diff --git a/.github/workflows/testflight.yml b/.github/workflows/testflight.yml index 8bca53a..ab982b6 100644 --- a/.github/workflows/testflight.yml +++ b/.github/workflows/testflight.yml @@ -10,9 +10,15 @@ # "App Manager" role) # base64 encode: base64 -i AuthKey_XXXXXXXXXX.p8 | pbcopy # -# The build number is the workflow run number (monotonic per repo), so TestFlight never -# rejects a duplicate CFBundleVersion. Uploads become available to INTERNAL testers -# automatically once App Store Connect finishes processing — no extra distribution step. +# Archive uses Apple Distribution (not Apple Development). Ephemeral GitHub runners have an +# empty keychain, so Automatic+Development minted a new development cert every run until +# the account hit Apple's cap and every archive died with "Choose a certificate to revoke" +# plus "No profiles for com.sanylax.continuity" (development profiles). +# +# CFBundleVersion is 1000 + github.run_number. TestFlight already has build 130 (Xcode Cloud, +# Jul 18) while run_number is still in the 30s — a raw run_number would be rejected as older. +# Uploads become available to INTERNAL testers automatically once App Store Connect finishes +# processing — no extra distribution step. name: TestFlight on: @@ -58,20 +64,34 @@ jobs: echo "$ASC_KEY_P8" | base64 --decode > "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" - name: Archive + env: + ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }} + ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }} run: | + set -eu + BUILD_NUMBER=$((1000 + ${{ github.run_number }})) + echo "CFBundleVersion=${BUILD_NUMBER}" xcodebuild archive \ -project Continuity.xcodeproj \ -scheme Continuity \ + -configuration Release \ -destination 'generic/platform=iOS' \ -archivePath build/Continuity.xcarchive \ - CURRENT_PROJECT_VERSION=${{ github.run_number }} \ + CURRENT_PROJECT_VERSION="$BUILD_NUMBER" \ + DEVELOPMENT_TEAM=KP832RV67A \ + CODE_SIGN_STYLE=Automatic \ + CODE_SIGN_IDENTITY="Apple Distribution" \ -allowProvisioningUpdates \ - -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \ - -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \ - -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}" + -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \ + -authenticationKeyID "$ASC_KEY_ID" \ + -authenticationKeyIssuerID "$ASC_ISSUER_ID" - name: Upload to TestFlight + env: + ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }} + ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }} run: | + set -eu cat > ExportOptions.plist <<'EOF' @@ -83,6 +103,8 @@ jobs: upload signingStyle automatic + signingCertificate + Apple Distribution teamID KP832RV67A manageAppVersionAndBuildNumber @@ -95,6 +117,6 @@ jobs: -exportOptionsPlist ExportOptions.plist \ -exportPath build/export \ -allowProvisioningUpdates \ - -authenticationKeyPath "$HOME/private_keys/AuthKey_${{ secrets.ASC_KEY_ID }}.p8" \ - -authenticationKeyID "${{ secrets.ASC_KEY_ID }}" \ - -authenticationKeyIssuerID "${{ secrets.ASC_ISSUER_ID }}" + -authenticationKeyPath "$HOME/private_keys/AuthKey_${ASC_KEY_ID}.p8" \ + -authenticationKeyID "$ASC_KEY_ID" \ + -authenticationKeyIssuerID "$ASC_ISSUER_ID" diff --git a/project.yml b/project.yml index c4f791f..c18cb07 100644 --- a/project.yml +++ b/project.yml @@ -19,6 +19,12 @@ settings: CURRENT_PROJECT_VERSION: "2" DEVELOPMENT_TEAM: "KP832RV67A" CODE_SIGN_STYLE: Automatic + configs: + # Release archives must use Distribution. Automatic + Development on ephemeral + # CI runners minted a new Apple Development cert every TestFlight run until the + # account hit the cap ("Choose a certificate to revoke"). + Release: + CODE_SIGN_IDENTITY: Apple Distribution targets: Continuity: @@ -70,6 +76,8 @@ targets: # relying on Xcode's per-user scheme auto-creation (which xcodebuild does not perform). scheme: gatherCoverageData: false + archive: + config: Release settings: base: PRODUCT_BUNDLE_IDENTIFIER: com.sanylax.continuity