Skip to content

Add TestFlight workflow: upload to internal testing on every merge to main - #106

Merged
sanylax0 merged 1 commit into
mainfrom
claude/repo-review-improvements-yvk3t7-testflight-action
Jul 19, 2026
Merged

sanylax0 merged 1 commit into
mainfrom
claude/repo-review-improvements-yvk3t7-testflight-action

Conversation

@sanylax2

Copy link
Copy Markdown
Collaborator

What

.github/workflows/testflight.yml: every push to main (i.e., every merged PR) archives the app on a macOS runner and uploads it to App Store Connect — builds land with internal TestFlight testers automatically once processing finishes (internal distribution needs no extra step or review).

How

  • xcodegen generate first (the .xcodeproj is gitignored), newest Xcode on the macos-26 image.
  • Cloud-managed signing: xcodebuild -allowProvisioningUpdates with an App Store Connect API key mints certs/profiles on the fly — no certificates or provisioning profiles stored anywhere.
  • Build number = workflow run number (CURRENT_PROJECT_VERSION override), monotonic per repo, so TestFlight never rejects a duplicate CFBundleVersion.
  • -exportArchive with method: app-store-connect, destination: upload uploads directly; manageAppVersionAndBuildNumber=false keeps our numbering authoritative.
  • A concurrency group serializes uploads (no cancel mid-upload); rapid merges queue.

Setup required (once, before first run)

Create an App Store Connect API key (Users and Access → Integrations → App Store Connect API, role App Manager) and add three repository secrets:

Secret Value
ASC_KEY_ID the key's ID
ASC_ISSUER_ID the issuer ID shown on the same page
ASC_KEY_P8 the downloaded .p8, base64-encoded (base64 -i AuthKey_XXX.p8 | pbcopy)

The job fails with a clear message if they're missing; set the repo variable TESTFLIGHT_ENABLED=false to pause the workflow without deleting it.

Notes

  • This coexists with Xcode Cloud. If Xcode Cloud's Archive workflow is also configured to upload on main pushes, you'll get duplicate builds — either disable that workflow's TestFlight action in App Store Connect or set TESTFLIGHT_ENABLED=false here, whichever pipeline you prefer to own releases.
  • Runner label macos-26 assumes GitHub's current image lineup; if the runs queue forever, switch to macos-latest.

🤖 Generated with Claude Code

https://claude.ai/code/session_013TJoWkqg8bzkGdzxWhWjWP


Generated by Claude Code

… main

macOS runner, xcodegen generate, cloud-managed signing via an App Store
Connect API key (no certificates in secrets), build number pinned to
the run number so uploads never collide, and -exportArchive with
destination=upload pushes straight to App Store Connect — internal
testers get the build automatically once processing finishes. Requires
ASC_KEY_ID / ASC_ISSUER_ID / ASC_KEY_P8 repository secrets (documented
in the workflow header); serialized via a concurrency group.
@sanylax0
sanylax0 merged commit b3c5557 into main Jul 19, 2026
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants