Skip to content

ci: add Azure desktop packaging pipeline - #284

Merged
cxxxxxn (cxxxxxn) merged 1 commit into
mainfrom
ci/azure-desktop-pipeline
Oct 8, 2026
Merged

cxxxxxn (cxxxxxn) merged 1 commit into
mainfrom
ci/azure-desktop-pipeline

Conversation

@cxxxxxn

Copy link
Copy Markdown
Contributor

Summary

Add an Azure DevOps pipeline that packages the Huabu desktop app on independent Microsoft-hosted Windows and macOS jobs, reusing the existing GitHub Actions release commands and electron-builder configuration.

  • Read Node.js from .nvmrc and pass it to UseNode@1; use Corepack with the integrity-pinned pnpm packageManager.
  • Preserve tag-derived versions, including prereleases, and support a manual releaseTag parameter without committing generated version changes.
  • Validate and publish the complete output directory as huabu-windows and huabu-macos, retaining auto-update metadata and blockmaps.
  • Preserve macOS signing/notarization environment variables and reject missing credentials. Keep Windows unsigned with a clearly marked ESRP insertion point after packaging and before validation/publication.
  • Document onboarding, required secrets, artifact locations, and the post-merge cloud validation procedure.

Existing package scripts, electron-builder configuration, and GitHub Actions release publishing are unchanged. This PR does not publish GitHub Releases or configure ESRP.

Validation

  • pnpm install --frozen-lockfile completed in an isolated worktree based on current main.
  • pnpm typecheck passed.
  • pnpm format and pnpm lint:fix completed; lint reported 0 errors and 350 existing warnings. Only the pipeline and its architecture documentation are included.
  • Focused YAML, PowerShell syntax, Node version propagation, tag/prerelease/manual version behavior, and missing-asset/credential checks passed.
  • Final targeted Prettier check passed.
  • Local validation used Node 24.12.0 and emitted the repository's >=24.16.0 engine warning. The pipeline reads the required version from .nvmrc (currently 24.16.0).

Post-merge cloud validation required

The current governed Azure DevOps creation flow only reads YAML from the repository's default branch, so actual hosted Windows/macOS packaging and Apple signing/notarization have NOT been run yet. Compatibility with any organization-required governed templates must also be confirmed during onboarding.

  1. After merge, create the pipeline using /azure-pipelines.yml from the default branch.
  2. Configure Azure secret variables CSC_LINK (base64 Developer ID .p12), CSC_KEY_PASSWORD, APPLE_ID, APPLE_APP_SPECIFIC_PASSWORD, and APPLE_TEAM_ID.
  3. Run manually with a prerelease releaseTag; do not push a real version tag for this test, since that also triggers the existing GitHub Actions release workflow.
  4. Validate both platform outputs and macOS signatures/notarization, and download artifacts from the run's Artifacts section.
  5. Configure ESRP separately at Windows build -> ESRP Sign -> Publish artifact. If signing changes installer bytes, regenerate matching update metadata and blockmaps before publishing.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Release-tag and version-rewrite logic is duplicated across four CI paths, creating avoidable drift risk.

1 open finding
What changed in this PR

Adds Azure DevOps packaging for Windows and signed/notarized macOS desktop artifacts while preserving the existing release configuration.

Changes:

  • Adds tag-triggered and manual Azure packaging jobs.
  • Validates and publishes complete platform artifacts.
  • Documents setup, secrets, ESRP integration, and validation.
File Description
azure-pipelines.yml Defines Windows and macOS packaging jobs.
docs/​architecture/​desktop-auto-update.md Documents Azure packaging and onboarding.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread azure-pipelines.yml
Comment on lines +44 to +48
@'
const fs = require('node:fs');
const path = 'apps/desktop/package.json';
const ref = process.env.BUILD_SOURCEBRANCH ?? '';
const tag = ref.startsWith('refs/tags/') ? ref.slice('refs/tags/'.length) : (process.env.RELEASE_TAG ?? '');
@cxxxxxn
cxxxxxn (cxxxxxn) merged commit f9145f6 into main Oct 8, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants