name: Build desktop # Build the Tauri desktop installers (.deb + .AppImage) on every push to dev/main and # upload them as workflow ARTIFACTS — a downloadable, per-commit build for testing the # native shell. This is NOT a release: it's unsigned (no updater key) and creates no Gitea # Release. Signed, versioned releases stay on release.yml (tag v* → .deb/.rpm/.AppImage + # latest.json for the auto-updater). See wiki/decisions/desktop-shell-tauri.md. on: push: branches: [dev, main] paths: - 'apps/desktop/**' - 'apps/web/**' - 'packages/**' - 'package.json' - 'pnpm-lock.yaml' - 'pnpm-workspace.yaml' - '.gitea/workflows/build-desktop.yml' workflow_dispatch: jobs: desktop: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node 22 uses: actions/setup-node@v4 with: node-version: 22 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.24.0 --activate - name: Install Tauri system deps # Same set release.yml uses (verified): WebKitGTK 4.1 + libsoup-3 + the GTK/ # appindicator/rsvg stack + AppImage tooling (patchelf, file). run: | sudo apt-get update sudo apt-get install -y --no-install-recommends \ libwebkit2gtk-4.1-dev \ libsoup-3.0-dev \ libgtk-3-dev \ libayatana-appindicator3-dev \ librsvg2-dev \ patchelf \ file \ build-essential \ curl \ wget - name: Set up Rust uses: dtolnay/rust-toolchain@stable - name: Cache cargo + target uses: actions/cache@v4 with: path: | ~/.cargo/registry ~/.cargo/git apps/desktop/src-tauri/target key: ${{ runner.os }}-cargo-${{ hashFiles('apps/desktop/src-tauri/Cargo.lock') }} restore-keys: ${{ runner.os }}-cargo- - name: Install dependencies run: pnpm install --frozen-lockfile - name: Build desktop bundle (.deb + .AppImage) # Unsigned — no TAURI_SIGNING_* here (this is a test artifact, not an updater # release). The config sets createUpdaterArtifacts:true (release.yml signs them), # which makes tauri DEMAND the signing key and fail without it — so override it to # false for this build via --config (a JSON patch merged over tauri.conf.json). # --bundles restricts to the two installers we ship; tauri builds the web SPA # first (beforeBuildCommand), so the desktop UI matches. run: > pnpm --filter @parking/desktop bundle --bundles deb,appimage --config '{"bundle":{"createUpdaterArtifacts":false}}' - name: Collect installers id: collect # Copy out the two installers under SPACE-FREE names (tauri names them # "Parking System_0.0.0_amd64.deb" — spaces break asset URLs). Short SHA in the # name so a downloaded file is traceable to its commit. run: | set -e BUNDLE=apps/desktop/src-tauri/target/release/bundle SHA="$(echo "${GITHUB_SHA}" | cut -c1-7)" mkdir -p dist deb=$(find "$BUNDLE/deb" -name '*.deb' | head -1) app=$(find "$BUNDLE/appimage" -name '*.AppImage' | head -1) cp "$deb" "dist/parking-desktop-${GITHUB_REF_NAME}-${SHA}.deb" cp "$app" "dist/parking-desktop-${GITHUB_REF_NAME}-${SHA}.AppImage" echo "Artifacts:"; ls -la dist/ - name: Publish to a rolling per-branch pre-release # actions/upload-artifact's backend isn't reliable on this Gitea runner, so we # publish to a Gitea RELEASE via the API instead (the proven pattern from # release.yml — built-in token, plain curl). One ROLLING pre-release per branch # (tag desktop-): delete + recreate each push so it always holds the # latest dev/main installer. This is NOT the signed updater release (release.yml, # tag v*) — it's a prerelease, unsigned, with no latest.json. env: TOKEN: ${{ secrets.GITHUB_TOKEN }} API: ${{ github.api_url }} REPO: ${{ github.repository }} TAG: desktop-${{ github.ref_name }} run: | set -e auth="Authorization: token ${TOKEN}" # Drop any existing rolling release for this branch (ignore if absent) so its # tag + stale assets don't pile up; recreate it fresh below. OLD=$(curl -sS -H "$auth" "${API}/repos/${REPO}/releases/tags/${TAG}" \ | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2 || true) if [ -n "$OLD" ]; then curl -sS -X DELETE -H "$auth" "${API}/repos/${REPO}/releases/${OLD}" || true # Also delete the tag itself so the recreate points at this commit. curl -sS -X DELETE -H "$auth" "${API}/repos/${REPO}/git/refs/tags/${TAG}" || true fi REL=$(curl -sS -X POST -H "$auth" -H "Content-Type: application/json" \ -d "{\"tag_name\":\"${TAG}\",\"target_commitish\":\"${GITHUB_SHA}\",\"name\":\"Desktop build (${GITHUB_REF_NAME})\",\"body\":\"Unsigned per-commit desktop installers from ${GITHUB_REF_NAME} @ ${GITHUB_SHA}. Rolling — overwritten each push. Not an updater release.\",\"draft\":false,\"prerelease\":true}" \ "${API}/repos/${REPO}/releases") REL_ID=$(printf '%s' "$REL" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2) echo "release id: ${REL_ID}" for f in dist/*; do name=$(basename "$f") echo "uploading ${name}" curl -sS -X POST -H "$auth" -H "Content-Type: application/octet-stream" \ --data-binary @"${f}" \ "${API}/repos/${REPO}/releases/${REL_ID}/assets?name=${name}" >/dev/null done echo "done"