config.py 12 KB
Newer Older
Daniel Martí's avatar
Daniel Martí committed
1
#!/usr/bin/env python3
2

3 4
# Copy this file to config.py, then amend the settings below according to
# your system configuration.
Ciaran Gultnieks's avatar
Ciaran Gultnieks committed
5

6
# Custom path to the Android SDK, defaults to $ANDROID_HOME
Daniel Martí's avatar
Daniel Martí committed
7
# sdk_path = "$ANDROID_HOME"
8

Boris Kraut's avatar
Boris Kraut committed
9
# Custom paths to various versions of the Android NDK, defaults to 'r12b' set
10 11
# to $ANDROID_NDK. Most users will have the latest at $ANDROID_NDK, which is
# used by default. If a version is missing or assigned to None, it is assumed
12 13
# not installed.
# ndk_paths = {
14
#     'r9b': None,
Daniel Martí's avatar
Daniel Martí committed
15
#     'r10e': None,
Boris Kraut's avatar
Boris Kraut committed
16
#     'r11c': None,
Daniel Martí's avatar
Daniel Martí committed
17
#     'r12b': "$ANDROID_NDK",
est's avatar
est committed
18
#     'r13b': None,
19
#     'r14b': None,
20
#     'r15c': None,
Marcus Hoffmann's avatar
Marcus Hoffmann committed
21
#     'r16': None,
22
# }
23

24
# java_paths = {
Daniel Martí's avatar
Daniel Martí committed
25
#     '1.8': "/usr/lib/jvm/java-8-openjdk",
26 27
# }

28
# Build tools version to be used
29
# build_tools = "25.0.2"
30

31 32 33 34
# Force all build to use the above version of build -tools, good for testing
# builds without having all of the possible build-tools installed.
# force_build_tools = True

35
# Command or path to binary for running Ant
36
# ant = "ant"
37

38
# Command or path to binary for running maven 3
39
# mvn3 = "mvn"
Daniel Martí's avatar
Daniel Martí committed
40

41
# Command or path to binary for running Gradle
42
# gradle = "gradle"
43

44 45 46 47 48
# Set the maximum age (in days) of an index that a client should accept from
# this repo. Setting it to 0 or not setting it at all disables this
# functionality. If you do set this to a non-zero value, you need to ensure
# that your index is updated much more frequently than the specified interval.
# The same policy is applied to the archive repo, if there is one.
49
# repo_maxage = 0
50

51
repo_url = "https://MyFirstFDroidRepo.org/fdroid/repo"
52
repo_name = "My First F-Droid Repo Demo"
Ciaran Gultnieks's avatar
Ciaran Gultnieks committed
53
repo_icon = "fdroid-icon.png"
54
repo_description = """
55
This is a repository of apps to be used with F-Droid. Applications in this
56 57 58 59
repository are either official binaries built by the original application
developers, or are binaries built from source by the admin of f-droid.org
using the tools on https://gitlab.com/u/fdroid.
"""
Ciaran Gultnieks's avatar
Ciaran Gultnieks committed
60

61 62 63 64 65 66
# As above, but for the archive repo.
# archive_older sets the number of versions kept in the main repo, with all
# older ones going to the archive. Set it to 0, and there will be no archive
# repository, and no need to define the other archive_ values.
archive_older = 3
archive_url = "https://f-droid.org/archive"
67
archive_name = "My First F-Droid Archive Demo"
68
archive_icon = "fdroid-icon.png"
69 70 71
archive_description = """
The repository of older versions of applications from the main demo repository.
"""
72

73 74 75 76 77 78 79 80 81
# This allows a specific kind of insecure APK to be included in the
# 'repo' section.  Since April 2017, APK signatures that use MD5 are
# no longer considered valid, jarsigner and apksigner will return an
# error when verifying.  `fdroid update` will move APKs with these
# disabled signatures to the archive.  This option stops that
# behavior, and lets those APKs stay part of 'repo'.
#
# allow_disabled_algorithms = True

82
# Normally, all apps are collected into a single app repository, like on
83 84
# https://f-droid.org. For certain situations, it is better to make a repo
# that is made up of APKs only from a single app. For example, an automated
85 86 87
# build server that publishes nightly builds.
# per_app_repos = True

88
# `fdroid update` will create a link to the current version of a given app.
89
# This provides a static path to the current APK. To disable the creation of
90 91 92 93
# this link, uncomment this:
# make_current_version_link = False

# By default, the "current version" link will be based on the "Name" of the
94
# app from the metadata. You can change it to use a different field from the
95
# metadata here:
96
# current_version_name_source = 'packageName'
97

98
# Optionally, override home directory for gpg
99
# gpghome = '/home/fdroid/somewhere/else/.gnupg'
100

101
# The ID of a GPG key for making detached signatures for apks. Optional.
Daniel Martí's avatar
Daniel Martí committed
102
# gpgkey = '1DBA2E89'
103

104
# The key (from the keystore defined below) to be used for signing the
105 106
# repository itself. This is the same name you would give to keytool or
# jarsigner using -alias. (Not needed in an unsigned repository).
Daniel Martí's avatar
Daniel Martí committed
107
# repo_keyalias = "fdroidrepo"
108

109 110 111 112 113 114 115
# Optionally, the public key for the key defined by repo_keyalias above can
# be specified here. There is no need to do this, as the public key can and
# will be retrieved from the keystore when needed. However, specifying it
# manually can allow some processing to take place without access to the
# keystore.
# repo_pubkey = "..."

116 117 118
# The keystore to use for release keys when building. This needs to be
# somewhere safe and secure, and backed up!  The best way to manage these
# sensitive keys is to use a "smartcard" (aka Hardware Security Module). To
119
# configure F-Droid to use a smartcard, set the keystore file using the keyword
120
# "NONE" (i.e. keystore = "NONE"). That makes Java find the keystore on the
121
# smartcard based on 'smartcardoptions' below.
Daniel Martí's avatar
Daniel Martí committed
122
# keystore = "~/.local/share/fdroidserver/keystore.jks"
123 124 125

# You should not need to change these at all, unless you have a very
# customized setup for using smartcards in Java with keytool/jarsigner
Daniel Martí's avatar
Daniel Martí committed
126
# smartcardoptions = "-storetype PKCS11 -providerName SunPKCS11-OpenSC \
127 128
#    -providerClass sun.security.pkcs11.SunPKCS11 \
#    -providerArg opensc-fdroid.cfg"
129

130
# The password for the keystore (at least 6 characters). If this password is
131
# different than the keypass below, it can be OK to store the password in this
132
# file for real use. But in general, sensitive passwords should not be stored
133
# in text files!
Daniel Martí's avatar
Daniel Martí committed
134
# keystorepass = "password1"
135 136

# The password for keys - the same is used for each auto-generated key as well
137
# as for the repository key. You should not normally store this password in a
138
# file since it is a sensitive password.
Daniel Martí's avatar
Daniel Martí committed
139
# keypass = "password2"
140

Daniel Martí's avatar
Daniel Martí committed
141
# The distinguished name used for all keys.
142
# keydname = "CN=Birdman, OU=Cell, O=Alcatraz, L=Alcatraz, S=California, C=US"
143

Daniel Martí's avatar
Daniel Martí committed
144 145
# Use this to override the auto-generated key aliases with specific ones
# for particular applications. Normally, just leave it empty.
146 147
# keyaliases = {}
# keyaliases['com.example.app'] = 'example'
Daniel Martí's avatar
Daniel Martí committed
148 149
# You can also force an app to use the same key alias as another one, using
# the @ prefix.
150
# keyaliases['com.example.another.plugin'] = '@com.example.another'
151

152

153
# The full path to the root of the repository. It must be specified in
154
# rsync/ssh format for a remote host/path. This is used for syncing a locally
155
# generated repo to the server that is it hosted on. It must end in the
156
# standard public repo name of "/fdroid", but can be in up to three levels of
157
# sub-directories (i.e. /var/www/packagerepos/fdroid). You can include
158 159
# multiple servers to sync to by wrapping the whole thing in {} or [], and
# including the serverwebroot strings in a comma-separated list.
160
#
Daniel Martí's avatar
Daniel Martí committed
161
# serverwebroot = '[email protected]:/var/www/fdroid'
162 163 164 165
# serverwebroot = {
#     'foo.com:/usr/share/nginx/www/fdroid',
#     'bar.info:/var/www/fdroid',
#     }
166

TheZ3ro's avatar
TheZ3ro committed
167 168 169 170 171 172 173 174 175 176 177
# The full URL to a git remote repository. You can include
# multiple servers to mirror to by wrapping the whole thing in {} or [], and
# including the servergitmirrors strings in a comma-separated list.
# Servers listed here will also be automatically inserted in the mirrors list.
#
# servergitmirrors = 'https://github.com/user/repo'
# servergitmirrors = {
#     'https://github.com/user/repo',
#     'https://gitlab.com/user/repo',
#     }

178
# Any mirrors of this repo, for example all of the servers declared in
TheZ3ro's avatar
TheZ3ro committed
179 180
# serverwebroot and all the servers declared in servergitmirrors,
# will automatically be used by the client.  If one
181 182 183 184 185 186
# mirror is not working, then the client will try another.  If the
# client has Tor enabled, then the client will prefer mirrors with
# .onion addresses. This base URL will be used for both the main repo
# and the archive, if it is enabled.  So these URLs should end in the
# 'fdroid' base of the F-Droid part of the web server like serverwebroot.
#
187
# mirrors = (
188 189
#     'https://foo.bar/fdroid',
#     'http://foobarfoobarfoobar.onion/fdroid',
190
# )
191

192
# optionally specify which identity file to use when using rsync or git over SSH
193
#
194 195
# identity_file = '~/.ssh/fdroid_id_rsa'

196 197 198

# If you are running the repo signing process on a completely offline machine,
# which provides the best security, then you can specify a folder to sync the
199 200 201
# repo to when running `fdroid server update`. This is most likely going to
# be a USB thumb drive, SD Card, or some other kind of removable media. Make
# sure it is mounted before running `fdroid server update`. Using the
202 203 204 205 206 207
# standard folder called 'fdroid' as the specified folder is recommended, like
# with serverwebroot.
#
# local_copy_dir = '/media/MyUSBThumbDrive/fdroid'


208 209
# If you are using local_copy_dir on an offline build/signing server, once the
# thumb drive has been plugged into the online machine, it will need to be
210
# synced to the copy on the online machine. To make that happen
211 212 213 214 215
# automatically, set sync_from_local_copy_dir to True:
#
# sync_from_local_copy_dir = True


216 217 218 219 220 221
# To upload the repo to an Amazon S3 bucket using `fdroid server
# update`.  Warning, this deletes and recreates the whole fdroid/
# directory each time. This prefers s3cmd, but can also use
# apache-libcloud.  To customize how s3cmd interacts with the cloud
# provider, create a 's3cfg' file next to this file (config.py), and
# those settings will be used instead of any 'aws' variable below.
222
#
Daniel Martí's avatar
Daniel Martí committed
223 224 225
# awsbucket = 'myawsfdroid'
# awsaccesskeyid = 'SEE0CHAITHEIMAUR2USA'
# awssecretkey = 'yourverysecretkeywordpassphraserighthere'
226

227

228
# If you want to force 'fdroid server' to use a non-standard serverwebroot
229
#
Daniel Martí's avatar
Daniel Martí committed
230
# nonstandardwebroot = False
231

232

233 234
# If you want to upload the release apk file to androidobservatory.org
#
235
# androidobservatory = False
236 237


TheZ3ro's avatar
TheZ3ro committed
238 239 240 241 242 243
# If you want to upload the release apk file to virustotal.com
# You have to enter your profile apikey to enable the upload.
#
# virustotal_apikey = "virustotal_apikey"


244 245 246 247 248 249
# The build logs can be posted to a mediawiki instance, like on f-droid.org.
# wiki_protocol = "http"
# wiki_server = "server"
# wiki_path = "/wiki/"
# wiki_user = "login"
# wiki_password = "1234"
Ciaran Gultnieks's avatar
Ciaran Gultnieks committed
250

251 252 253 254 255 256 257
# Keep a log of all generated index files in a git repo to provide a
# "binary transparency" log for anyone to check the history of the
# binaries that are published.  This is in the form of a "git remote",
# which this machine where `fdroid update` is run has already been
# configured to allow push access (e.g. ssh key, username/password, etc)
# binary_transparency_remote = "[email protected]:fdroid/binary-transparency-log.git"

Daniel Martí's avatar
Daniel Martí committed
258 259
# Only set this to true when running a repository where you want to generate
# stats, and only then on the master build servers, not a development
260 261
# machine. If you want to keep the "added" and "last updated" dates for each
# app and APK in your repo, then you should enable this.
262
# update_stats = True
263

264 265
# When used with stats, this is a list of IP addresses that are ignored for
# calculation purposes.
266
# stats_ignore = []
267

268
# Server stats logs are retrieved from. Required when update_stats is True.
269
# stats_server = "example.com"
270 271

# User stats logs are retrieved from. Required when update_stats is True.
272
# stats_user = "bob"
273

Daniel Martí's avatar
Daniel Martí committed
274
# Use the following to push stats to a Carbon instance:
275 276 277
# stats_to_carbon = False
# carbon_host = '0.0.0.0'
# carbon_port = 2003
278

Daniel Martí's avatar
Daniel Martí committed
279 280
# Set this to true to always use a build server. This saves specifying the
# --server option on dedicated secure build server hosts.
281
# build_server_always = True
282

283
# By default, fdroid will use YAML .yml and the custom .txt metadata formats. It
284
# is also possible to have metadata in JSON by adding 'json'.
285
# accepted_formats = ('txt', 'yml')
286

287 288
# Limit in number of characters that fields can take up
# Only the fields listed here are supported, defaults shown
289 290 291 292
# char_limits = {
#     'Summary': 80,
#     'Description': 4000,
# }
293 294

# It is possible for the server operator to specify lists of apps that
295 296 297
# must be installed or uninstalled on the client (aka "push installs).
# If the user has opted in, or the device is already setup to respond
# to these requests, then F-Droid will automatically install/uninstall
298 299 300
# the packageNames listed.  This is protected by the same signing key
# as the app index metadata.
#
301
# install_list = (
302 303 304
#     'at.bitfire.davdroid',
#     'com.fsck.k9',
#     'us.replicant',
305
# )
306
#
307
# uninstall_list = (
308 309
#     'com.facebook.orca',
#     'com.android.vending',
310
# )