android-client: a release-signed APK, published through the server
...
Release builds had no signingConfig, so assembleRelease produced an APK that
Android refuses to install. Sign with a key kept out of the repo: the keystore
lives in ~/.navi-android/, and android-client/keystore.properties (gitignored,
600) points at it and carries the passwords. A clone without that file still
builds — it just gets an unsigned APK, which is the right thing to fail into
for someone who has no business signing a release.
tools/publish-apk.sh builds the release APK into webclient/public/download/
and writes a JSON sidecar (version, size, sha256, build time) for the settings
page to read. The server mounts that directory at /download, so the APK ships
with a plain git pull like everything else. dist/download is ignored: vite
copies public/ into dist/ on every build, and serving the copy out of public/
means one binary in git instead of two.
Eugene Sukhodolskiy
committed
6 hours ago