Skip to content

Workflow, secrets & variables ​

rnd build:configure copies eas/templates/eas-build.yml to .github/workflows/eas-build.yml. The CLI never rewrites it: every decision arrives as a dispatch input, so you can also start a build by hand from the repository's Actions tab.

Keep it current

Workflow fixes ship in the template, not in your repository. After upgrading React Native Deploy, copy the template over your workflow and push.

Inputs ​

GitHub allows at most ten workflow_dispatch inputs, so the resolved plan travels as one JSON blob.

InputContents
dispatch_idRandom UUID; stamped into the run name so the CLI can find the run, and keys the install page
platformios or android
profileBuild profile name
runnerRunner label, from resourceClass
config_jsonThe resolved build plan: export method, configuration, scheme, Gradle task, toolchain, env, app name and version, …

Steps ​

StepRuns whenDoes
Prepare projectalwaysUnpacks config_json into step outputs
CheckoutalwaysFull history (some expo-updates runtime versions depend on it)
Read eas.jsonalwaysFails early if the commit has no eas.json
Export build environmentalwaysExports the profile's env before anything reads the app config
Set up Node / package manageralwaysNode version and package manager from the plan
Install JS dependenciesalwaysnpm ci, yarn install --immutable, pnpm install --frozen-lockfile or bun install --frozen-lockfile
Set up JDK / Android SDKAndroidTemurin 17, android-actions/setup-android@v4
Select XcodeiOSPins /Applications/Xcode.app
Prebuildalwaysexpo prebuild, or prebuildCommand; skipped when ios/ or android/ is committed
Restore pods cache / Install podsiOSKeyed by cache.key and Podfile.lock
Resolve Xcode schemeiOSThe profile's scheme, else the only ios/*.xcworkspace
Import signing credentialsiOS, signed buildsThrowaway keychain; picks EAS_IOS_PROFILE or EAS_IOS_PROFILE_INTERNAL by export method
Apply signing settingsiOS device buildsManual signing on the target that builds the profile's bundle id
Archive (iOS) / Export IPAiOS device buildsxcodebuild archive and -exportArchive with the profile mapping
Build for simulator (iOS)iOS simulator buildsUnsigned .app, tarred to keep the bundle intact
Build (Android)AndroidThe Gradle task; keystore injected when present
Publish for installinternal device builds, EAS_INSTALL_URL setMultipart upload to the install service; adds an install link to the run summary
Upload application archivealwaysArtifact application-archive, kept 90 days
Upload Xcode logsiOS, even on failureArtifact xcode-logs
Clean up credentialsiOS, even on failureDeletes the keychain and installed profiles

Runs are grouped per platform, profile and branch with concurrency, and nothing is cancelled automatically: a second build of the same profile waits for the first.

Secrets ​

SecretNeeded for
EAS_IOS_DIST_P12, EAS_IOS_P12_PASSWORDSigned iOS builds
EAS_IOS_PROFILEiOS store builds
EAS_IOS_PROFILE_INTERNALiOS internal builds
EAS_ANDROID_KEYSTORE, EAS_ANDROID_STORE_PASSWORD, EAS_ANDROID_KEY_ALIAS, EAS_ANDROID_KEY_PASSWORDAndroid release signing (optional; debug key otherwise)
EAS_INSTALL_TOKENPublishing internal builds

How to create each one: Credentials.

Variables ​

VariableEffect
EAS_INSTALL_URLBase URL of the install service. When unset, internal builds are not published

Builds run on your GitHub Actions minutes; signing assets stay in your repo secrets.