Decky/app/UPDATES.md

3.8 KiB

Installer and signed updates

Decky is distributed on Windows as a per-user Tauri NSIS installer. Installed copies update from signed Forgejo release assets; they never run git pull.

Trust model

Two signing systems are independent:

  • The Tauri updater signature is mandatory. It proves an update was made with Decky's updater private key before the installer is executed.
  • Windows Authenticode signing is optional but recommended for wider distribution because it reduces SmartScreen warnings. It requires a separate code-signing certificate and is not configured yet.

Decky's permanent updater key is stored outside the repository:

%USERPROFILE%\.tauri\decky.key
%USERPROFILE%\.tauri\decky.key.password

Back up both files securely. Never regenerate this key after shipping: existing installations would reject every artifact signed by a replacement key.

Forgejo layout

The installed app checks this stable, public HTTPS URL:

https://git.elijahkuntz.com/Elijah/Decky/raw/branch/main/releases/latest.json

releases/latest.json contains the newest semantic version, release notes, versioned installer URL, and the contents of its .sig file. Installer assets are attached to immutable Forgejo releases such as v0.2.0.

The repository and release assets must be readable without authentication. Tauri cannot attach the user's Forgejo credentials to an updater request.

Hybrid Windows + Forgejo release flow

The Unraid Forgejo runner is a Linux container. It validates the Svelte and TypeScript client on every push, but it does not build the native Windows/MSVC installer. Build and sign Windows releases on this trusted Windows machine.

Keep all three version fields synchronized, commit and push the source, then prepare the installer from that same commit:

powershell -ExecutionPolicy Bypass -File .\scripts\Set-Version.ps1 -Version 0.3.0
git add app/package.json app/package-lock.json app/src-tauri/Cargo.toml app/src-tauri/tauri.conf.json
git commit -m "release: Decky 0.3.0"
git push origin main
powershell -ExecutionPolicy Bypass -File .\scripts\Prepare-Release.ps1 -Version 0.3.0 -Notes "Board and stack management"

The preparation script runs dependency installation, validation, tests, the Tauri build, and creates:

artifacts/release/v0.3.0/
  Decky_0.3.0_x64-setup.exe
  Decky_0.3.0_x64-setup.exe.sig
  latest.json

Installer files do not belong in Git. To publish them, set the same personal access token value used for the FORGEJO_PAT repository secret only in the current PowerShell process and run:

$env:FORGEJO_PAT = 'paste-token-for-this-session'
powershell -ExecutionPolicy Bypass -File .\scripts\Publish-ForgejoRelease.ps1 -Version 0.3.0 -Notes "Board and stack management"
Remove-Item Env:FORGEJO_PAT
git pull --ff-only

For an interactive, double-clickable option, run:

scripts\Publish-DeckyRelease.cmd

It bypasses PowerShell's script policy only for the publisher process, prompts for the version and a hidden personal access token, and leaves the window open so any error can be read. The token is not saved.

The publisher creates the v0.3.0 Forgejo release/tag at main, uploads the installer, signature, and metadata, then commits the tracked releases/latest.json through the Forgejo API. The final pull synchronizes that small metadata commit locally. Existing Decky installations then discover the release through Settings.

Forgejo Actions

.forgejo/workflows/validate.yml uses the existing Docker runner to install locked dependencies, type-check, test, and build the web client. The repository secret is intentionally not exposed to validation jobs. If the runner uses a custom label instead of docker, update the workflow's runs-on value to the label shown on Forgejo's runner page.