# How to Deploy Palmier Pro to a Production Environment: Complete macOS Distribution Guide

> Deploy Palmier Pro to production with this macOS guide. Learn to build, sign, notarize, and distribute your app efficiently for a seamless user experience.

- Repository: [Palmier/palmier-pro](https://github.com/palmier-io/palmier-pro)
- Tags: how-to-guide
- Published: 2026-06-22

---

**Deploying Palmier Pro to a production environment requires building a release binary with Swift Package Manager, code-signing the macOS app bundle with a Developer ID certificate, notarizing it with Apple, and embedding production backend credentials in the `Info.plist` before distributing via DMG or the Mac App Store.**

Palmier Pro is an AI-native macOS video editor written in Swift 6.2 that compiles to a native `.app` bundle rather than a traditional backend service. To deploy Palmier Pro to a production environment, you must follow Apple's macOS distribution requirements including code signing, notarization, and proper configuration of the Convex backend endpoints. This guide walks through the end-to-end workflow supported by the repository's build scripts and configuration files.

## Building the Production Binary

The first step in deploying Palmier Pro is compiling a release version optimized for distribution.

### Compile with Swift Package Manager

Palmier Pro uses the Swift Package Manager defined in [`Package.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Package.swift) to manage dependencies and build targets. Run the release build command to generate an optimized binary:

```bash
swift build -c release

```

The compiled `.app` bundle will be located in the `.build/release/` directory. This bundle contains the executable, resources, and the `Info.plist` required for macOS execution.

## Code Signing and Notarization

macOS requires all distributed applications to be signed with a valid Developer ID certificate and notarized by Apple to pass Gatekeeper checks.

### Sign the App Bundle

Use the `codesign` utility to apply a Developer ID certificate to the entire application bundle. This step is mandatory for the built-in updater in [`Sources/PalmierPro/App/Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Sources/PalmierPro/App/Updater.swift) to function correctly:

```bash
APP_PATH=.build/release/PalmierPro.app

codesign --deep --force --verify \
  --options runtime \
  --timestamp \
  --sign "Developer ID Application: <YOUR COMPANY> (<TEAM_ID>)" \
  "$APP_PATH"

```

Replace `<YOUR COMPANY>` and `<TEAM_ID>` with your Apple Developer account details. The `--options runtime` flag ensures the hardened runtime is enabled, which is required for notarization.

### Notarize with Apple

Submit the signed bundle to Apple's notary service and wait for approval. This process validates that the app does not contain malicious content:

```bash
xcrun notarytool submit "$APP_PATH" \
  --apple-id <APPLE_ID> \
  --password <APP_SPECIFIC_PASSWORD> \
  --team-id <TEAM_ID> \
  --wait

```

Once approved, staple the notarization ticket to the bundle so macOS can verify it offline:

```bash
xcrun stapler staple "$APP_PATH"

```

## Configuring Production Backend Services

Palmier Pro connects to a Convex backend for AI-generated assets and uses Clerk for authentication. These endpoints must be configured before distribution.

### Embed Backend Credentials in Info.plist

The [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift) file reads production URLs and API keys from the bundle's `Info.plist` at runtime. According to the source code in [`Sources/PalmierPro/Account/BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Sources/PalmierPro/Account/BackendConfig.swift), you must set the following keys:

- `PalmierClerkPublishableKey`
- `PalmierConvexDeploymentURL`
- `PalmierConvexHttpURL`

Update your `Info.plist` (located in the Xcode project under **Sources/PalmierPro/App/Info.plist**) with production values:

```xml
<key>PalmierClerkPublishableKey</key>
<string>prod-your-clerk-publishable-key</string>
<key>PalmierConvexDeploymentURL</key>
<string>https://your-production-convex-deployment.com</string>
<key>PalmierConvexHttpURL</key>
<string>https://your-production-convex-http.com</string>

```

The `BackendConfig` helper exposes these values at runtime, enabling the app to communicate with live AI services:

```swift
if BackendConfig.isConfigured {
    let baseURL = BackendConfig.convexDeploymentURL!
    // Initialize Convex client with production endpoint
}

```

## Packaging and Distribution

After signing and configuration, package the application for end-user distribution.

### Create a DMG Distribution File

While the repository provides a [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh) helper that handles final assembly and `Info.plist` injection, you can manually create a compressed DMG for web distribution:

```bash
hdiutil create -volname "Palmier Pro" \
  -srcfolder "$APP_PATH" \
  -ov -format UDZO \
  PalmierPro.dmg

```

This produces a `PalmierPro.dmg` file suitable for hosting on any HTTPS-enabled web server. The repo's [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh) script automates this process by compiling the release binary, injecting the required plist configuration, and assembling the final distributable.

## Enabling Automatic Updates

Palmier Pro includes a built-in update mechanism that checks for new releases against your distribution server.

### Configure the Updater

The [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) file in [`Sources/PalmierPro/App/Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Sources/PalmierPro/App/Updater.swift) handles in-app update checks. It relies on the app being correctly signed and notarized to function. After publishing a new production build, upload the DMG to the URL configured in your backend. Users can trigger manual checks or wait for automatic background polling:

```swift
// Trigger an update check programmatically
Updater.shared.checkForUpdates()

```

The updater compares the current version against the release metadata hosted at your configured endpoint and prompts users to download the latest version.

## Summary

- **Build** the release binary using `swift build -c release` as defined in [`Package.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Package.swift).
- **Sign** the `.app` bundle with a Developer ID certificate using `codesign --deep --options runtime`.
- **Notarize** the bundle using `xcrun notarytool submit` and staple the ticket with `xcrun stapler staple`.
- **Configure** production backend endpoints by setting `PalmierConvexDeploymentURL` and `PalmierClerkPublishableKey` in `Info.plist`, read by [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift).
- **Package** the signed app into a DMG using `hdiutil create` or the provided [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh).
- **Distribute** the notarized DMG via HTTPS, enabling the auto-updater in [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) to deliver seamless updates.

## Frequently Asked Questions

### Can Palmier Pro be deployed as a web application?

No, Palmier Pro is a native macOS application compiled with Swift 6.2 and distributed as a signed `.app` bundle. It cannot run as a web application or on non-Apple platforms, as it relies on macOS-specific frameworks and the native video editing pipeline.

### What backend services are required for production deployment?

Palmier Pro requires a **Convex** deployment for AI-generated assets and **Clerk** for authentication. The [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift) file expects the `PalmierConvexDeploymentURL`, `PalmierConvexHttpURL`, and `PalmierClerkPublishableKey` entries in `Info.plist` to connect to these services in production.

### How does the automatic update mechanism work?

The [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) class periodically checks your configured distribution URL for new release metadata. When a user installs a notarized build, the updater compares the local version against the server version and prompts for download. This requires the app to be properly code-signed with a Developer ID certificate.

### Is Mac App Store distribution supported?

While the repository is structured for direct distribution via DMG or Apple Business Manager, Mac App Store distribution would require additional entitlements and sandboxing configurations not explicitly detailed in the current [`Package.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Package.swift) or build scripts. The current workflow focuses on Developer ID-signed distribution outside the App Store.