Merge pull request #167 from team-native/design-독서마라톤-ui개선 #80
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CD | |
| on: | |
| push: | |
| branches: | |
| - dev | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| deploy: | |
| name: Deploy to TestFlight | |
| runs-on: macos-15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup mise | |
| uses: jdx/mise-action@v2 | |
| - name: Cache Tuist | |
| uses: actions/cache@v4 | |
| with: | |
| path: ~/.tuist/Cache | |
| key: ${{ runner.os }}-tuist-${{ hashFiles('mise.toml') }} | |
| restore-keys: | | |
| ${{ runner.os }}-tuist- | |
| - name: Install xcpretty | |
| run: gem install xcpretty | |
| - name: Install dependencies | |
| run: tuist install | |
| - name: Restore Firebase configuration | |
| env: | |
| GOOGLE_SERVICE_INFO_PLIST: ${{ secrets.GOOGLE_SERVICE_INFO_PLIST }} | |
| run: | | |
| set -euo pipefail | |
| test -n "$GOOGLE_SERVICE_INFO_PLIST" | |
| FIREBASE_PLIST=Projects/App/Resources/GoogleService-Info.plist | |
| printf '%s\n' "$GOOGLE_SERVICE_INFO_PLIST" > "$FIREBASE_PLIST" | |
| plutil -lint "$FIREBASE_PLIST" | |
| test "$(/usr/libexec/PlistBuddy -c 'Print :BUNDLE_ID' "$FIREBASE_PLIST")" = 'com.bookonios.Book-on-iOS-V1' | |
| - name: Generate project | |
| run: tuist generate --no-open | |
| - name: Import signing certificate | |
| env: | |
| CERTIFICATE_BASE64: ${{ secrets.CERTIFICATE_BASE64 }} | |
| CERTIFICATE_PASSWORD: ${{ secrets.CERTIFICATE_PASSWORD }} | |
| KEYCHAIN_PASSWORD: ${{ secrets.KEYCHAIN_PASSWORD }} | |
| run: | | |
| KEYCHAIN_PATH=$RUNNER_TEMP/app-signing.keychain-db | |
| security create-keychain -p "$KEYCHAIN_PASSWORD" $KEYCHAIN_PATH | |
| security set-keychain-settings -lut 21600 $KEYCHAIN_PATH | |
| security unlock-keychain -p "$KEYCHAIN_PASSWORD" $KEYCHAIN_PATH | |
| echo -n "$CERTIFICATE_BASE64" | base64 --decode -o $RUNNER_TEMP/cert.p12 | |
| security import $RUNNER_TEMP/cert.p12 -P "$CERTIFICATE_PASSWORD" -A -t cert -f pkcs12 -k $KEYCHAIN_PATH | |
| security list-keychain -d user -s $KEYCHAIN_PATH | |
| - name: Import provisioning profile | |
| env: | |
| PROVISIONING_PROFILE_BASE64: ${{ secrets.PROVISIONING_PROFILE_BASE64 }} | |
| run: | | |
| PP_PATH=$RUNNER_TEMP/profile.mobileprovision | |
| PP_PLIST_PATH=$RUNNER_TEMP/profile.plist | |
| echo -n "$PROVISIONING_PROFILE_BASE64" | base64 --decode -o $PP_PATH | |
| openssl smime -inform der -verify -noverify -in $PP_PATH -out $PP_PLIST_PATH 2>/dev/null | |
| PROFILE_UUID=$(/usr/libexec/PlistBuddy -c 'Print :UUID' $PP_PLIST_PATH) | |
| PROFILE_NAME=$(/usr/libexec/PlistBuddy -c 'Print :Name' $PP_PLIST_PATH) | |
| test "$PROFILE_NAME" = "BookOn App Store" | |
| mkdir -p ~/Library/MobileDevice/Provisioning\ Profiles | |
| cp $PP_PATH ~/Library/MobileDevice/Provisioning\ Profiles/$PROFILE_UUID.mobileprovision | |
| - name: Archive | |
| run: | | |
| xcodebuild archive \ | |
| -workspace Book-on-iOS-V1.xcworkspace \ | |
| -scheme Book-on-iOS-V1 \ | |
| -destination 'generic/platform=iOS' \ | |
| -archivePath $RUNNER_TEMP/Book-on-iOS-V1.xcarchive \ | |
| | xcpretty && exit ${PIPESTATUS[0]} | |
| - name: Verify bundled Firebase configuration | |
| run: | | |
| set -euo pipefail | |
| APP_PATH=$(find "$RUNNER_TEMP/Book-on-iOS-V1.xcarchive/Products/Applications" -maxdepth 1 -name '*.app' -print -quit) | |
| test -n "$APP_PATH" | |
| test "$(plutil -convert xml1 -o - Projects/App/Resources/GoogleService-Info.plist)" = "$(plutil -convert xml1 -o - "$APP_PATH/GoogleService-Info.plist")" | |
| - name: Export IPA | |
| env: | |
| EXPORT_OPTIONS_PLIST: ${{ secrets.EXPORT_OPTIONS_PLIST }} | |
| run: | | |
| EXPORT_OPTS_PATH=$RUNNER_TEMP/ExportOptions.plist | |
| echo -n "$EXPORT_OPTIONS_PLIST" | base64 --decode -o $EXPORT_OPTS_PATH | |
| xcodebuild -exportArchive \ | |
| -archivePath $RUNNER_TEMP/Book-on-iOS-V1.xcarchive \ | |
| -exportOptionsPlist $EXPORT_OPTS_PATH \ | |
| -exportPath $RUNNER_TEMP/ipa | |
| - name: Upload to TestFlight | |
| env: | |
| ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }} | |
| ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }} | |
| ASC_PRIVATE_KEY: ${{ secrets.ASC_PRIVATE_KEY }} | |
| run: | | |
| API_KEY_DIR=$HOME/.appstoreconnect/private_keys | |
| API_KEY_PATH=$API_KEY_DIR/AuthKey_$ASC_KEY_ID.p8 | |
| IPA_PATH=$(find "$RUNNER_TEMP/ipa" -maxdepth 1 -name '*.ipa' -print -quit) | |
| test -n "$IPA_PATH" | |
| mkdir -p "$API_KEY_DIR" | |
| printf '%s\n' "$ASC_PRIVATE_KEY" > "$API_KEY_PATH" | |
| xcrun altool --upload-app \ | |
| --type ios \ | |
| --file "$IPA_PATH" \ | |
| --apiKey "$ASC_KEY_ID" \ | |
| --apiIssuer "$ASC_ISSUER_ID" |