Every step, in order, with the exact commands. Follow it top to bottom and you cannot get it wrong.
Three separate things. Doing one without the others is the usual mistake:
| Step | What it means | If you skip it |
|---|---|---|
| Build | Turn the code into an installer file | Nothing to give anyone |
| Upload | Put those files on this server | The download link 404s |
| Publish | Set Latest on the admin page | Files are there, but no till is told to update |
| Page | Who it affects |
|---|---|
| /admin — purple | Real shops. Every live till. |
| /admin/dev — teal | Testers only. Cannot touch a real till. |
Windows installers must be built by GitHub Actions. Your Mac cannot build them — it has no Wine, and it is the wrong processor. The build now publishes itself, so for Windows there is nothing to download and nothing to upload.
cd ~/Desktop/AYO/retailstack-pos-desktop git status # must be clean — see the warning below npm version 1.3.5 --no-git-tag-version git commit -am "1.3.5" && git push
package.json to test the
update block. If that edit is still there, the build carries the wrong version and nothing updates.
git status must be clean before you build.-dev.1, -dev.2, and must be a pre-release of the
next version: after 1.3.9 ships, a tester build is 1.4.0-dev.1.gh workflow run build-windows.yml -f channel=stable -f version=1.3.5 gh run watch
-f channel=dev for a tester build.v1.3.5 tag. A tag push starts this same
workflow on its own, so doing both runs two builds at once and they fight over the download link.
Pick one. If it happens, cancel the extra run with gh run cancel <id>.Published. A green tick on the job is not enough on its own — the step can be
skipped if the R2 keys are missing, and a skipped step still looks like success.gh run download -n windows-installer-stable -D ~/Downloads/1.3.5 cd ~/Desktop/AYO/retailstack-pos-desktop source ~/.retailstack-signing/r2.sh node scripts/publish.mjs ~/Downloads/1.3.5 --version 1.3.5Running it again costs nothing — it skips whatever already arrived.
Mac builds happen on your own Mac. They take 25–40 minutes, most of it waiting on Apple, and they produce two of everything — one set for Apple Silicon, one for Intel.
source ~/.retailstack-signing/env.sh
skipped macOS notarization. An unsigned
build is blocked by the Mac's security and cannot auto-update. Never upload one.cd ~/Desktop/AYO/retailstack-pos-desktop git status # must be clean npm version 1.3.5 --no-git-tag-version npm run build
npm run build:mac:dev for a tester build. Go and do something else —
Apple's notarisation queue often sits for 20 minutes with no output. That is normal, not a hang.cd release spctl -a -t install "RetailStack POS-1.3.5-arm64.dmg" spctl -a -t install "RetailStack POS-1.3.5-x64.dmg"
source=Notarized Developer ID.rejected — means stop. Do not upload it.
Check that you ran step 1, then build again.cd ~/Desktop/AYO/retailstack-pos-desktop source ~/.retailstack-signing/r2.sh node scripts/publish.mjs release --version 1.3.5
latest-mac.yml — and it tells you which. About 450MB, so give it ten minutes on a
normal connection. Add --channel dev for a tester build.release/ keeps every build you have ever made. That is why
--version is there: without it the command stops and asks, rather than letting an older
build quietly take over the public download link.A tester build installs alongside the real till app, with its own database, and talks to the dev API. It can never be offered to a real till: it publishes to a different feed.
1.4.0-dev.1, then
-dev.2. Going backwards or reusing a number means nothing is offered.gh workflow run build-windows.yml -f channel=dev -f version=1.4.0-dev.1 npm run build:mac:dev node scripts/publish.mjs release --channel dev --version 1.4.0-dev.1
https://dl.retailstack.co/Retailstack-dev.exe,
https://dl.retailstack.co/Retailstack-dev.dmg,
https://dl.retailstack.co/Retailstack-dev-intel.dmg1.3.5 — into
Latest version and press Save channel. That is the release done. Tills pick it up at
their next launch and see an update prompt they can dismiss.1.3.5.| Who | Link |
|---|---|
| Mac — Apple Silicon | https://download.retailstack.rivrafrica.com/Retailstack.dmg |
| Mac — Intel | https://download.retailstack.rivrafrica.com/Retailstack-intel.dmg |
| Windows | https://download.retailstack.rivrafrica.com/Retailstack.exe |
Run the same publish.mjs command again. Files go up in 16MB pieces and each
piece retries on its own, so a wobble costs seconds. Anything that did finish is skipped on the second
run, so it picks up roughly where it stopped.
The file never reached Cloudflare. publish.mjs checks every file at the end
and refuses to say Published if one is missing, so this means the command did not finish — scroll
back and look for the error, then run it again.
Almost always one of three things: the feed file (latest.yml /
latest-mac.yml) was never uploaded; Latest was never changed; or the version number is
not higher than what they already run. Check in that order.
npm run dev stopped working after a Mac buildA Mac build rebuilds the database library for each processor it packages, and leaves it
set to the last one. Running the app from source then fails with
incompatible architecture. It is not a code problem — put it back with
npx @electron/rebuild -f -w better-sqlite3.
You forgot source ~/.retailstack-signing/env.sh. Run it and build again.
Delete the unsigned files from release/ first so you cannot upload them by accident.
Nothing on this server can stop a till from selling unless Minimum supported is set above what they run. If you set it by mistake, lower it and press Save — they recover at their next launch. If this whole service is down, tills simply carry on trading.