GitHub Actions
Change one runs-on label and a macOS job runs on XenoCI runners.
GitHub Actions needs no package. Connect the repository with the XenoCI GitHub App and change the runs-on label. When a job is queued, a single-use runner is registered for it and removed with the VM when the job ends.
Labels
| Label | Shape | Image |
|---|---|---|
xenoci-macos | 4 vCPU · 8 GiB · 1 credit/min | macOS 26.6.2 · Xcode 26.2, 26.3, 26.4.1, 26.5, 26.6, 27.0 (default 27.0) |
name: build
on: [push, workflow_dispatch]
jobs:
ios:
runs-on: xenoci-macos
steps:
- uses: actions/checkout@v4
- run: xcodebuild -scheme App -destination 'platform=iOS Simulator,name=iPhone 16' testCode signing and TestFlight
Use the steps from GitHub’s signing Xcode applications guide as they are. Keep the certificate (.p12) and provisioning profile in GitHub repository secrets and import them into a temporary keychain inside the job. XenoCI never receives or stores your certificates.
- The whole VM is deleted when the job ends, so the keychain and profile go with it. Keeping the clean-up step from GitHub’s guide does no harm.
fastlaneandpodare on PATH. Withfastlane match, callsetup_ciat the start of the lane.- Apple hosts for App Store Connect uploads (
xcrun altool, fastlanepilot) and Xcode automatic provisioning are allowed by default.
Things to know
- Artifacts and caches are stored on GitHub. The XenoCI VM is deleted when the job ends.
- Runners reach only allowed domains; add private registries as allowed domains in the console settings.
- A job has a 60-minute time limit.
- Usage costs 1 credit per minute, charged per second.