82 lines
2.8 KiB
Markdown
82 lines
2.8 KiB
Markdown
# Installer and signed updates
|
|
|
|
Decky is distributed on Windows as a per-user Tauri NSIS installer. Installed
|
|
copies update from signed Forgejo release assets; they never run `git pull`.
|
|
|
|
## Trust model
|
|
|
|
Two signing systems are independent:
|
|
|
|
- The Tauri updater signature is mandatory. It proves an update was made with
|
|
Decky's updater private key before the installer is executed.
|
|
- Windows Authenticode signing is optional but recommended for wider
|
|
distribution because it reduces SmartScreen warnings. It requires a separate
|
|
code-signing certificate and is not configured yet.
|
|
|
|
Decky's permanent updater key is stored outside the repository:
|
|
|
|
```text
|
|
%USERPROFILE%\.tauri\decky.key
|
|
%USERPROFILE%\.tauri\decky.key.password
|
|
```
|
|
|
|
Back up both files securely. Never regenerate this key after shipping: existing
|
|
installations would reject every artifact signed by a replacement key.
|
|
|
|
## Forgejo layout
|
|
|
|
The installed app checks this stable, public HTTPS URL:
|
|
|
|
```text
|
|
https://git.elijahkuntz.com/Elijah/Decky/raw/branch/main/releases/latest.json
|
|
```
|
|
|
|
`releases/latest.json` contains the newest semantic version, release notes,
|
|
versioned installer URL, and the contents of its `.sig` file. Installer assets
|
|
are attached to immutable Forgejo releases such as `v0.2.0`.
|
|
|
|
The repository and release assets must be readable without authentication.
|
|
Tauri cannot attach the user's Forgejo credentials to an updater request.
|
|
|
|
## Preparing a release locally
|
|
|
|
Keep all three version fields synchronized with `Set-Version.ps1`, commit the
|
|
release, and tag that exact commit:
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File .\scripts\Set-Version.ps1 -Version 0.2.1
|
|
powershell -ExecutionPolicy Bypass -File .\scripts\Prepare-Release.ps1 -Version 0.2.1 -Notes "Release notes"
|
|
git tag v0.2.1
|
|
git push origin main v0.2.1
|
|
```
|
|
|
|
The preparation script runs dependency installation, validation, tests, the
|
|
Tauri build, and creates:
|
|
|
|
```text
|
|
artifacts/release/v0.2.1/
|
|
Decky_0.2.1_x64-setup.exe
|
|
Decky_0.2.1_x64-setup.exe.sig
|
|
latest.json
|
|
```
|
|
|
|
To publish manually, set `FORGEJO_TOKEN` only in the current process and run:
|
|
|
|
```powershell
|
|
powershell -ExecutionPolicy Bypass -File .\scripts\Publish-ForgejoRelease.ps1 -Version 0.2.1 -Notes "Release notes"
|
|
```
|
|
|
|
The publisher creates the Forgejo release, uploads all three assets, and updates
|
|
the tracked `releases/latest.json` through the Forgejo API.
|
|
|
|
## Forgejo Actions
|
|
|
|
`.forgejo/workflows/release.yml` performs the same process when a `v*` tag is
|
|
pushed. Configure a trusted Windows runner whose label matches
|
|
`windows-latest`, then add these repository secrets:
|
|
|
|
- `TAURI_SIGNING_PRIVATE_KEY`: contents of `decky.key`
|
|
- `TAURI_SIGNING_PRIVATE_KEY_PASSWORD`: contents of `decky.key.password`
|
|
|
|
The short-lived `${{ forgejo.token }}` publishes only to this repository. The
|
|
workflow intentionally runs only for trusted tags, never pull requests.
|