6.2 图标、打包、签名与自动更新

原文链接: Distribute

6.2 图标、打包、签名与自动更新

当你完成功能开发,工作还没有结束:需要生成图标、打包成各平台格式、签名,最后分发和更新。

第一步:生成图标

Tauri 可以从一张 PNG/SVG 源图生成各平台所有尺寸的图标:

1
npm run tauri icon ./app-icon.png

图标输出到 src-tauri/icons/。如果已经初始化 Android/iOS,移动端图标会直接放入对应资源目录。

第二步:设置 bundle

src-tauri/tauri.conf.json 的 bundle 控制打包:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
{
  "productName": "MyApp",
  "version": "1.0.0",
  "identifier": "com.example.myapp",
  "bundle": {
    "active": true,
    "targets": "all",
    "icon": [
      "icons/32x32.png",
      "icons/128x128.png",
      "icons/128x128@2x.png",
      "icons/icon.icns",
      "icons/icon.ico"
    ],
    "resources": {
      "assets/**": "./"
    },
    "category": "Productivity"
  }
}

targets 可以用 "all",也可以写数组,例如 ["nsis", "msi"]。

第三步:各平台构建

目标命令常见产物
macOS 桌面npm run tauri build.app、.dmg
Windowsnpm run tauri build(在 Windows 上).exe、.msi
Linuxnpm run tauri build(在 Linux 上).deb、.rpm、AppImage
Androidnpm run tauri android build -- --aab.aab
iOSnpm run tauri ios build -- --export-method app-store-connect.ipa

产物位置

桌面构建统一在:

1
src-tauri/target/release/bundle/<格式>/

移动端构建在生成的原生工程里:

1
2
src-tauri/gen/android/app/build/outputs/...
src-tauri/gen/apple/build/...

详见 第 5 章。

签名为什么重要

签名用于证明“这个安装包确实来自你,并且没有被篡改”。

  • macOS:需要 Apple Developer 证书;不签名会被 Gatekeeper 拦截。
  • iOS:真机与上架必须签名。
  • Windows:推荐 EV/OV 代码签名证书,减少 SmartScreen 警告。
  • Android:发布 AAB 需要上传密钥签名。

Tauri 支持在 CI 中签名。典型流程:

  1. 密钥/证书放入 GitHub Actions Secrets;
  2. 构建前导出环境变量;
  3. 执行 tauri build;
  4. 上传签名产物到 Release 或商店。

自动更新

Tauri 提供 tauri-plugin-updater 插件,让桌面应用从服务器拉取新版本。

1. 添加并注册插件

1
npm run tauri add updater

在 src-tauri/src/lib.rs 的 setup 中注册(桌面端):

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
#[cfg_attr(mobile, tauri::mobile_entry_point)]
pub fn run() {
    tauri::Builder::default()
        .setup(|app| {
            #[cfg(desktop)]
            app.handle().plugin(tauri_plugin_updater::Builder::new().build())?;
            Ok(())
        })
        .run(tauri::generate_context!())
        .expect("运行 Tauri 应用时出错");
}

2. 生成签名密钥

更新包必须签名,无法关闭。先生成密钥对:

1
npm run tauri signer generate -- -w ~/.tauri/myapp.key

私钥文件要妥善保管,不要提交进 Git。同目录下通常还会生成对应的公钥文件(类似 myapp.key.pub),把它的内容粘贴到 tauri.conf.json。

3. 配置 tauri.conf.json

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
{
  "bundle": {
    "createUpdaterArtifacts": true
  },
  "plugins": {
    "updater": {
      "pubkey": "把上面生成的公钥内容粘贴到这里,不能写文件路径",
      "endpoints": [
        "https://example.com/updates/{{target}}/{{arch}}/{{current_version}}"
      ],
      "windows": {
        "installMode": "passive"
      }
    }
  }
}

4. 构建带签名的更新包

构建前导出私钥环境变量(不能放在普通 .env 文件中):

1
2
export TAURI_SIGNING_PRIVATE_KEY="你的私钥路径或内容"
export TAURI_SIGNING_PRIVATE_KEY_PASSWORD="如果有密码就填这里"

然后正常执行 tauri build,CLI 会同时生成更新包与签名。

5. 前端检查更新

1
2
3
4
5
6
7
8
9
import { check } from '@tauri-apps/plugin-updater';
import { relaunch } from '@tauri-apps/plugin-process';

const update = await check();

if (update) {
  await update.downloadAndInstall();
  await relaunch();
}

上面的 relaunch() 来自 @tauri-apps/plugin-process,需要先添加并注册 process 插件,还要在 capabilities 中放行 process:allow-restart。如果只想先验证下载,可以暂时删除 relaunch() 调用。

更新包需要单独签名。运行时只接受与配置公钥匹配的更新,所以私钥必须妥善保管,不要提交到 Git;一旦丢失私钥,就无法再为已安装的老用户签发后续更新。

分发渠道

渠道适合场景
官网/GitHub Releases个人工具、开源软件
Microsoft StoreWindows 桌面分发
Mac App StoremacOS 分发
Apple App StoreiOS 分发
Google PlayAndroid 分发
Snapcraft/FlathubLinux 分发

每个渠道都有自己的审核与签名规则,建议决定上架前先读官方 Distribute 文档。

减小安装包

发布前可给 Cargo.toml 的 release profile 开启优化:

1
2
3
4
5
6
[profile.release]
codegen-units = 1
lto = true
opt-level = "s"
panic = "abort"
strip = true

注释说明:

  • codegen-units = 1:让 LLVM 做更多全局优化;
  • lto = true:开启链接期优化;
  • opt-level = "s":偏重体积;
  • panic = "abort":去掉 unwinding 代码;
  • strip = true:移除符号与调试信息。

下一步

最后,我们给出一条从零到能独立开发的学习路线: 6.3 练习路线与进阶资源。