fix(ci): unsigned desktop build must disable updater artifacts
createUpdaterArtifacts:true (for release.yml's .sig signing) makes `tauri build`
demand TAURI_SIGNING_PRIVATE_KEY and fail without it — even though the .deb/.AppImage
built fine. Override it off for the unsigned per-commit build via
--config '{"bundle":{"createUpdaterArtifacts":false}}'. release.yml keeps signing.
Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
This commit is contained in:
@@ -68,10 +68,16 @@ jobs:
|
|||||||
run: pnpm install --frozen-lockfile
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
- name: Build desktop bundle (.deb + .AppImage)
|
- name: Build desktop bundle (.deb + .AppImage)
|
||||||
# Unsigned — no TAURI_SIGNING_* needed here (this is a test artifact, not an
|
# Unsigned — no TAURI_SIGNING_* here (this is a test artifact, not an updater
|
||||||
# updater release). --bundles restricts to the two installers we ship; tauri
|
# release). The config sets createUpdaterArtifacts:true (release.yml signs them),
|
||||||
# builds the web SPA first (beforeBuildCommand), so the desktop UI matches.
|
# which makes tauri DEMAND the signing key and fail without it — so override it to
|
||||||
run: pnpm --filter @parking/desktop bundle --bundles deb,appimage
|
# false for this build via --config (a JSON patch merged over tauri.conf.json).
|
||||||
|
# --bundles restricts to the two installers we ship; tauri builds the web SPA
|
||||||
|
# first (beforeBuildCommand), so the desktop UI matches.
|
||||||
|
run: >
|
||||||
|
pnpm --filter @parking/desktop bundle
|
||||||
|
--bundles deb,appimage
|
||||||
|
--config '{"bundle":{"createUpdaterArtifacts":false}}'
|
||||||
|
|
||||||
- name: Collect installers
|
- name: Collect installers
|
||||||
id: collect
|
id: collect
|
||||||
|
|||||||
@@ -183,3 +183,10 @@ The desktop bundle now runs in CI under **two distinct workflows** — keep the
|
|||||||
testing of the native shell, and catches a broken Tauri/Rust build early. Same system-deps + cargo
|
testing of the native shell, and catches a broken Tauri/Rust build early. Same system-deps + cargo
|
||||||
cache as `release.yml`. The container images (`build-images.yml`) and the desktop installers are
|
cache as `release.yml`. The container images (`build-images.yml`) and the desktop installers are
|
||||||
deliberately separate pipelines — the desktop app is **not** containerized ([[container-deployment]]).
|
deliberately separate pipelines — the desktop app is **not** containerized ([[container-deployment]]).
|
||||||
|
- **Gotcha (the unsigned build still demands the key).** `tauri.conf.json` sets
|
||||||
|
`bundle.createUpdaterArtifacts: true` (so `release.yml` produces the `.sig` updater signatures).
|
||||||
|
With that on, `tauri build` **fails** if `TAURI_SIGNING_PRIVATE_KEY` is absent — *"A public key
|
||||||
|
has been found, but no private key"* — even though the `.deb`/`.AppImage` themselves built fine.
|
||||||
|
The unsigned CI build therefore overrides it off with
|
||||||
|
`--config '{"bundle":{"createUpdaterArtifacts":false}}'` (a JSON patch merged over the config),
|
||||||
|
so no `.sig` is attempted and no key is required. `release.yml` keeps the config default (signs).
|
||||||
|
|||||||
Reference in New Issue
Block a user