|
32 | 32 | - name: Bundle |
33 | 33 | run: cargo cntp-bundle --target x86_64-apple-darwin --target aarch64-apple-darwin |
34 | 34 | working-directory: thegrid |
| 35 | + # Codesigning adapted from https://federicoterzi.com/blog/automatic-code-signing-and-notarization-for-macos-apps-using-github-actions/ |
| 36 | + - name: Codesign app bundle |
| 37 | + env: |
| 38 | + MACOS_CERTIFICATE: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE }} |
| 39 | + MACOS_CERTIFICATE_PWD: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }} |
| 40 | + MACOS_CERTIFICATE_NAME: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_NAME }} |
| 41 | + MACOS_CI_KEYCHAIN_PWD: ${{ secrets.APPLE_DEVELOPER_KEYCHAIN_PASSWORD }} |
| 42 | + run: | |
| 43 | + # Turn our base64-encoded certificate back to a regular .p12 file |
| 44 | +
|
| 45 | + echo $MACOS_CERTIFICATE | base64 --decode > certificate.p12 |
| 46 | +
|
| 47 | + # We need to create a new keychain, otherwise using the certificate will prompt |
| 48 | + # with a UI dialog asking for the certificate password, which we can't |
| 49 | + # use in a headless CI environment |
| 50 | +
|
| 51 | + security create-keychain -p "$MACOS_CI_KEYCHAIN_PWD" build.keychain |
| 52 | + security default-keychain -s build.keychain |
| 53 | + security unlock-keychain -p "$MACOS_CI_KEYCHAIN_PWD" build.keychain |
| 54 | + security import certificate.p12 -k build.keychain -P "$MACOS_CERTIFICATE_PWD" -T /usr/bin/codesign |
| 55 | + security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$MACOS_CI_KEYCHAIN_PWD" build.keychain |
| 56 | +
|
| 57 | + # We finally codesign our app bundle, specifying the Hardened runtime option |
| 58 | +
|
| 59 | + /usr/bin/codesign --force -s "$MACOS_CERTIFICATE_NAME" --options runtime target/bundle/*/release/*.app -v |
| 60 | + - name: "Notarize app bundle" |
| 61 | + env: |
| 62 | + PROD_MACOS_NOTARIZATION_APPLE_ID: ${{ secrets.APPLE_NOTARIZATION_APPLE_ID }} |
| 63 | + PROD_MACOS_NOTARIZATION_TEAM_ID: ${{ secrets.APPLE_NOTARIZATION_TEAM_ID }} |
| 64 | + PROD_MACOS_NOTARIZATION_PWD: ${{ secrets.APPLE_NOTARIZATION_PASSWORD }} |
| 65 | + run: | |
| 66 | + # Store the notarization credentials so that we can prevent a UI password dialog |
| 67 | + # from blocking the CI |
| 68 | +
|
| 69 | + echo "Create keychain profile" |
| 70 | + xcrun notarytool store-credentials "notarytool-profile" --apple-id "$PROD_MACOS_NOTARIZATION_APPLE_ID" --team-id "$PROD_MACOS_NOTARIZATION_TEAM_ID" --password "$PROD_MACOS_NOTARIZATION_PWD" |
| 71 | +
|
| 72 | + # We can't notarize an app bundle directly, but we need to compress it as an archive. |
| 73 | + # Therefore, we create a zip file containing our app bundle, so that we can send it to the |
| 74 | + # notarization service |
| 75 | +
|
| 76 | + echo "Creating temp notarization archive" |
| 77 | + ditto -c -k --keepParent "target/bundle/*/release/*.app" "notarization.zip" |
| 78 | +
|
| 79 | + # Here we send the notarization request to the Apple's Notarization service, waiting for the result. |
| 80 | + # This typically takes a few seconds inside a CI environment, but it might take more depending on the App |
| 81 | + # characteristics. Visit the Notarization docs for more information and strategies on how to optimize it if |
| 82 | + # you're curious |
| 83 | +
|
| 84 | + echo "Notarize app" |
| 85 | + xcrun notarytool submit "notarization.zip" --keychain-profile "notarytool-profile" --wait |
| 86 | +
|
| 87 | + # Finally, we need to "attach the staple" to our executable, which will allow our app to be |
| 88 | + # validated by macOS even when an internet connection is not available. |
| 89 | + echo "Attach staple" |
| 90 | + xcrun stapler staple "target/bundle/*/release/*.app" |
35 | 91 | - name: Deploy |
36 | 92 | run: cargo cntp-deploy --target x86_64-apple-darwin --target aarch64-apple-darwin --output-file "$HOME/theGrid-macOS.dmg" |
37 | 93 | working-directory: thegrid |
|
0 commit comments