Public Access
CI: build, sign and publish firmware releases on Gitea #5
Notifications
Due Date
No due date set.
Blocks
#6 Updates: check Gitea for new releases and install them
twisla/roro9stack
Reference: twisla/roro9stack#5
Reference in New Issue
Block a user
Idea
Pushing a tag builds the release firmware and the Debug Build in CI, makes signed Update Files (
.ota) and creates a Gitea release with the files and the notes attached.Why
Today releases are built and signed on my machine. To install releases from the device, the images have to be built the same way every time and published where the device can find them.
What's known
scripts/ci.shand the same build image.~/.config/roro9stack/ota-key.pem. Putting it in CI as a secret means a CI compromise can sign firmware every device would accept.firmware.ota, and a+debug.otafor the Debug Build.factory.binfor USB flashing..pio/elves.Questions for the design round
v*? Should there be pre-releases for testing?In place (merge
edc140e)..gitea/workflows/ci.ymlruns the host tests and both builds on every push; a tagv*also builds, signs and publishes a release. The thirteen tags from v0.1.0 to v0.10.0 have their releases, and each Update File was downloaded and verified. Decisions and how it was built:docs/milestones/R1.md,docs/adr/0008-ci-signs-releases.md.