Public App Store Release Checklist
Public App Store Release Checklist
This checklist prepares a normal public App Store release. It does not authorize upload, submission, approval, publication, a Git tag, a GitHub release, or use of signing secrets.
Current reversible preparation
- Godot 4.7.2 and the pinned Apple toolchain are documented.
- The credential-free iOS export and generic-device compile path exists.
- The public workflow is manual-only and main-only, with separate
app-storeauthorization andtestflightsigning approvals. - The public export omits
testFlightInternalTestingOnly. - The workflow uploads no signed IPA, archive, certificate, profile, or key as a GitHub artifact.
- Metadata copy, category recommendations, privacy answers, age-rating inputs, App Review notes, screenshot plan, support copy, and privacy policy templates are versioned.
- A deterministic seven-image 13-inch iPad screenshot harness, manifest, Windows generator, and opaque-image validation are versioned.
- TestFlight is documented as unavailable for the target under-13 Apple Account and is not the selected installation path.
- A separate Ad Hoc validation path is prepared for the three registered iPads. Its default mode publishes no signed artifact.
- Create the separately authorized private Azure OTA path with a resource-only governance exclusion, private container, revocable upload and read policies, explicit workflow confirmation, anonymous-access rejection, incomplete-upload rollback, and no GitHub artifact publication.
- Store the three supplied iPad identifiers as separate masked secrets in the protected signing environment without recording their values in Git.
- Configure the separate Admin Team API key for protected provisioning only, retain it for future provisioning per owner request, and keep the App Manager metadata secrets unchanged.
- Automate exact device/profile reconciliation so no manually downloaded Ad Hoc profile or profile secret is required.
Uploaded candidate record
- Version:
0.1.0 - Build:
33576432175.1 - Source commit:
646011df800dc35aaed98d1ba8e8f775430341d8 - Workflow run: iOS App Store candidate upload 33576432175
- Upload completed: September 1, 2026 at 20:46 EDT
- App Store Connect status at workflow completion: package uploaded and processing.
- Signing material cleanup completed and verified.
- The build was not selected for a version, submitted for App Review, or released.
- This candidate is superseded by later gameplay and release-preparation changes and must not be submitted.
Current replacement candidate:
- Version:
0.1.0 - Build:
33770597608.1 - Source commit:
cab65511405f5c6b17865d2283d4a636a59da8be - Workflow run: iOS App Store candidate upload 33770597608
- Apple processing state:
VALID; the build is selected for version0.1.0, is not expired, and declares no non-exempt encryption. - Seven final 13-inch iPad screenshots and the protected App Review contact are complete.
- Release type remains
MANUAL. The candidate has not been submitted or released.
Required owner-supplied listing fields
- Replace every
REQUIRED_BEFORE_SUBMISSIONvalue intools/app-store-metadata.json,docs/privacy-policy.md, anddocs/app-support.md. - Verify the renamed HTTPS support URL and public GitHub Issue contact
form at
FrogCityFeast. - Verify the renamed HTTPS privacy policy URL and public privacy-question
form at
FrogCityFeast. - Confirm copyright owner and year:
2026 Chase Dafnis. - Choose free pricing with no in-app purchases. Do not add in-app purchases without a separately reviewed product and privacy change.
- Select all available storefronts except China mainland.
- Record the owner-selected EU Digital Services Act status as non-trader. App Store Connect may still require the Account Holder to complete or confirm the declaration.
Final build and device acceptance
- Complete Windows validation on source commit
2e4f60160db67f6715844aac234d6a47e4e40843. - Complete Godot CI on that source commit: run
33662838762. - Manually run the unsigned iOS smoke build on that source commit: run
33664214769. - Let the protected Ad Hoc workflow register only missing exact iPad
records and create or reuse one matching profile containing exactly the
three configured devices as documented in
docs/ios-ad-hoc-testing.md. Run33703681354reused all three device records and the exact profile. - Run the protected Ad Hoc validation workflow without retaining a signed
IPA. Run
33703681354, build33703681354.1, completed signing, export, embedded-profile validation, and verified cleanup. - Run the separately authorized private OTA workflow. Run
33768105238, build33768105238.1, uploaded the private IPA and manifest, confirmed both reject anonymous access, retained no GitHub artifact, and verified cleanup. - Install build
33768105238.1on each of the three registered iPads by scanning the private local QR and confirming the iOS installation prompt. - Physical A16 iPad acceptance: signed Release build sustains at least 58 FPS over 30 seconds, targets 60 FPS, and meets the documented frame, process, physics, memory, draw, object, and primitive budgets.
- Capture GPU frame time and thermal behavior with Xcode/Metal tools.
- Perform the deferred final visual review on the publication build.
- Perform target-device audio mix, haptics, safe-area, touch-target, readability, Reduce Motion, and larger-controls checks.
- Confirm cold launch, background/foreground, interruption recovery, low-storage save warning, reinstall, and local-data deletion behavior.
App Store Connect listing
- Run the protected
App Store metadata syncworkflow for the exact reviewed commit and confirm the API-supported product-page, category, manual-release, copyright, and age-rating values. Run 33661855538 completed successfully from commit6202d2833a69a60cfe15d19cf000bc5b30b18d6c. - Replace the protected Developer-role App Store Connect API key with an
App Manager-equivalent key before retrying metadata synchronization. Run
33616496541
completed authenticated read-only preflight but Apple denied the first
category write with
403 FORBIDDEN_ERROR; no metadata was changed. - Complete a protected metadata rerun after the first-release
whatsNewpayload fix. Runs 33648261223 and 33653860478 applied the Games categories, app-information localization, and editable version0.1.0; run33661855538then completed version-localization and age-rating updates. - Copy the validated
en-USfields fromtools/app-store-metadata.json. - Set Games > Casual with Adventure as the secondary Games subcategory.
- Confirm content rights using the repository asset provenance ledgers.
- Answer App Privacy with No, we do not collect data from this app.
- Confirm the App Privacy response is published, not only saved. In Apps > Frog City Feast > App Privacy, verify the no-data answer, click Publish, and accept Apple’s accuracy confirmation.
- Enter the live privacy policy URL.
- Complete the current age-rating questionnaire with the inputs in
docs/app-store-metadata.md, including Frequent cartoon or fantasy violence. - Accept Apple’s calculated regional rating. Do not lower answers or bypass restrictions if the under-13 Apple Account cannot install it.
- Confirm non-exempt encryption is No.
- Confirm no ads, tracking, account, Game Center, cloud save, StoreKit products, subscriptions, or purchases are declared.
- Enter current App Review contact information in international format where required.
- Add the App Review notes from
docs/app-store-metadata.md. - Re-run the approved automated final iPad landscape screenshot set from
the exact publication build using
scripts\generate-app-store-screenshots.ps1, perform the deferred visual review, upload its seven images without debug overlays or placeholders, and verify their dimensions in App Store Connect. Protected run33784524004uploaded and processed all seven exact-source images. - Choose Manually release this version so approval cannot publish the app automatically.
Protected GitHub environment
- Confirm the
app-storeenvironment still allows only branchmain. - Confirm the
ad-hocenvironment allows only branchmain, requiresCHDAFNI-MSFT, permits no administrator bypass, and contains no secrets. - Confirm
CHDAFNI-MSFTremains the required reviewer. - Confirm administrators cannot bypass the
app-storeortestflightprotection rules. - Confirm the environment variables are the reviewed Team ID and bundle ID.
- Confirm the protected
testflightenvironment retains the six validated signing and App Store Connect secrets and requires its own approval. - Confirm the three device secrets and separate
APPLE_PROVISIONING_KEY_ID/APPLE_PROVISIONING_PRIVATE_KEY_BASE64Admin credentials remain configured, are used only by the provisioning step, and require the same protected approval. - Confirm the public workflow consumes those secrets in place and that the
app-storeenvironment contains no signing secrets. - Confirm no signing value exists at repository scope or in a workflow, log, artifact, issue, pull request, commit, or local repository file.
Separate authorization gates
- Explicit upload authorization: version
0.1.0from exact source commitcab65511405f5c6b17865d2283d4a636a59da8bewas authorized and uploaded as build33770597608.1in workflow run33770597608. - Set the workflow’s
confirm_uploadinput, approve the protectedapp-storeauthorization job, and separately approve the protectedtestflightsigning job for the exact replacement run. - Confirm the replacement workflow completed cleanup and produced no downloadable signed artifact.
- Wait for Apple processing and inspect export compliance, minimum OS,
exact build selection, screenshots, review detail, and build metadata.
Read-only run
33823901657confirmed the exact valid build, seven screenshots, App Review detail, content rights, age rating, free pricing, every current territory except China mainland, and manual release. - Complete the Apple account’s EU Digital Services Act declaration as
non-trader. Run
33825382288confirmed that Apple no longer reportsTRADER_STATUS_NOT_PROVIDED. - Rerun the protected candidate inspection after the DSA declaration and
App Privacy publication. Apple cleared the DSA-specific status but continued
returning generic
CANNOT_SELLfor the unreleased storefronts; the authoritative review-submission request subsequently succeeded. - Explicit submission authorization: authorize selection of the processed build and submission to App Review. Upload authorization alone is not submission authorization.
- Run the separately protected exact-build App Review submission workflow
and confirm Apple acknowledges the submission.
Run
33826716016was rejected while adding the exact version with Apple’s generic409 STATE_ERROR.ENTITY_STATE_INVALIDand no associated validation errors. The no-data App Privacy response was then prepared, but retry33827587415produced the identical rejection because the final Publish confirmation had not completed. Run33828163019recreated the deleted review draft, submitted exact version0.1.0and build33770597608.1, and Apple returnedWAITING_FOR_REVIEWwithreleaseType: MANUALandreleasePerformed: false. - Resolve only accurate App Review questions; do not change age, privacy, content, or account answers to evade a restriction.
- Explicit release authorization: after approval, authorize manual public release. Submission authorization alone is not release authorization.
- Create a Git tag or GitHub release only under separate explicit authorization.
Post-release
- Confirm the public product page, screenshots, privacy label, age rating, support link, and privacy link are correct.
- Confirm installation on an eligible iPad through the normal App Store.
- Verify the target under-13 Apple Account only if Apple’s assigned rating and Family settings permit installation; do not bypass Apple restrictions.
- Record the released commit, version, build number, App Store URL, release date, and any approved storefront exclusions.
- Monitor support and crash information available through Apple without adding in-app analytics or tracking.