name: Desktop Build on: # Lancement manuel uniquement : aucun runner self-hosted [windows/linux, desktop] # n'est enregistré dans Gitea. Le build Windows se fait en local # (desktop/build-windows.bat). Ce workflow reste disponible pour un futur runner. workflow_dispatch: jobs: build-windows: runs-on: [self-hosted, windows, desktop] # runner sur ta machine Windows steps: - uses: actions/checkout@v4 - name: Setup Rust run: rustup default stable && rustup update - name: Setup Tauri CLI run: cargo install tauri-cli --version "^2.0" - name: Setup Python 3.11 embed run: | curl -L -o python-embed.zip "https://www.python.org/ftp/python/3.11.15/python-3.11.15-embed-amd64.zip" powershell Expand-Archive -Path python-embed.zip -DestinationPath desktop/python-embed echo import site >> desktop/python-embed/python311._pth cd desktop/python-embed ./python.exe -m pip install --no-cache-dir -r ../../backend/requirements.txt - name: Stage backend + frontend for bundle working-directory: desktop run: | xcopy /E /I /Q /Y "..\backend" "backend" xcopy /E /I /Q /Y "..\frontend" "frontend" - name: Build MSI working-directory: desktop shell: powershell env: TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} run: | if ([string]::IsNullOrEmpty($env:TAURI_SIGNING_PRIVATE_KEY)) { Write-Host "TAURI_SIGNING_PRIVATE_KEY absent - build sans artefacts de mise a jour." cargo tauri build --bundles msi --config '{"bundle":{"createUpdaterArtifacts":false}}' } else { Write-Host "Signature des artefacts de mise a jour activee." cargo tauri build --bundles msi } if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } - name: Upload MSI artifact uses: actions/upload-artifact@v4 with: name: obsigate-windows-msi path: | desktop/target/release/bundle/msi/*.msi desktop/target/release/bundle/msi/*.msi.sig retention-days: 30 - name: Publish to Gitea Release if: startsWith(github.ref, 'refs/tags/v') run: | $MSI = Get-ChildItem desktop/target/release/bundle/msi/*.msi | Select-Object -First 1 echo "MSI ready: $MSI" build-linux: runs-on: [self-hosted, linux, desktop] # runner sur une machine Linux steps: - uses: actions/checkout@v4 - name: Setup Rust run: rustup default stable && rustup update - name: Install system deps run: | sudo apt-get update sudo apt-get install -y libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev - name: Setup Tauri CLI run: cargo install tauri-cli --version "^2.0" - name: Setup Python venv run: | python3 -m venv desktop/python-embed/venv source desktop/python-embed/venv/bin/activate pip install -r backend/requirements.txt - name: Stage backend + frontend for bundle working-directory: desktop run: | cp -r ../backend backend cp -r ../frontend frontend - name: Build AppImage working-directory: desktop env: TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} run: | if [ -z "$TAURI_SIGNING_PRIVATE_KEY" ]; then echo "TAURI_SIGNING_PRIVATE_KEY absent - build sans artefacts de mise a jour." cargo tauri build --bundles appimage --config '{"bundle":{"createUpdaterArtifacts":false}}' else echo "Signature des artefacts de mise a jour activee." cargo tauri build --bundles appimage fi - name: Build deb working-directory: desktop env: TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} run: | if [ -z "$TAURI_SIGNING_PRIVATE_KEY" ]; then echo "TAURI_SIGNING_PRIVATE_KEY absent - build sans artefacts de mise a jour." cargo tauri build --bundles deb --config '{"bundle":{"createUpdaterArtifacts":false}}' else echo "Signature des artefacts de mise a jour activee." cargo tauri build --bundles deb fi - name: Upload Linux artifacts uses: actions/upload-artifact@v4 with: name: obsigate-linux path: | desktop/target/release/bundle/appimage/*.AppImage desktop/target/release/bundle/appimage/*.AppImage.sig desktop/target/release/bundle/deb/*.deb desktop/target/release/bundle/deb/*.deb.sig retention-days: 30