#!/bin/bash # Generates Android signing credentials if they don't exist yet. # Works correctly regardless of which directory this script is called from. # # Optional env vars: # ANDROID_KEYSTORE_PASSWORD – keystore password (auto-generated and cached if not set) # ANDROID_KEY_ALIAS – key alias (default: workflow) # ANDROID_KEY_PASSWORD – key password (same as keystore password if not set) set -euo pipefail # Resolve repo root from the location of this script, not from CWD SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" REPO_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)" CREDS_DIR="$REPO_ROOT/mobile/credentials" KEYSTORE="$CREDS_DIR/keystore.p12" CREDS_JSON="$REPO_ROOT/mobile/credentials.json" PASS_CACHE="$CREDS_DIR/.keystore_pass" mkdir -p "$CREDS_DIR" # Determine keystore password: # 1. Prefer explicit env var # 2. Otherwise reuse cached value from previous run (keeps existing keystore valid) # 3. Otherwise generate a random one and cache it if [ -n "${ANDROID_KEYSTORE_PASSWORD:-}" ]; then KEYSTORE_PASSWORD="$ANDROID_KEYSTORE_PASSWORD" elif [ -f "$PASS_CACHE" ]; then KEYSTORE_PASSWORD="$(cat "$PASS_CACHE")" else KEYSTORE_PASSWORD="$(openssl rand -hex 20)" echo "$KEYSTORE_PASSWORD" > "$PASS_CACHE" chmod 600 "$PASS_CACHE" echo "Generated and cached new keystore password." fi KEY_ALIAS="${ANDROID_KEY_ALIAS:-workflow}" KEY_PASSWORD="${ANDROID_KEY_PASSWORD:-$KEYSTORE_PASSWORD}" if [ ! -f "$KEYSTORE" ]; then echo "Generating Android keystore..." keytool -genkeypair -v -storetype PKCS12 \ -keystore "$KEYSTORE" \ -storepass "$KEYSTORE_PASSWORD" \ -alias "$KEY_ALIAS" \ -keypass "$KEY_PASSWORD" \ -keyalg RSA -keysize 2048 -validity 10000 \ -dname "CN=Workflow App, OU=Dev, O=Company, L=Moscow, ST=Moscow, C=RU" 2>/dev/null echo "Keystore created: $KEYSTORE" else echo "Keystore already exists: $KEYSTORE" fi cat > "$CREDS_JSON" <