Skip to content

pkg: expose signing, asc, distribute, release and ipa as a library - #28

Merged
Interlap01 merged 1 commit into
mainfrom
signing-pkg
Sep 20, 2026
Merged

Interlap01 merged 1 commit into
mainfrom
signing-pkg

Conversation

@Interlap01

Copy link
Copy Markdown
Collaborator

What

signing setup and the on-demand provisioning behind ios build --profile lived in cmd/builder, so nothing outside this module could provision a signing set or release a build. This moves their non-interactive core into internal/signing/sets.go (Setup, EnsureSecrets) and adds the missing pkg/ wrappers.

  • internal/signing/sets.go — the signing-set core: Setup (provision + upload + write the builder.json profile), EnsureSecrets (on-demand provisioning before a dispatch), UploadSet/UploadSecrets/MissingSecrets and the key/path helpers. Nothing in it prompts or prints a summary.
  • cmd/builder keeps what a CLI owns: the plan, the confirmation, the password prompt and the summary. The JSON result is now signing.SetupResult, and the failed upload is read from UploadError rather than recomputed.
  • signing.Commands lets an embedding CLI name its own verbs where error messages point at builder auth apple / builder signing setup.
  • New pkg/asc, pkg/distribute, pkg/release, pkg/ipa, pkg/signing — alias wrappers, so values pass between them without conversion and release.Builder stays the one-method interface a foreign build backend implements. pkg/auth grows the App Store Connect key accessors, pkg/config the distributions, profiles and signing-set names they need.
  • auth.AppleCredentialsFromEnv is exported for a program with its own credential store.

Review notes

The refactor left six wrappers in cmd/builder/signing_auto.go with no callers (missingSigningSecrets, findSigningKey, recordSigningDir, signingKeyDirs, certificateRefused, fileExists) and a verbatim second copy of expandPath in cmd/builder/signing.go. Both are cleaned up here: the dead wrappers are gone and expandPath delegates to signing.ExpandPath.

Verification

  • go build ./..., go vet ./..., gofmt -l . clean.
  • go test ./... passes, including the existing cmd/builder signing tests that drive ensureSigningSecrets and writeSigningProfile through the new wrappers.
  • A throwaway external consumer implementing signing.SecretStore with pkg/github.PublicKey and calling signing.Setup / signing.EnsureSecrets compiles, so the exported surface is usable from outside the module.

No behaviour change to any command.

Another program embedding Builder (mobai-dev) could already reach the
build and config packages through pkg/, but not the App Store Connect
flows: `signing setup` and on-demand provisioning lived in cmd/builder,
so nothing outside this module could provision a signing set or release
a build.

Move the non-interactive core of `signing setup` and `ios build`'s
on-demand provisioning into internal/signing/sets.go as Setup and
EnsureSecrets. cmd/builder keeps everything a CLI owns -- the prompts,
the plan, the confirmation and the summary -- and calls them; the JSON
result is now signing.SetupResult, with the failed upload carried in
UploadError instead of being recomputed by the caller. signing.Commands
lets an embedding CLI name its own verbs where the error messages point
at `builder auth apple` / `builder signing setup`.

Add pkg/asc, pkg/distribute, pkg/release, pkg/ipa and pkg/signing as
alias wrappers, so values pass between them without conversion, and
release.Builder stays the one-method interface a foreign build backend
implements. pkg/auth grows the App Store Connect key accessors and
pkg/config the distributions, profiles and signing-set names those need;
auth.AppleCredentialsFromEnv is exported for a program with its own
credential store.

No behaviour change to any command.
@Interlap01
Interlap01 merged commit 780aa3f into main Sep 20, 2026
8 checks passed
@Interlap01
Interlap01 deleted the signing-pkg branch September 20, 2026 10:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant