# How to Deploy Palmier Pro to Production: A Complete macOS Distribution Guide

> Deploy Palmier Pro to production on macOS. Learn to build, code-sign, notarize, and package your .app bundle into a DMG for seamless distribution.

- Repository: [Palmier/palmier-pro](https://github.com/palmier-io/palmier-pro)
- Tags: how-to-guide
- Published: 2026-06-23

---

**Deploy Palmier Pro to production by building a release binary with Swift Package Manager, code-signing and notarizing the .app bundle with Apple, embedding production backend credentials in Info.plist, and packaging the result as a notarized DMG for distribution.**

Palmier Pro is an AI-native macOS video editor written in Swift 6.2 and distributed as a signed `.app` bundle rather than a traditional backend service. Because the application relies on external AI services via Convex and Clerk, production deployment requires configuring secure backend endpoints before distribution. The following guide covers the end-to-end workflow supported by the `palmier-io/palmier-pro` repository.

## Build the Release Binary

Start by compiling an optimized release version of the application using the Swift Package Manager. The top-level [`Package.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Package.swift) defines the executable target and dependencies for the macOS client.

Run the release build command from the repository root:

```bash
swift build -c release

```

This generates the compiled binary and `.app` bundle structure under `.build/release/`. Locate the built application at `.build/release/PalmierPro.app` before proceeding to signing.

## Code-Sign and Notarize the Application

macOS requires all distributed applications to be signed with a valid Developer ID certificate and notarized by Apple to pass Gatekeeper verification. The built-in updater located in [`Sources/PalmierPro/App/Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Sources/PalmierPro/App/Updater.swift) specifically requires a correctly signed and notarized bundle to function.

Execute the following commands to sign, submit, and staple the application:

```bash

# Sign the application with hardened runtime

codesign --deep --force --verify \
  --options runtime \
  --timestamp \
  --sign "Developer ID Application: <YOUR COMPANY> (<TEAM_ID>)" \
  ".build/release/PalmierPro.app"

# Submit to Apple's notary service (requires app-specific password)

xcrun notarytool submit ".build/release/PalmierPro.app" \
  --apple-id <APPLE_ID> \
  --password <APP_SPECIFIC_PASSWORD> \
  --team-id <TEAM_ID> \
  --wait

# Staple the notarization ticket to the bundle

xcrun stapler staple ".build/release/PalmierPro.app"

```

The `--options runtime` flag enables the hardened runtime required for notarization, while the `notarytool` command synchronously waits for Apple’s approval before stapling the ticket.

## Configure Production Backend Endpoints

Palmier Pro connects to Convex for AI-generated assets and Clerk for authentication. The [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift) file reads these production URLs and keys from the bundle’s `Info.plist` at runtime, making pre-flight configuration critical.

Embed the production credentials into `Sources/PalmierPro/App/Info.plist`:

```xml
<key>PalmierClerkPublishableKey</key>
<string>prod_YOUR_CLERK_KEY</string>
<key>PalmierConvexDeploymentURL</key>
<string>https://your-production-convex-deployment.convex.cloud</string>
<key>PalmierConvexHttpURL</key>
<string>https://your-production-convex-http-endpoint.com</string>

```

At runtime, the application validates and exposes these values through the `BackendConfig` helper:

```swift
if BackendConfig.isConfigured {
    let convexURL = BackendConfig.convexDeploymentURL!
    let clerkKey = BackendConfig.clerkPublishableKey!
    // Initialize AI services with production endpoints
}

```

The repository includes a helper script at [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh) that can inject these values during the build process using `inject_plist` calls, ensuring consistent configuration across CI/CD pipelines.

## Package and Distribute the Application

Once signed, notarized, and configured, package the application for end-user distribution. The most common method for macOS is creating a compressed DMG file.

Generate the final distributable with `hdiutil`:

```bash
hdiutil create -volname "Palmier Pro" \
  -srcfolder ".build/release/PalmierPro.app" \
  -ov -format UDZO \
  PalmierPro.dmg

```

Upload the resulting `PalmierPro.dmg` to an HTTPS-enabled web server, or distribute through Apple Business Manager or the Mac App Store. The entry point in [`Sources/PalmierPro/App/AppDelegate.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Sources/PalmierPro/App/AppDelegate.swift) initializes both the MCP service and the auto-updater on launch, ensuring users immediately connect to the production backend specified in your `Info.plist`.

## Enable Automatic Updates

The [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) module provides in-app update checks by contacting the server URLs defined in `BackendConfig`. After publishing a new release, upload the updated DMG to your designated hosting location; the application will automatically detect and prompt users to install the new version.

Trigger an explicit update check programmatically:

```swift
Updater.shared.checkForUpdates()

```

The updater verifies the code signature of downloaded updates against the original signing identity, preventing tampered binaries from installing on client machines.

## Summary

- **Build** the release binary using `swift build -c release` as defined in [`Package.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Package.swift).
- **Sign** the `.app` bundle with a Developer ID certificate and the hardened runtime flag.
- **Notarize** using `xcrun notarytool submit` and staple the ticket with `xcrun stapler staple`.
- **Configure** production backend endpoints in `Info.plist` for [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift) to read Convex and Clerk credentials.
- **Package** the final bundle into a DMG using `hdiutil create` for web distribution.
- **Distribute** via HTTPS download or Apple Business Manager, leveraging [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) for seamless version management.

## Frequently Asked Questions

### Do I need a Mac App Store distribution certificate to deploy Palmier Pro?

No. You can distribute Palmier Pro using a Developer ID Application certificate for direct download distribution outside the Mac App Store. The [`App/Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/App/Updater.swift) component is designed for this distribution model, though Mac App Store certificates are supported if you choose that channel.

### What backend services does Palmier Pro require for production?

The application requires a Convex deployment for AI asset generation and a Clerk instance for user authentication. The [`BackendConfig.swift`](https://github.com/palmier-io/palmier-pro/blob/main/BackendConfig.swift) file expects three specific keys in `Info.plist`: `PalmierConvexDeploymentURL`, `PalmierConvexHttpURL`, and `PalmierClerkPublishableKey`. Without these, the AI editing features will fail to initialize.

### How does the auto-updater verify the integrity of new releases?

The [`Updater.swift`](https://github.com/palmier-io/palmier-pro/blob/main/Updater.swift) module checks the code signature of downloaded updates against the original signing identity used during the initial installation. Because the application requires notarization to function, the updater implicitly trusts only binaries that pass Gatekeeper validation and match the original Developer ID team identifier.

### Can I automate the notarization process in a CI/CD pipeline?

Yes. The `xcrun notarytool` command supports non-interactive authentication using app-specific passwords stored in environment variables. You can integrate the signing, notarization, and [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh) steps into GitHub Actions or other CI platforms, ensuring the `Info.plist` injection and DMG creation happen automatically on tagged releases.