Skip to content

Keryx operator actions

Last updated: 13 September 2026 (#119 host screenshots F–H)

Single checklist of human / portal / secret-store steps for Keryx for SafeCall. Policy packets remain the source for how; this log is what is still owed.

Do not put passwords, keystores, .p12, .p8, or tokens in this file or in git. Record only where they live.

Statuses: blocking (launch or a named GitLab close is waiting), pending (owed, not currently blocking repo work), later (named so it is not forgotten; not this phase), done (verified).

Bulk session: work blocking then pending together; tick Verify after we confirm together.

How-to: iOS signing, Android signing, Secret store, NAS unlock, Internal TestFlight, ntfy auth dual-run and Play Internal, Keryx Firebase / FCM / APNs, Publishing Keryx, iOS delivery.

Blocking now

Closed-app host/portal rows for #119 (workflow::doing). Local 1.2.0+7 AAB+IPA verified on GLaDOS 13 September 2026 (bun run release:keryx -- --contracts, git HEAD 4a37cfca, dirty docs only). Upload cert 0D:AC:61:B1:5F:85:91:3F:2B:21:20:5E:46:14:81:90:20:13:85:8B:76:D2:00:91:36:FD:30:9D:18:D8:0D:AA. AAB SHA-256 f3a93e6e806a46096503b4160c0411693c26487c42dc69a0aece656ea8b90c88. IPA SHA-256 3e5b93a9ef1d16d6372336a046fb49730491d8335c764f039d5b09db068a9faa, 1.2.0 (7), aps-environment=production, team 8P59575P2K. ExportOptions.plist now sets manageAppVersionAndBuildNumber=false (first export had rewritten CFBundleVersion to 8). Local evidence: keryx/build/release-evidence/1.2.0+7.txt and Mac scratch ~/sourcectl/keryx-release-evidence/2026-09-13-release-keryx-1.2.0+7.txt. Copy that file to NAS evidence/keryx/. OA-110-apns-p8, OA-119-firebase, OA-119-ntfy-apns, OA-119-ntfy-auth, and OA-119-ntfy-fcm are done (13 September 2026). Part I1: GLaDOS curl 200 to /keryx-fcm-probe-1789299971; hetest2 DEBUG log message_firebase=true and Publishing to Firebase with no Unable to publish to Firebase. /v1/config base_url stays empty on ntfy 2.16. Play Internal 7 (1.2.0) is available to testers (13 September 2026, not reviewed). ASC 1.2.0 (7) upload is Complete / Ready to Submit (90-day expiry); Internal Testing Groups is still empty and Installs is -. Next: attach/install 1.2.0 (7) on one Android + one iPhone, then OA-119-closed-push-proof. Dual-run users/limits/SafeCall config stay parallel. Do not start Play production; listing copy is #125. #124 stays open. Installed Internal 1.0.0+3 cannot receive this wake.

GLaDOS pipeline IPA (7 September 2026, bun run release:keryx -- --contracts, working-loop 1.0.0+3): SHA-256 7592a1b537f424c31b186d3d1b6372da395a8484d6e129f88f08c3bfd6e0d517. Do not upload the first Internal 1.0.0+2 IPA (commit 16349de3, SHA-256 c93492ec367b5b4a2514f7b1b1642060cc509b7451d3cea908f76ee4650935e2) as the working-loop candidate, or the superseded 1 September 2026 1.0.0+1 IPA (commit 6665a480, SHA-256 68ac735b22688daa0049ba492f99b712bbcd82b26232a6ad038a14f2c0b1f565). Earlier GLaDOS IPA (30 August 2026) SHA-256 353be9df68f4313ef8d556eb5869d5661b5757d1d44be866267d5f1050b3942a. MiniVan-3 SHA-256 a924af769b8fe27d6d942f74772bfa27c77707c1ae83aae10619a979e7a49f96 (Path B Distribution cert). CocoaPods 1.16.2 and launch-image warnings are not #110. Durable checksum copy is NAS evidence/keryx/ (OA-114-archive, 1 September 2026); Mac scratch ~/sourcectl/keryx-release-evidence/ may remain. After a NAS reboot, unlock gocryptfs before using File Browser. ASC: Keryx for SafeCall, Prepare for Submission, Czech Republic only (Available on App Release). Pricing base Greece (EUR) is the price list, not store availability. EU trader banner is OA-114-eu-trader, not this row. GLaDOS signed AAB verified 30 August 2026: upload cert SHA-256 0D:AC:61:B1:5F:85:91:3F:2B:21:20:5E:46:14:81:90:20:13:85:8B:76:D2:00:91:36:FD:30:9D:18:D8:0D:AA, AAB file SHA-256 a9a4db25474a7c8ddfb1cb8811e1f087b57b9b9cb0eec10f065b47486c5bf756. jarsigner self-signed/PKIX warnings are expected for a Play upload key. MiniVan-3 recovery 30 August 2026: same commit 459d18f6, fingerprint match, AAB file SHA-256 964144428ad0ad96a1e729254b947ffeb8b0ef445d6713a826e017b0d7f95ba4. Play Console 30 August 2026: Keryx for SafeCall, Czech Republic only, internal-testing AAB saved as draft, upload key SHA-256 matches GLaDOS (screenshot of Upload key certificate; do not request an upload key reset). Google's app signing key fingerprint is different and expected.

Pending (bulk with blocking)

IDStatusIssueWhereActionVerify
OA-114-apple-orgpending#114Apple Developer / ASCVerify legal entity, agreements, Account Holder, 2FA, recovery, least-privilege admin/developer/marketing/support roles.[ ]
OA-114-play-orgpending#114Play ConsoleVerify organization account, 2FA, recovery, least-privilege admins / release managers.[ ]
OA-114-eu-traderpending#114ASCDeclare sourcectl as EU trader; public address, phone, email in controlled records (values not in git).[ ]
OA-119-ntfy-fcmdone#119Client ntfy (hetest2)server.yml + firebase.json root:ntfy 640. ntfy 2.16 listens on 127.0.0.1:2586. Part I1 13 September 2026: GLaDOS 200 POST /keryx-fcm-probe-1789299971; journal message_firebase=true and Publishing to Firebase (no send error). /v1/config base_url is always empty on 2.16. Path: ntfy-fcm-apns.md Part I.[x]
OA-119-closed-push-proofpending#119 / #117One Android + one iPhoneBoth phones show Keryx 1.2.1 (8) in Settings. After this SafeCall deploy, Watch/Panic Test Send is urgent (no hardware needed). Re-scan QR, swipe away (not force-stop), send Long Push, then lock-screen banner + matching test card. Note #119/#117; do not close them. Path: ntfy-fcm-apns.md Parts J–K.[ ]
OA-119-ntfy-userspending#119Client ntfy + NAS secrets/keryx/ntfy/Create safecall-publisher (write) and safecall-token-manager (read-only). Mint the publish tk_…. Store passwords/tokens in Apple Passwords; NAS notes only (host, usernames). Path: ntfy-auth-and-play-internal.md Part B.[ ]
OA-119-ntfy-limitspending#119Client ntfyAssign both users to a safecall tier (starting message-limit=100000). Exempt each SafeCall egress IP via visitor-request-limit-exempt-hosts. Verify an open Keryx instance uses one multiplexed SSE connection; raise visitor-subscription-limit only if authenticated devices still hit the cap after that check. Path: ntfy-auth-and-play-internal.md Part C.[ ]
OA-119-safecall-configpending#119Each SafeCall installSet server_ntfy_publish_token, server_ntfy_token_manager_user, and server_ntfy_token_manager_password. Prove a new Keryx QR is Bearer tk_… and not tk_local_…. Official ntfy app must still receive the same topics. Path: ntfy-auth-and-play-internal.md Part D.[ ]

Later (named so they are not missed)

IDStatusIssueWhereActionVerify
OA-119-ntfy-cutoverlater#119Client ntfyAfter official ntfy app clients are retired, set auth-default-access: deny-all. Do not do this during the dual-run. Path: ntfy-auth-and-play-internal.md. iOS then needs a Notification Service Extension for generic poll_request banners.[ ]
OA-107-httpslater#107Public webDeploy live HTTPS {public_base}/keryx/* pages.[ ]
OA-legal-cslater#108CounselReview Czech legal drafts.[ ]
OA-125-listingslater#125ASC + Play ConsolePaste listing copy, privacy/Data Safety forms, screenshots.[ ]

Done

IDStatusIssueWhereActionVerify
OA-110-apns-p8done#119NAS secrets/keryx/iOS/Team APNs auth key stored as apns-keryx.p8 (13 September 2026 File Browser). Key ID lives in Apple Passwords / Firebase Cloud Messaging, not git. Path: ntfy-fcm-apns.md Part F.[x]
OA-119-firebasedone#119Firebase Console + NAS secrets/keryx/firebase/Project Keryx for SafeCall (keryx-for-safecall): Android com.sourcectl.keryx and iOS com.sourcectl.keryxapp (team 8P59575P2K). Admin SDK JSON on NAS as ntfy-firebase-adminsdk.json. Client files already in repo. Path: ntfy-fcm-apns.md Part G.[x]
OA-119-ntfy-apnsdone#119Firebase Cloud MessagingFCM HTTP v1 enabled. Production and Development APNs auth keys uploaded for com.sourcectl.keryxapp, team 8P59575P2K. upstream-base-url on the notify host is empty, not https://ntfy.sh. Path: ntfy-fcm-apns.md Part H.[x]
OA-119-ntfy-authdone#119Client ntfy (hetest2)auth-file: /var/lib/ntfy/user.db, auth-default-access: read-write, behind-proxy: true (13 September 2026 server.yml). Do not set deny-all. Users/tokens/limits remain OA-119-ntfy-users / limits / safecall-config. Path: ntfy-auth-and-play-internal.md Part A.[x]
OA-124-play-internaldone#124Play ConsoleOperator installed Keryx from Play Internal testing on 10 September 2026. Working-loop AAB 1.0.0+3 (SHA-256 dff47ac927687950c25c574ee9ecd1283cbc3355dbcc0d6c902f74a93e488601). Upload cert 0D:AC:61:B1:…:0D:AA. Path: ntfy-auth-and-play-internal.md Part E. Do not paste listings (#125). Do not start Production. Do not close #124.[x]
OA-124-testflightdone#124ASC TestFlightOperator installed Keryx from Internal TestFlight on 10 September 2026. Working-loop IPA 1.0.0+3 (SHA-256 7592a1b537f424c31b186d3d1b6372da395a8484d6e129f88f08c3bfd6e0d517). First Internal install was 1.0.0+2. Path: internal-testflight.md. Do not paste listings (#125). Full soak stays #124. Do not close #124.[x]
OA-launch-imagedone#104 / #106Flutter iOS / Android assetsReplaced the default Flutter launch image with the navy megaphone mark in 1.0.0+2 (7 September 2026).[x]
OA-111-pipelinedone#111GLaDOS + NAS evidence/keryx/bun run release:keryx -- --contracts passed 1 September 2026 (no bump/tag/upload). Version 1.0.0+1, commit 6665a480. AAB SHA-256 a9a4db25474a7c8ddfb1cb8811e1f087b57b9b9cb0eec10f065b47486c5bf756 (upload cert 0D:AC:61:B1:…:0D:AA). IPA SHA-256 68ac735b22688daa0049ba492f99b712bbcd82b26232a6ad038a14f2c0b1f565, aps-environment=production, team 8P59575P2K. NAS file evidence/keryx/2026-09-01-release-keryx-1.0.0+1.txt verified 1 September 2026 (File Browser). Mac scratch may remain. CI/SBOM remains #112. Superseded as the TestFlight candidate by 1.0.0+2.[x]
OA-114-archivedone#114NAS evidence/keryx/CT 500 File Browser from GLaDOS and MiniVan-3 (1 September 2026). Checksums in evidence/keryx/. Unlock after reboot: nas-unlock.md. #114 stays open for org roles and EU trader.[x]
OA-110-cert-backupdone#110NAS secrets/keryx/iOS/Both Macs’ Apple Distribution .p12 (keryx-apple-distribution-glados-8P59575P2K.p12, keryx-apple-distribution-minivan-8P59575P2K.p12). Export passwords in Apple Passwords, not git.[x]
OA-110-pushdone#110Apple Developer → IdentifiersApp ID com.sourcectl.keryxapp has Push: store IPA proves aps-environment=production (GLaDOS and MiniVan-3, 30 August 2026). Do not enable Broadcast.[x]
OA-110-recoverydone#110MiniVan-3Second-Mac IPA: verify:keryx-ipa -- --expect-team=8P59575P2K passed. SHA-256 a924af769b8fe27d6d942f74772bfa27c77707c1ae83aae10619a979e7a49f96, aps-environment=production, team 8P59575P2K, Path B Distribution cert.[x]
OA-110-evidencedone#110NAS evidence/keryx/IPA checksum notes on the NAS share (2026-08-30-ios-ipa.txt). Mac scratch ~/sourcectl/keryx-release-evidence/ may remain.[x]
OA-110-ascdone#110App Store ConnectApp Keryx for SafeCall exists (iOS 1.0 Prepare for Submission). Availability: Czech Republic only (Available on App Release). Pricing base Greece (EUR) is not store availability. No listing copy pasted.[x]
OA-109-play-recorddone#109Play ConsoleApp Keryx for SafeCall exists. Category Business. Countries Czech Republic only. Internal testing release saved as draft. Package from first AAB com.sourcectl.keryx. No listing copy pasted.[x]
OA-109-play-signingdone#109Play ConsolePlay App Signing enrolled. Upload key SHA-256 0D:AC:61:B1:5F:85:91:3F:2B:21:20:5E:46:14:81:90:20:13:85:8B:76:D2:00:91:36:FD:30:9D:18:D8:0D:AA matches GLaDOS (30 August 2026 screenshot). App signing key is Google-managed (different fingerprint, expected). No production rollout.[x]
OA-109-keystoredone#109 / #111NAS secrets/keryx/android/upload-keystore.jks + key.properties on the share (1 September 2026). Upload cert SHA-256 0D:AC:61:B1:5F:85:91:3F:2B:21:20:5E:46:14:81:90:20:13:85:8B:76:D2:00:91:36:FD:30:9D:18:D8:0D:AA. Local gitignored copies remain for builds.[x]
OA-109-recoverydone#109MiniVan-3Same upload keystore copied from GLaDOS. verify:keryx-aab -- --expect-fingerprint=0D:AC:61:B1:5F:85:91:3F:2B:21:20:5E:46:14:81:90:20:13:85:8B:76:D2:00:91:36:FD:30:9D:18:D8:0D:AA passed. AAB file SHA-256 964144428ad0ad96a1e729254b947ffeb8b0ef445d6713a826e017b0d7f95ba4.[x]

Using bun keryx

Operator store-candidate cut. Same prompts as bun commit. It bumps keryx/pubspec.yaml, builds and verifies the signed AAB and IPA, commits, tags keryx-vX.Y.Z, and pushes to origin. It does not upload to Play or TestFlight, and it does not replace this log.

bash
bun keryx                          # prompt for bump type + message
bun keryx patch                    # prompt for message only
bun keryx patch "Fix notifications"

After a successful run, upload the printed AAB and IPA paths using ntfy-auth-and-play-internal.md Part E and internal-testflight.md. Copy keryx/build/release-evidence/ to NAS evidence/keryx/.

Using bun run release:keryx

Local rebuild for P3-03 / #111. It fails closed without Android key.properties and without iOS distribution signing. It does not upload, push tags, or replace this log. Prefer bun keryx when you intend to bump, commit, and push.

First recorded run: 1 September 2026 on GLaDOS (--contracts, no bump/tag). Second recorded run: 7 September 2026 (1.0.0+2, commit 16349de3, --contracts, no bump/tag). AAB SHA-256 a884dc07c8f5a78f7da42526fca1db27287b1172d56995adbd71e80471ef247c (upload cert still 0D:AC:61:B1:…:0D:AA). IPA SHA-256 c93492ec367b5b4a2514f7b1b1642060cc509b7451d3cea908f76ee4650935e2. Local evidence: keryx/build/release-evidence/1.0.0+2.txt. Third recorded run: 7 September 2026 (1.0.0+3, --contracts, no bump/tag). Evidence git HEAD 9dbd1d49 (binary includes uncommitted working-loop sources). AAB SHA-256 dff47ac927687950c25c574ee9ecd1283cbc3355dbcc0d6c902f74a93e488601. IPA SHA-256 7592a1b537f424c31b186d3d1b6372da395a8484d6e129f88f08c3bfd6e0d517. Local evidence: keryx/build/release-evidence/1.0.0+3.txt. Fourth recorded run: 13 September 2026 (1.2.0+7, --contracts, no bump/tag). Evidence git HEAD 4a37cfca. AAB SHA-256 f3a93e6e806a46096503b4160c0411693c26487c42dc69a0aece656ea8b90c88 (upload cert still 0D:AC:61:B1:…:0D:AA). IPA SHA-256 3e5b93a9ef1d16d6372336a046fb49730491d8335c764f039d5b09db068a9faa (1.2.0 (7) after pinning manageAppVersionAndBuildNumber=false). Local evidence: keryx/build/release-evidence/1.2.0+7.txt. After each successful run, copy the printed checksums into NAS evidence/keryx/ and optionally the local scratch ~/sourcectl/keryx-release-evidence/.