diff --git a/templates/vanilla-golden-gate.pkr.hcl b/templates/vanilla-golden-gate.pkr.hcl index a23902c..9a7dffa 100644 --- a/templates/vanilla-golden-gate.pkr.hcl +++ b/templates/vanilla-golden-gate.pkr.hcl @@ -20,93 +20,31 @@ source "tart-cli" "tart" { ssh_password = "admin" ssh_username = "admin" ssh_timeout = "180s" + // Requires Tart 2.33.0+ and macOS 27+ on both the host and guest VM + run_extra_args = [ + "--provisioning-opts=${join(",", [ + "fullName=Managed via Tart", + "username=admin", + "password=admin", + "logsInAutomatically=true", + "enablesRemoteLogin=true", + ])}", + ] boot_command = [ - # hello, hola, bonjour, etc. - "", - # Language: most of the times we have a list of "English"[1], "English (UK)", etc. with - # "English" language already selected. If we type "english", it'll cause us to switch - # to the "English (UK)", which is not what we want. To solve this, we switch to some other - # language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the - # first entry in a list of "english"-prefixed items, which will be "English". - # - # [1]: should be named "English (US)", but oh well 🤷 - "italianoenglish", - # Select Your Country or Region - "united states", - # Transfer Your Data to This Mac - "", - # Written and Spoken Languages - "", - # Accessibility - "", - # Data & Privacy - "", - # Create a Mac Account - "Managed via Tartadminadminadmin", - # Enable Voice Over - "", - # Sign In to Your Apple Account - # - # We choose "Other Sign-In Options" → "Sign in Later in Settings" here. - "", - # Are you sure you want to skip signing in with an Apple Account? - "", - # Terms and Conditions - "", - # I have read and agree to the macOS Software License Agreement - "", - # Age Range -> Adult - "", - # Choose Your Look - "", - # Enable Location Services - "", - # Are you sure you don't want to use Location Services? - "", - # Select Your Time Zone - "UTC", - # Analytics - "", - # Screen Time - "", - # Siri - "", - # You Mac is Ready for FileVault - "", - # Mac Data Will Not Be Securely Encrypted - "", - # Update Mac Automatically - "", - # Liquid Glass - "", - # Welcome to Mac - "", - # Disable Voice Over - "", + # Wait for first-boot provisioning to finish automatic login + "", # Enable Keyboard navigation # This is so that we can navigate the System Settings app using the keyboard "Terminal", "defaults write NSGlobalDomain AppleKeyboardUIMode -int 3", - # Now that the installation is done, open "System Settings" - # On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information - "open '/System/Applications/System Settings.app'", - "", - # Navigate to "Sharing" - "", - # Navigate to "Screen Sharing" and enable it - "", - # Type in the password to allow enabling Screen Sharing - "admin", - # Navigate to "Remote Login" and enable it - "", - # Quit System Settings - "q", # Disable Gatekeeper (1/2) "sudo spctl --global-disable", "admin", # Disable Gatekeeper (2/2) # On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information "open '/System/Applications/System Settings.app'", + # Wait for System Settings to fully open before navigating with the keyboard + "", "Privacy & Security", "", "", @@ -131,11 +69,10 @@ build { inline = [ // Enable passwordless sudo "echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"", - // Enable auto-login - // - // See https://github.com/xfreebird/kcpassword for details. - "echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword", - "sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin", + // Enable Screen Sharing for "tart run --vnc" + "sudo launchctl enable system/com.apple.screensharing", + // Use the same timezone as the previous Setup Assistant flow + "sudo systemsetup -settimezone GMT 2>/dev/null", // Disable screensaver at login screen "sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0", // Disable screensaver for admin user @@ -161,7 +98,9 @@ build { provisioner "shell" { inline = [ # Ensure that Gatekeeper is disabled - "spctl --status | grep -q 'assessments disabled'" + "spctl --status | grep -q 'assessments disabled'", + # Ensure that FileVault remains disabled by default + "sudo fdesetup status | grep -q 'FileVault is Off'", ] } }