How to Deploy Palmier Pro to a Production Server: Build, Sign, and Distribute

Deploy Palmier Pro to a production server by compiling a release binary with Swift Package Manager, code-signing and notarizing the macOS app bundle, embedding production Convex backend URLs in the Info.plist, and distributing the final signed DMG to end-users.

Palmier Pro is an AI-native macOS video editor written in Swift 6.2 and distributed as a signed .app bundle. Because it is a desktop application rather than a traditional backend service, deploying it to production involves building a release binary, configuring backend endpoints, and preparing the bundle for distribution. This guide covers the complete workflow using the actual build scripts and configuration files found in the palmier-io/palmier-pro repository.

Build a Release Binary with Swift Package Manager

The foundation of a production deployment is a release build compiled from the source. The repository uses Swift Package Manager defined in Package.swift to manage dependencies and build targets.

Run the following command from the repository root to create an optimized release binary:

swift build -c release

This generates the executable under .build/release/. Locate the resulting PalmierPro.app bundle, which serves as the base artifact for all subsequent packaging steps.

Code Sign and Notarize the macOS App Bundle

macOS requires all distributed applications to be signed with a valid Developer ID certificate and notarized by Apple to prevent Gatekeeper warnings. The Sources/PalmierPro/App/Updater.swift component specifically requires a correctly signed bundle to function.

First, sign the application using your Developer ID certificate:

codesign --deep --force --verify \
  --options runtime \
  --timestamp \
  --sign "Developer ID Application: <YOUR COMPANY> (<TEAM_ID>)" \
  .build/release/PalmierPro.app

Next, submit the signed bundle to Apple’s notary service using your Apple ID and an app-specific password:

xcrun notarytool submit .build/release/PalmierPro.app \
  --apple-id <APPLE_ID> \
  --password <APP_SPECIFIC_PASSWORD> \
  --team-id <TEAM_ID> \
  --wait

Once notarization completes successfully, staple the ticket to the bundle:

xcrun stapler staple .build/release/PalmierPro.app

Configure Production Backend Endpoints

Palmier Pro connects to a Convex backend for AI-generated assets. Production deployments must embed the production URLs and API keys directly into the bundle’s Info.plist file, which Sources/PalmierPro/Account/BackendConfig.swift reads at runtime.

According to the source code, the application expects the following keys in the Info.plist:

  • PalmierClerkPublishableKey
  • PalmierConvexDeploymentURL
  • PalmierConvexHttpURL

Add these entries to your Info.plist (located in the Xcode project under Sources/PalmierPro/App/Info.plist):

<key>PalmierClerkPublishableKey</key>
<string>prod-CLERK_KEY</string>
<key>PalmierConvexDeploymentURL</key>
<string>https://your-prod-convex-endpoint.com</string>
<key>PalmierConvexHttpURL</key>
<string>https://your-prod-convex-http.com</string>

At runtime, the BackendConfig helper exposes these values:

if BackendConfig.isConfigured {
    let baseURL = BackendConfig.convexDeploymentURL!
    // Use baseURL for AI generation requests
}

Package the Application for Distribution

After signing and configuring the backend, create a distributable package. The repository includes scripts/bundle.sh, which handles the final assembly and can inject runtime configuration into the plist.

For a standard web distribution, create a compressed DMG:

hdiutil create -volname "Palmier Pro" \
  -srcfolder .build/release/PalmierPro.app \
  -ov -format UDZO PalmierPro.dmg

Upload the resulting PalmierPro.dmg to an HTTPS-enabled web server or distribute it through the Mac App Store or Apple Business Manager.

Enable Automatic Updates

The built-in updater located in Sources/PalmierPro/App/Updater.swift periodically checks the configured backend for new releases. The entry point in Sources/PalmierPro/App/AppDelegate.swift initializes this service at launch.

To ensure users receive seamless updates, publish new DMG files to the same URL endpoint referenced in your BackendConfig. Trigger an update check programmatically using:

Updater.shared.checkForUpdates()

The updater validates the signature of the downloaded bundle before installation, ensuring only notarized updates from your team are applied.

Summary

  • Build the release binary using swift build -c release as defined in Package.swift.
  • Sign the .app bundle with a Developer ID certificate and notarize it using xcrun notarytool to satisfy Gatekeeper requirements enforced by Updater.swift.
  • Configure production backend URLs (PalmierConvexDeploymentURL, PalmierClerkPublishableKey) in Info.plist for BackendConfig.swift to read at runtime.
  • Package the signed app into a DMG using hdiutil create or use the scripts/bundle.sh helper.
  • Distribute via HTTPS or Mac App Store, knowing Updater.swift will handle future updates automatically.

Frequently Asked Questions

Does Palmier Pro require a traditional server deployment?

No. Palmier Pro is a native macOS application distributed as a signed .app bundle, not a server-side service. Deploying it to production means preparing the binary for end-user installation through code signing, notarization, and packaging, rather than running it on a remote server.

What certificates do I need to deploy Palmier Pro?

You need a valid Apple Developer ID Application certificate to sign the bundle and access to Apple’s notary service. The App/Updater.swift component requires a valid signature to function correctly, and macOS Gatekeeper will block unsigned or unnotarized apps by default.

How do I switch between development and production Convex backends?

Set the PalmierConvexDeploymentURL and PalmierConvexHttpURL keys in the Info.plist file before building. The BackendConfig.swift module reads these values at launch. For production, point these keys to your live Convex deployment URLs; for development, use your local or staging endpoints.

Can users update the app automatically after I deploy a new version?

Yes. The Updater.swift system checks the backend URL configured in BackendConfig for new release metadata. When you upload a new signed DMG to your distribution endpoint, existing users will receive an in-app notification and can download the update directly without manual reinstallation.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →