Skip to content

Setting Up and Securing a Keystore for CI CD

NailLaraqui edited this page Dec 15, 2025 · 1 revision

This tutorial covers the steps needed to create and secure a keystore, retrieve its SHA-1 and SHA-256 fingerprints, encode it for secure storage as GitHub secrets, and configure the GitHub Actions workflow to use it for signing an APK during the build process.

Step 1: Create a Keystore Using Android Studio

Follow the instructions provided by the official Android Developer guide on creating a keystore.

  1. Open Android Studio.
  2. Go to Build > Generate Signed Bundle / APK.
  3. Select APK or Android App Bundle based on your needs.
  4. Click Next, then select Create new… to generate a new keystore.
  5. Follow the prompts to set the location, password, alias, and key passwords.
  6. Click Finish. Your new keystore (e.g., upload-keystore.jks) is now ready.

Step 2: Retrieve SHA-1 and SHA-256 Fingerprints of the Keystore

To use Firebase Authentication or other Firebase services, add your keystore’s SHA-1 and SHA-256 fingerprints to Firebase.

  1. Open a terminal or Command Prompt.

  2. Run the following command, replacing <path_to_your_keystore>, <key_alias>, and <keystore_password> with your specific values:

    keytool -list -v -keystore <path_to_your_keystore> -alias <key_alias> -storepass <keystore_password>
    • Example:

      keytool -list -v -keystore path/to/my/wophy.jks -alias wophy -storepass wophy
      
  3. The output will display both SHA-1 and SHA-256 fingerprints. Copy these fingerprints and add them to your Firebase project:

    • Go to the Firebase Console.
    • Open Project Settings > General > Your Apps.
    • Add the SHA-1 and SHA-256 fingerprints.

Step 3: Keep the Keystore Secure

Follow the best practices to keep your keystore secure, as detailed in the Android Developer guide. Here are some essential tips:

  • Never commit your keystore.jks file to version control.
  • Use secure storage options like GitHub Secrets, environment variables, or a secure keystore management tool for CI/CD systems.
  • Ensure access to the keystore and its credentials is limited to trusted personnel.

Step 4: Encode keystore.properties and keystore.jks in Base64 and Upload to GitHub Secrets

  1. Encode keystore.jks in Base64:
  • Open a terminal or Command Prompt and run:

    • On macOS/Linux:

      base64 wophy.jks > wophy.jks.base64
    • On Windows (PowerShell):

      [Convert]::ToBase64String([IO.File]::ReadAllBytes("wophy.jks")) | Out-File -Encoding ASCII "wophy.jks.base64"
  1. Encode keystore.properties in Base64:

    • First, create a keystore.properties file with the following content, adjusting the values for your keystore:

      storePassword=your_store_password
      keyPassword=your_key_password
      keyAlias=your_key_alias
      storeFile=app/wophy.jks
    • Run the following commands to encode it:

      • On macOS/Linux:

        base64 keystore.properties > keystore.properties.base64
      • On Windows (PowerShell):

      [Convert]::ToBase64String([IO.File]::ReadAllBytes("keystore.properties")) | Out-File -Encoding ASCII "keystore.properties.base64"
  2. Upload Encoded Files to GitHub Secrets:

    • Go to your GitHub repository.
    • Navigate to Settings > Secrets and variables > Actions.
    • Click New repository secret and add the encoded Base64 contents:
      • For keystore.jks, create a secret named KEYSTORE_BASE_64.
      • For keystore.properties, create a secret named KEYSTORE_PROPERTIES.
    • Paste the corresponding Base64-encoded strings into each secret field and save.

Configure the GitHub Actions Workflow to Decode the Secrets and Create the Files

In your GitHub Actions workflow file (e.g., .github/workflows/apk-release.yml), add a step to decode the secrets and save them as files.

- name: Decode secrets
  env:
    KEYSTORE: ${{ secrets.KEYSTORE_BASE_64 }}
    KEYSTORE_PROPERTIES: ${{ secrets.KEYSTORE_PROPERTIES }}
  run: |
    echo "$KEYSTORE" | base64 --decode > ./app/wophy.jks
    echo "$KEYSTORE_PROPERTIES" | base64 --decode > ./keystore.properties

Explanation

  • KEYSTORE: Decodes the KEYSTORE_BASE_64 secret and saves it as wophy.jks in the ./app directory.
  • KEYSTORE_PROPERTIES: Decodes the KEYSTORE_PROPERTIES secret and saves it as keystore.properties in the root directory.

By following these steps, your GitHub Actions workflow will be able to access and use the keystore and properties file securely to sign the APK during the build process.

Clone this wiki locally