Builds run on Apple Silicon Mac mini hosts in Seoul, on a wired internal network that is not exposed directly to the internet.
01
A fresh VM per job
Each job gets a fresh macOS VM, and the whole VM is deleted when it ends. The default runner is an M4 with 4 vCPU and 8 GiB.
02
Where data lives
Customer data is not kept on the Macs. Anything that must persist, such as a build cache, is stored on a separate server, and finished job VMs have their disks deleted.
03
Image updates
A new macOS and Xcode image is verified before it becomes the default, and the previous image stays available for a while. Changes are announced in the docs and the release notes.
Security settings for each image, such as SIP, Gatekeeper, and sudo, are published in the docs.
1Build requestGitHub Actions or the API
2Apple Silicon MacMac mini in Seoul
3A fresh macOS VM per jobDeleted when the job ends