ci: move workflows to the repository root

GitHub only runs workflows from .github/workflows at the root, so the six
workflows inherited from the two projects have to live there rather than under
web/ and android/. Each one gets a path filter so web-only changes do not
trigger Android builds, a working directory for its subproject, and a prefixed
filename to keep the two sets apart.

Gradle now sits at android/android, the Firebase action reads its config from
web/ via entryPoint, and the Android checkout no longer needs submodules.
This commit is contained in:
tiennm99 committed 2026-08-03 18:04:39 +07:00
1 parent d1b68b2fe4
commit 59b884c47e
6 files changed
+72 -24

No files matched your search

@@ -1,18 +1,28 @@
name: build-debug
name: android / build debug
on:
pull_request:
paths:
- 'web/**'
- 'android/**'
- '.github/workflows/android-build-debug.yml'
push:
branches: [main]
paths:
- 'web/**'
- 'android/**'
- '.github/workflows/android-build-debug.yml'
jobs:
build:
runs-on: ubuntu-latest
defaults:
run:
working-directory: android
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
- name: Set up Node 22
uses: actions/setup-node@v7
@@ -33,17 +43,17 @@ jobs:
- name: Install wrapper deps
run: npm ci
- name: Build loto + sync into Android
- name: Build web + sync into Android
run: npm run build
- name: Assemble debug APK
working-directory: android
working-directory: android/android
run: ./gradlew :app:assembleDebug
- name: Upload debug APK
uses: actions/upload-artifact@v7
with:
name: app-debug.apk
path: android/app/build/outputs/apk/debug/*.apk
path: android/android/app/build/outputs/apk/debug/*.apk
archive: false
retention-days: 7
@@ -1,4 +1,4 @@
name: release
name: android / release
on:
push:
@@ -11,10 +11,13 @@ jobs:
build:
runs-on: ubuntu-latest
defaults:
run:
working-directory: android
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
persist-credentials: false
- name: Set up Node 22
@@ -36,16 +39,16 @@ jobs:
- name: Install wrapper deps
run: npm ci
- name: Build loto + sync into Android
- name: Build web + sync into Android
run: npm run build
- name: Decode keystore
env:
KEYSTORE_BASE64: ${{ secrets.KEYSTORE_BASE64 }}
run: printf '%s' "$KEYSTORE_BASE64" | base64 --decode > keystore.p12
run: printf '%s' "$KEYSTORE_BASE64" | base64 --decode > "$GITHUB_WORKSPACE/keystore.p12"
- name: Build signed AAB + APK
working-directory: android
working-directory: android/android
env:
LOTO_KEYSTORE_PATH: ${{ github.workspace }}/keystore.p12
LOTO_KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
@@ -57,8 +60,8 @@ jobs:
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
with:
files: |
android/app/build/outputs/apk/release/*.apk
android/app/build/outputs/bundle/release/*.aab
android/android/app/build/outputs/apk/release/*.apk
android/android/app/build/outputs/bundle/release/*.aab
# Auto-publish to Google Play (gated on the service-account secret).
# Skips silently if PLAY_SERVICE_ACCOUNT_JSON is not configured, so
@@ -83,8 +86,8 @@ jobs:
with:
serviceAccountJsonPlainText: ${{ secrets.PLAY_SERVICE_ACCOUNT_JSON }}
packageName: com.miti99.loto
releaseFiles: android/app/build/outputs/bundle/release/*.aab
releaseFiles: android/android/app/build/outputs/bundle/release/*.aab
tracks: internal
status: completed
# Bumps versionCode automatically? No — must be incremented
# manually in android/app/build.gradle before tagging.
# manually in android/android/app/build.gradle before tagging.
@@ -1,8 +1,11 @@
name: Deploy to GitHub Pages
name: web / deploy to GitHub Pages
on:
push:
branches: [main]
paths:
- 'web/**'
- '.github/workflows/web-deploy-github-pages.yml'
workflow_dispatch:
permissions:
@@ -17,19 +20,25 @@ concurrency:
jobs:
build:
runs-on: ubuntu-latest
defaults:
run:
working-directory: web
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
package_json_file: web/package.json
- uses: actions/setup-node@v7
with:
node-version: '24'
cache: pnpm
cache-dependency-path: web/pnpm-lock.yaml
- run: pnpm install --frozen-lockfile
- run: pnpm build:gh
- uses: actions/configure-pages@v6
- uses: actions/upload-pages-artifact@v5
with:
path: build
path: web/build
deploy:
needs: build
@@ -1,20 +1,26 @@
# This file was auto-generated by the Firebase CLI
# Originally generated by the Firebase CLI
# https://github.com/firebase/firebase-tools
# entryPoint points the action at web/, where firebase.json and .firebaserc live.
name: Deploy to Firebase Hosting on merge
name: web / deploy to Firebase Hosting on merge
on:
push:
branches:
- main
paths:
- 'web/**'
- '.github/workflows/web-firebase-hosting-merge.yml'
jobs:
build_and_deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- run: npm ci && npm run build
working-directory: web
- uses: FirebaseExtended/action-hosting-deploy@v0
with:
repoToken: ${{ secrets.GITHUB_TOKEN }}
firebaseServiceAccount: ${{ secrets.FIREBASE_SERVICE_ACCOUNT_LOOTOO }}
channelId: live
projectId: lootoo
entryPoint: web
@@ -1,8 +1,13 @@
# This file was auto-generated by the Firebase CLI
# Originally generated by the Firebase CLI
# https://github.com/firebase/firebase-tools
# entryPoint points the action at web/, where firebase.json and .firebaserc live.
name: Deploy to Firebase Hosting on PR
on: pull_request
name: web / deploy to Firebase Hosting on PR
on:
pull_request:
paths:
- 'web/**'
- '.github/workflows/web-firebase-hosting-pull-request.yml'
permissions:
checks: write
contents: read
@@ -14,8 +19,10 @@ jobs:
steps:
- uses: actions/checkout@v7
- run: npm ci && npm run build
working-directory: web
- uses: FirebaseExtended/action-hosting-deploy@v0
with:
repoToken: ${{ secrets.GITHUB_TOKEN }}
firebaseServiceAccount: ${{ secrets.FIREBASE_SERVICE_ACCOUNT_LOOTOO }}
projectId: lootoo
entryPoint: web
@@ -1,28 +1,41 @@
name: Verify build
name: web / verify build
on:
pull_request:
branches: [main]
paths:
- 'web/**'
- '.github/workflows/web-verify-build.yml'
push:
branches: [main]
paths:
- 'web/**'
- '.github/workflows/web-verify-build.yml'
permissions:
contents: read
concurrency:
group: verify-build-${{ github.ref }}
group: web-verify-build-${{ github.ref }}
cancel-in-progress: true
defaults:
run:
working-directory: web
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
package_json_file: web/package.json
- uses: actions/setup-node@v7
with:
node-version: '24'
cache: pnpm
cache-dependency-path: web/pnpm-lock.yaml
- run: pnpm install --frozen-lockfile
- run: pnpm test
- run: pnpm build