Repository navigation
distribute: s3, azure and testflight backends - #35
Closed
Interlap01 wants to merge 9 commits into
Closed
Interlap01 wants to merge 9 commits into
Interlap01 wants to merge 9 commits into
Conversation
SubmitTestFlight gains Internal, which refuses an external group before anything changes and creates missing names internal; ToInternalGroup checks the group, uploads with wait and adds the build. release.Options passes Internal through as InternalGroups.
distribute.backend in builder.json (with the bucket, account and group settings) and BackendName pick github, s3, azure or testflight. Inspect and CheckDistribution take the backend: the over-the-air ones keep refusing App Store builds, testflight refuses everything else.
The IPA and a short m.plist go under <prefix>ios-builder/<id>/ with marker metadata and are linked by SigV4 presigned GET URLs (query presign written here, checked against AWS's published vectors), valid for --ttl up to seven days. Each mint presigns the IPA again and rewrites the manifest in place. Cleanup lists the upload folder and deletes only objects whose HEAD shows the marker. Credentials come from AWS_* or the shared credentials file; R2, MinIO and GCS go through distribute.endpoint, path-style. A presigned manifest URL makes a version 13 code (69 modules) against the gist's version 6; temporary credentials push it to ~105, and the session says so when a code is wider than 80 columns.
The same bucket backend on Azure Blob Storage: every request, Builder's own included, carries a service SAS signed with the account key, so one signer covers upload, delete, list and the install links. The SAS keeps its colons, slashes and padding unescaped, which leaves a version 10 code (57 modules). TestBucketQRSizes pins each backend's size.
…uild --backend (else distribute.backend, else github) picks the store; the target is resolved before a build is pushed, so a missing bucket, credential or group fails first. testflight uploads an App Store IPA and adds it to the internal group --group; ios build --distribute --backend testflight runs ios release to that one internal group, which also picks the next build number. --ttl sets the s3/azure link lifetime; the backend flags on ios build need --distribute.
ios distribute without a GitHub login reported the missing token instead of the missing IPA, as it did before backends existed.
Collaborator
Author
|
Dropped: the GitHub draft release + gist backend stays the only distribute backend. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
builder ios distributeandios build --distributetake--backend(elsedistribute.backendin builder.json, else github):distribute.endpoint. The IPA and a shortm.plistgo under<prefix>ios-builder/<id>/with marker metadata. They are linked by SigV4 presigned GET URLs, written in Go without the AWS SDK.--ttlruns from 2m to 168h (default 1h). Credentials come fromAWS_*, elseAWS_PROFILEin~/.aws/credentials.AZURE_STORAGE_KEY(or the connection string).--group/distribute.group, creating the group if it is missing. An external group is refused before the upload.ios build --distribute --backend testflightrunsios releaseto that one internal group, so it also picks the next build number.InspectandCheckDistributionnow take the backend. The whole target (client, bucket, credentials, group) is resolved before a build is pushed.Why
The GitHub draft-release + gist backend needs the
gistscope, and its links last only five minutes. Teams with a bucket get links that last up to a week (--once --ttl 168h). App Store builds, which iOS cannot install over the air, now have a route to devices through internal TestFlight.QR size
The bucket link is longer, so the code is bigger. Measured on representative links and pinned in
TestBucketQRSizes:At ~105 modules the code no longer fits 80 columns, and the session prints a note saying so. The Azure SAS escapes only the signature's
+, which keeps that code a version smaller.Cleanup
--onceleaves them.--cleanupdeletes only objects under<prefix>ios-builder/that carry the marker metadata. S3 checks the marker with HEAD, Azure throughinclude=metadata.How tested
go test -race ./...,go vet,gofmtand golangci-lint v2.12.2 are clean.No live calls were made to any cloud.
Left out
credential_processAWS profiles are not read. The error says to export static or temporary keys instead.