diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5dd48de..d99192b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -49,8 +49,13 @@ jobs: # because fastlane provisions instead. SWIFT_MK_VERIFY_SIGNING_ROOTS verifies each # runnable product is signed with the team and is not ad-hoc. import-signing-cert: true - signing-identity-name: "Apple Distribution: Alex Goodkind (H3BMXM4W7H)" - apple-team-id: H3BMXM4W7H + # The identity and team come from repository variables, so rotating a + # certificate or moving teams is one settings edit rather than a commit in + # every repository. The two certificates keep separate variables: this job + # signs Apple Distribution, the release signs Developer ID, and one shared + # slot for both was a defect once already. + signing-identity-name: ${{ vars.APPLE_DISTRIBUTION_IDENTITY }} + apple-team-id: ${{ vars.APPLE_TEAM_ID }} setup-target: ci-provision make-args: TUIST_DEVELOPER_ID_SIGNING=1 secrets: inherit diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 65fe42a..5116bf0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -25,8 +25,10 @@ jobs: # publishes something a person can download, marked as not the recommended build, # and a run that proves itself is promoted to stable deliberately. release-on-merge: prerelease - signing-identity-name: "Developer ID Application: Alex Goodkind (H3BMXM4W7H)" - apple-team-id: H3BMXM4W7H + # Developer ID here, Apple Distribution in CI. Both come from repository + # variables, and each keeps its own so the two are never confused. + signing-identity-name: ${{ vars.APPLE_DEVELOPER_ID_IDENTITY }} + apple-team-id: ${{ vars.APPLE_TEAM_ID }} notarize-pattern: "*.zip" candidate-asset-pattern: "*.zip" sbom-subject-path: "Products/Release/CellTunnelAgent.app"