JAR signing keys
Maven Central requires every published artifact to be signed with a GPG key. This runbook covers creating a key, getting it into GitHub Actions, and publishing the public half.
Creating a key
Section titled “Creating a key”gpg --gen-keyUse these values in the interactive prompts, and choose a strong password to protect the private key (for instance with this password generator):
Real name : Federated EGA NorwayEmail : fega-norway-support@elixir.noFinding the fingerprint
Section titled “Finding the fingerprint”gpg --list-keyspub ed25519 2025-04-09 [SC] [expires: 2027-04-09] A9CD638727AE6815FB12EB8FF97FCD66B6BD0F8Duid [ultimate] FEGA Norway Team <fega-norway-support@elixir.no>sub cv25519 2025-04-09 [E] [expires: 2027-04-09]The hex string on the second line is the fingerprint, the key’s unique identifier. You need it for the commands below.
Exporting for GitHub Actions
Section titled “Exporting for GitHub Actions”Gradle cannot read variables containing newlines, and an ASCII-armoured key is inherently multi-line. So the key is base64-encoded to a single line:
gpg --armor --export-secret-keys <fingerprint> | base64 -w 0The result is roughly 1220 characters on one line, like LS0tLS1CRUdJTiBQ.....xPQ0stLS0tLQo=.
Rotating the key in GitHub
Section titled “Rotating the key in GitHub”- Go to the FEGA-Norway repository → Settings
- Secrets and Variables → Actions
- Edit the
SIGNING_KEY_BASE64secret and paste the single-line key - Update
SIGNING_PASSWORDto match the new key’s password
Both secrets must be updated together. A mismatched pair fails the publish step with a signing error rather than anything more descriptive.
Publishing the public key
Section titled “Publishing the public key”The public half lets others verify our signatures. It has to be uploaded to a public keyserver:
gpg --keyserver <keyserver> --send-keys <fingerprint>The key is currently published on:
keyserver.ubuntu.comkeys.openpgp.org
Built from f91944d