diff --git a/.github/workflows/testflight.yml b/.github/workflows/testflight.yml
index 8bca53a..ab982b6 100644
--- a/.github/workflows/testflight.yml
+++ b/.github/workflows/testflight.yml
@@ -10,9 +10,15 @@
# "App Manager" role)
# base64 encode: base64 -i AuthKey_XXXXXXXXXX.p8 | pbcopy
#
-# The build number is the workflow run number (monotonic per repo), so TestFlight never
-# rejects a duplicate CFBundleVersion. Uploads become available to INTERNAL testers
-# automatically once App Store Connect finishes processing — no extra distribution step.
+# Archive uses Apple Distribution (not Apple Development). Ephemeral GitHub runners have an
+# empty keychain, so Automatic+Development minted a new development cert every run until
+# the account hit Apple's cap and every archive died with "Choose a certificate to revoke"
+# plus "No profiles for com.sanylax.continuity" (development profiles).
+#
+# CFBundleVersion is 1000 + github.run_number. TestFlight already has build 130 (Xcode Cloud,
+# Jul 18) while run_number is still in the 30s — a raw run_number would be rejected as older.
+# Uploads become available to INTERNAL testers automatically once App Store Connect finishes
+# processing — no extra distribution step.
name: TestFlight
on:
@@ -58,20 +64,34 @@ jobs:
echo "$ASC_KEY_P8" | base64 --decode > "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8"
- name: Archive
+ env:
+ ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
+ ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
run: |
+ set -eu
+ BUILD_NUMBER=$((1000 + ${{ github.run_number }}))
+ echo "CFBundleVersion=${BUILD_NUMBER}"
xcodebuild archive \
-project Continuity.xcodeproj \
-scheme Continuity \
+ -configuration Release \
-destination 'generic/platform=iOS' \
-archivePath build/Continuity.xcarchive \
- CURRENT_PROJECT_VERSION=${{ github.run_number }} \
+ CURRENT_PROJECT_VERSION="$BUILD_NUMBER" \
+ DEVELOPMENT_TEAM=KP832RV67A \
+ CODE_SIGN_STYLE=Automatic \
+ CODE_SIGN_IDENTITY="Apple Distribution" \
-allowProvisioningUpdates \
- -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \
- -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \
- -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}"
+ -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \
+ -authenticationKeyID "$ASC_KEY_ID" \
+ -authenticationKeyIssuerID "$ASC_ISSUER_ID"
- name: Upload to TestFlight
+ env:
+ ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
+ ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
run: |
+ set -eu
cat > ExportOptions.plist <<'EOF'
@@ -83,6 +103,8 @@ jobs:
upload
signingStyle
automatic
+ signingCertificate
+ Apple Distribution
teamID
KP832RV67A
manageAppVersionAndBuildNumber
@@ -95,6 +117,6 @@ jobs:
-exportOptionsPlist ExportOptions.plist \
-exportPath build/export \
-allowProvisioningUpdates \
- -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \
- -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \
- -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}"
+ -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \
+ -authenticationKeyID "$ASC_KEY_ID" \
+ -authenticationKeyIssuerID "$ASC_ISSUER_ID"
diff --git a/project.yml b/project.yml
index c4f791f..c18cb07 100644
--- a/project.yml
+++ b/project.yml
@@ -19,6 +19,12 @@ settings:
CURRENT_PROJECT_VERSION: "2"
DEVELOPMENT_TEAM: "KP832RV67A"
CODE_SIGN_STYLE: Automatic
+ configs:
+ # Release archives must use Distribution. Automatic + Development on ephemeral
+ # CI runners minted a new Apple Development cert every TestFlight run until the
+ # account hit the cap ("Choose a certificate to revoke").
+ Release:
+ CODE_SIGN_IDENTITY: Apple Distribution
targets:
Continuity:
@@ -70,6 +76,8 @@ targets:
# relying on Xcode's per-user scheme auto-creation (which xcodebuild does not perform).
scheme:
gatherCoverageData: false
+ archive:
+ config: Release
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.sanylax.continuity