-
Notifications
You must be signed in to change notification settings - Fork 0
Setting Up and Securing a Keystore for CI CD
This tutorial covers the steps needed to create and secure a keystore, retrieve its SHA-1 and SHA-256 fingerprints, encode it for secure storage as GitHub secrets, and configure the GitHub Actions workflow to use it for signing an APK during the build process.
Follow the instructions provided by the official Android Developer guide on creating a keystore.
- Open Android Studio.
- Go to Build > Generate Signed Bundle / APK.
- Select APK or Android App Bundle based on your needs.
- Click Next, then select Create new… to generate a new keystore.
- Follow the prompts to set the location, password, alias, and key passwords.
- Click Finish. Your new keystore (e.g.,
upload-keystore.jks) is now ready.
To use Firebase Authentication or other Firebase services, add your keystore’s SHA-1 and SHA-256 fingerprints to Firebase.
-
Open a terminal or Command Prompt.
-
Run the following command, replacing
<path_to_your_keystore>,<key_alias>, and<keystore_password>with your specific values:keytool -list -v -keystore <path_to_your_keystore> -alias <key_alias> -storepass <keystore_password>
-
Example:
keytool -list -v -keystore path/to/my/wophy.jks -alias wophy -storepass wophy
-
-
The output will display both SHA-1 and SHA-256 fingerprints. Copy these fingerprints and add them to your Firebase project:
- Go to the Firebase Console.
- Open Project Settings > General > Your Apps.
- Add the SHA-1 and SHA-256 fingerprints.
Follow the best practices to keep your keystore secure, as detailed in the Android Developer guide. Here are some essential tips:
- Never commit your
keystore.jksfile to version control. - Use secure storage options like GitHub Secrets, environment variables, or a secure keystore management tool for CI/CD systems.
- Ensure access to the keystore and its credentials is limited to trusted personnel.
- Encode keystore.jks in Base64:
-
Open a terminal or Command Prompt and run:
-
On macOS/Linux:
base64 wophy.jks > wophy.jks.base64 -
On Windows (PowerShell):
[Convert]::ToBase64String([IO.File]::ReadAllBytes("wophy.jks")) | Out-File -Encoding ASCII "wophy.jks.base64"
-
-
Encode
keystore.propertiesin Base64:-
First, create a
keystore.propertiesfile with the following content, adjusting the values for your keystore:storePassword=your_store_password keyPassword=your_key_password keyAlias=your_key_alias storeFile=app/wophy.jks
-
Run the following commands to encode it:
-
On macOS/Linux:
base64 keystore.properties > keystore.properties.base64 -
On Windows (PowerShell):
[Convert]::ToBase64String([IO.File]::ReadAllBytes("keystore.properties")) | Out-File -Encoding ASCII "keystore.properties.base64"
-
-
-
Upload Encoded Files to GitHub Secrets:
- Go to your GitHub repository.
- Navigate to Settings > Secrets and variables > Actions.
- Click New repository secret and add the encoded Base64 contents:
- For
keystore.jks, create a secret namedKEYSTORE_BASE_64. - For
keystore.properties, create a secret namedKEYSTORE_PROPERTIES.
- For
- Paste the corresponding Base64-encoded strings into each secret field and save.
In your GitHub Actions workflow file (e.g., .github/workflows/apk-release.yml), add a step to decode the secrets and save them as files.
- name: Decode secrets
env:
KEYSTORE: ${{ secrets.KEYSTORE_BASE_64 }}
KEYSTORE_PROPERTIES: ${{ secrets.KEYSTORE_PROPERTIES }}
run: |
echo "$KEYSTORE" | base64 --decode > ./app/wophy.jks
echo "$KEYSTORE_PROPERTIES" | base64 --decode > ./keystore.propertiesExplanation
-
KEYSTORE: Decodes theKEYSTORE_BASE_64secret and saves it aswophy.jksin the./app directory. -
KEYSTORE_PROPERTIES: Decodes theKEYSTORE_PROPERTIESsecret and saves it askeystore.propertiesin the root directory.
By following these steps, your GitHub Actions workflow will be able to access and use the keystore and properties file securely to sign the APK during the build process.