diff --git a/.github/workflows/desktop-build.yml b/.github/workflows/desktop-build.yml index bf3b3f16d..8b481d9a6 100644 --- a/.github/workflows/desktop-build.yml +++ b/.github/workflows/desktop-build.yml @@ -7,6 +7,10 @@ name: desktop-build # macOS is signed with a Developer ID certificate + notarized (so it opens on # any Mac without the "app is damaged" Gatekeeper block) when `sign-macos` is # true and the Apple secrets are configured. Windows/Linux ship unsigned in v1. +# +# Triggered two ways: +# - workflow_dispatch: manual ad-hoc builds from the Actions tab. +# - workflow_call: called by release.yml to attach installers to a release. on: workflow_dispatch: inputs: @@ -20,6 +24,39 @@ on: required: false type: number default: 5 + upload-artifact-prefix: + description: 'Prefix for uploaded artifact name' + required: false + type: string + default: 'kimi-desktop' + workflow_call: + inputs: + sign-macos: + description: 'Sign + notarize macOS (needs Apple secrets)' + required: false + type: boolean + default: false + retention-days: + description: 'Artifact retention in days' + required: false + type: number + default: 7 + upload-artifact-prefix: + description: 'Prefix for uploaded artifact name' + required: false + type: string + default: 'kimi-desktop' + secrets: + APPLE_CERTIFICATE_P12: + required: false + APPLE_CERTIFICATE_PASSWORD: + required: false + APPLE_NOTARIZATION_KEY_P8: + required: false + APPLE_NOTARIZATION_KEY_ID: + required: false + APPLE_NOTARIZATION_ISSUER_ID: + required: false permissions: contents: read @@ -60,6 +97,11 @@ jobs: - name: Build Kimi web assets # The SEA blob embeds apps/kimi-code/dist-web; build the web app and # stage its assets before producing the native executable. + # KIMI_WEB_DESKTOP=1 bakes the internal-build banner into the web bundle + # (see apps/kimi-web/src/components/InternalBuildBanner.vue); only the + # desktop sets this flag, so the CLI `kimi web` stays banner-free. + env: + KIMI_WEB_DESKTOP: '1' run: | pnpm --filter @moonshot-ai/kimi-web run build node apps/kimi-code/scripts/copy-web-assets.mjs @@ -108,7 +150,7 @@ jobs: - name: Upload installers uses: actions/upload-artifact@v7 with: - name: kimi-desktop-${{ matrix.target }} + name: ${{ inputs.upload-artifact-prefix }}-${{ matrix.target }} retention-days: ${{ inputs.retention-days }} path: | apps/kimi-desktop/dist-app/*.dmg diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1f74dc9d9..49b9952a9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -97,6 +97,22 @@ jobs: APPLE_NOTARIZATION_KEY_ID: ${{ secrets.APPLE_NOTARIZATION_KEY_ID }} APPLE_NOTARIZATION_ISSUER_ID: ${{ secrets.APPLE_NOTARIZATION_ISSUER_ID }} + desktop-artifacts: + name: Desktop release artifact + needs: release + if: needs.release.outputs.kimi_native_release == 'true' + uses: ./.github/workflows/desktop-build.yml + with: + upload-artifact-prefix: kimi-desktop + retention-days: 7 + sign-macos: true + secrets: + APPLE_CERTIFICATE_P12: ${{ secrets.APPLE_CERTIFICATE_P12 }} + APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }} + APPLE_NOTARIZATION_KEY_P8: ${{ secrets.APPLE_NOTARIZATION_KEY_P8 }} + APPLE_NOTARIZATION_KEY_ID: ${{ secrets.APPLE_NOTARIZATION_KEY_ID }} + APPLE_NOTARIZATION_ISSUER_ID: ${{ secrets.APPLE_NOTARIZATION_ISSUER_ID }} + publish-native-assets: name: Publish native release assets needs: @@ -128,3 +144,30 @@ jobs: GH_TOKEN: ${{ github.token }} RELEASE_TAG: ${{ needs.release.outputs.kimi_release_tag }} run: gh release upload "$RELEASE_TAG" dist-native-release/* --clobber + + publish-desktop-assets: + name: Publish desktop release assets + needs: + - release + - desktop-artifacts + if: needs.release.outputs.kimi_native_release == 'true' + runs-on: ubuntu-latest + permissions: + contents: write + + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Download desktop artifacts + uses: actions/download-artifact@v8 + with: + pattern: kimi-desktop-* + path: dist-desktop-release + merge-multiple: true + + - name: Upload assets to GitHub Release + env: + GH_TOKEN: ${{ github.token }} + RELEASE_TAG: ${{ needs.release.outputs.kimi_release_tag }} + run: gh release upload "$RELEASE_TAG" dist-desktop-release/* --clobber