Compare commits

...

366 Commits

Author SHA1 Message Date
edi-oai d6ee41d6d5
Install Tart Guest Agent from OpenAI tap (#370) 2026-08-14 22:34:20 -04:00
Fedor Kororkov 741758b9ba
Use ASIF for Golden Gate vanilla image (#369) 2026-08-14 14:30:54 -04:00
Jiawen Geng f03344599b
Pre-install pnpm alongside yarn in base image (#357)
* Pre-install pnpm alongside yarn in base image

Install pnpm globally in the Node.js provisioner so base images
include both common package managers.

Assisted-by: Cursor Agent

Co-authored-by: Jiawen Geng <technicalcute@gmail.com>

* Install yarn and pnpm in a single npm command

Assisted-by: Cursor Agent

Co-authored-by: Jiawen Geng <technicalcute@gmail.com>

* Configure PNPM_HOME in the base image shell profile

Assisted-by: Cursor Agent

Co-authored-by: Jiawen Geng <technicalcute@gmail.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-08-14 14:02:34 -04:00
Nikolay Edigaryev 16e9ad7d00 Pass "--provisioning-opts" to "tart run" to simplify installation 2026-08-13 15:04:29 +01:00
Nikolay Edigaryev 85b77e41bc Produce macOS Golden Gate vanilla image 2026-08-13 15:04:29 +01:00
Fedor Kororkov 9be4b9dc86
Fix base image automation microphone permissions (#367) 2026-08-11 21:45:23 -04:00
Fedor Kororkov 46050816d8
Update release.yml 2026-08-07 19:55:39 -04:00
Fedor Kororkov d358da6f50
Use base image Ruby for Xcode builds (#366) 2026-08-07 19:54:31 -04:00
Fedor Kororkov b4926493fb
Update Ruby for Xcode 27 image builds (#365) 2026-08-07 14:24:09 -04:00
Fedor Kororkov c166ec1698
Merge pull request #364 from cirruslabs/dev/fkorotkov/tahoe-26-6-1-automation-permissions
Update Tahoe restore image and automation permissions
2026-08-07 10:38:00 -04:00
Fedor Korotkov 3d6445b446
Update Tahoe restore image and automation permissions 2026-08-07 10:24:00 -04:00
Fedor Kororkov f5a7e1e631
Merge pull request #363 from cirruslabs/dev/fkorotkov/fix-monthly-buildkite-tap-trust
Fix Homebrew 6 trust failure in monthly image builds
2026-08-06 12:20:10 -04:00
Fedor Korotkov 0a9ad1a419
Fix Buildkite formula trust in monthly builds 2026-08-06 08:36:12 -04:00
Fedor Korotkov cd2d1c6698 Decouple runner release builds from Xcode releases 2026-07-05 12:00:02 -04:00
Fedor Korotkov 65519d3874
Remove dependency on release-xcode for runner image 2026-07-05 11:57:09 -04:00
Fedor Korotkov 71b405bd0c
Add Tahoe runner Xcode 26.6 and beta 2 (#356)
* Add Tahoe runner Xcode 26.6 and beta 2

* Add PR template validation workflow

* Install Ansible for template validation

* Build template images in PR workflow

* Authenticate Packer plugin downloads

* Prepare Xcode archives for PR builds

* Support authenticated Xcode archive downloads

* Use Xcode 27 beta 2 version token

* Increase Tahoe runner disk size

* Select Xcode apps by path during runner builds

* Update Homebrew before Tuist install

* Avoid Tuist cask validation during image builds

* Trust Tuist formula during image builds

* Add Tahoe iOS 27 beta runtime expectation
2026-07-04 22:21:50 -04:00
Fedor Kororkov 2be4479694
Update release.yml (#352) 2026-06-08 16:30:42 -07:00
Fedor Korotkov 206d99a672
Migrate CI to GitHub Actions (#351) 2026-06-03 06:37:04 -07:00
Fedor Korotkov 0ad265b76d
macOS and Xcode 26.5 (#349)
* macOS and Xcode 26.5

* Updated expected tahoe runtimes
2026-05-25 19:14:54 -04:00
Nikolay Edigaryev 154a7604f9
vanilla-sequoia.pkr.hcl: click "Select Your Country or Region" (#335) 2026-05-16 10:36:46 -04:00
Fedor Korotkov 5a2d4fd8cc
Xcode 26.4.1 (#348) 2026-05-02 19:53:10 -04:00
Diogo Araújo 70cb4395fe
feat: boot command changes to tahoe 26.4 (#344)
* feat: boot command changes to tahoe 26.4

* add first time password to enable screen sharing
2026-04-05 12:38:36 -04:00
Fedor Korotkov 7360b62106 Adjusted disk sizes for macOS Tahoe configurations in CI setup. 2026-04-05 12:35:16 -04:00
Fedor Korotkov e46673151d
Xcode 26.5-beta (#345)
* Xcode 26.5-beta

* Fixed syntax error in Xcode versions list for Tahoe configuration.

* Updated Tahoe runtimes to include Xcode 26.5 beta versions

* Updated Tahoe runtimes to include Xcode 26.5 beta versions
2026-04-04 20:30:07 -04:00
Jacob Rhoda 5e65e3e712
Update Android SDK tools version and dependencies (#343)
Updated Android SDK tools versions to reflect most up-to-date default versions used by the Android gradle plugin (9.1.0)

- Platform: 36
- Build Tools: 36.0.0
- NDK: 28.2.13676358
2026-03-26 15:40:01 -04:00
Fedor Korotkov 5cf26631b9
macOS & Xcode 26.4 (#340)
* macOS & Xcode 26.4

* No Sonoma runner image

* Updated Tahoe tvOS 26.4 runtime to release version 23L243
2026-03-24 21:26:24 -04:00
Fedor Korotkov 0d8fe3156a
Xcode 26.4 RC (#337)
* Xcode 16.4 RC

* Updated disk size for Sonoma CI runner and Tahoe runtimes to final Xcode 26.4 release versions.
2026-03-21 08:07:50 -04:00
Fedor Korotkov 69866eb29b
Xcode 26.4 Beta 3 (#332)
* Xcode 26.4 Beta 3

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Removed iOS 26.2 from Tahoe runtimes list
2026-03-15 16:32:38 -04:00
Nikolay Edigaryev f2e700cda3
xcode.pkr.hcl: increase disk size from 120 to 140 GB (#333) 2026-03-15 13:08:44 -04:00
Nikolay Edigaryev 494e62f0b8
Disable SIP before running templates/base.pkr.hcl (#331)
* Disable SIP before running templates/base.pkr.hcl

* Don't forget to "packer init" before each "packer build"
2026-03-15 10:46:21 +01:00
Nikolay Edigaryev 27def7c5ce
Prevent an array with empty element when XCODE_COMPONENTS is unset (#330) 2026-03-13 17:23:50 -04:00
Nikolay Edigaryev f9c2b3c122
base.pkr.hcl: update TCC.db and allow automation tools (#329) 2026-03-12 13:01:54 +01:00
Fedor Korotkov 7132d10945
Xcode 26.3 Release (#326) 2026-02-26 16:03:56 -05:00
Fedor Korotkov 33e373e65b
Xcode 26.4 Beta 2 (#325)
* Xcode 26.4 Beta 2

* Updated Tahoe runtimes to latest Xcode 26.4 release versions
2026-02-23 19:52:43 -05:00
Fedor Korotkov cfa9e2361c
Xcode 26.3 RC 2 (#324)
* Xcode 26.3 RC 2

* Increase DISK_SIZE from 230 to 240
2026-02-21 08:08:10 -05:00
Fedor Korotkov 09fce08792
Xcode 26.4 Beta (#323)
* Xcode 26.4 Beta

* Updated Tahoe runtimes to Xcode 26.4 Beta versions
2026-02-17 07:00:35 -05:00
Fedor Korotkov 01365193b9
Updated Tahoe template to use macOS 26.3 restore image. (#322)
Fixes #321
2026-02-13 16:20:18 +01:00
Fedor Korotkov 1414d3bf4b
Added Buildkite agent installation to base Packer template. (#320) 2026-02-05 06:56:38 -05:00
Fedor Korotkov fbaec2adaa
Xcode 26.3 RC (#319)
* Xcode 26.3 RC

* Removed unavailable runtimes from Tahoe list.
2026-02-04 10:13:22 -05:00
Fedor Korotkov f47f8bf08c Added rbenv 3.3.10 installation to address Fastlane compatibility in Xcode packer template. 2026-01-10 18:16:37 +01:00
Fedor Korotkov d56bd82e5d Refined Tuist installation steps in Xcode packer template. 2026-01-10 11:47:22 +01:00
Nikolay Edigaryev 4b95c2c93f
Use the new <click 'Select Your Country or Region'> command (#317) 2025-12-16 21:02:14 +01:00
Fedor Korotkov 75924563a8 Updated macOS restore image comments for Sequoia 15.7.2 and Sonoma 14.8.2 2025-12-16 09:35:29 -05:00
Nikolay Edigaryev f3319b8eb8
Revert "Remove explicit FileVault step from Packer boot command for macOS 26.1 compatibility (#305)" (#316) 2025-12-15 19:07:52 -05:00
Fedor Korotkov 5ee829f2c8
macOS Tahoe 26.2 (#315) 2025-12-15 08:55:32 -05:00
Fedor Korotkov 64d9651dca
Upgrade Node.js installation from version 20 to 24 (#314)
20 is retiring https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
2025-12-15 08:54:13 -05:00
Fedor Korotkov 0682bdb108
Xcode 26.2 (#313)
* Xcode 26.2

* Corrected Xcode version to 26.1.1 in Cirrus config.

* Updated Tahoe runtime build number for iOS 26.2.
2025-12-13 10:30:58 -05:00
Fedor Korotkov 3abe5ef330 Fixed syntax 2025-12-06 17:44:39 -05:00
Fedor Korotkov 36c1f1d9b7 Updated Tahoe runtimes to Xcode 26.2 release versions 2025-12-05 16:30:31 -05:00
Fedor Korotkov 413eb891fe Xcode 26.2 RC 2025-12-05 16:30:31 -05:00
Dominik Abilio de Jesus Moreira be895f2507
Fix Gatekeeper disable step in boot command (#311)
Added the missing "tab" command in the "Disable GateKeeper (2/2)" section. Without this command, Gatekeeper was not fully disabled, causing the provisioner check to fail when verifying that Gatekeeper is disabled.

Co-authored-by: Dominik Wunderlich <dominik.wunderlich@teamviewer.com>
2025-12-05 14:42:22 +01:00
Fedor Korotkov 9115ef2553 Increase DISK_SIZE from 290 to 300 2025-11-22 11:36:44 -05:00
Fedor Korotkov 11b22ea0d0
Preinstall common AI agents (#308)
So it's possible to automate things within VMs.
2025-11-20 12:24:31 -05:00
Fedor Korotkov 062ecd3e0e
Xcode 26.2 Beta 2 (#307)
* Xcode 26.2 Beta 2

Plus wait for simulators to become available.

* Update expected runtimes for Xcode 26.2 Beta 2

* Try to wait an hour

* Cleanup LLM generated script

* Add `exex-script.pkr.hcl` template and adjust simulator wait logic

* Finalize

* Fixed script name

* Fixed typo

* Use scrript option.
2025-11-20 10:16:45 -05:00
Fedor Korotkov 329c3e137e
Add iOS 18.6 runtime to Tahoe (#306)
* Add iOS 18.7.2 runtime to Tahoe

* 18.6

* Updated expected runtimes

* Bump disk
2025-11-14 11:35:52 -05:00
Dominik Wunderlich e681fe0983
Remove explicit FileVault step from Packer boot command for macOS 26.1 compatibility (#305)
Remove the explicit FileVault step from the Packer boot command sequence used during macOS setup.
In macOS 26.1, the FileVault setup screen no longer appears consistently during initial setup because FileVault encryption is now automatically handled via system defaults, Apple ID, or MDM profiles.
This change prevents script failure or waiting on a missing UI prompt.
2025-11-13 19:57:38 +04:00
Fedor Korotkov 2e6e2dfb6e Removed redundant `xcodes version` command in provisioner 2025-11-12 20:23:10 -05:00
Fedor Korotkov 0652373c8c Updated simulator 2025-11-12 20:21:25 -05:00
Fedor Korotkov 082799eb6f
Fixed Xcodes installation (#304)
* Fixed Xcodes installation

* Removed redundant execution lock from Cirrus runner configuration
2025-11-12 19:14:44 -05:00
Fedor Korotkov 3b47c8dfc6 Revert GitHub Actions Runner compatibility provisioner changes 2025-11-12 19:00:34 -05:00
Fedor Korotkov 69ed3fe0fa
Xcode 26.1.1 (#302)
* Xcode 26.1.1

* Proper literal

* Install prebuilt binary for xcodes

* split

* Revert "split"

This reverts commit 8a0363fe31.

* Fix xcodes installation and update file ownership logic

* echo path

* Use full path

* revert chmod
2025-11-12 18:18:51 -05:00
Fedor Korotkov 256b8cc1c8
Restart VM while building Xcode variant (#301)
* Restart VM while building Xcode variant

In an attempt to make https://github.com/actions/runner-images/issues/12948 less flaky. Xcode Release Notes at some point mentioend a first boot for another issue so let's make the VM boot twoce and do caching population just to be extra cautios.

* just `xcrun simctl list -v`

* support sonoma
2025-11-11 18:10:42 -05:00
Fedor Korotkov d7752dd971
Xcode 26.1 Release and 26.2 Beta (#298)
* Xcode 26.1 Release and 26.2 Beta

Plus installed tvOS 17.5 on Sequoia runner

* Update .ci/cirrus.runner.yml

Co-authored-by: Christoph Aldrian <caldrian@users.noreply.github.com>

* Updated expected runtimes

* Bump disk for Tahoe

* install `otel-cli`

---------

Co-authored-by: Christoph Aldrian <caldrian@users.noreply.github.com>
2025-11-08 09:26:25 -05:00
Fedor Korotkov 64b8b7407b macOS Tahoe 26.1 2025-11-04 08:44:11 -05:00
Fedor Korotkov 91c8fbf624 Do not auto-update Ventura 2025-11-01 12:01:55 -04:00
Fedor Korotkov aec76f172d Ruby 3.3.10 2025-11-01 12:00:49 -04:00
Fedor Korotkov a2b4e1ebfe
Xcode 26.1-rc (#297)
* Xcode 26.1-rc

* Updated simulators
2025-11-01 10:41:03 -04:00
Fedor Korotkov 1f481f72c7
Xcode 26 Beta 3 (#296)
* Xcode 26 Beta 3

* Updated expected runtimes

* Removed iOS 26 due to

> iOS 26 is not available for download.

Seems only 26.0.1 is available.
2025-10-25 10:57:45 -04:00
Fedor Korotkov 463004bc84
Xcode 26 Beta 2 (#291)
* Xcode 26 Beta 2

* Updated expected runtimes

* new line
2025-10-10 12:27:20 -04:00
Fedor Korotkov 6755f3d245
Removed update (#293) 2025-10-10 20:25:46 +04:00
Nikolay Edigaryev aa8af495d1
README.md: update image descriptions (#289)
* README.md: update image descriptions

* Proper Xcode spelling
2025-09-29 15:57:11 +04:00
Fedor Korotkov 4232c64336
Remove asdf installation from base image (#290) 2025-09-29 07:44:04 -04:00
Fedor Korotkov f4565a71c7
Xcode 26.1 Beta (#286)
* Xcode 26.1 Beta

* Updated runtimes

* Bump disk
2025-09-26 10:33:06 -04:00
Fedor Korotkov 971a78c341
Xcode 16 on Sonoma (#287)
* Xcode 16 on Sonoma

* Updated runtimes

* Bump disk
2025-09-26 08:00:13 -04:00
Jakub Olejník 4f13a88f28
Use Terminal to open System settings on Tahoe (#283) 2025-09-25 21:04:19 +04:00
Fedor Korotkov ba783a5bc7
Xcode 26.0.1 (#285)
* Xcode 26.0.1

* Update .ci/cirrus.runner.yml

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>

* Fixed build

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2025-09-25 09:10:25 -04:00
Fedor Korotkov db71c44bc1 Fixed syntax 2025-09-20 09:45:23 +02:00
Fedor Korotkov 5ed6926ec7 Fixed syntax 2025-09-20 09:40:41 +02:00
Fedor Korotkov 95ee5a5656
Pre-install asdf and mise (#284)
* Pre-install asdf

* Install mise
2025-09-19 06:30:06 -04:00
Fedor Korotkov ea02816fa7
Xcode 26 Release (#281)
* Xcode 26 Release

Make it default for Sequoia runner.

* Update .ci/cirrus.runner.yml

Co-authored-by: Matouš Skála <skala.matous@gmail.com>

* Updated 23R353

* Update .ci/cirrus.runner.yml

Co-authored-by: Aleš Hanžlík <hanzlikale@gmail.com>

---------

Co-authored-by: Matouš Skála <skala.matous@gmail.com>
Co-authored-by: Aleš Hanžlík <hanzlikale@gmail.com>
2025-09-16 15:21:27 -04:00
Tony Arnold e6a57fc713
iOS Simulator Runtime 23A343 (#280) 2025-09-16 08:00:35 -04:00
Fedor Korotkov 17dc1dab05
Bumped all vanillas (#279) 2025-09-16 07:26:04 -04:00
Fedor Korotkov b86acf6821
No need to update Tahoe 2025-09-12 16:56:43 -04:00
Fedor Korotkov 537b590859
Tahoe runner (#278) 2025-09-11 22:10:21 -04:00
Fedor Korotkov 45c214692c
Xcode 26 RC (#276)
* Xcode 26 RC

* Updated expected list
2025-09-09 17:33:00 -04:00
Fedor Korotkov b94738812f Fixed components 2025-09-07 14:32:40 -04:00
Fedor Korotkov 2d4e5b9968
macOS 26.0 beta 9 2025-09-02 15:07:24 -04:00
Fedor Korotkov 24607711dc
Include XCODE_COMPONENTS on release cuts (#272)
* Include XCODE_COMPONENTS on release cuts

Fixes https://github.com/cirruslabs/macos-image-templates/issues/264#issuecomment-3242673167

* -var xcode_components
2025-09-01 12:01:22 -04:00
Nikolay Edigaryev 081c8ac4e3
vanilla-tahoe.pkr.hcl: adapt "boot_command" to recent installer changes (#271) 2025-08-29 11:15:40 -04:00
Fedor Korotkov d0f94cc4c8
Xcode 26 Beta 7 and macOS 26.0 beta 8 (#270)
* Xcode 26 Beta 7 and macOS 26.0 beta 8

* fixed syntax
2025-08-29 10:47:35 -04:00
Tony Arnold fe19dc9f17
Install Metal toolchain for Xcode 26 and newer (#268)
* Install Metal toolchain when Xcode version is 26 or newer

* Define a variable rather than using a regex

* Provide the Xcode components as a list

* Use “shell” rather than “provisioner”

* Update .ci/cirrus.xcode.yml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-26 08:05:50 -04:00
Nikolay Edigaryev 6f8ae07451
Disable SIP on "-base" and "-xcode" images only (#269)
* Disable SIP on "-base" and "-xcode" images only

* Ventura needs DISABLE_SIP_TEMPLATE too
2025-08-26 00:17:00 +04:00
Fedor Korotkov 16a5100187
macOS Sequoia 15.6.1 (#267) 2025-08-20 15:45:07 -04:00
Fedor Korotkov 7058092d82
Xcode 26 Beta 6 and other updates (#266)
Related to #265
2025-08-20 14:08:27 -04:00
Fedor Korotkov 0d3b4f4efd
Update latest betas (#259)
* Latest betas

* Ruby 3.3.9

* Updated simulators

* New line
2025-08-09 07:17:50 -04:00
Nikolay Edigaryev aad3ba254d
vanilla-sequoia.pkr.hcl: upgrade IPSW from 15.5 to 15.6 (#261) 2025-08-07 06:32:08 -04:00
Nikolay Edigaryev 0c0a90071d
vanilla-sonoma.pkr.hcl: use macOS Sonoma IPSW instead of Sequoia IPSW (#260) 2025-08-07 05:38:29 -04:00
Fedor Korotkov 276b6dde65
Include SwiftLint version in `.setup_info` (#258) 2025-08-04 12:27:24 -04:00
Fedor Korotkov 5e8c823ef0
Install all iOS packages after Xcode installation 2025-08-02 05:05:49 -04:00
Fedor Korotkov b6445b9d3a
Xcode 26 Beta 4 (#256)
* Xcode 26 Beta 4

* Updated simulators

* Updated simulators

* Fixes after CI

* New line

* bring back 18.5

* bump disk
2025-08-02 04:48:25 -04:00
Fedor Korotkov ad9ce34d12
Install additional common packages (#257) 2025-08-01 15:14:46 -04:00
Fedor Korotkov 9746337eeb
Sonoma 15.6 2025-07-29 17:08:48 -04:00
Fedor Korotkov f7880705ec
All simulators for the last 3 versions of Xcode (#254) 2025-07-23 16:44:14 -04:00
Fedor Korotkov bc67673068
Update cirrus.runner.yml 2025-07-14 16:17:41 -04:00
Fedor Korotkov 393d7c615b
Sonoma Xcode 15.4 (#253)
* Sonoma Xcode 15.4

* More disk

* watchOS 10.5 on sonoma

* Removed watchOS
2025-07-14 15:38:02 -04:00
Fedor Korotkov f292033e59 Fixed index out of bound 2025-07-14 14:43:21 -04:00
Fedor Korotkov e3cf995511
Xcode 26 Beta 3 (#251)
* Xcode 26 Beta 3

* Print disk sizes between Xcodes

* Tweak sizes

* Strip some simulators

* 17.5 for sonoma

* fixed expected runtimes

* Tweaked disk sizes
2025-07-11 15:01:42 -04:00
James Smith 3c3581a46f
Update image to macOS 26 beta 3 (#250) 2025-07-08 00:45:56 -04:00
Fedor Korotkov 2fbdfd6186 Beta 1 runtimes 2025-07-07 08:14:11 +04:00
Fedor Korotkov a806b2d4ef Reverted to 26-beta 2025-07-07 08:09:46 +04:00
Fedor Korotkov c48cab887b Reverted to 26-beta-1 2025-07-07 08:06:34 +04:00
Fedor Korotkov d5d126deaa Revert "Updated runtimes"
This reverts commit ac6cbef9a6.
2025-07-07 08:06:28 +04:00
fedor ac6cbef9a6 Updated runtimes 2025-06-29 06:54:08 -07:00
Fedor Korotkov 9736671744
Xcode 26 Beta 2 (#249)
* Xcode 26 Beta 2

* Updated runtimes
2025-06-28 16:25:56 -07:00
Fedor Korotkov 2ec40d16cb
macOS Tahoe Beta 2 (#248) 2025-06-24 10:39:45 -04:00
Nikolay Edigaryev ce496aa3ad
Increase timeouts before "Select Your Country or Region" (#247)
...and "Welcome to Mac" screens.
2025-06-16 09:34:15 -04:00
fedor 660eac6ae0 Removed brew doctor
Because of Tahoe
2025-06-12 21:45:23 -07:00
fedor 530036c1bc Trigger vanilla 2025-06-12 18:05:15 -07:00
Fedor Korotkov 69ca3f729a
Build `base`/`xcode`/`runner` variants for Tahoe (#245) 2025-06-12 16:23:41 -07:00
Nikolay Edigaryev e70eea50c4
Automated macOS 26 (Tahoe) installation (#244)
* Automated macOS 26 (Tahoe) installation

* Support "Command Line Tools beta  for Xcode-26.0" label

* account for "beta"
* preserve multiple spaces

* .ci/cirrus.vanilla.yml: add "MACOS_VERSION: tahoe"

* Disable SIP for Tahoe
2025-06-12 10:16:46 -07:00
Nikolay Edigaryev 3ac0f46b3e
tart-guest-agent: specify TERM and set working directory to HOME (#243) 2025-06-12 00:08:06 +04:00
Fedor Korotkov 63e44895a7 New line 2025-06-09 16:27:39 -07:00
Fedor Korotkov c1d543be58
Xcode 26 beta (#241)
* Xcode 26 beta

* Updated Runtimes
2025-06-09 14:52:00 -07:00
fedor ca553f0b1d Fixed syntax 2025-05-31 10:50:39 -04:00
fedor b9ffc31440 Build runners on release 2025-05-31 10:48:36 -04:00
Fedor Korotkov 0b4954f232
Pre install `swiftformat` (#239) 2025-05-30 17:47:05 -04:00
Fedor Korotkov f2d0330eec
Xcode 16.4 (#238) 2025-05-29 09:01:24 -04:00
Nikolay Edigaryev 6ae3ffd75f
Tart Guest Agent: use component groups (#237) 2025-05-19 14:26:23 -04:00
fedor 64f4871059 400GB for runners 2025-05-18 09:56:13 -04:00
fedor 5f35113643 new line 2025-05-18 08:27:39 -04:00
fedor 9ec94173b3 Updated expected runtimes 2025-05-17 17:38:59 -04:00
fedor 0eafad7bcf Xcode 16.4-rc 2025-05-15 17:38:28 -04:00
Nikolay Edigaryev 1fd4c5e3ae
xcode.pkr.hcl: increase default disk size from 100 to 120 GB (#235) 2025-05-13 15:23:45 +04:00
Fedor Korotkov cfed2eac90
macOS Sequoia 15.5 2025-05-12 15:49:46 -04:00
Nikolay Edigaryev 7be8facd36
Use separate log file for tart-guest-daemon (#234)
* Use separate log file for tart-guest-daemon

* Add /usr/sbin to PATH
2025-05-12 16:41:35 +04:00
fedor 6f66644628 Bring back iOS 17.5 2025-05-05 06:23:49 -04:00
fedor 2401e19f34 Updated runners push logic 2025-05-04 09:03:34 -04:00
Fedor Korotkov 1a09db706a
Xcode 16.4-beta (#233) 2025-05-04 08:21:46 -04:00
Nikolay Edigaryev 99ef3f49c7
Split Tart Guest Agent invocations into daemon and agent variants (#232)
* Split Tart Guest Agent invocations into daemon and agent variants

* Write logs to /tmp, otherwise there are permission issues

* Correct use of ProgramArguments
2025-04-29 21:34:41 +04:00
Fedor Korotkov 7d267ec27b
macOS 15.4.1 2025-04-23 18:02:50 -04:00
Fedor Korotkov 7dc9dd706d
Add Xcode versions to `.setup_info` (#231) 2025-04-14 10:29:44 -04:00
Fedor Korotkov 6a21d56c86
Install fastlane via bundler (#228)
As recommended by docs and since we have newer Ruby version from rbenv
2025-04-08 11:09:50 -04:00
fedor f64d712020 Include Bundler Version 2025-04-07 17:50:58 -04:00
Nikolay Edigaryev 7b41df79bd
base.pkr.hcl: install guest agent for Tart VMs (#227)
* base.pkr.hcl: install guest agent for Tart VMs

* Don't forget to "source ~/.zprofile" to have "brew" available
2025-04-08 00:03:09 +04:00
fedor bf4ddcee86 Update only Xcode 16+ 2025-04-06 19:55:53 -04:00
fedor 56a1ec662e Updated runtimes 2025-04-04 20:07:12 -04:00
fedor 1b15ebd8b2 Fixed format 2025-04-04 16:30:35 -04:00
fedor 1271f59338 Check runtimes 2025-04-04 15:31:46 -04:00
Stefan Mitterrutzner 3c4bbd340d
swich to Xcode 16.3 release (#225) 2025-04-04 15:19:25 -04:00
Nikolay Edigaryev 92a5e245cc
Adapt disable-sip.pkr.hcl for new "csrutil" version in macOS Sequoia (#226) 2025-04-02 00:25:01 +02:00
Nikolay Edigaryev ec6a446fc1
Support macOS Sequoia 15.4 (#224)
* Support macOS Sequoia 15.4

* Navigate to "Sharing" and "Privacy & Security" through menu bar

System Settings's search box does not always work as intended.

* Choose "Only Download Automatically"

* Use "Managed via Tart" full user name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* Use "Managed via Tart" user full name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* macOS 15.4 RC 2

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

* Use macOS 15.4 release IPSW

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>
Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>
2025-03-31 22:34:07 +04:00
Nikolay Edigaryev 4206908127
vanilla-sequoia.pkr.hcl: disable Gatekeeper (#220)
* vanilla-sequoia.pkr.hcl: disable Gatekeeper

* Don't forget to enter sudo password

Since passwordless sudo is not yet enabled at this point.
2025-03-21 22:54:15 +04:00
fedor d42ba4a1e1 Additional iOS builds 2025-03-11 03:01:50 +04:00
fedor 005b272792 Additional iOS 18.2 runtime
Related https://github.com/cirruslabs/macos-image-templates/issues/219#issuecomment-2709774915
2025-03-10 19:51:22 +04:00
fedor ec0c478a02 Escape runtime 2025-03-10 14:07:10 +04:00
Fedor Korotkov ad419122b2
Bump disk size 2025-03-09 12:35:45 +04:00
fedor 2335029721 Xcode 16.3-beta-2 2025-03-08 14:41:16 +04:00
Sergio Pinheiro c3819d6d35
Fix syntax issue (#218) 2025-03-03 22:16:25 +04:00
Fedor Korotkov 1f9fdd5630 Xcode 16.3-beta-1 2025-02-21 15:15:56 -08:00
Fedor Korotkov 447a46c522
Integrate `.setup_info` tool (#216)
I generate the tool from the specs a few weeks ago using AI. This PR also is generated fully using AI.
2025-02-17 08:42:28 -08:00
Nikolay Edigaryev 345b223e76
Resolve the version of the VM image just built, not the one in the OCI (#217) 2025-02-16 20:28:00 +04:00
Nikolay Edigaryev 5f66cb1ca2
Use "-productVersion" instead of "--productVersion" to support Monterey (#215)
* Use "-productVersion" instead of "--productVersion" to support Monterey

* No need to relocate anything as we're starting from scratch (IPSW)
2025-02-16 01:03:05 +04:00
Nikolay Edigaryev 0542253d49
Ignore errors for "install available update" Ansible task (#213)
* Ignore errors for "install available update" Ansible task

* Do not fail when update_result is not defined
2025-02-13 17:07:58 -05:00
Nikolay Edigaryev cdc53f0a12
vanilla-monterey.pkr.hcl: remove duplicate extra_arguments (#212) 2025-02-12 18:39:37 +04:00
Nikolay Edigaryev 99e619e634
Increase vanilla VM images disk size from 40 to 50 GB and use "relocate" (#211) 2025-02-12 18:09:39 +04:00
Nikolay Edigaryev 946adbfc95
Use single instead of double quotes to avoid YAML syntax error (#210) 2025-02-12 03:39:32 +04:00
Nikolay Edigaryev e134909aa8
Provide a default when stdinpass variable is not set (#209) 2025-02-12 02:12:06 +04:00
Nikolay Edigaryev 998bbf8ca8
Parse available updates to avoid upgrading to the next macOS version (#208)
* Parse available updates to avoid upgrading to the next macOS version

* Do not override ANSIBLE_CONFIG with our ansible.cfg

Otherwise Packer + Ansible integration goes haywire.

Instead, only modify the required variables through ansible_env_vars.

* Support Monterey
2025-02-12 01:45:40 +04:00
Nikolay Edigaryev 5a55351c81
Use xargs fix for all vanilla images, not just Sequoia (#207) 2025-02-06 18:55:36 +04:00
Nikolay Edigaryev 64b1190f65
Only pass a single item to "softwareupdate --install" each time (#206) 2025-02-06 17:39:40 +04:00
Nikolay Edigaryev 4df29efc66
Run "softwareupdate" on vanilla images (#204)
* Run "softwareupdate" on vanilla images

* Install Command Line Tools for Xcode

* Run Ansible after password-less sudo is configured

* Don't use SFTP

* Fix Ansible playbook path

* No updates are available → No new software available

* stderr_lines → stderr

* Dynamically resolve MACOS_NUMBER
2025-02-01 01:23:11 +04:00
Fedor Korotkov b205e70322
macOS Sequoia 15.3 (#205) 2025-01-27 14:38:08 -05:00
Nikolay Edigaryev c18ef9c553
Use Slack workflows (#201)
* Use Slack workflows

* Use SLACK_WEBHOOK_URL
2025-01-14 23:47:30 +04:00
fedor cec270adb3 No software updates 2025-01-06 17:54:53 -05:00
fedor 6d14eaee8c Install recommended updates 2025-01-06 17:36:50 -05:00
Fedor Korotkov f1a9e22ed2
Fixed known host creation (#202)
`~/.ssh` should exist for `file` provisioner.
2025-01-06 14:35:10 -05:00
Fedor Korotkov 2545826772
Add github.com keys to `~/.ssh/known_hosts` (#200)
* Add github.com keys to `~/.ssh/known_hosts`

* Static known hosts

* Fixed path
2025-01-06 09:54:14 -05:00
fedor 0b49ba6651 Xcode 16.2 2024-12-30 09:29:55 -05:00
jxlwqq e5474440fc
Sequoia 15.2 (#199) 2024-12-28 05:31:37 -05:00
Nikolay Edigaryev 0c165a93d2
Compatibility with GitHub Actions Runner Images for /usr/local/bin (#198) 2024-12-11 19:56:48 +04:00
fedor d3ad77c873 Xcode 16.2 RC 2024-12-05 16:06:21 -05:00
Kevin M. Cox 40128d40e2
Update vanilla-sequoia.pkr.hcl (#196)
It looks like the tab sequence for the Time Zone screen changed in one of the releases after 15.0.

I've testing this key sequence manually and via a packer build and it works with macOS 15.1.1.
2024-12-05 01:27:54 +04:00
Fedor Korotkov 7920f0cda2
Include Xcode 15.1 in Somoma runner (#197)
We unintentionally pushed Xcode 16.1 variant for `sonoma-xcode` image. We plan to only include new versions of Xcode with Sequoia images.

Instead for removing the 16.1 artifact. Let's include it in the runner image for consistency.
2024-12-04 16:08:58 -05:00
Fedor Korotkov b3b4dafc83
Update cirrus.release.yml 2024-12-04 11:36:28 -05:00
fedor ae70c6052d Ignore curl failure 2024-11-26 10:18:40 -05:00
fedor 1ea5f77e35 Build Monterey 2024-11-26 09:02:31 -05:00
fedor 8392fd1b30 Xcode 16.2 Beta 3 2024-11-20 16:04:50 -05:00
Fedor Korotkov fdff7d8daf
Sequoia 15.1.1 2024-11-19 22:15:26 -05:00
Michal Moczulski 6a01707630
Update Android dependencies (#195)
* Use latest stable versions of Android dependencies

* Fix link to Android command line tools
2024-11-13 09:05:09 -05:00
fedor 49718082b2 Updated disk sizes 2024-11-13 07:09:41 -05:00
Nikolay Edigaryev 5b17f4e264
Wait 30 minutes instead of 15 (#194)
Just to be sure.
2024-11-12 21:29:32 +04:00
Nikolay Edigaryev 14fb85f5b3
Disable apsd daemon and wait before shutting down (#193) 2024-11-12 21:26:35 +04:00
fedor c8a1e808b6 Xcode 16.2 Beta 2 2024-11-06 10:50:07 -05:00
Fedor Korotkov 8c1f0c213f
Release Sequoia IPSW
Fixes #192
2024-11-04 13:43:48 -05:00
Fedor Korotkov 9875d24c4b
Added 15.1 and 15.0.1 2024-11-03 22:37:22 -05:00
fedor 8425f62a71 Update one runner image at a time
So while the second one is building runners can download the first one.
2024-11-02 09:49:05 -04:00
fedor 7ebaf88c48 Include {15.1,15.0.1} into runner 2024-11-01 11:51:50 -04:00
fedor 639b46cb2f Update sonoma-xcode:{15.1,15.0.1} 2024-11-01 11:26:11 -04:00
fedor 77cc104d6d Updated release cadence to highlight supported Xcode version. 2024-10-31 15:55:48 -04:00
fedor 159d4c1c36 Xcode 16.1 2024-10-30 10:19:34 -07:00
fedor 2a0a476e3b Sequoia 15.1 2024-10-28 09:19:43 -07:00
fedor 74040f6870 Sort Xcodes to always install the freshest first
Seems it's leading to things like:

> Unable to connect to simulator.
2024-10-27 08:42:58 -07:00
fedor 9f061dacb4 Sort Xcodes to always install the freshest first
Seems it's leading to things like:

> Unable to connect to simulator.
2024-10-27 08:38:03 -07:00
Fedor Korotkov f8fd129df6
Xcode 16.2 Beta 1 2024-10-24 09:14:43 -07:00
fedor 80bedb81db Xcode 16.1 RC 2024-10-21 17:14:35 -04:00
fedor 7692f27396 Sequoia 15.1 RC 2024-10-21 17:10:02 -04:00
fedor 2bd3a78831 Quotes 2024-10-21 09:59:00 -04:00
fedor 39e0ccf2e4 Fixed command 2024-10-21 08:55:41 -04:00
fedor e3cad7e8c2 Reverse Xcode installation order 2024-10-21 07:21:43 -04:00
fedor 47f36a33f8 Retry downloads 2024-10-20 16:19:19 -04:00
fedor c198ef9957 Removed ADDITIONAL_RUNTIMES 2024-10-20 16:16:20 -04:00
fedor d038ed85d2 no only_if 2024-10-20 13:05:03 -04:00
fedor da102cc5e6 Additional runtimes 2024-10-20 12:36:59 -04:00
fedor b0520dfd1d Fixed empty runtimes 2024-10-20 11:27:03 -04:00
fedor 37c77845c8 Refactored release scripts 2024-10-19 11:14:07 -04:00
fedor 9a16028831 No additional_runtimes 2024-10-15 14:42:06 -04:00
fedor cd817762c5 Xcode 16.1 Beta 3 2024-10-15 14:40:31 -04:00
fedor 32c59db145 No additional runtimes 2024-10-06 20:44:48 -04:00
fedor 8dcd824d76 Default for additional_runtimes 2024-10-05 20:27:36 -04:00
Fedor Korotkov 200bc65efb
Update vanilla-sequoia.pkr.hcl 2024-10-05 20:26:00 -04:00
Nikolay Edigaryev 74aca70ef6
Send Slack alerts on build failures (#189)
* Send Slack alerts on build failures

* Only send Slack notifications for failed cron builds
2024-10-01 14:54:02 -04:00
Fedor Korotkov 1e710b24b9
Pre-install `gnupg` (#188)
Useful for doing manual encription/decryption
2024-10-01 10:42:25 -04:00
Fedor Korotkov 26c6575d1c
Add additional runtimes (#186) 2024-09-26 06:21:40 -04:00
Fedor Korotkov 63e491fbf8
Fixed version 2024-09-24 10:39:24 -04:00
Fedor Korotkov 600cb89e35
Start building Sequoia images (#184)
Only base the runner images. We are not planning to build per Xcode images to reduce amount of variants to support.

Related to #183
2024-09-19 10:45:24 -04:00
fedor dbde34c6a8 Reapply "Sonoma 14.6.1 (#170)" (#179)
This reverts commit 760e04e340.
2024-09-18 17:55:42 -07:00
Fedor Korotkov ef6d97a77e
Build more images (#178)
Build Sequoia 15.0 and 15.1 separately since 15.0 is RC and about ot be released and 15.1 is still in beta.

Plus added Xcode 16 RC to the big runner image. But since it's RC put it first in the list so it's not default.
2024-09-10 10:18:11 -04:00
Fedor Korotkov 760e04e340
Revert "Sonoma 14.6.1 (#170)" (#179) 2024-09-10 08:39:26 -04:00
Nikolay Edigaryev b863116992
macOS Sequoia 15.1 beta 3 (#175)
* macOS Sequoia 15.1 beta 3

* No need to disable Voice Over
2024-09-09 14:57:03 +04:00
Isaac Halvorson 444b21aba2
Use Keyboard navigation instead of Voice Over for System Settings navigation (#174)
* Enable Keyboard navigation setting instead of using Voice Over for System Settings

* Only use space bar to get past final setup screen

* Remove unnecessary setdisplaysleep and setcomputersleep usage
2024-09-09 11:58:39 +04:00
fedor 525f51a54e macOS 15 beta 8 2024-08-31 09:44:45 -04:00
fedor 5c7259d9a9 Sequoia 15 Beta 5
And build on Sonoma
2024-08-23 13:00:23 -04:00
Fedor Korotkov 24ff639c4d
Update .cirrus.yml
Don't build runner on beta
2024-08-12 16:06:31 -04:00
Fedor Korotkov 0be36e7056
Update .cirrus.yml 2024-08-12 15:31:28 -04:00
Fedor Korotkov ed0b1e4c15
sequoia 15.1 beta 2 2024-08-12 15:30:03 -04:00
Fedor Korotkov 489255bec4
Sonoma 14.6.1 (#170) 2024-08-07 14:12:46 -04:00
fedor 92c70a2e79 Proper Tags 2024-07-30 15:22:35 -04:00
fedor 5de5e0997b Sonoma 14.6 and Sequoia 15.1 2024-07-30 15:21:21 -04:00
Fedor Korotkov 127683c285
Sequoia Beta 3 (#166) 2024-07-11 09:36:31 -04:00
leavesster 98a8ed97a4
Update README.md (#165) 2024-07-05 22:06:22 -04:00
Fedor Korotkov 3d76cfe25e
Do not use Sequoia hosts
Fixes https://github.com/cirruslabs/tart/issues/851
2024-07-01 11:31:47 -04:00
Fedor Korotkov 4a45e89e9f
Update .cirrus.yml 2024-06-28 15:34:57 -04:00
Fedor Korotkov f887c42ab1
Don't use experimental yet 2024-06-28 15:20:03 -04:00
Fedor Korotkov cabda00d2a
Sequoia Beta 2 (#164) 2024-06-24 15:45:08 -04:00
Fedor Korotkov 118270dd45
Use `dev-mini-experimental` for Sequoia images (#163) 2024-06-24 09:09:43 -04:00
fedor c80a91a5bf Longer SSH timeout 2024-06-17 16:14:12 -04:00
fedor da6beb5b44 Account for an extra screen and long user creation 2024-06-17 15:44:35 -04:00
Fedor Korotkov 7a36c811f9
macOS Sequoia (#161)
* macOS Sequoia

* Sequoia cadence and base/xcode variants
2024-06-17 10:56:57 -04:00
Fedor Korotkov 07be5a66be
Update xcode.pkr.hcl 2024-06-10 16:42:24 -04:00
Fedor Korotkov 61f4dee507
Guarantee `runner` variant to have 100GB free disk space (#159)
Some of the clients require it and hence we use sparsed files it won't be actually 250GB images.
2024-06-05 08:37:35 -04:00
Fedor Korotkov fbcbf4cbfe
Align Xcode location with GHA images (#157) 2024-05-17 16:59:24 -04:00
Fedor Korotkov c90679131d
Install `yq` (#156)
fixes #155
2024-05-16 11:21:21 -04:00
Fedor Korotkov c9a92d7a31
Bump runner disk size
Due to all three latest Xcode have different version of simulators
2024-05-14 06:14:33 -04:00
Fedor Korotkov 2793f40e9a
Xcode 15.4 (#154)
* Xcode 15.4

* Build runner on a release
2024-05-13 15:18:50 -04:00
Fedor Korotkov 7a7778be0f
macOS 14.5 (#153) 2024-05-13 14:47:27 -04:00
Fedor Korotkov 6f7ef84825
Make sure `/Users/runner` exists in `xcode` variant (#152)
A follow-up to #145. It seems right now only base variant preserves the symlink. `xcode` and `runner` are missing it and my guess it's due to disk resizing.

This change adds a validation script, so we verify `/Users/runner` folder exists in every variant.
2024-05-13 07:56:29 -04:00
Fedor Korotkov d594e1add0
Install Git Credentials Helper and xcpretty/xcbeauty (#150)
* Install Git Credentials Helper and xcpretty/xcbeauty

Plus move rosetta installation and some other common packages into base variant.

* Fixed Node Path
2024-05-07 15:57:00 -04:00
Fedor Korotkov d50adeeaa2
Use latest Packer plugin (#149) 2024-05-02 13:10:34 -04:00
Fedor Korotkov 5d1abcb935
Lower the expected free disk size 2024-05-02 09:28:23 -04:00
Fedor Korotkov 8151177d8f
Revert "Fixed Simulator Opening" (#148)
This reverts commit e45042edb8.
2024-05-02 09:27:49 -04:00
Fedor Korotkov 2cd59ec2b4
Fixed Simulator Opening (#146) 2024-05-01 15:39:25 +02:00
fedor 2dcf12940d Add Java to path 2024-05-01 08:07:25 -04:00
fedor acd0ec5913 Use OpenJDK 2024-05-01 08:00:09 -04:00
fedor f2d703668c Fixed JDK 2024-05-01 07:55:20 -04:00
fedor 54a41a1e0a Use sudo 2024-05-01 07:51:33 -04:00
Nikolay Edigaryev 57a0eb2d30
/Users/runner → /Users/admin symlink to support certain GitHub Actions (#145) 2024-04-22 11:04:53 -04:00
Fedor Korotkov c73a2a5fe9
Update .cirrus.yml 2024-04-22 05:01:14 -04:00
Fedor Korotkov 989b0d8f1a
Updated ReadMe (#144)
Included release and update cadence of the images

Fixes #142
2024-04-18 14:07:51 -04:00
Fedor Korotkov 415bb40956
Install Node.js LTS (#143)
Right now `brew install node` installs the current version 21 of Node.js. Let's make sure we install an LTS version. It's updated not that often so can update it manually.
2024-04-18 21:11:25 +04:00
Fedor Korotkov 9ccac855c3
Update README.md 2024-04-08 12:41:50 -04:00
fedor 31bc126bc4 fixes 2024-04-07 20:10:13 -04:00
Fedor Korotkov 7932133d6f
Pass as list 2024-04-07 19:38:13 -04:00
Fedor Korotkov c254792f80
Only two version of Ruby 2024-04-07 14:18:20 -04:00
Fedor Korotkov 00fd234514
Update .cirrus.yml 2024-04-05 15:55:30 -04:00
Fedor Korotkov df763eb2d6
Latest runner 2024-04-05 15:54:59 -04:00
Fedor Korotkov e1755912e6
Preinstall last 3 versions of Ruby (#141) 2024-04-05 10:29:53 -04:00
Fedor Korotkov f1715dca7b
Automatically re-run tasks in case of network issues (#140)
* Automatically re-run tasks in case of network issues

* new line
2024-04-01 08:06:20 -04:00
Fedor Korotkov e89c673a33
Change macOS runner image name (#139)
To be consistent with ubuntu ones where tag is the version of OS.
2024-04-01 07:40:57 -04:00
fedor 264c3e8fb0 Fixed typo 2024-03-27 12:16:34 +04:00
fedor 0215733c42 Runner variant tweaks 2024-03-27 11:09:42 +04:00
fedor d3f7a8f37d Sonoma 14.4.1 2024-03-26 13:51:09 +04:00
Fedor Korotkov 7026060433
Introduce Runner Variant (#138)
* Introduce Runner Variant

This image will contain multiple version of Xcode to pick with https://github.com/MobileDevOps/xcode-select-version-action

This image will updated weekly and will be warm on our runners.

* Introduce Runner Variant

This image will contain multiple version of Xcode to pick with https://github.com/MobileDevOps/xcode-select-version-action

This image will updated weekly and will be warm on our runners.

* Don't forget brackets

* Update templates/xcode.pkr.hcl

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2024-03-25 12:40:18 -04:00
Nikolay Edigaryev 9b2a899ea8
Enable UI automation by default (#137) 2024-03-19 10:32:12 -04:00
fedor 08d9f601e4 Fixed ReadMe examples 2024-03-11 14:02:48 -04:00
anders-nylander 8b0607128f
Don't run rbenv'd gem commands with sudo (#135) 2024-03-11 08:36:49 -04:00
Fedor Korotkov bf9f6a6146
Sonoma 14.4 (#133) 2024-03-07 13:54:03 -05:00
Fedor Korotkov d367ab61c8
Fixed Xcode release 2024-03-06 07:55:57 -05:00
Fedor Korotkov f06b997060
Xcode 15.3 2024-03-06 07:53:50 -05:00
Fedor Korotkov 5b625c9167
Delete the right VM 2024-03-02 09:32:15 -05:00
Fedor Korotkov 03e06aff01
Fixed VM name 2024-03-02 08:25:55 -05:00
Fedor Korotkov 7849005130
Pull Vanilla Images (#132)
Don't forget to pull the latest Vanilla version first
2024-02-28 13:04:00 -05:00
Fedor Korotkov c03e2f3253
Concurrent builds (#131) 2024-02-28 11:04:51 -05:00
Fedor Korotkov 882cbe2344
Regularly update multiple tags (#130)
* Regularly update multiple tags

Update the last two version of macOS and the last two versions of Xcode for each of macOS versions.

Fixed #128

* Missing `matrix`
2024-02-27 17:14:29 -05:00
Fedor Korotkov 0cc9b01623
No need to populate `/usr/local/bin/` (#129)
Plus we only need `add-certificate` during the build and don't need it in the image
2024-02-26 08:39:54 -05:00
Fedor Korotkov 9940dd3705
Backport language fix to Ventura and Sonoma (#126)
Fixes #125
Related to #107
2024-02-01 09:56:39 -05:00
Fedor Korotkov a1a1fd7d36
14.3 2024-01-25 14:17:35 -05:00
Fedor Korotkov fc41a4d619
Update .cirrus.yml 2024-01-25 12:43:27 -05:00
Fedor Korotkov a80bae15d9
Fixed full disk access (#124)
As the default was changed in Sonoma as reported in #113

Fixes #113
2024-01-24 12:33:37 -05:00
umläute 104e432eb4
parameterize 'xcodes' (#123)
Closes: https://github.com/cirruslabs/macos-image-templates/issues/122
2024-01-24 12:09:28 -05:00
Fedor Korotkov 002717156a
Use local Xcode cache (#121) 2024-01-24 15:15:09 +04:00
Fedor Korotkov 13071e71be
Just enable remote automation for Safari (#120)
Enabling `Develop` menu started failing in 14.3 with:

```console
Could not write domain /Users/admin/Library/Containers/com.apple.Safari/Data/Library/Preferences/com.apple.Safari; exiting
```

We actually only interested in enabling remote automation for CI which is done by `safaridriver`. Having `Develop` menu item is not necessary.
2024-01-23 14:14:16 -05:00
Fedor Korotkov fb83953b1b
macOS 14.3 (#119)
Plus automatically update vanilla images
2024-01-22 13:34:52 -05:00
Nikolay Edigaryev 19ccfde91c
Always install the latest GitHub Actions Runner (#117) 2024-01-17 08:56:53 -05:00
Fedor Korotkov 4b3f94df8d
Update variables.pkrvars.hcl 2024-01-16 23:04:32 -05:00
Fedor Korotkov 5aa1d63f6a
Update variables.pkrvars.hcl 2024-01-16 23:04:01 -05:00
fedor a63fb03f2e Ventura 13.6 2024-01-10 20:04:47 +04:00
Fedor Korotkov 8f93e8eae2
Removed chunking 2023-12-26 07:59:50 -05:00
Nikolay Edigaryev 8b9f6ce141
Tag vanilla image as 14.1 (#111)
Since we currently use UniversalMac_14.1_23B74_Restore.ipsw to build it.
2023-12-22 12:31:18 +04:00
Nikolay Edigaryev a9d8536f46
disable-sip.pkr.hcl: a better way to open Terminal (#110)
Without it, we open the "Share Disk..." menu option instead.

Also there's no more default language choice on Sonoma.
2023-12-21 21:03:02 +04:00
Nikolay Edigaryev 73dea7bcb0
Disable SIP in vanilla images (#109) 2023-12-20 19:14:56 +04:00
Nikolay Edigaryev e5f5edca05
.cirrus.yml: introduce "Update Vanilla Images" task (#108) 2023-12-20 15:11:26 +01:00
Nikolay Edigaryev 21522999bb
Don't mistakenly select "English (UK)" language instead of "English" one (#107) 2023-12-19 12:12:17 +04:00
Nikolay Edigaryev 664d47260e
Hide useless systemsetup errors and avoid scary Safari kill error (#106) 2023-12-15 11:14:20 +04:00
fedor 67a57c3064 Xcode 15.1 2023-12-12 21:56:50 +01:00
fedor fabd89cead Fixed tag 2023-12-12 21:56:10 +01:00
Fedor Korotkov b19d3fa66c
Use alias for ECR pushes 2023-11-27 12:51:22 -05:00
Fedor Korotkov 3f1850ad07
ECR chunked push 2023-11-27 12:50:17 -05:00
Fedor Korotkov 4b7ac1f76f
Increased timeout 2023-11-10 13:20:59 -05:00
Fedor Korotkov 98b522dbfa
Push images to public ECR (#103)
* Push images to public ECR

Related to https://github.com/cirruslabs/tart/discussions/652

* Use the default alias until we get the custom one
2023-11-10 09:28:47 -05:00
fedor 41b20ab533 Revert "Pin version of `activesupport` (#101)"
This reverts commit 6555932569.
2023-11-06 11:22:57 -05:00
Fedor Korotkov b28936faa2
Xcode 15.0.1 2023-11-06 11:21:47 -05:00
fedor 3e3e6818f3 Sonoma 14.1 2023-10-25 16:10:45 -04:00
Fedor Korotkov 47695a9abd
Runner 2.311.0 2023-10-23 16:30:43 -04:00
Fedor Korotkov 6555932569
Pin version of `activesupport` (#101)
* Pin version of `activesupport`

Fixes #100 while https://github.com/CocoaPods/CocoaPods/issues/12081 is not released.

* Fixed installation
2023-10-10 07:56:40 -04:00
Fedor Korotkov 4513f2adad
GHA Runner 2.310.0 2023-10-09 09:51:05 -04:00
Fedor Korotkov 0a4f436302
Update README.md 2023-10-05 07:03:08 -04:00
Rui Marinho 277b13fb59
macOS 13.5.2 (#97) 2023-09-27 12:34:46 -04:00
Fedor Korotkov 19a8271935
Switch to Sonoma (#98)
Use RC and update all the scripts
2023-09-20 10:59:13 -04:00
fedor ba158f524c Removed quotes from Xcode version 2023-09-04 00:24:18 +02:00
fedor a34d6d3e51 macOS 13.5.1 2023-09-04 00:11:48 +02:00
Fedor Korotkov 59624221fe
Update Xcode Image (#94)
During the monthly cron update. Fixes #93
2023-08-14 11:22:36 -04:00
Fedor Korotkov ac0d6efcf5
Update variables.pkrvars.hcl 2023-08-14 09:29:17 -04:00
Fedor Korotkov 4e75d95247
Update variables.pkrvars.hcl 2023-07-25 09:19:13 -04:00
fedor 7fcf10afd6 Build sonoma 2023-07-13 06:46:47 -04:00
fedor 0f7f741d45 Use latest 2023-07-13 06:46:17 -04:00
fedor f0e06a7c5e Bump the GHA runner 2023-07-13 06:46:09 -04:00
Melvin Gundlach 21e5a3eb86
Update vanilla-sonoma to Beta 3 Update (#91)
Co-authored-by: Melvin Gundlach <mgundlach@it-economics.de>
2023-07-12 07:46:12 -04:00
Melvin Gundlach a2d379b619
Update vanilla-sonoma to Beta 3 (#90)
Co-authored-by: Melvin Gundlach <mgundlach@it-economics.de>
2023-07-11 07:50:09 -04:00
Grigory Entin 5d00757016
Disabled screensaver for admin user. (#88) 2023-06-22 18:50:44 +04:00
Fedor Korotkov 04eaf0415f
Update vanilla-sonoma 2023-06-21 17:56:27 -04:00
Nikolay Edigaryev fc12391db4
Use host's DNS servers (#87) 2023-06-21 17:04:50 +04:00
fedor 62bb71fc2c Persist `add-certificate` binary
Fixes #82
2023-06-16 12:34:42 -04:00
Fedor Korotkov 4625de36fc
Update .cirrus.yml 2023-06-14 07:51:50 -04:00
fedor 7221de2158 Bump xcode version 2023-06-14 07:28:53 -04:00
fedor 3ac3ec803c Bump Xcode 2023-06-14 07:28:33 -04:00
fedor 620771594e Bump GHA version 2023-06-14 07:27:53 -04:00
fedor a7907e34db Source 2023-06-14 07:27:53 -04:00
Fedor Korotkov 0f02d0a14f
Update .cirrus.yml 2023-06-13 17:00:46 -04:00
fedor 7be84bd9d9 Reverted 2023-06-13 07:27:11 -04:00
fedor 8c1d1b889a Support beta tags 2023-06-13 07:26:46 -04:00
fedor 703e5f8e35 Formatted 2023-06-13 07:21:03 -04:00
Szymon Mrozek 94dc6c6d03
Add AWS-CLI and ImageMagick tools (#85)
* Add AWS-CLI and ImageMagick tools

* Apply code review suggestions
2023-06-13 07:20:34 -04:00
fedor 7e5b78ae4c macOS 13.4 as base
Related to #84
2023-06-12 10:27:02 -04:00
Nikolay Edigaryev 42b40752b5
macOS 14 (Sonoma) template (#81)
* macOS 14 (Sonoma) template

* Use publicly available IPSW link in "from_ipsw"
2023-06-08 15:26:06 +04:00
fedor 072558f6ab Bump version 2023-04-27 14:12:57 -04:00
fedor e4af3c70c1 Don't check brew temporary 2023-04-14 09:38:45 +02:00
fedor 55ec020db9 Fixed syntax 2023-04-14 09:20:03 +02:00
fedor a7bdd003d4 Check flutter first 2023-04-14 09:17:42 +02:00
fedor 19ff55570e Install yarn 2023-04-09 18:51:52 -04:00
fedor 4d038de343 Install node through brew 2023-04-09 16:25:45 -04:00
fedor 8faf32710b Install NVM via official script 2023-04-09 14:18:53 -04:00
fedor be1be002c4 Fixed NVM installation 2023-04-08 20:22:11 -04:00
fedor 920aa01e4f Bump Xcode version 2023-04-08 19:45:25 -04:00
fedor b24d5c0ffb Better NVM installation 2023-04-08 19:45:07 -04:00
Fedor Korotkov 1629c949a6
Install Ruby 2.x.x and Node.JS LTS (#79)
* Install Ruby 2.x.x and Node.JS LTS

* Install Yarn as well

* Pre-install graphicsmagick and applesimutils

* Tweak maxfiles

* macOS 13.3.1
2023-04-08 11:25:32 -04:00
Fedor Korotkov 5828bf5b7c
Preinstall gitlab-runner 2023-04-04 17:37:28 -04:00
35 changed files with 2582 additions and 195 deletions

View File

@ -1,47 +0,0 @@
task:
name: "Update Base Image"
only_if: $CIRRUS_CRON != ""
persistent_worker:
labels:
name: dev-mini
env:
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
update_script: brew update && brew upgrade
info_script:
- tart --version
- packer --version
build_script:
- packer init templates/base.pkr.hcl
- packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
push_script:
- tart push ventura-base ghcr.io/cirruslabs/macos-ventura-base:latest
always:
cleanup_script:
- tart delete ventura-base
task:
name: "Release Xcode $CIRRUS_TAG"
only_if: $CIRRUS_TAG != ""
persistent_worker:
labels:
name: dev-mini
env:
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
update_script: brew update && brew upgrade
info_script:
- tart --version
- packer --version
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-ventura-base:latest
- tart clone ghcr.io/cirruslabs/macos-ventura-base:latest ventura-base
build_script:
- packer init templates/xcode.pkr.hcl
- packer build -var-file="variables.pkrvars.hcl" -var xcode_version="$CIRRUS_TAG" templates/xcode.pkr.hcl
push_script:
- tart push ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:latest
always:
cleanup_script:
- tart delete ventura-base || true
- tart delete ventura-xcode:$CIRRUS_TAG || true

203
.github/workflows/monthly.yml vendored Normal file
View File

@ -0,0 +1,203 @@
name: Monthly Images
on:
schedule:
- cron: "0 8 * * 6"
workflow_dispatch:
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
should-run:
name: Check Monthly Cadence
runs-on: [self-hosted, macOS, ARM64]
outputs:
build: ${{ steps.cadence.outputs.build }}
steps:
- name: Check first Saturday
id: cadence
env:
EVENT_NAME: ${{ github.event_name }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
build=true
else
day="$(date -u +%d)"
if (( 10#$day <= 7 )); then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
if [[ "$build" != "true" ]]; then
echo "Not the first Saturday of the month; skipping image rebuilds."
fi
update-base:
name: Update Base Images (${{ matrix.macos_version }})
needs: should-run
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
MACOS_VERSION: ${{ matrix.macos_version }}
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull vanilla image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Push base image
run: |
tart push "$MACOS_VERSION-base" "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-base" || true
update-xcode:
name: Update Xcode Images (${{ matrix.macos_version }} ${{ matrix.xcode_version }})
needs:
- should-run
- update-base
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_version: "26.2"
xcode_components: '"MetalToolchain"'
latest: true
- macos_version: tahoe
xcode_version: "26.1.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: tahoe
xcode_version: "26.0.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: sequoia
xcode_version: "16.4"
xcode_components: ""
latest: true
- macos_version: sequoia
xcode_version: "16.3"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.2"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.1"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "16.1"
xcode_components: ""
latest: true
- macos_version: sonoma
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "15.4"
xcode_components: ""
latest: false
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSION: ${{ matrix.xcode_version }}
LATEST: ${{ matrix.latest }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build Xcode image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push Xcode image
run: |
if [[ "$LATEST" == "true" ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION" || true

167
.github/workflows/release.yml vendored Normal file
View File

@ -0,0 +1,167 @@
name: Release Images
on:
release:
types:
- published
workflow_dispatch:
inputs:
xcode_version:
description: "Xcode version/tag to release"
required: true
type: string
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
XCODE_RELEASE_VERSION: ${{ github.event.release.tag_name || inputs.xcode_version }}
jobs:
release-xcode:
name: Release Xcode ${{ github.event.release.tag_name || inputs.xcode_version }} (${{ matrix.macos_version }})
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- tahoe
- sequoia
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: '"MetalToolchain"'
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Validate release version
run: |
set -euo pipefail
if [[ -z "$XCODE_RELEASE_VERSION" ]]; then
echo "XCODE_RELEASE_VERSION is required."
exit 1
fi
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build release image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_RELEASE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push release image
run: |
if [[ "$XCODE_RELEASE_VERSION" == *beta* ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION"
else
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" || true
release-runner:
name: Update Runner Image (${{ matrix.macos_version }})
# Keep runner refreshes independent from the release-xcode matrix so one
# Xcode image failure does not skip the runner matrix.
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-4","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build runner image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Push runner image
run: |
tart push "$MACOS_VERSION-xcode:runner" "ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true

View File

@ -0,0 +1,381 @@
name: Template Builds
on:
pull_request:
paths:
- ".github/workflows/monthly.yml"
- ".github/workflows/release.yml"
- ".github/workflows/template-validation.yml"
- "data/**"
- "scripts/**"
- "templates/**"
permissions:
contents: read
packages: read
concurrency:
group: template-builds-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
env:
FASTLANE_SESSION: ${{ secrets.FASTLANE_SESSION }}
FASTLANE_USER: ${{ secrets.FASTLANE_USER }}
HOMEBREW_NO_AUTO_UPDATE: 1
HOMEBREW_NO_INSTALL_CLEANUP: 1
PACKER_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
packer-validate:
name: Packer Validate
runs-on: macos-15
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Packer
uses: hashicorp/setup-packer@v3
- name: Install validation dependencies
run: |
brew install ansible
- name: Prepare validation inputs
run: |
mkdir -p "$HOME/XcodesCache"
touch "$HOME/XcodesCache/Xcode_26.6.xip"
- name: Validate templates
run: |
set -euo pipefail
validate() {
local template="$1"
shift
packer init "$template"
packer validate "$@" "$template"
}
for template in templates/vanilla-*.pkr.hcl; do
validate "$template"
done
validate templates/base.pkr.hcl \
-var vm_name=template-validation-base
validate templates/disable-sip.pkr.hcl \
-var vm_name=template-validation-disable-sip
validate templates/disable-sip-with-username.pkr.hcl \
-var vm_name=template-validation-disable-sip-user
validate templates/exex-script.pkr.hcl \
-var vm_name=template-validation-exec \
-var script_path=scripts/finalize-tahoe.sh
validate templates/resolve-macos-number.pkr.hcl \
-var vm_base_name=template-validation-base \
-var vm_name=template-validation-resolve \
-var resolve_file=macos-version.txt
validate templates/xcode.pkr.hcl \
-var macos_version=tahoe \
-var 'xcode_version=["26.6"]' \
-var expected_runtimes_file=data/expected.tahoe.runtimes.txt
build-vanilla:
name: Build Vanilla Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
build-base:
name: Build Base Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Eq '^(templates/base\.pkr\.hcl|templates/disable-sip.*\.pkr\.hcl|data/(github_known_hosts|limit\.maxfiles\.plist|setup-info-template\.json|tart-guest-.*\.plist)|scripts/(install-actions-runner|update-tcc-database)\.sh|ansible/)' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-base" || true
build-runner:
name: Build Runner Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-2","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq ".github/workflows/release.yml" changed-files.txt; then
build=true
elif grep -Fxq "data/expected.$MACOS_VERSION.runtimes.txt" changed-files.txt; then
build=true
elif grep -Fxq "scripts/finalize-$MACOS_VERSION.sh" changed-files.txt; then
build=true
elif grep -Eq '^(templates/xcode\.pkr\.hcl|data/setup-info-template\.json|scripts/install-actions-runner\.sh)$' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull base image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Prepare Xcode archives
if: steps.select.outputs.build == 'true'
run: |
set -euo pipefail
source ~/.zprofile || true
if ! command -v xcodes >/dev/null; then
brew install xcodes
fi
mkdir -p "$HOME/XcodesCache"
IFS=',' read -ra versions <<< "$XCODE_VERSIONS"
for raw_version in "${versions[@]}"; do
version="${raw_version//\"/}"
target="$HOME/XcodesCache/Xcode_${version}.xip"
if [[ -f "$target" ]]; then
echo "Using cached Xcode $version at $target"
continue
fi
echo "Downloading Xcode $version"
if [[ -z "${FASTLANE_SESSION:-}" ]]; then
echo "::error::Missing $target and FASTLANE_SESSION is not configured. Pre-cache the Xcode archive on the runner or add Apple Developer auth secrets."
exit 1
fi
download_args=(download "$version" --directory "$HOME/XcodesCache" --use-fastlane-auth)
if [[ -n "${FASTLANE_USER:-}" ]]; then
download_args+=(--fastlane-user "$FASTLANE_USER")
fi
xcodes "${download_args[@]}"
candidate=""
case "$version" in
27-beta-2)
candidate="$HOME/XcodesCache/Xcode_27_beta_2.xip"
;;
27-beta)
candidate="$HOME/XcodesCache/Xcode_27_beta.xip"
;;
*)
candidate="$(find "$HOME/XcodesCache" -maxdepth 1 -type f -name "Xcode_${version}*.xip" -print -quit)"
;;
esac
if [[ -n "$candidate" && -f "$candidate" && "$candidate" != "$target" ]]; then
mv "$candidate" "$target"
fi
test -f "$target"
done
- name: Build runner image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
if: steps.select.outputs.build == 'true'
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true

129
.github/workflows/vanilla.yml vendored Normal file
View File

@ -0,0 +1,129 @@
name: Vanilla Images
on:
push:
paths:
- "templates/vanilla-*.pkr.hcl"
workflow_dispatch:
inputs:
macos_version:
description: "macOS vanilla image to build"
required: true
default: all
type: choice
options:
- all
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
update-vanilla:
name: Update Vanilla Image (${{ matrix.macos_version }})
if: >-
${{
github.event_name == 'workflow_dispatch' ||
github.ref == format('refs/heads/{0}', github.event.repository.default_branch)
}}
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
RESOLVE_VM_NAME: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}
RESOLVE_FILE: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}.txt
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BEFORE_SHA: ${{ github.event.before }}
EVENT_NAME: ${{ github.event_name }}
INPUT_MACOS_VERSION: ${{ inputs.macos_version || 'all' }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
if [[ "$INPUT_MACOS_VERSION" == "all" || "$INPUT_MACOS_VERSION" == "$MACOS_VERSION" ]]; then
build=true
fi
else
if [[ "$BEFORE_SHA" =~ ^0+$ ]]; then
git diff-tree --no-commit-id --name-only -r "$GITHUB_SHA" > changed-files.txt
else
git diff --name-only "$BEFORE_SHA" "$GITHUB_SHA" > changed-files.txt
fi
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Resolve macOS version
id: resolve
if: steps.select.outputs.build == 'true'
run: |
packer build \
-var "vm_base_name=$MACOS_VERSION-vanilla" \
-var "vm_name=$RESOLVE_VM_NAME" \
-var "resolve_file=$RESOLVE_FILE" \
templates/resolve-macos-number.pkr.hcl
echo "macos_number=$(cat "$RESOLVE_FILE")" >> "$GITHUB_OUTPUT"
rm -f "$RESOLVE_FILE"
- name: Push vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart push "$MACOS_VERSION-vanilla" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:${{ steps.resolve.outputs.macos_number }}"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
tart delete "$RESOLVE_VM_NAME" || true

25
DEVELOPMENT.md Normal file
View File

@ -0,0 +1,25 @@
## Building Vanilla Image
To build `macos-sonoma-vanilla`:
```bash
packer build templates/vanilla-sonoma.pkr.hcl
```
Optionally, SIP can be disabled for each image by running the following commands:
```bash
packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
```
## Building Base Image
```bash
packer build -var vm_name=sonoma-vanilla templates/base.pkr.hcl
```
## Building Xcode Image
```bash
packer build -var macos_version=sonoma -var xcode_version="[15.4]" templates/xcode.pkr.hcl
```

View File

@ -1,45 +1,25 @@
## macOS Packer Templates for Cirrus CI
## macOS Packer Templates for Tart
Repository with Packer templates to build [Tart VMs](https://github.com/cirruslabs/tart) to use with [Cirrus CI](https://cirrus-ci.org/guide/macOS/).
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with self-hosted
GitHub Actions runners, [Cirrus Runners](https://cirrus-runners.app/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
* `macos-{monterey,ventura}-vanilla` image has nothing pre-installed
* `macos-{monterey,ventura}-base` image has only `brew` pre-installed
* `macos-{monterey,ventura}-xcode:N` image is based on `macos-{monterey,ventura}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
The following image variants are currently available:
See a full list of VMs available on Cirrus CI [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
* `macos-{golden-gate,tahoe,sequoia,sonoma}-vanilla` — a vanilla macOS installation with helpful tweaks such as auto-login, but no additional software preinstalled
* `macos-{tahoe,sequoia,sonoma}-base` — based on `macos-{tahoe,sequoia,sonoma}-vanilla` image, it comes with `brew` and [other useful software](https://github.com/cirruslabs/macos-image-templates/blob/main/templates/base.pkr.hcl) pre-installed, but without Xcode
* `macos-{tahoe,sequoia,sonoma}-xcode:N` — based on `macos-{tahoe,sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
* `macos-runner:{tahoe,sequoia,sonoma}` — a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
## Building Vanilla Image
See a full list of VMs available [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
To build `macos-monterey-vanilla`:
## Release Cadence
```bash
packer build templates/vanilla-monterey.pkr.hcl
```
Once a new version of Xcode is released, we will initiate a GitHub release which will automatically build and push
a new version of the `macos-{tahoe,sequoia}-xcode:N`. This generally happens the next weekend after a release.
Please watch this repository releases to get notified about new images.
To build `macos-ventura-vanilla`:
## Update Cadence
```bash
packer build templates/vanilla-ventura.pkr.hcl
```
Some of the images are regularly getting rebuild in order to update the pre-installed packages.
Optionally, SIP can be disabled for each image by running the following commands:
```bash
packer build -var vm_name=monterey-vanilla templates/disable-sip.pkr.hcl
```
```bash
packer build -var vm_name=ventura-vanilla templates/disable-sip.pkr.hcl
```
## Building Base Image
```bash
packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
```
## Building Xcode Image
```bash
packer build -var-file="variables.pkrvars.hcl" templates/xcode.pkr.hcl
```
[This workflow](.github/workflows/monthly.yml) defines images that are getting rebuilt monthly on the first Saturday of the month.

View File

@ -0,0 +1,5 @@
- hosts: default
roles:
- system-updater
vars:
ansible_password: admin

View File

@ -0,0 +1,37 @@
- name: Perform first "softwareupdate" invocation
include_tasks: softwareupdate.yml
# Needed after a major macOS update, otherwise things like
# Command Line Tools won't be updated
- name: Perform second "softwareupdate" invocation
include_tasks: softwareupdate.yml
# This one looks weird, but unfortunately there's no other way around, because Homebrew
# is not designed to run as root (see https://gist.github.com/irazasyed/7732946
# for more details).
- name: fix up /usr/local permissions for Homebrew
file:
path: /usr/local/share/man
state: directory
owner: "{{ ansible_user_id }}"
recurse: yes
become: yes
- name: "ensure that there are no more software updates available: check for available updates"
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: "ensure that there are no more software updates available: parse available updates"
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: "ensure that there are no more software updates available: print available updates"
debug:
var: software_updates
- name: "ensure that there are no more software updates available: fail if some updates were not installed"
fail:
msg: "Found unapplied update: {{ item.label }}"
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"

View File

@ -0,0 +1,43 @@
- name: check for available updates
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: parse available updates
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: print available updates
debug:
var: software_updates
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
- name: install available update
command:
cmd: "softwareupdate --install --agree-to-license --force --restart --user admin --stdinpass {{ stdinpass | default('') }} '{{ item.label }}'"
stdin: "{{ ansible_password }}"
register: update_result
# Work around the following:
# > Data could not be sent to remote host [...].
# > Make sure this host can be reached over ssh:
# > ssh: connect to host [...] port 22: Connection refused.
ignore_unreachable: yes
# Ignore SIGTERM/SIGKILL sent "softwareupdate" process
# when the system reboots due to --restart and any other errors,
# since we'll check whether the update was installed in main.yml
# anyway.
ignore_errors: yes
become: yes
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
# Wait for the connection since the previous command could restart the host
- name: wait for connection
wait_for_connection:
# We need to wait long enough for the "softwareupdate" to initiate the reboot,
# otherwise it's possible that we'll interrupt the process by running
# the commands below on a non-restarted system.
delay: 60
timeout: 1800
when: update_result is defined and not update_result.skipped | default(false)

View File

@ -0,0 +1,20 @@
== Runtimes ==
iOS 17.5 (17.5 - 21F79) - com.apple.CoreSimulator.SimRuntime.iOS-17-5
iOS 18.0 (18.0 - 22A3351) - com.apple.CoreSimulator.SimRuntime.iOS-18-0
iOS 18.1 (18.1 - 22B81) - com.apple.CoreSimulator.SimRuntime.iOS-18-1
iOS 18.2 (18.2 - 22C150) - com.apple.CoreSimulator.SimRuntime.iOS-18-2
iOS 18.3 (18.3.1 - 22D8075) - com.apple.CoreSimulator.SimRuntime.iOS-18-3
iOS 18.4 (18.4 - 22E238) - com.apple.CoreSimulator.SimRuntime.iOS-18-4
iOS 18.5 (18.5 - 22F77) - com.apple.CoreSimulator.SimRuntime.iOS-18-5
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0.1 - 23A8464) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
tvOS 17.5 (17.5 - 21L569) - com.apple.CoreSimulator.SimRuntime.tvOS-17-5
tvOS 18.4 (18.4 - 22L254) - com.apple.CoreSimulator.SimRuntime.tvOS-18-4
tvOS 18.5 (18.5 - 22L572) - com.apple.CoreSimulator.SimRuntime.tvOS-18-5
tvOS 26.0 (26.0 - 23J352) - com.apple.CoreSimulator.SimRuntime.tvOS-26-0
watchOS 11.4 (11.4 - 22T250) - com.apple.CoreSimulator.SimRuntime.watchOS-11-4
watchOS 11.5 (11.5 - 22T572) - com.apple.CoreSimulator.SimRuntime.watchOS-11-5
watchOS 26.0 (26.0 - 23R353) - com.apple.CoreSimulator.SimRuntime.watchOS-26-0
visionOS 2.4 (2.4 - 22O237) - com.apple.CoreSimulator.SimRuntime.xrOS-2-4
visionOS 2.5 (2.5 - 22O473) - com.apple.CoreSimulator.SimRuntime.xrOS-2-5
visionOS 26.0 (26.0 - 23M336) - com.apple.CoreSimulator.SimRuntime.xrOS-26-0

View File

@ -0,0 +1,9 @@
== Runtimes ==
iOS 18.0 (18.0 - 22A3351) - com.apple.CoreSimulator.SimRuntime.iOS-18-0
iOS 18.1 (18.1 - 22B81) - com.apple.CoreSimulator.SimRuntime.iOS-18-1
tvOS 18.0 (18.0 - 22J356) - com.apple.CoreSimulator.SimRuntime.tvOS-18-0
tvOS 18.1 (18.1 - 22J578) - com.apple.CoreSimulator.SimRuntime.tvOS-18-1
watchOS 11.0 (11.0 - 22R349) - com.apple.CoreSimulator.SimRuntime.watchOS-11-0
watchOS 11.1 (11.1 - 22R581) - com.apple.CoreSimulator.SimRuntime.watchOS-11-1
visionOS 2.0 (2.0 - 22N318) - com.apple.CoreSimulator.SimRuntime.xrOS-2-0
visionOS 2.1 (2.1 - 22N580) - com.apple.CoreSimulator.SimRuntime.xrOS-2-1

View File

@ -0,0 +1,15 @@
== Runtimes ==
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0.1 - 23A8464) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
iOS 26.1 (26.1 - 23B86) - com.apple.CoreSimulator.SimRuntime.iOS-26-1
iOS 26.3 (26.3.1 - 23D8133) - com.apple.CoreSimulator.SimRuntime.iOS-26-3
iOS 26.4 (26.4.1 - 23E254a) - com.apple.CoreSimulator.SimRuntime.iOS-26-4
iOS 26.5 (26.5 - 23F77) - com.apple.CoreSimulator.SimRuntime.iOS-26-5
iOS 27.0 (27.0 - 24A5355p) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
iOS 27.0 (27.0 - 24A5370g) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
tvOS 26.5 (26.5 - 23L470) - com.apple.CoreSimulator.SimRuntime.tvOS-26-5
tvOS 27.0 (27.0 - 24J5305f) - com.apple.CoreSimulator.SimRuntime.tvOS-27-0
watchOS 26.5 (26.5 - 23T570) - com.apple.CoreSimulator.SimRuntime.watchOS-26-5
watchOS 27.0 (27.0 - 24R5305f) - com.apple.CoreSimulator.SimRuntime.watchOS-27-0
visionOS 26.5 (26.5 - 23O470) - com.apple.CoreSimulator.SimRuntime.xrOS-26-5
visionOS 27.0 (27.0 - 24M5306g) - com.apple.CoreSimulator.SimRuntime.xrOS-27-0

3
data/github_known_hosts Normal file
View File

@ -0,0 +1,3 @@
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=

21
data/limit.maxfiles.plist Normal file
View File

@ -0,0 +1,21 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN"
"http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>limit.maxfiles</string>
<key>ProgramArguments</key>
<array>
<string>launchctl</string>
<string>limit</string>
<string>maxfiles</string>
<string>65536</string>
<string>524288</string>
</array>
<key>RunAtLoad</key>
<true/>
<key>ServiceIPC</key>
<false/>
</dict>
</plist>

View File

@ -0,0 +1,52 @@
[
{
"group": "Runner Detail",
"detail": [
{
"name": "OS Information",
"script": "echo \"macOS $(sw_vers -productVersion) ($(sw_vers -buildVersion))\""
},
{
"name": "Build Date",
"script": "date +\"%Y-%m-%d\""
}
]
},
{
"group": "Software Detail",
"detail": [
{
"name": "Xcode Versions",
"script": "xcodes installed --no-color || echo \"Xcode not installed\""
},
{
"name": "Python Version",
"script": "python3 --version"
},
{
"name": "Node Version",
"script": "node --version"
},
{
"name": "Ruby Version",
"script": "ruby --version"
},
{
"name": "Bundler Version",
"script": "bundler --version"
},
{
"name": "CocoaPods Version",
"script": "pod --version"
},
{
"name": "Fastlane Version",
"script": "fastlane --version"
},
{
"name": "SwiftLint Version",
"script": "swiftlint --version"
}
]
}
]

View File

@ -0,0 +1,30 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>org.cirruslabs.tart-guest-agent</string>
<key>ProgramArguments</key>
<array>
<string>/opt/homebrew/bin/tart-guest-agent</string>
<string>--run-agent</string>
</array>
<key>EnvironmentVariables</key>
<dict>
<key>PATH</key>
<string>/bin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/homebrew/bin</string>
<key>TERM</key>
<string>xterm-256color</string>
</dict>
<key>WorkingDirectory</key>
<string>/Users/admin</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<true/>
<key>StandardOutPath</key>
<string>/tmp/tart-guest-agent.log</string>
<key>StandardErrorPath</key>
<string>/tmp/tart-guest-agent.log</string>
</dict>
</plist>

View File

@ -0,0 +1,28 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>org.cirruslabs.tart-guest-daemon</string>
<key>ProgramArguments</key>
<array>
<string>/opt/homebrew/bin/tart-guest-agent</string>
<string>--run-daemon</string>
</array>
<key>EnvironmentVariables</key>
<dict>
<key>PATH</key>
<string>/bin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/homebrew/bin</string>
</dict>
<key>WorkingDirectory</key>
<string>/var/empty</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<true/>
<key>StandardOutPath</key>
<string>/tmp/tart-guest-daemon.log</string>
<key>StandardErrorPath</key>
<string>/tmp/tart-guest-daemon.log</string>
</dict>
</plist>

View File

@ -0,0 +1,6 @@
#!/usr/bin/expect -f
spawn automationmodetool enable-automationmode-without-authentication
expect "Enter the password for user 'admin':"
send "admin\n"
expect "Setting up machine to allow Automation Mode without requiring user authentication... succeeded."

72
scripts/finalize-tahoe.sh Normal file
View File

@ -0,0 +1,72 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
# Wait until `xcrun simctl list devices -v` no longer reports any devices as "unavailable".
#
# Exit codes:
# 0 - Success: no devices are marked as unavailable within the timeout window
# 1 - Failure: timed out waiting for devices to become available
# 2 - Failure: prerequisites missing (e.g., xcrun not found)
DEFAULT_TIMEOUT_MINUTES=60
TIMEOUT_MINUTES=${1:-$DEFAULT_TIMEOUT_MINUTES}
if ! [[ "$TIMEOUT_MINUTES" =~ ^[0-9]+$ ]]; then
echo "[wait-simulators] ERROR: TIMEOUT_MINUTES must be an integer number of minutes (got: '$TIMEOUT_MINUTES')." >&2
exit 2
fi
SECONDS_TOTAL=$(( TIMEOUT_MINUTES * 60 ))
DEADLINE=$(( $(date +%s) + SECONDS_TOTAL ))
SLEEP_SECONDS=15
# Print a one-line status snapshot of current unavailable devices (if any)
print_status() {
if xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] Still seeing 'unavailable' devices at $(date '+%Y-%m-%d %H:%M:%S')"
# Show a concise list of unavailable lines for debugging
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /'
else
echo "[wait-simulators] No 'unavailable' devices detected at $(date '+%Y-%m-%d %H:%M:%S')"
fi
}
trap 'echo "[wait-simulators] Interrupted" >&2; exit 130' INT TERM
echo "[wait-simulators] Waiting up to ${TIMEOUT_MINUTES} minute(s) for simulators to become available..."
while true; do
if ! xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] All simulators are available."
exit 0
fi
NOW=$(date +%s)
if (( NOW >= DEADLINE )); then
echo "[wait-simulators] TIMEOUT after ${TIMEOUT_MINUTES} minute(s). Some simulators remain 'unavailable'." >&2
echo "[wait-simulators] Final snapshot of unavailable devices:" >&2
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /' >&2
exit 1
fi
print_status
REMAIN=$(( DEADLINE - NOW ))
# Sleep in chunks to allow quicker exit when they become available
SLEEP=$SLEEP_SECONDS
if (( REMAIN < SLEEP_SECONDS )); then SLEEP=$REMAIN; fi
sleep "$SLEEP"
# Loop and re-check
done

View File

@ -0,0 +1,20 @@
#!/bin/bash
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
source ~/.zprofile
brew install jq
DOWNLOAD_URL=$(curl -sS 'https://api.github.com/repos/actions/runner/releases/latest' | jq --raw-output '.assets[] | select(.name | test("actions-runner-osx-arm64-[0-9.]+.tar.gz")) | .browser_download_url')
rm -rf actions-runner && mkdir actions-runner && cd actions-runner
wget -O - "${DOWNLOAD_URL}" | tar xz

View File

@ -0,0 +1,60 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
update_tcc_database() {
local tart_guest_agent_path
tart_guest_agent_path="$(realpath /opt/homebrew/bin/tart-guest-agent)"
sudo sqlite3 "$1" <<-EOF
INSERT OR REPLACE
INTO access (
service,
client_type,
client,
auth_value,
auth_reason,
auth_version,
indirect_object_identifier_type,
indirect_object_identifier
) VALUES
-- Indirect osascript invocation via SSH
('kTCCServiceAccessibility', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct osascript invocation
('kTCCServiceAccessibility', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct Python invocation
('kTCCServiceAccessibility', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceMicrophone', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
-- Commands invoked through the Tart Guest Agent
('kTCCServiceAccessibility', 1, '${tart_guest_agent_path}', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '${tart_guest_agent_path}', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceMicrophone', 1, '${tart_guest_agent_path}', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '${tart_guest_agent_path}', 2, 0, 1, NULL, 'UNUSED');
EOF
}
# Update TCC.db for all users
update_tcc_database "/Library/Application Support/com.apple.TCC/TCC.db"
# Update TCC.db for the current user
update_tcc_database "${HOME}/Library/Application Support/com.apple.TCC/TCC.db"

View File

@ -1,23 +1,18 @@
packer {
required_plugins {
tart = {
version = ">= 0.5.4"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "macos_version" {
type = string
}
variable "gha_version" {
type = string
variable "vm_name" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:13.3"
vm_name = "${var.macos_version}-base"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
@ -29,17 +24,19 @@ source "tart-cli" "tart" {
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
"echo 'Disabling spotlight...'",
"sudo mdutil -a -i off",
]
provisioner "file" {
source = "data/limit.maxfiles.plist"
destination = "~/limit.maxfiles.plist"
}
# setup DNS
provisioner "shell" {
inline = [
"networksetup -setdnsservers Ethernet 8.8.8.8 8.8.4.4 1.1.1.1",
"echo 'Configuring maxfiles...'",
"sudo mv ~/limit.maxfiles.plist /Library/LaunchDaemons/limit.maxfiles.plist",
"sudo chown root:wheel /Library/LaunchDaemons/limit.maxfiles.plist",
"sudo chmod 0644 /Library/LaunchDaemons/limit.maxfiles.plist",
"echo 'Disabling spotlight...'",
"sudo mdutil -a -i off",
]
}
@ -51,15 +48,6 @@ build {
]
}
provisioner "shell" {
inline = [
"cd $HOME",
"mkdir actions-runner && cd actions-runner",
"curl -O -L https://github.com/actions/runner/releases/download/v${var.gha_version}/actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"tar xzf ./actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"rm actions-runner-osx-arm64-${var.gha_version}.tar.gz",
]
}
provisioner "shell" {
inline = [
"/bin/bash -c \"$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\"",
@ -67,22 +55,78 @@ build {
"echo 'eval \"$(/opt/homebrew/bin/brew shellenv)\"' >> ~/.zprofile",
"echo \"export HOMEBREW_NO_AUTO_UPDATE=1\" >> ~/.zprofile",
"echo \"export HOMEBREW_NO_INSTALL_CLEANUP=1\" >> ~/.zprofile",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew --version",
"brew update",
"brew install wget cmake gcc git-lfs jq gh",
"brew install wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
"brew install buildkite/buildkite/buildkite-agent@3",
"brew install equinix-labs/otel-cli/otel-cli",
"brew install curl || true", // doesn't work on Monterey
"brew install --cask git-credential-manager",
"git lfs install",
"sudo softwareupdate --install-rosetta --agree-to-license"
]
}
// Add GitHub to known hosts
// Similar to https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/configure-ssh.sh
provisioner "shell" {
inline = [
"mkdir -p ~/.ssh"
]
}
provisioner "file" {
source = "data/github_known_hosts"
destination = "~/.ssh/known_hosts"
}
// Install the GitHub Actions runner
provisioner "shell" {
script = "scripts/install-actions-runner.sh"
}
// Create a /Users/runner /Users/admin symlink to support certain GitHub Actions
// like ruby/setup-ruby that hard-code the "/Users/runner/hostedtoolcache" path[1]
//
// [1]: https://github.com/ruby/setup-ruby/blob/6bd3d993c602f6b675728ebaecb2b569ff86e99b/common.js#L268
provisioner "shell" {
inline = [
"sudo ln -s /Users/admin /Users/runner"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libyaml", # https://github.com/rbenv/ruby-build/discussions/2118
"brew install rbenv",
"echo 'if which rbenv > /dev/null; then eval \"$(rbenv init -)\"; fi' >> ~/.zprofile",
"brew install mise",
"source ~/.zprofile",
"rbenv install 2.7.8", // latest 2.x.x before EOL
"rbenv install -l | grep -v - | tail -2 | xargs -L1 rbenv install",
"rbenv global $(rbenv install -l | grep -v - | tail -1)",
"gem install bundler",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install rbenv",
"echo 'if which rbenv > /dev/null; then eval \"$(rbenv init -)\"; fi' >> ~/.zprofile",
"brew install node@24",
"echo 'export PATH=\"/opt/homebrew/opt/node@24/bin:$PATH\"' >> ~/.zprofile",
"source ~/.zprofile",
"rbenv install 3.0.5",
"rbenv global 3.0.5",
"gem install bundler",
"node --version",
"npm install --global yarn pnpm",
"echo 'export PNPM_HOME=\"$HOME/Library/pnpm\"' >> ~/.zprofile",
"echo 'export PATH=\"$PNPM_HOME:$PATH\"' >> ~/.zprofile",
"source ~/.zprofile",
"yarn --version",
"pnpm --version",
]
}
provisioner "shell" {
@ -90,4 +134,56 @@ build {
"sudo safaridriver --enable",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install awscli"
]
}
# Enable UI automation, see https://github.com/cirruslabs/macos-image-templates/issues/136
provisioner "shell" {
script = "scripts/automationmodetool.expect"
}
// some other health checks
provisioner "shell" {
inline = [
"source ~/.zprofile",
"test -d /Users/runner",
"test -f ~/.ssh/known_hosts"
]
}
// Guest agent for Tart VMs
provisioner "file" {
source = "data/tart-guest-daemon.plist"
destination = "~/tart-guest-daemon.plist"
}
provisioner "file" {
source = "data/tart-guest-agent.plist"
destination = "~/tart-guest-agent.plist"
}
provisioner "shell" {
inline = [
# Install Tart Guest Agent
"source ~/.zprofile",
"brew install openai/tools/tart-guest-agent",
# Install daemon variant of the Tart Guest Agent
"sudo mv ~/tart-guest-daemon.plist /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
"sudo chown root:wheel /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
"sudo chmod 0644 /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
# Install agent variant of the Tart Guest Agent
"sudo mv ~/tart-guest-agent.plist /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
"sudo chown root:wheel /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
"sudo chmod 0644 /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
]
}
# Update TCC.db and allow automation tools
provisioner "shell" {
script = "scripts/update-tcc-database.sh"
}
}

View File

@ -0,0 +1,39 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_name" {
type = string
}
source "tart-cli" "tart" {
vm_name = "${var.vm_name}"
recovery = true
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
communicator = "none"
boot_command = [
# Skip over "Macintosh" and select "Options"
# to boot into macOS Recovery
"<wait60s><right><right><enter>",
# Open Terminal
"<wait10s><leftAltOn>T<leftAltOff>",
# Disable SIP
"<wait10s>csrutil disable<enter>",
"<wait10s>y<enter>",
"<wait10s>admin<enter>",
"<wait10s>admin<enter>",
# Shutdown
"<wait10s>halt<enter>"
]
}
build {
sources = ["source.tart-cli.tart"]
}

View File

@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 0.5.4"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
@ -22,11 +22,8 @@ source "tart-cli" "tart" {
# Skip over "Macintosh" and select "Options"
# to boot into macOS Recovery
"<wait60s><right><right><enter>",
# Select default language
"<wait10s><enter>",
# Open Terminal
"<wait10s><leftCtrlOn><f2><leftCtrlOff>",
"<right><right><right><right><down><down><down><enter>",
"<wait10s><leftAltOn>T<leftAltOff>",
# Disable SIP
"<wait10s>csrutil disable<enter>",
"<wait10s>y<enter>",

View File

@ -0,0 +1,39 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_name" {
type = string
}
variable "script_path" {
type = string
description = "Path to a local script that should be uploaded and executed inside the VM."
}
variable "pause_before" {
type = string
default = "60s"
description = "How long Packer should wait before running the uploaded script."
}
source "tart-cli" "tart" {
vm_name = "${var.vm_name}"
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
script = var.script_path
pause_before = var.pause_before
}
}

View File

@ -0,0 +1,48 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_base_name" {
type = string
}
variable "vm_name" {
type = string
}
variable "resolve_file" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "${var.vm_base_name}"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
# Use "-productVersion" instead of "--productVersion"
# to support old-style syntax used on macOS Monterey
"sw_vers -productVersion > /tmp/sw-vers-product-version.txt",
]
}
provisioner "file" {
source = "/tmp/sw-vers-product-version.txt"
destination = "${var.resolve_file}"
direction = "download"
}
}

View File

@ -0,0 +1,107 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2026SummerSeed/fullrestores/140-55718/5809AFC6-1923-4590-AAFC-904A0283E659/UniversalMac_27.0_26A5388g_Restore.ipsw"
vm_name = "golden-gate-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
disk_format = "asif"
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
// Requires Tart 2.33.0+ and macOS 27+ on both the host and guest VM
run_extra_args = [
"--provisioning-opts=${join(",", [
"fullName=Managed via Tart",
"username=admin",
"password=admin",
"logsInAutomatically=true",
"enablesRemoteLogin=true",
])}",
]
boot_command = [
# Wait for first-boot provisioning to finish automatic login
"<wait120s>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
# Disable Gatekeeper (1/2)
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
# Disable Gatekeeper (2/2)
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
# Wait for System Settings to fully open before navigating with the keyboard
"<wait120s>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable Screen Sharing for "tart run --vnc"
"sudo launchctl enable system/com.apple.screensharing",
// Use the same timezone as the previous Setup Assistant flow
"sudo systemsetup -settimezone GMT 2>/dev/null",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'",
# Ensure that FileVault remains disabled by default
"sudo fdesetup status | grep -q 'FileVault is Off'",
]
}
}

View File

@ -1,28 +1,37 @@
packer {
required_plugins {
tart = {
version = ">= 0.5.4"
version = ">= 1.2.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
# and https://www.theiphonewiki.com/wiki/Beta_Firmware/Mac/13.x
from_ipsw = "https://updates.cdn-apple.com/2022FallFCS/fullrestores/012-40537/0EC7C669-13E9-49FB-BD64-9EECC1D174B2/UniversalMac_12.6_21G115_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2022FallFCS/fullrestores/012-66032/8D8D90C6-A876-4FFF-BBF4-D158939B3841/UniversalMac_12.6.1_21G217_Restore.ipsw"
vm_name = "monterey-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language
"<wait30s><enter>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
@ -74,6 +83,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@ -90,18 +102,20 @@ build {
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off",
"sudo systemsetup -setsleep Off",
"sudo systemsetup -setcomputersleep Off",
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"sleep 3",
"kill -9 %1",
// Enable Safari's remote automation and "Develop" menu
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
"defaults write com.apple.Safari IncludeDevelopMenu -bool true",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
@ -109,4 +123,26 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
"--extra-vars", "stdinpass=admin",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}

View File

@ -0,0 +1,177 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
// will be update to 15.7.2
from_ipsw = "https://updates.cdn-apple.com/2025SummerFCS/fullrestores/093-10809/CFD6DD38-DAF0-40DA-854F-31AAD1294C6F/UniversalMac_15.6.1_24G90_Restore.ipsw"
vm_name = "sequoia-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait30s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab>UTC<enter><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><spacebar>",
# Welcome to Mac
"<wait10s><spacebar>",
# Disable Voice Over
"<leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Now that the installation is done, open "System Settings"
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (2/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}

View File

@ -0,0 +1,147 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
// will be update to 14.8.2
from_ipsw = "https://updates.cdn-apple.com/2024SummerFCS/fullrestores/062-52859/932E0A8F-6644-4759-82DA-F8FA8DEA806A/UniversalMac_14.6.1_23G93_Restore.ipsw"
vm_name = "sonoma-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Migration Assistant
"<wait10s><tab><tab><tab><spacebar>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Create a Computer Account
"<wait10s>admin<tab><tab>admin<tab>admin<tab><tab><tab><spacebar>",
# Enable Location Services
"<wait30s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Enable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff><wait5s>v",
# Now that the installation is done, open "System Settings"
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
# Navigate to "Sharing"
"<wait10s><leftAltOn>f<leftAltOff>sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Disable Voice Over
"<leftAltOn><f5><leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}

View File

@ -0,0 +1,163 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2026SummerFCS/fullrestores/140-83079/25315EF6-AEAB-4588-9774-A3723774C47F/UniversalMac_26.6.1_25G76_Restore.ipsw"
vm_name = "tahoe-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s><tab><tab><tab><tab><tab><tab>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar><up><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Age Range -> Adult
"<wait10s><tab><tab><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><tab><spacebar>",
# Welcome to Mac
"<wait30s><spacebar>",
# Disable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
# Now that the installation is done, open "System Settings"
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait120s>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Type in the password to allow enabling Screen Sharing
"<wait10s>admin<enter>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
# Disable Gatekeeper (2/2)
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
}

View File

@ -1,28 +1,38 @@
packer {
required_plugins {
tart = {
version = ">= 0.5.4"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
# and https://www.theiphonewiki.com/wiki/Beta_Firmware/Mac/13.x
from_ipsw = "https://updates.cdn-apple.com/2023WinterSeed/fullrestores/002-75537/8250FA0E-0962-46D6-8A90-57A390B9FFD7/UniversalMac_13.3_22E252_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2023FallFCS/fullrestores/042-55833/C0830847-A2F8-458F-B680-967991820931/UniversalMac_13.6_22G120_Restore.ipsw"
vm_name = "ventura-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language
"<wait30s>english<enter>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
@ -80,6 +90,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@ -96,23 +109,47 @@ build {
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off",
"sudo systemsetup -setsleep Off",
"sudo systemsetup -setcomputersleep Off",
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 %1",
// Enable Safari's remote automation and "Develop" menu
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
"defaults write com.apple.Safari IncludeDevelopMenu -bool true",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
"defaults -currentHost write com.apple.screensaver idleTime 0"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}

View File

@ -1,71 +1,128 @@
packer {
required_plugins {
tart = {
version = ">= 0.5.4"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "macos_version" {
type = string
type = string
}
variable "xcode_version" {
type = string
type = list(string)
}
variable "gha_version" {
type = string
variable "additional_ios_builds" {
type = list(string)
default = []
}
variable "additional_tvos_builds" {
type = list(string)
default = []
}
variable "xcode_components" {
type = list(string)
default = []
description = "Additional Xcode components to download."
}
variable "expected_runtimes_file" {
type = string
default = ""
description = "Path to file containing expected simulator runtimes. If empty, runtime verification is skipped."
}
variable "tag" {
type = string
default = ""
}
variable "disk_size" {
type = number
default = 140
}
variable "disk_free_mb" {
type = number
default = 15000
}
variable "android_sdk_tools_version" {
type = string
default = "9477386" # https://developer.android.com/studio/#command-tools
type = string
default = "14742923" # https://developer.android.com/studio#command-line-tools-only
}
source "tart-cli" "tart" {
vm_base_name = "${var.macos_version}-base"
vm_name = "${var.macos_version}-xcode:${var.xcode_version}"
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-base:latest"
// use tag or the last element of the xcode_version list
vm_name = "${var.macos_version}-xcode:${var.tag != "" ? var.tag : var.xcode_version[0]}"
cpu_count = 4
memory_gb = 8
disk_size_gb = 90
disk_size_gb = var.disk_size
headless = true
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
locals {
xcode_install_provisioners = [
for version in reverse(sort(var.xcode_version)) : {
type = "shell"
inline = [
"source ~/.zprofile",
"sudo xcodes install ${version} --experimental-unxip --path /Users/admin/Downloads/Xcode_${version}.xip --select --empty-trash",
// get selected xcode path, strip /Contents/Developer and move to GitHub compatible locations
"INSTALLED_PATH=$(xcodes select -p)",
"CONTENTS_DIR=$(dirname $INSTALLED_PATH)",
"APP_DIR=$(dirname $CONTENTS_DIR)",
"sudo mv $APP_DIR /Applications/Xcode_${version}.app",
"sudo xcode-select -s /Applications/Xcode_${version}.app",
"xcodebuild -downloadPlatform iOS",
"xcodebuild -runFirstLaunch",
"df -h",
]
}
]
}
build {
sources = ["source.tart-cli.tart"]
// re-install the actions runner
provisioner "shell" {
inline = [
"cd $HOME",
"rm -rf actions-runner",
"mkdir actions-runner && cd actions-runner",
"curl -O -L https://github.com/actions/runner/releases/download/v${var.gha_version}/actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"tar xzf ./actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"rm actions-runner-osx-arm64-${var.gha_version}.tar.gz",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew --version",
"brew update",
"brew upgrade",
"brew install curl wget unzip zip ca-certificates",
"sudo softwareupdate --install-rosetta --agree-to-license"
"brew install codex",
"brew install --cask claude-code",
"brew install --cask amazon-q"
]
}
// Re-install the GitHub Actions runner
provisioner "shell" {
script = "scripts/install-actions-runner.sh"
}
// make sure our workaround from base is still valid
provisioner "shell" {
inline = [
"sudo ln -s /Users/admin /Users/runner || true"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install homebrew/cask-versions/temurin11",
"brew install openjdk@17",
"echo 'export PATH=\"/opt/homebrew/opt/openjdk@17/bin:$PATH\"' >> ~/.zprofile",
"echo 'export ANDROID_HOME=$HOME/android-sdk' >> ~/.zprofile",
"echo 'export ANDROID_SDK_ROOT=$ANDROID_HOME' >> ~/.zprofile",
"echo 'export PATH=$PATH:$ANDROID_HOME/cmdline-tools/latest/bin:$ANDROID_HOME/platform-tools:$ANDROID_HOME/emulator' >> ~/.zprofile",
@ -76,28 +133,140 @@ build {
"rm android-sdk-tools.zip",
"mv $ANDROID_HOME/cmdline-tools/cmdline-tools $ANDROID_HOME/cmdline-tools/latest",
"yes | sdkmanager --licenses",
"yes | sdkmanager 'platform-tools' 'platforms;android-33' 'build-tools;33.0.1' 'ndk;25.1.8937393'"
"yes | sdkmanager 'platform-tools' 'platforms;android-36' 'build-tools;36.0.0' 'ndk;28.2.13676358'"
]
}
provisioner "shell" {
inline = [
"echo 'export PATH=/usr/local/bin/:$PATH' >> ~/.zprofile",
"source ~/.zprofile",
"wget --quiet https://github.com/RobotsAndPencils/xcodes/releases/latest/download/xcodes.zip",
"unzip xcodes.zip",
"rm xcodes.zip",
"chmod +x xcodes",
"sudo mkdir -p /usr/local/bin/",
"sudo mv xcodes /usr/local/bin/xcodes",
"brew install xcodes",
"xcodes version",
"wget --quiet https://storage.googleapis.com/xcodes-cache/Xcode_${var.xcode_version}.xip",
"xcodes install ${var.xcode_version} --experimental-unxip --path $PWD/Xcode_${var.xcode_version}.xip",
"sudo rm -rf ~/.Trash/*",
"xcodes select ${var.xcode_version}",
"xcodebuild -downloadAllPlatforms",
"xcodebuild -runFirstLaunch",
]
}
provisioner "file" {
sources = [for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
destination = "/Users/admin/Downloads/"
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"df -h",
]
}
// iterate over all Xcode versions and install them
// select the latest one as the default
dynamic "provisioner" {
for_each = local.xcode_install_provisioners
labels = ["shell"]
content {
inline = provisioner.value.inline
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 2 ? [2] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[2]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 1 ? [1] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[1]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[0]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for runtime in var.additional_ios_builds : "xcodebuild -downloadPlatform iOS -buildVersion ${runtime}"
]
)
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for runtime in var.additional_tvos_builds : "xcodebuild -downloadPlatform tvOS -buildVersion ${runtime}"
]
)
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for component in var.xcode_components : "xcodebuild -downloadComponent ${component}"
]
)
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy carthage",
"brew install xcbeautify swiftformat swiftlint swiftgen licenseplist",
"brew install mint",
"git clone --depth 1 https://github.com/tuist/homebrew-tuist.git \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist\"",
"rm -rf \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Casks\"",
"tuist_version=$(ruby -ne 'if $_ =~ %r{/download/([^/]+)/}; puts $1; exit; end' \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Aliases/tuist\") && brew trust --formula \"tuist/tuist/tuist@$tuist_version\" && brew install --formula \"tuist/tuist/tuist@$tuist_version\"",
"gem update",
"gem install fastlane",
"gem install cocoapods",
"gem install xcpretty",
"gem uninstall --ignore-dependencies ffi && gem install ffi -- --enable-libffi-alloc"
]
}
// Copy expected runtimes file if provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["file"]
content {
source = var.expected_runtimes_file
destination = "/Users/admin/runtimes.expected.txt"
}
}
// Verify simulator runtimes match expected list if file was provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"xcrun simctl list runtimes > /Users/admin/runtimes.actual.txt",
"diff -q /Users/admin/runtimes.actual.txt /Users/admin/runtimes.expected.txt || (echo 'Simulator runtimes do not match expected list' && cat /Users/admin/runtimes.actual.txt && exit 1)",
"rm /Users/admin/runtimes.actual.txt /Users/admin/runtimes.expected.txt"
]
}
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
@ -112,34 +281,110 @@ build {
"flutter precache",
]
}
# useful utils for mobile development
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy fastlane carthage",
"sudo gem update",
"sudo gem install cocoapods",
"sudo gem uninstall --ignore-dependencies ffi && sudo gem install ffi -- --enable-libffi-alloc"
"brew install graphicsmagick imagemagick",
"brew install wix/brew/applesimutils",
"brew install gnupg"
]
}
# inspired by https://github.com/actions/runner-images/blob/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/configure-machine.sh#L33-L61
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo security delete-certificate -Z FF6797793A3CD798DC5B2ABEF56F73EDC9F83A64 /Library/Keychains/System.keychain",
"curl -o add-certificate.swift https://raw.githubusercontent.com/actions/runner-images/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/add-certificate.swift",
"swiftc add-certificate.swift",
"curl -o AppleWWDRCAG3.cer https://www.apple.com/certificateauthority/AppleWWDRCAG3.cer",
"curl -o DeveloperIDG2CA.cer https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer",
"curl -o add-certificate.swift https://raw.githubusercontent.com/actions/runner-images/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/add-certificate.swift",
"swiftc -suppress-warnings add-certificate.swift",
"sudo ./add-certificate AppleWWDRCAG3.cer",
"sudo ./add-certificate DeveloperIDG2CA.cer",
"rm add-certificate* *.cer"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew doctor",
"flutter doctor"
]
}
// check there is at least 15GB of free space and fail if not
provisioner "shell" {
inline = [
"source ~/.zprofile",
"df -h",
"export FREE_MB=$(df -m | awk '{print $4}' | head -n 2 | tail -n 1)",
"[[ $FREE_MB -gt ${var.disk_free_mb} ]] && echo OK || exit 1"
]
}
// some other health checks
provisioner "shell" {
inline = [
"source ~/.zprofile",
"test -d /Users/runner"
]
}
# Disable apsd[1][2] daemon as it causes high CPU usage after boot
#
# [1]: https://iboysoft.com/wiki/apsd-mac.html
# [2]: https://discussions.apple.com/thread/4459153
provisioner "shell" {
inline = [
"sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.apsd.plist"
]
}
# Wait for the "update_dyld_sim_shared_cache" process[1][2] to finish
# to avoid wasting CPU cycles after boot
#
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
# [2]: https://stackoverflow.com/a/68394101/9316533
provisioner "shell" {
inline = [
"source ~/.zprofile",
"xcrun simctl runtime dyld_shared_cache update --all || sleep 180",
"xcrun simctl list -v"
]
}
# Compatibility with GitHub Actions Runner Images, where
# /usr/local/bin belongs to the default user. Also see [2].
#
# [1]: https://github.com/actions/runner-images/blob/6bbddd20d76d61606bea5a0133c950cc44c370d3/images/macos/scripts/build/configure-machine.sh#L96
# [2]: https://github.com/actions/runner-images/discussions/7607
provisioner "shell" {
inline = [
"sudo chown admin /usr/local/bin"
]
}
// Install setup-info-generator
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install cirruslabs/cli/setup-info-generator"
]
}
// Copy setup info template
provisioner "file" {
source = "data/setup-info-template.json"
destination = "~/setup-info-template.json"
}
// Generate setup info
provisioner "shell" {
inline = [
"source ~/.zprofile",
"cat ~/setup-info-template.json | setup-info-generator > ~/actions-runner/.setup_info",
"rm ~/setup-info-template.json"
]
}
}

View File

@ -1,3 +0,0 @@
macos_version = "ventura"
gha_version = "2.303.0"
xcode_version = "14.2"