You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助GitHub Actions+Fastlane实现Xcode自动签名的问题与解决

iOS自动构建问题排查与解决

场景描述

我需要配置GitHub Actions工作流,结合Fastlane实现代码推送到指定分支时自动构建Debug和Release版本,过程中遇到了签名和构建卡住的问题。

初始尝试(Xcode自动签名+Fastlane配置)

最初尝试用Xcode自动签名,但Fastlane一直提示Xcode未关联账号,于是在Fastlane中添加了App Store Connect API Key相关配置:

lane :myLaneToBuildDev do
  increment_build_number(xcodeproj: "App/App.xcodeproj")
  build_app(workspace: "App.xcworkspace", scheme: "App", configuration: "Debug", export_method: "ad-hoc", xcargs: "-allowProvisioningUpdates -authenticationKeyID #{ENV["APPSTORE_CONNECT_API_KEY"]} -authenticationKeyIssuerID #{ENV["APPSTORE_CONNECT_ISSUER_ID"]} -authenticationKeyPath #{File.expand_path('pathToP8')}")
  firebase_app_distribution(app: ENV["FIREBASE_PRO_APP_ID"], service_credentials_file: ENV["SERVICE_CREDENTIALS_FILE_PATH"], groups: "developers", release_notes: "Lots of amazing new features to test out!")
  slack(message: "Successfully distributed a new Firebase build for app", slack_url: ENV["FASTLANE_SLACK_URL"], channel: ENV["FASTLANE_SLACK_CHANNEL"])
end

配置后登录错误消失,但构建卡在生成dSYM步骤:

[12:37:20]: ▸ Compiling LaunchScreen.storyboard
[12:37:20]: ▸ Processing App.plist
[12:37:21]: ▸ Linking App
[12:37:22]: ▸ Generating 'App.app.dSYM'
##[debug]Re-evaluate condition on job cancellation for step: 'Run fastlane'.
Error: The operation was canceled.

二次尝试(手动下载证书与配置文件)

之后尝试在GitHub Actions工作流中手动下载证书和配置文件,但依然出现“无账号”错误,工作流配置如下:

name: Build
on:
  push:
    branches:
      - 'releases/app-**'

concurrency:
  group: build-ios-${{ github.ref }}
  cancel-in-progress: true
  
jobs:
  build:
    permissions: write-all
    runs-on: macos-13
    steps:
    - uses: actions/checkout@v2
    - uses: actions/cache@v2
      with:
        path: Pods
        key: ${{ runner.os }}-pods-${{ hashFiles('**/Podfile.lock') }}
        restore-keys: |
          ${{ runner.os }}-pods-
          
    - name: Install the Apple certificate and provisioning profile
      env:
          PROD_CERTIFICATE_BASE64: ${{ secrets.IOS_PROD_P12 }}
          DEV_CERTIFICATE_BASE64: ${{ secrets.IOS_DEV_P12 }}
          P12_PASSWORD: ${{ secrets.P12_PASSWORD }}
          KEYCHAIN_PASSWORD: ${{ secrets.KEYCHAIN_PASSWORD }}
      run: |
          echo $PROD_CERTIFICATE_BASE64 | base64 --decode > prod.p12
          echo $DEV_CERTIFICATE_BASE64 | base64 --decode > dev.p12
          security create-keychain -p $KEYCHAIN_PASSWORD build.keychain
          security default-keychain -s build.keychain
          security unlock-keychain -p $KEYCHAIN_PASSWORD build.keychain
          security import prod.p12 -k build.keychain -P $P12_PASSWORD -T /usr/bin/codesign
          security import dev.p12 -k build.keychain -P $P12_PASSWORD -T /usr/bin/codesign
          security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k $KEYCHAIN_PASSWORD build.keychain

    - name: 'Download Provisioning Profiles Dev'
      uses: apple-actions/download-provisioning-profiles@v1
      if: contains(github.ref, 'releases/app')
      with: 
        bundle-id: 'com.*.*.dev'
        profile-type: 'IOS_APP_DEVELOPMENT'
        issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }}
        api-key-id: ${{ secrets.APPSTORE_KEY_ID }}
        api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}

    - name: 'Download Provisioning Profiles Prod'
      uses: apple-actions/download-provisioning-profiles@v1
      if: contains(github.ref, 'releases/app')
      with: 
        bundle-id: 'com.*.*'
        profile-type: 'IOS_APP_STORE'
        issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }}
        api-key-id: ${{ secrets.APPSTORE_KEY_ID }}
        api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}
  

    - name: Set up netrc file for mapbox
      run: echo "machine api.mapbox.com" > ~/.netrc && echo "login mapbox" >> ~/.netrc && echo "password ${{ secrets.MAPBOX_SECRET }}" >> ~/.netrc

    - name: Bundle dependencies
      run: bundle install

    - name: CocoaPods dependencies
      run: bundle exec pod install

    - name: Run fastlane
      run: bundle exec fastlane myLaneToBuildDev

    - name: Clean up keychain and provisioning profile
      if: ${{ always() }}
      run: |
        security delete-keychain build.keychain
        cat /Users/runner/Library/Logs/gym/*-*.log
          

注:应用采用模块化框架构建,两个应用共享部分代码(框架无需签名)。

问题清单

  • 使用App Store Connect API Key配合Xcode自动签名是否可行?若可行,是否可以移除配置文件下载及P12证书相关步骤?
  • 为何已在工作流中下载证书和配置文件,仍出现登录错误,仿佛未配置的Xcode账号优先级更高?
  • 构建为何卡在生成dSYM步骤?是否与签名有关?可能是密钥登录失败但未报错?

最终解决方法

问题根源在于手动下载证书并创建钥匙链的操作,与App Store Connect自动认证方式存在冲突,移除所有证书和配置文件下载步骤后,构建流程恢复正常。


内容的提问来源于stack exchange,提问作者John Smith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 23:27:07