키스토어 생성 및 AAB 서명하기
keytool로 릴리스 키스토어를 생성하고 gradle.properties 및 build.gradle에 서명 구성을 설정한 뒤 EAS Build로 서명된 Android App Bundle을 빌드합니다.
키스토어 생성 및 AAB 서명하기은(는) CoddyKit의 무료 React Native Academy 강의입니다. 이것은 4개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 React Native Academy 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. React Native Academy 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Why Android Signing Matters
Every Android app must be digitally signed with a private key before it can be installed or distributed. The signature is embedded in the APK or AAB file and verifies that all future updates to the app come from the same developer. If you lose your keystore, you can never issue an update to that app — you would have to publish an entirely new app with a different package name. Back up your keystore file securely.
What Is a Keystore File
A keystore is a binary file (typically .jks or .keystore) that stores one or more cryptographic key pairs. It is protected by two passwords: a store password (protects the file) and a key password (protects the individual key alias inside). Think of it like a password-protected vault containing your signing identity. Android uses a key inside this vault to sign your APK or AAB.
APK vs AAB: Which to Use
Google Play now requires Android App Bundles (AAB) for new apps (since August 2021). An AAB is smaller than an APK because it contains resources for all device configurations and lets Google Play build a device-specific APK for each user. This reduces download size by 15–50%. Local testing and side-loading still use APKs. Build AAB for Play Store submissions and APK only for direct installation or internal testing outside Play.
// eas.json — build AAB for production
{
'build': {
'production': {
'android': {
'buildType': 'app-bundle' // produces .aab
}
},
'preview': {
'android': {
'buildType': 'apk' // produces .apk for side-loading
}
}
}
}Generating a Keystore with keytool
Java's keytool utility generates keystores. The key parameters are: -genkeypair to generate a new key pair, -keystore for the output filename, -alias for the key alias (a name for the key inside the keystore), -validity for how many days the certificate is valid (25 years = 9125 days is typical for app signing), and -keyalg RSA -keysize 2048 for the cryptographic algorithm.
# Generate a release keystore
keytool -genkeypair \
-keystore myapp-release-key.jks \
-alias myapp-key \
-keyalg RSA \
-keysize 2048 \
-validity 9125 \
-storepass yourStorePassword \
-keypass yourKeyPassword
# You'll be prompted for:
# First and last name:
# Organizational unit:
# Organization:
# City or locality:
# State or province:
# Two-letter country code (e.g., US):
# Then type 'yes' to confirmEAS Auto-Generated Keystore
EAS Build can generate and securely store a keystore for you automatically. When you first run a production Android build, EAS prompts you to generate a new keystore or upload an existing one. If you let EAS generate it, the keystore is stored encrypted in EAS's cloud — you can download it any time via eas credentials --platform android. This is the safest option for teams because no keystore lives on a single developer's laptop.
# Let EAS generate and manage the keystore
eas build --platform android --profile production
# EAS prompts:
# ? Would you like to set up an Android Keystore?
# > Generate new keystore <- choose this
#
# EAS creates and stores it securely.
# Download your keystore for backup:
eas credentials --platform android
# Select: Download existing keystoreConfiguring Manual Signing in build.gradle
If you are using a bare React Native workflow (not managed Expo) and want to sign locally rather than with EAS, configure signing in android/app/build.gradle. Add a signingConfigs block referencing your keystore file and passwords. Store keystore credentials in ~/.gradle/gradle.properties (not in the source code) to keep them out of git history.
// android/app/build.gradle
android {
signingConfigs {
release {
storeFile file(MYAPP_UPLOAD_STORE_FILE)
storePassword MYAPP_UPLOAD_STORE_PASSWORD
keyAlias MYAPP_UPLOAD_KEY_ALIAS
keyPassword MYAPP_UPLOAD_KEY_PASSWORD
}
}
buildTypes {
release {
signingConfig signingConfigs.release
minifyEnabled true
proguardFiles getDefaultProguardFile('proguard-android.txt')
}
}
}
// ~/.gradle/gradle.properties (NOT in git)
// MYAPP_UPLOAD_STORE_FILE=myapp-release-key.jks
// MYAPP_UPLOAD_STORE_PASSWORD=yourStorePassword
// MYAPP_UPLOAD_KEY_ALIAS=myapp-key
// MYAPP_UPLOAD_KEY_PASSWORD=yourKeyPasswordBuilding the Signed AAB with EAS
Once credentials are set up, trigger the production Android build with EAS. The cloud runner checks out your code, applies config plugins, builds the AAB, signs it with your keystore, and makes it available for download or direct upload to Play Console. Monitor progress with eas build:list or the EAS dashboard. The finished AAB is typically 5–20MB depending on app size.
# Build signed AAB for Play Store
eas build --platform android --profile production
# Watch build progress (or use dashboard URL provided)
eas build:list --platform android --limit 5
# Download the .aab when complete
eas build:download --id <build-id>
# Alternatively: build AND auto-submit to Play Console
eas build --platform android --profile production --auto-submitPlay App Signing: Upgrading Security
Google Play App Signing is a program where Google holds a secondary app signing key. You upload the AAB signed with your upload key (a simpler key you generate), and Google re-signs it with the managed app signing key before delivery to users. The benefit: if your upload key is compromised or lost, Google can issue a new one. Once enrolled, you cannot unenroll, but it is strongly recommended for new apps.
// Play App Signing flow:
// You sign with: Upload Key (your keystore)
// |
// v
// [Upload to Play Console]
// |
// Google re-signs with:
// App Signing Key
// |
// v
// Device receives: App signed by Google's key
// Enroll when creating app in Play Console:
// Setup > App Signing > Use Google-managed keyVerifying the AAB Signature
Before uploading to Play Console, verify your AAB is correctly signed using bundletool or apksigner. Inspect the signing certificate SHA-256 fingerprint — this fingerprint is what Google Play expects to match. A mismatch between your upload certificate and what Play Console has on record will cause the upload to be rejected with a signing error.
# Verify keystore details
keytool -list -v -keystore myapp-release-key.jks
# Shows: Certificate fingerprint (SHA-256):
# AB:CD:EF:... (copy this for your records)
# Check what signed an APK/AAB
apksigner verify --verbose myapp.apk
# Bundletool (download from Google)
bundletool dump manifest --bundle=myapp.aabBacking Up the Keystore
The keystore backup is critical — treat it like a password or private key. Store it in: a password manager that supports file attachments, an encrypted cloud storage location (not the same git repo), and optionally a hardware security device. Record the store password, key alias, and key password alongside it. Losing the keystore means you can never update the app — you would need to publish under a new package name and lose all your existing users and reviews.
# Keystore backup checklist:
# 1. Store the .jks file in encrypted storage
# - 1Password, Bitwarden, or similar
# - Do NOT commit to git
# 2. Record credentials alongside it:
# Store file: myapp-release-key.jks
# Store password: [store securely]
# Key alias: myapp-key
# Key password: [store securely]
# 3. Test restoration:
# - Copy backup to a new machine
# - Run: keytool -list -keystore myapp-release-key.jks
# - Verify you can list the key alias
# 4. Tell your team where the backup livesVersion Code and Version Name
Android uses two version identifiers: versionCode (an integer, must increment with each Play Store upload) and versionName (the string shown to users, e.g., '1.2.3'). Play Console rejects a build if versionCode is not strictly greater than the last uploaded build. In Expo, set android.versionCode in app.json and increment it for every new build uploaded to Play.
// app.json
{
'expo': {
'version': '1.2.3', // versionName shown to users
'android': {
'versionCode': 12, // must be higher than previous upload
'package': 'com.yourcompany.myapp'
}
}
}
// After submitting to Play Console, before next build:
// Increment versionCode: 12 -> 13
// Update version if user-facing: '1.2.3' -> '1.2.4'
// EAS can auto-increment:
// eas.json: 'autoIncrement': true (in android profile)Quick Check
Test your understanding of React Native Mobile Development concepts from this lesson.
Lesson Recap
In this lesson you learned: how to generate an Android keystore with keytool or EAS Build, the difference between APK and AAB and why Play Store requires AAB, and how to configure signing in build.gradle for bare workflow projects. You also saw Google Play App Signing and why backing up the keystore is non-negotiable. Next up we set up the Play Console listing.
자주 묻는 질문
“키스토어 생성 및 AAB 서명하기” 강의는 무료인가요?
네 — “키스토어 생성 및 AAB 서명하기” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 React Native Academy 강의 전체를 잠금 해제할 수 있습니다. React Native Academy 강의에는 총 4개의 강의가 포함되어 있습니다.
“키스토어 생성 및 AAB 서명하기”에서 뭘 배우나요?
keytool로 릴리스 키스토어를 생성하고 gradle.properties 및 build.gradle에 서명 구성을 설정한 뒤 EAS Build로 서명된 Android App Bundle을 빌드합니다. 브라우저에서 직접 실행하는 실습 코드로 React Native Academy을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
React Native Academy을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 React Native Academy은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 1번째 강의입니다.
“키스토어 생성 및 AAB 서명하기” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 React Native Academy 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 React Native Academy 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- 키스토어 생성 및 AAB 서명하기
- Play Console 등록 정보 설정하기
- 콘텐츠 등급, 정책 및 개인정보 보호
- 내부 테스트, 단계적 출시 및 프로덕션