_android
-    - build_android_aarch64
-    - build_android_x86
+    - sign_android
   script:
     - |
       set -eu

This change is Reviewable

@Frenzie

Frenzie commented Sep 29, 2026 •

Copy link
Copy Markdown
Member Author

Dropping this idea.

See koreader/koreader#16092.

@Frenzie Frenzie closed this Sep 29, 2026
@Frenzie
Frenzie deleted the apk-signing branch September 29, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant