Pillar guides
Comprehensive guides for shipping signed Apple builds
End-to-end walkthroughs for the parts of Apple development that usually live in scattered Stack Overflow answers: certificates and profiles, notarization, CI signing, and the fastlane match migration story. Every guide is written for engineers who need to ship, not for documentation completeness.
iOS code signing: the complete guide
Everything you need to know about signing iOS, iPadOS, tvOS, watchOS, and visionOS builds. Certificates, provisioning profiles, App IDs, the signing flow, the three-certificate cap, rotation, the most common errors, and how to do it on CI.
What happens when your Apple certificates expire
Which apps break, which keep working, and what to do next when an Apple Development, Distribution, Enterprise, Developer ID, or push certificate expires. The honest per-certificate breakdown, plus the rotation playbook that makes expiry a non-event.
macOS notarization for Electron and native apps
A practical guide to notarizing Mac apps in 2026. Developer ID signing, hardened runtime, notarytool, stapling, and the Electron-specific gotchas (electron-builder, electron-forge, @electron/notarize) that account for most rejection emails.
Apple code signing in CI/CD
Why CI signing breaks where local signing doesn't, how the keychain plumbing actually works on macOS runners, the fastlane match pattern, the HexSign pattern, and ready-to-paste setups for GitHub Actions, Bitrise, CircleCI, GitLab, and fastlane.
8 fastlane match alternatives, compared (2026)
Eight ways to stop keeping iOS signing material in an encrypted git repo behind a shared passphrase: Appcircle, Codemagic, Bitrise, Expo EAS, Capawesome Cloud, Xcode Cloud, GitLab Secure Files, and HexSign. What each one stores, whether it renews and alerts, and which CI it ties you to.
Building and signing an iOS app on Windows
What you can genuinely do from a Windows PC, what still requires macOS and why, and the four practical ways to get a signed .ipa without owning a Mac.
Where to start
These guides are not meant to be read in order. If Apple code signing is still mostly a mystery, start with iOS code signing: the complete guide, which explains the pieces (certificates, private keys, CSRs, provisioning profiles, entitlements) and how they connect. Everything else on this page assumes it. If you landed here because a build failed this morning, Apple code signing in CI/CD covers the CI-side mechanics: keychains on ephemeral runners, why a profile that works in Xcode fails inside a container, and how to get signing material onto a build machine without committing it. And if the question on the table is whether to move off a shared fastlane match repo, 8 fastlane match alternatives walks the options with a migration plan that never involves nuke.
They are written for engineers who have to ship something, not for documentation completeness, so each one stays at working depth and links into the glossary and the help centre where the fine detail lives. Expect roughly 10 to 20 minutes of reading per guide, a table of contents on the right, and code you can paste rather than adapt.