How to Deploy Palmier Pro to a Production Environment: Complete macOS Distribution Guide

Deploying Palmier Pro to a production environment requires building a release binary with Swift Package Manager, code-signing the macOS app bundle with a Developer ID certificate, notarizing it with Apple, and embedding production backend credentials in the Info.plist before distributing via DMG or the Mac App Store.

Palmier Pro is an AI-native macOS video editor written in Swift 6.2 that compiles to a native .app bundle rather than a traditional backend service. To deploy Palmier Pro to a production environment, you must follow Apple's macOS distribution requirements including code signing, notarization, and proper configuration of the Convex backend endpoints. This guide walks through the end-to-end workflow supported by the repository's build scripts and configuration files.

Building the Production Binary

The first step in deploying Palmier Pro is compiling a release version optimized for distribution.

Compile with Swift Package Manager

Palmier Pro uses the Swift Package Manager defined in Package.swift to manage dependencies and build targets. Run the release build command to generate an optimized binary:

swift build -c release

The compiled .app bundle will be located in the .build/release/ directory. This bundle contains the executable, resources, and the Info.plist required for macOS execution.

Code Signing and Notarization

macOS requires all distributed applications to be signed with a valid Developer ID certificate and notarized by Apple to pass Gatekeeper checks.

Sign the App Bundle

Use the codesign utility to apply a Developer ID certificate to the entire application bundle. This step is mandatory for the built-in updater in Sources/PalmierPro/App/Updater.swift to function correctly:

APP_PATH=.build/release/PalmierPro.app

codesign --deep --force --verify \
  --options runtime \
  --timestamp \
  --sign "Developer ID Application: <YOUR COMPANY> (<TEAM_ID>)" \
  "$APP_PATH"

Replace <YOUR COMPANY> and <TEAM_ID> with your Apple Developer account details. The --options runtime flag ensures the hardened runtime is enabled, which is required for notarization.

Notarize with Apple

Submit the signed bundle to Apple's notary service and wait for approval. This process validates that the app does not contain malicious content:

xcrun notarytool submit "$APP_PATH" \
  --apple-id <APPLE_ID> \
  --password <APP_SPECIFIC_PASSWORD> \
  --team-id <TEAM_ID> \
  --wait

Once approved, staple the notarization ticket to the bundle so macOS can verify it offline:

xcrun stapler staple "$APP_PATH"

Configuring Production Backend Services

Palmier Pro connects to a Convex backend for AI-generated assets and uses Clerk for authentication. These endpoints must be configured before distribution.

Embed Backend Credentials in Info.plist

The BackendConfig.swift file reads production URLs and API keys from the bundle's Info.plist at runtime. According to the source code in Sources/PalmierPro/Account/BackendConfig.swift, you must set the following keys:

  • PalmierClerkPublishableKey
  • PalmierConvexDeploymentURL
  • PalmierConvexHttpURL

Update your Info.plist (located in the Xcode project under Sources/PalmierPro/App/Info.plist) with production values:

<key>PalmierClerkPublishableKey</key>
<string>prod-your-clerk-publishable-key</string>
<key>PalmierConvexDeploymentURL</key>
<string>https://your-production-convex-deployment.com</string>
<key>PalmierConvexHttpURL</key>
<string>https://your-production-convex-http.com</string>

The BackendConfig helper exposes these values at runtime, enabling the app to communicate with live AI services:

if BackendConfig.isConfigured {
    let baseURL = BackendConfig.convexDeploymentURL!
    // Initialize Convex client with production endpoint
}

Packaging and Distribution

After signing and configuration, package the application for end-user distribution.

Create a DMG Distribution File

While the repository provides a scripts/bundle.sh helper that handles final assembly and Info.plist injection, you can manually create a compressed DMG for web distribution:

hdiutil create -volname "Palmier Pro" \
  -srcfolder "$APP_PATH" \
  -ov -format UDZO \
  PalmierPro.dmg

This produces a PalmierPro.dmg file suitable for hosting on any HTTPS-enabled web server. The repo's scripts/bundle.sh script automates this process by compiling the release binary, injecting the required plist configuration, and assembling the final distributable.

Enabling Automatic Updates

Palmier Pro includes a built-in update mechanism that checks for new releases against your distribution server.

Configure the Updater

The Updater.swift file in Sources/PalmierPro/App/Updater.swift handles in-app update checks. It relies on the app being correctly signed and notarized to function. After publishing a new production build, upload the DMG to the URL configured in your backend. Users can trigger manual checks or wait for automatic background polling:

// Trigger an update check programmatically
Updater.shared.checkForUpdates()

The updater compares the current version against the release metadata hosted at your configured endpoint and prompts users to download the latest version.

Summary

  • Build the release binary using swift build -c release as defined in Package.swift.
  • Sign the .app bundle with a Developer ID certificate using codesign --deep --options runtime.
  • Notarize the bundle using xcrun notarytool submit and staple the ticket with xcrun stapler staple.
  • Configure production backend endpoints by setting PalmierConvexDeploymentURL and PalmierClerkPublishableKey in Info.plist, read by BackendConfig.swift.
  • Package the signed app into a DMG using hdiutil create or the provided scripts/bundle.sh.
  • Distribute the notarized DMG via HTTPS, enabling the auto-updater in Updater.swift to deliver seamless updates.

Frequently Asked Questions

Can Palmier Pro be deployed as a web application?

No, Palmier Pro is a native macOS application compiled with Swift 6.2 and distributed as a signed .app bundle. It cannot run as a web application or on non-Apple platforms, as it relies on macOS-specific frameworks and the native video editing pipeline.

What backend services are required for production deployment?

Palmier Pro requires a Convex deployment for AI-generated assets and Clerk for authentication. The BackendConfig.swift file expects the PalmierConvexDeploymentURL, PalmierConvexHttpURL, and PalmierClerkPublishableKey entries in Info.plist to connect to these services in production.

How does the automatic update mechanism work?

The Updater.swift class periodically checks your configured distribution URL for new release metadata. When a user installs a notarized build, the updater compares the local version against the server version and prompts for download. This requires the app to be properly code-signed with a Developer ID certificate.

Is Mac App Store distribution supported?

While the repository is structured for direct distribution via DMG or Apple Business Manager, Mac App Store distribution would require additional entitlements and sandboxing configurations not explicitly detailed in the current Package.swift or build scripts. The current workflow focuses on Developer ID-signed distribution outside the App Store.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →