Skip to content

Add fastlane + GitHub Actions release automation - #6

Merged
adborbas merged 1 commit into
mainfrom
chore/release-automation
Jul 14, 2026
Merged

adborbas merged 1 commit into
mainfrom
chore/release-automation

Conversation

@adborbas

Copy link
Copy Markdown
Owner

Automates the release process from RELEASING.md with fastlane + GitHub Actions. Each step is a fastlane lane plus a workflow_dispatch workflow.

What's included

  • cut_release (Cut Release workflow) — branch release/<version> from main and bump MARKETING_VERSION.
  • beta (Release workflow) — sign via match, auto-bump the build number, archive, upload to TestFlight, and enable the build for the internal Testers group. Fails fast if MARKETING_VERSION is already released (closed TestFlight train).
  • publish (Publish Release workflow) — tag v<version>, create the GitHub release, and open a back-merge PR to main.

Signing & secrets

  • Signing via fastlane match; certs live encrypted in a private repo, fetched read-only on CI via an SSH deploy key.
  • ASC API key, match passphrase, and deploy key are stored in the protected release environment (required reviewer). The Team ID is a repo variable, read from env / gitignored Local.xcconfig.
  • No secrets or personal identifiers are committed (security-audited).

Access control

  • Sensitive workflows (release, publish) run in the release environment (approval gate) and are guarded by if: github.actor == 'adborbas'.

Validation

  • Verified end-to-end locally: real signed build uploaded to TestFlight and distributed to the Testers group.
  • The version guard and group distribution were both exercised.
  • fastlane pinned to 2.237.0.

Note

  • The MARKETING_VERSION bump is intentionally not in this PR — start the next version via cut_release after merge.
  • The release/publish CI paths (runner + deploy-key transport) run for the first time only after merge, since workflow_dispatch workflows must be on the default branch.

🤖 Generated with Claude Code

Automates the three release steps documented in RELEASING.md via fastlane
lanes, each with a matching workflow_dispatch workflow:

- cut_release: branch from main and bump MARKETING_VERSION
- beta: sign via match, auto-bump the build number, archive, upload to
  TestFlight, and enable the build for the internal "Testers" group.
  Fails fast if MARKETING_VERSION is already released (closed train).
- publish: tag, create the GitHub release, and open a back-merge PR

Signing uses fastlane match (certs in a private repo, fetched read-only on
CI via an SSH deploy key). Secrets and the Team ID are injected via the
protected `release` environment and repo variables — nothing sensitive is
committed. fastlane is pinned to 2.237.0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@adborbas
adborbas merged commit 2bb8640 into main Jul 14, 2026
1 check passed
@adborbas
adborbas deleted the chore/release-automation branch July 14, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant