Compare commits

...
251 Commits
Author SHA1 Message Date
Nikolay Edigaryev 081c8ac4e3 vanilla-tahoe.pkr.hcl: adapt "boot_command" to recent installer changes (#271) 2025-08-29 11:15:40 -04:00
Fedor Korotkov d0f94cc4c8 Xcode 26 Beta 7 and macOS 26.0 beta 8 (#270)
* Xcode 26 Beta 7 and macOS 26.0 beta 8

* fixed syntax
2025-08-29 10:47:35 -04:00
fe19dc9f17 Install Metal toolchain for Xcode 26 and newer (#268)
* Install Metal toolchain when Xcode version is 26 or newer

* Define a variable rather than using a regex

* Provide the Xcode components as a list

* Use “shell” rather than “provisioner”

* Update .ci/cirrus.xcode.yml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-26 08:05:50 -04:00
Nikolay Edigaryev 6f8ae07451 Disable SIP on "-base" and "-xcode" images only (#269)
* Disable SIP on "-base" and "-xcode" images only

* Ventura needs DISABLE_SIP_TEMPLATE too
2025-08-26 00:17:00 +04:00
Fedor Korotkov 16a5100187 macOS Sequoia 15.6.1 (#267) 2025-08-20 15:45:07 -04:00
Fedor Korotkov 7058092d82 Xcode 26 Beta 6 and other updates (#266)
Related to #265
2025-08-20 14:08:27 -04:00
Fedor Korotkov 0d3b4f4efd Update latest betas (#259)
* Latest betas

* Ruby 3.3.9

* Updated simulators

* New line
2025-08-09 07:17:50 -04:00
Nikolay Edigaryev aad3ba254d vanilla-sequoia.pkr.hcl: upgrade IPSW from 15.5 to 15.6 (#261) 2025-08-07 06:32:08 -04:00
Nikolay Edigaryev 0c0a90071d vanilla-sonoma.pkr.hcl: use macOS Sonoma IPSW instead of Sequoia IPSW (#260) 2025-08-07 05:38:29 -04:00
Fedor Korotkov 276b6dde65 Include SwiftLint version in .setup_info (#258) 2025-08-04 12:27:24 -04:00
Fedor Korotkov 5e8c823ef0 Install all iOS packages after Xcode installation 2025-08-02 05:05:49 -04:00
Fedor Korotkov b6445b9d3a Xcode 26 Beta 4 (#256)
* Xcode 26 Beta 4

* Updated simulators

* Updated simulators

* Fixes after CI

* New line

* bring back 18.5

* bump disk
2025-08-02 04:48:25 -04:00
Fedor Korotkov ad9ce34d12 Install additional common packages (#257) 2025-08-01 15:14:46 -04:00
Fedor Korotkov 9746337eeb Sonoma 15.6 2025-07-29 17:08:48 -04:00
Fedor Korotkov f7880705ec All simulators for the last 3 versions of Xcode (#254) 2025-07-23 16:44:14 -04:00
Fedor Korotkov bc67673068 Update cirrus.runner.yml 2025-07-14 16:17:41 -04:00
Fedor Korotkov 393d7c615b Sonoma Xcode 15.4 (#253)
* Sonoma Xcode 15.4

* More disk

* watchOS 10.5 on sonoma

* Removed watchOS
2025-07-14 15:38:02 -04:00
Fedor Korotkov f292033e59 Fixed index out of bound 2025-07-14 14:43:21 -04:00
Fedor Korotkov e3cf995511 Xcode 26 Beta 3 (#251)
* Xcode 26 Beta 3

* Print disk sizes between Xcodes

* Tweak sizes

* Strip some simulators

* 17.5 for sonoma

* fixed expected runtimes

* Tweaked disk sizes
2025-07-11 15:01:42 -04:00
James Smith 3c3581a46f Update image to macOS 26 beta 3 (#250) 2025-07-08 00:45:56 -04:00
Fedor Korotkov 2fbdfd6186 Beta 1 runtimes 2025-07-07 08:14:11 +04:00
Fedor Korotkov a806b2d4ef Reverted to 26-beta 2025-07-07 08:09:46 +04:00
Fedor Korotkov c48cab887b Reverted to 26-beta-1 2025-07-07 08:06:34 +04:00
Fedor Korotkov d5d126deaa Revert "Updated runtimes"
This reverts commit ac6cbef9a6.
2025-07-07 08:06:28 +04:00
fedor ac6cbef9a6 Updated runtimes 2025-06-29 06:54:08 -07:00
Fedor Korotkov 9736671744 Xcode 26 Beta 2 (#249)
* Xcode 26 Beta 2

* Updated runtimes
2025-06-28 16:25:56 -07:00
Fedor Korotkov 2ec40d16cb macOS Tahoe Beta 2 (#248) 2025-06-24 10:39:45 -04:00
Nikolay Edigaryev ce496aa3ad Increase timeouts before "Select Your Country or Region" (#247)
...and "Welcome to Mac" screens.
2025-06-16 09:34:15 -04:00
fedor 660eac6ae0 Removed brew doctor
Because of Tahoe
2025-06-12 21:45:23 -07:00
fedor 530036c1bc Trigger vanilla 2025-06-12 18:05:15 -07:00
Fedor Korotkov 69ca3f729a Build base/xcode/runner variants for Tahoe (#245) 2025-06-12 16:23:41 -07:00
Nikolay Edigaryev e70eea50c4 Automated macOS 26 (Tahoe) installation (#244)
* Automated macOS 26 (Tahoe) installation

* Support "Command Line Tools beta  for Xcode-26.0" label

* account for "beta"
* preserve multiple spaces

* .ci/cirrus.vanilla.yml: add "MACOS_VERSION: tahoe"

* Disable SIP for Tahoe
2025-06-12 10:16:46 -07:00
Nikolay Edigaryev 3ac0f46b3e tart-guest-agent: specify TERM and set working directory to HOME (#243) 2025-06-12 00:08:06 +04:00
Fedor Korotkov 63e44895a7 New line 2025-06-09 16:27:39 -07:00
Fedor Korotkov c1d543be58 Xcode 26 beta (#241)
* Xcode 26 beta

* Updated Runtimes
2025-06-09 14:52:00 -07:00
fedor ca553f0b1d Fixed syntax 2025-05-31 10:50:39 -04:00
fedor b9ffc31440 Build runners on release 2025-05-31 10:48:36 -04:00
Fedor Korotkov 0b4954f232 Pre install swiftformat (#239) 2025-05-30 17:47:05 -04:00
Fedor Korotkov f2d0330eec Xcode 16.4 (#238) 2025-05-29 09:01:24 -04:00
Nikolay Edigaryev 6ae3ffd75f Tart Guest Agent: use component groups (#237) 2025-05-19 14:26:23 -04:00
fedor 64f4871059 400GB for runners 2025-05-18 09:56:13 -04:00
fedor 5f35113643 new line 2025-05-18 08:27:39 -04:00
fedor 9ec94173b3 Updated expected runtimes 2025-05-17 17:38:59 -04:00
fedor 0eafad7bcf Xcode 16.4-rc 2025-05-15 17:38:28 -04:00
Nikolay Edigaryev 1fd4c5e3ae xcode.pkr.hcl: increase default disk size from 100 to 120 GB (#235) 2025-05-13 15:23:45 +04:00
Fedor Korotkov cfed2eac90 macOS Sequoia 15.5 2025-05-12 15:49:46 -04:00
Nikolay Edigaryev 7be8facd36 Use separate log file for tart-guest-daemon (#234)
* Use separate log file for tart-guest-daemon

* Add /usr/sbin to PATH
2025-05-12 16:41:35 +04:00
fedor 6f66644628 Bring back iOS 17.5 2025-05-05 06:23:49 -04:00
fedor 2401e19f34 Updated runners push logic 2025-05-04 09:03:34 -04:00
Fedor Korotkov 1a09db706a Xcode 16.4-beta (#233) 2025-05-04 08:21:46 -04:00
Nikolay Edigaryev 99ef3f49c7 Split Tart Guest Agent invocations into daemon and agent variants (#232)
* Split Tart Guest Agent invocations into daemon and agent variants

* Write logs to /tmp, otherwise there are permission issues

* Correct use of ProgramArguments
2025-04-29 21:34:41 +04:00
Fedor Korotkov 7d267ec27b macOS 15.4.1 2025-04-23 18:02:50 -04:00
Fedor Korotkov 7dc9dd706d Add Xcode versions to .setup_info (#231) 2025-04-14 10:29:44 -04:00
Fedor Korotkov 6a21d56c86 Install fastlane via bundler (#228)
As recommended by docs and since we have newer Ruby version from rbenv
2025-04-08 11:09:50 -04:00
fedor f64d712020 Include Bundler Version 2025-04-07 17:50:58 -04:00
Nikolay Edigaryev 7b41df79bd base.pkr.hcl: install guest agent for Tart VMs (#227)
* base.pkr.hcl: install guest agent for Tart VMs

* Don't forget to "source ~/.zprofile" to have "brew" available
2025-04-08 00:03:09 +04:00
fedor bf4ddcee86 Update only Xcode 16+ 2025-04-06 19:55:53 -04:00
fedor 56a1ec662e Updated runtimes 2025-04-04 20:07:12 -04:00
fedor 1b15ebd8b2 Fixed format 2025-04-04 16:30:35 -04:00
fedor 1271f59338 Check runtimes 2025-04-04 15:31:46 -04:00
Stefan Mitterrutzner 3c4bbd340d swich to Xcode 16.3 release (#225) 2025-04-04 15:19:25 -04:00
Nikolay Edigaryev 92a5e245cc Adapt disable-sip.pkr.hcl for new "csrutil" version in macOS Sequoia (#226) 2025-04-02 00:25:01 +02:00
ec6a446fc1 Support macOS Sequoia 15.4 (#224)
* Support macOS Sequoia 15.4

* Navigate to "Sharing" and "Privacy & Security" through menu bar

System Settings's search box does not always work as intended.

* Choose "Only Download Automatically"

* Use "Managed via Tart" full user name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* Use "Managed via Tart" user full name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* macOS 15.4 RC 2

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

* Use macOS 15.4 release IPSW

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>
Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>
2025-03-31 22:34:07 +04:00
Nikolay Edigaryev 4206908127 vanilla-sequoia.pkr.hcl: disable Gatekeeper (#220)
* vanilla-sequoia.pkr.hcl: disable Gatekeeper

* Don't forget to enter sudo password

Since passwordless sudo is not yet enabled at this point.
2025-03-21 22:54:15 +04:00
fedor d42ba4a1e1 Additional iOS builds 2025-03-11 03:01:50 +04:00
fedor 005b272792 Additional iOS 18.2 runtime
Related https://github.com/cirruslabs/macos-image-templates/issues/219#issuecomment-2709774915
2025-03-10 19:51:22 +04:00
fedor ec0c478a02 Escape runtime 2025-03-10 14:07:10 +04:00
Fedor Korotkov ad419122b2 Bump disk size 2025-03-09 12:35:45 +04:00
fedor 2335029721 Xcode 16.3-beta-2 2025-03-08 14:41:16 +04:00
Sergio Pinheiro c3819d6d35 Fix syntax issue (#218) 2025-03-03 22:16:25 +04:00
Fedor Korotkov 1f9fdd5630 Xcode 16.3-beta-1 2025-02-21 15:15:56 -08:00
Fedor Korotkov 447a46c522 Integrate .setup_info tool (#216)
I generate the tool from the specs a few weeks ago using AI. This PR also is generated fully using AI.
2025-02-17 08:42:28 -08:00
Nikolay Edigaryev 345b223e76 Resolve the version of the VM image just built, not the one in the OCI (#217) 2025-02-16 20:28:00 +04:00
Nikolay Edigaryev 5f66cb1ca2 Use "-productVersion" instead of "--productVersion" to support Monterey (#215)
* Use "-productVersion" instead of "--productVersion" to support Monterey

* No need to relocate anything as we're starting from scratch (IPSW)
2025-02-16 01:03:05 +04:00
Nikolay Edigaryev 0542253d49 Ignore errors for "install available update" Ansible task (#213)
* Ignore errors for "install available update" Ansible task

* Do not fail when update_result is not defined
2025-02-13 17:07:58 -05:00
Nikolay Edigaryev cdc53f0a12 vanilla-monterey.pkr.hcl: remove duplicate extra_arguments (#212) 2025-02-12 18:39:37 +04:00
Nikolay Edigaryev 99e619e634 Increase vanilla VM images disk size from 40 to 50 GB and use "relocate" (#211) 2025-02-12 18:09:39 +04:00
Nikolay Edigaryev 946adbfc95 Use single instead of double quotes to avoid YAML syntax error (#210) 2025-02-12 03:39:32 +04:00
Nikolay Edigaryev e134909aa8 Provide a default when stdinpass variable is not set (#209) 2025-02-12 02:12:06 +04:00
Nikolay Edigaryev 998bbf8ca8 Parse available updates to avoid upgrading to the next macOS version (#208)
* Parse available updates to avoid upgrading to the next macOS version

* Do not override ANSIBLE_CONFIG with our ansible.cfg

Otherwise Packer + Ansible integration goes haywire.

Instead, only modify the required variables through ansible_env_vars.

* Support Monterey
2025-02-12 01:45:40 +04:00
Nikolay Edigaryev 5a55351c81 Use xargs fix for all vanilla images, not just Sequoia (#207) 2025-02-06 18:55:36 +04:00
Nikolay Edigaryev 64b1190f65 Only pass a single item to "softwareupdate --install" each time (#206) 2025-02-06 17:39:40 +04:00
Nikolay Edigaryev 4df29efc66 Run "softwareupdate" on vanilla images (#204)
* Run "softwareupdate" on vanilla images

* Install Command Line Tools for Xcode

* Run Ansible after password-less sudo is configured

* Don't use SFTP

* Fix Ansible playbook path

* No updates are available → No new software available

* stderr_lines → stderr

* Dynamically resolve MACOS_NUMBER
2025-02-01 01:23:11 +04:00
Fedor Korotkov b205e70322 macOS Sequoia 15.3 (#205) 2025-01-27 14:38:08 -05:00
Nikolay Edigaryev c18ef9c553 Use Slack workflows (#201)
* Use Slack workflows

* Use SLACK_WEBHOOK_URL
2025-01-14 23:47:30 +04:00
fedor cec270adb3 No software updates 2025-01-06 17:54:53 -05:00
fedor 6d14eaee8c Install recommended updates 2025-01-06 17:36:50 -05:00
Fedor Korotkov f1a9e22ed2 Fixed known host creation (#202)
`~/.ssh` should exist for `file` provisioner.
2025-01-06 14:35:10 -05:00
Fedor Korotkov 2545826772 Add github.com keys to ~/.ssh/known_hosts (#200)
* Add github.com keys to `~/.ssh/known_hosts`

* Static known hosts

* Fixed path
2025-01-06 09:54:14 -05:00
fedor 0b49ba6651 Xcode 16.2 2024-12-30 09:29:55 -05:00
jxlwqq e5474440fc Sequoia 15.2 (#199) 2024-12-28 05:31:37 -05:00
Nikolay Edigaryev 0c165a93d2 Compatibility with GitHub Actions Runner Images for /usr/local/bin (#198) 2024-12-11 19:56:48 +04:00
fedor d3ad77c873 Xcode 16.2 RC 2024-12-05 16:06:21 -05:00
Kevin M. Cox 40128d40e2 Update vanilla-sequoia.pkr.hcl (#196)
It looks like the tab sequence for the Time Zone screen changed in one of the releases after 15.0.

I've testing this key sequence manually and via a packer build and it works with macOS 15.1.1.
2024-12-05 01:27:54 +04:00
Fedor Korotkov 7920f0cda2 Include Xcode 15.1 in Somoma runner (#197)
We unintentionally pushed Xcode 16.1 variant for `sonoma-xcode` image. We plan to only include new versions of Xcode with Sequoia images.

Instead for removing the 16.1 artifact. Let's include it in the runner image for consistency.
2024-12-04 16:08:58 -05:00
Fedor Korotkov b3b4dafc83 Update cirrus.release.yml 2024-12-04 11:36:28 -05:00
fedor ae70c6052d Ignore curl failure 2024-11-26 10:18:40 -05:00
fedor 1ea5f77e35 Build Monterey 2024-11-26 09:02:31 -05:00
fedor 8392fd1b30 Xcode 16.2 Beta 3 2024-11-20 16:04:50 -05:00
Fedor Korotkov fdff7d8daf Sequoia 15.1.1 2024-11-19 22:15:26 -05:00
Michal Moczulski 6a01707630 Update Android dependencies (#195)
* Use latest stable versions of Android dependencies

* Fix link to Android command line tools
2024-11-13 09:05:09 -05:00
fedor 49718082b2 Updated disk sizes 2024-11-13 07:09:41 -05:00
Nikolay Edigaryev 5b17f4e264 Wait 30 minutes instead of 15 (#194)
Just to be sure.
2024-11-12 21:29:32 +04:00
Nikolay Edigaryev 14fb85f5b3 Disable apsd daemon and wait before shutting down (#193) 2024-11-12 21:26:35 +04:00
fedor c8a1e808b6 Xcode 16.2 Beta 2 2024-11-06 10:50:07 -05:00
Fedor Korotkov 8c1f0c213f Release Sequoia IPSW
Fixes #192
2024-11-04 13:43:48 -05:00
Fedor Korotkov 9875d24c4b Added 15.1 and 15.0.1 2024-11-03 22:37:22 -05:00
fedor 8425f62a71 Update one runner image at a time
So while the second one is building runners can download the first one.
2024-11-02 09:49:05 -04:00
fedor 7ebaf88c48 Include {15.1,15.0.1} into runner 2024-11-01 11:51:50 -04:00
fedor 639b46cb2f Update sonoma-xcode:{15.1,15.0.1} 2024-11-01 11:26:11 -04:00
fedor 77cc104d6d Updated release cadence to highlight supported Xcode version. 2024-10-31 15:55:48 -04:00
fedor 159d4c1c36 Xcode 16.1 2024-10-30 10:19:34 -07:00
fedor 2a0a476e3b Sequoia 15.1 2024-10-28 09:19:43 -07:00
fedor 74040f6870 Sort Xcodes to always install the freshest first
Seems it's leading to things like:

> Unable to connect to simulator.
2024-10-27 08:42:58 -07:00
fedor 9f061dacb4 Sort Xcodes to always install the freshest first
Seems it's leading to things like:

> Unable to connect to simulator.
2024-10-27 08:38:03 -07:00
Fedor Korotkov f8fd129df6 Xcode 16.2 Beta 1 2024-10-24 09:14:43 -07:00
fedor 80bedb81db Xcode 16.1 RC 2024-10-21 17:14:35 -04:00
fedor 7692f27396 Sequoia 15.1 RC 2024-10-21 17:10:02 -04:00
fedor 2bd3a78831 Quotes 2024-10-21 09:59:00 -04:00
fedor 39e0ccf2e4 Fixed command 2024-10-21 08:55:41 -04:00
fedor e3cad7e8c2 Reverse Xcode installation order 2024-10-21 07:21:43 -04:00
fedor 47f36a33f8 Retry downloads 2024-10-20 16:19:19 -04:00
fedor c198ef9957 Removed ADDITIONAL_RUNTIMES 2024-10-20 16:16:20 -04:00
fedor d038ed85d2 no only_if 2024-10-20 13:05:03 -04:00
fedor da102cc5e6 Additional runtimes 2024-10-20 12:36:59 -04:00
fedor b0520dfd1d Fixed empty runtimes 2024-10-20 11:27:03 -04:00
fedor 37c77845c8 Refactored release scripts 2024-10-19 11:14:07 -04:00
fedor 9a16028831 No additional_runtimes 2024-10-15 14:42:06 -04:00
fedor cd817762c5 Xcode 16.1 Beta 3 2024-10-15 14:40:31 -04:00
fedor 32c59db145 No additional runtimes 2024-10-06 20:44:48 -04:00
fedor 8dcd824d76 Default for additional_runtimes 2024-10-05 20:27:36 -04:00
Fedor Korotkov 200bc65efb Update vanilla-sequoia.pkr.hcl 2024-10-05 20:26:00 -04:00
Nikolay Edigaryev 74aca70ef6 Send Slack alerts on build failures (#189)
* Send Slack alerts on build failures

* Only send Slack notifications for failed cron builds
2024-10-01 14:54:02 -04:00
Fedor Korotkov 1e710b24b9 Pre-install gnupg (#188)
Useful for doing manual encription/decryption
2024-10-01 10:42:25 -04:00
Fedor Korotkov 26c6575d1c Add additional runtimes (#186) 2024-09-26 06:21:40 -04:00
Fedor Korotkov 63e491fbf8 Fixed version 2024-09-24 10:39:24 -04:00
Fedor Korotkov 600cb89e35 Start building Sequoia images (#184)
Only base the runner images. We are not planning to build per Xcode images to reduce amount of variants to support.

Related to #183
2024-09-19 10:45:24 -04:00
fedor dbde34c6a8 Reapply "Sonoma 14.6.1 (#170)" (#179)
This reverts commit 760e04e340.
2024-09-18 17:55:42 -07:00
Fedor Korotkov ef6d97a77e Build more images (#178)
Build Sequoia 15.0 and 15.1 separately since 15.0 is RC and about ot be released and 15.1 is still in beta.

Plus added Xcode 16 RC to the big runner image. But since it's RC put it first in the list so it's not default.
2024-09-10 10:18:11 -04:00
Fedor Korotkov 760e04e340 Revert "Sonoma 14.6.1 (#170)" (#179) 2024-09-10 08:39:26 -04:00
Nikolay Edigaryev b863116992 macOS Sequoia 15.1 beta 3 (#175)
* macOS Sequoia 15.1 beta 3

* No need to disable Voice Over
2024-09-09 14:57:03 +04:00
Isaac Halvorson 444b21aba2 Use Keyboard navigation instead of Voice Over for System Settings navigation (#174)
* Enable Keyboard navigation setting instead of using Voice Over for System Settings

* Only use space bar to get past final setup screen

* Remove unnecessary setdisplaysleep and setcomputersleep usage
2024-09-09 11:58:39 +04:00
fedor 525f51a54e macOS 15 beta 8 2024-08-31 09:44:45 -04:00
fedor 5c7259d9a9 Sequoia 15 Beta 5
And build on Sonoma
2024-08-23 13:00:23 -04:00
Fedor Korotkov 24ff639c4d Update .cirrus.yml
Don't build runner on beta
2024-08-12 16:06:31 -04:00
Fedor Korotkov 0be36e7056 Update .cirrus.yml 2024-08-12 15:31:28 -04:00
Fedor Korotkov ed0b1e4c15 sequoia 15.1 beta 2 2024-08-12 15:30:03 -04:00
Fedor Korotkov 489255bec4 Sonoma 14.6.1 (#170) 2024-08-07 14:12:46 -04:00
fedor 92c70a2e79 Proper Tags 2024-07-30 15:22:35 -04:00
fedor 5de5e0997b Sonoma 14.6 and Sequoia 15.1 2024-07-30 15:21:21 -04:00
Fedor Korotkov 127683c285 Sequoia Beta 3 (#166) 2024-07-11 09:36:31 -04:00
leavesster 98a8ed97a4 Update README.md (#165) 2024-07-05 22:06:22 -04:00
Fedor Korotkov 3d76cfe25e Do not use Sequoia hosts
Fixes https://github.com/cirruslabs/tart/issues/851
2024-07-01 11:31:47 -04:00
Fedor Korotkov 4a45e89e9f Update .cirrus.yml 2024-06-28 15:34:57 -04:00
Fedor Korotkov f887c42ab1 Don't use experimental yet 2024-06-28 15:20:03 -04:00
Fedor Korotkov cabda00d2a Sequoia Beta 2 (#164) 2024-06-24 15:45:08 -04:00
Fedor Korotkov 118270dd45 Use dev-mini-experimental for Sequoia images (#163) 2024-06-24 09:09:43 -04:00
fedor c80a91a5bf Longer SSH timeout 2024-06-17 16:14:12 -04:00
fedor da6beb5b44 Account for an extra screen and long user creation 2024-06-17 15:44:35 -04:00
Fedor Korotkov 7a36c811f9 macOS Sequoia (#161)
* macOS Sequoia

* Sequoia cadence and base/xcode variants
2024-06-17 10:56:57 -04:00
Fedor Korotkov 07be5a66be Update xcode.pkr.hcl 2024-06-10 16:42:24 -04:00
Fedor Korotkov 61f4dee507 Guarantee runner variant to have 100GB free disk space (#159)
Some of the clients require it and hence we use sparsed files it won't be actually 250GB images.
2024-06-05 08:37:35 -04:00
Fedor Korotkov fbcbf4cbfe Align Xcode location with GHA images (#157) 2024-05-17 16:59:24 -04:00
Fedor Korotkov c90679131d Install yq (#156)
fixes #155
2024-05-16 11:21:21 -04:00
Fedor Korotkov c9a92d7a31 Bump runner disk size
Due to all three latest Xcode have different version of simulators
2024-05-14 06:14:33 -04:00
Fedor Korotkov 2793f40e9a Xcode 15.4 (#154)
* Xcode 15.4

* Build runner on a release
2024-05-13 15:18:50 -04:00
Fedor Korotkov 7a7778be0f macOS 14.5 (#153) 2024-05-13 14:47:27 -04:00
Fedor Korotkov 6f7ef84825 Make sure /Users/runner exists in xcode variant (#152)
A follow-up to #145. It seems right now only base variant preserves the symlink. `xcode` and `runner` are missing it and my guess it's due to disk resizing.

This change adds a validation script, so we verify `/Users/runner` folder exists in every variant.
2024-05-13 07:56:29 -04:00
Fedor Korotkov d594e1add0 Install Git Credentials Helper and xcpretty/xcbeauty (#150)
* Install Git Credentials Helper and xcpretty/xcbeauty

Plus move rosetta installation and some other common packages into base variant.

* Fixed Node Path
2024-05-07 15:57:00 -04:00
Fedor Korotkov d50adeeaa2 Use latest Packer plugin (#149) 2024-05-02 13:10:34 -04:00
Fedor Korotkov 5d1abcb935 Lower the expected free disk size 2024-05-02 09:28:23 -04:00
Fedor Korotkov 8151177d8f Revert "Fixed Simulator Opening" (#148)
This reverts commit e45042edb8.
2024-05-02 09:27:49 -04:00
Fedor Korotkov 2cd59ec2b4 Fixed Simulator Opening (#146) 2024-05-01 15:39:25 +02:00
fedor 2dcf12940d Add Java to path 2024-05-01 08:07:25 -04:00
fedor acd0ec5913 Use OpenJDK 2024-05-01 08:00:09 -04:00
fedor f2d703668c Fixed JDK 2024-05-01 07:55:20 -04:00
fedor 54a41a1e0a Use sudo 2024-05-01 07:51:33 -04:00
Nikolay Edigaryev 57a0eb2d30 /Users/runner → /Users/admin symlink to support certain GitHub Actions (#145) 2024-04-22 11:04:53 -04:00
Fedor Korotkov c73a2a5fe9 Update .cirrus.yml 2024-04-22 05:01:14 -04:00
Fedor Korotkov 989b0d8f1a Updated ReadMe (#144)
Included release and update cadence of the images

Fixes #142
2024-04-18 14:07:51 -04:00
Fedor Korotkov 415bb40956 Install Node.js LTS (#143)
Right now `brew install node` installs the current version 21 of Node.js. Let's make sure we install an LTS version. It's updated not that often so can update it manually.
2024-04-18 21:11:25 +04:00
Fedor Korotkov 9ccac855c3 Update README.md 2024-04-08 12:41:50 -04:00
fedor 31bc126bc4 fixes 2024-04-07 20:10:13 -04:00
Fedor Korotkov 7932133d6f Pass as list 2024-04-07 19:38:13 -04:00
Fedor Korotkov c254792f80 Only two version of Ruby 2024-04-07 14:18:20 -04:00
Fedor Korotkov 00fd234514 Update .cirrus.yml 2024-04-05 15:55:30 -04:00
Fedor Korotkov df763eb2d6 Latest runner 2024-04-05 15:54:59 -04:00
Fedor Korotkov e1755912e6 Preinstall last 3 versions of Ruby (#141) 2024-04-05 10:29:53 -04:00
Fedor Korotkov f1715dca7b Automatically re-run tasks in case of network issues (#140)
* Automatically re-run tasks in case of network issues

* new line
2024-04-01 08:06:20 -04:00
Fedor Korotkov e89c673a33 Change macOS runner image name (#139)
To be consistent with ubuntu ones where tag is the version of OS.
2024-04-01 07:40:57 -04:00
fedor 264c3e8fb0 Fixed typo 2024-03-27 12:16:34 +04:00
fedor 0215733c42 Runner variant tweaks 2024-03-27 11:09:42 +04:00
fedor d3f7a8f37d Sonoma 14.4.1 2024-03-26 13:51:09 +04:00
Fedor KorotkovandNikolay Edigaryev 7026060433 Introduce Runner Variant (#138)
* Introduce Runner Variant

This image will contain multiple version of Xcode to pick with https://github.com/MobileDevOps/xcode-select-version-action

This image will updated weekly and will be warm on our runners.

* Introduce Runner Variant

This image will contain multiple version of Xcode to pick with https://github.com/MobileDevOps/xcode-select-version-action

This image will updated weekly and will be warm on our runners.

* Don't forget brackets

* Update templates/xcode.pkr.hcl

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2024-03-25 12:40:18 -04:00
Nikolay Edigaryev 9b2a899ea8 Enable UI automation by default (#137) 2024-03-19 10:32:12 -04:00
fedor 08d9f601e4 Fixed ReadMe examples 2024-03-11 14:02:48 -04:00
anders-nylander 8b0607128f Don't run rbenv'd gem commands with sudo (#135) 2024-03-11 08:36:49 -04:00
Fedor Korotkov bf9f6a6146 Sonoma 14.4 (#133) 2024-03-07 13:54:03 -05:00
Fedor Korotkov d367ab61c8 Fixed Xcode release 2024-03-06 07:55:57 -05:00
Fedor Korotkov f06b997060 Xcode 15.3 2024-03-06 07:53:50 -05:00
Fedor Korotkov 5b625c9167 Delete the right VM 2024-03-02 09:32:15 -05:00
Fedor Korotkov 03e06aff01 Fixed VM name 2024-03-02 08:25:55 -05:00
Fedor Korotkov 7849005130 Pull Vanilla Images (#132)
Don't forget to pull the latest Vanilla version first
2024-02-28 13:04:00 -05:00
Fedor Korotkov c03e2f3253 Concurrent builds (#131) 2024-02-28 11:04:51 -05:00
Fedor Korotkov 882cbe2344 Regularly update multiple tags (#130)
* Regularly update multiple tags

Update the last two version of macOS and the last two versions of Xcode for each of macOS versions.

Fixed #128

* Missing `matrix`
2024-02-27 17:14:29 -05:00
Fedor Korotkov 0cc9b01623 No need to populate /usr/local/bin/ (#129)
Plus we only need `add-certificate` during the build and don't need it in the image
2024-02-26 08:39:54 -05:00
Fedor Korotkov 9940dd3705 Backport language fix to Ventura and Sonoma (#126)
Fixes #125
Related to #107
2024-02-01 09:56:39 -05:00
Fedor Korotkov a1a1fd7d36 14.3 2024-01-25 14:17:35 -05:00
Fedor Korotkov fc41a4d619 Update .cirrus.yml 2024-01-25 12:43:27 -05:00
Fedor Korotkov a80bae15d9 Fixed full disk access (#124)
As the default was changed in Sonoma as reported in #113

Fixes #113
2024-01-24 12:33:37 -05:00
umläute 104e432eb4 parameterize 'xcodes' (#123)
Closes: https://github.com/cirruslabs/macos-image-templates/issues/122
2024-01-24 12:09:28 -05:00
Fedor Korotkov 002717156a Use local Xcode cache (#121) 2024-01-24 15:15:09 +04:00
Fedor Korotkov 13071e71be Just enable remote automation for Safari (#120)
Enabling `Develop` menu started failing in 14.3 with:

```console
Could not write domain /Users/admin/Library/Containers/com.apple.Safari/Data/Library/Preferences/com.apple.Safari; exiting
```

We actually only interested in enabling remote automation for CI which is done by `safaridriver`. Having `Develop` menu item is not necessary.
2024-01-23 14:14:16 -05:00
Fedor Korotkov fb83953b1b macOS 14.3 (#119)
Plus automatically update vanilla images
2024-01-22 13:34:52 -05:00
Nikolay Edigaryev 19ccfde91c Always install the latest GitHub Actions Runner (#117) 2024-01-17 08:56:53 -05:00
Fedor Korotkov 4b3f94df8d Update variables.pkrvars.hcl 2024-01-16 23:04:32 -05:00
Fedor Korotkov 5aa1d63f6a Update variables.pkrvars.hcl 2024-01-16 23:04:01 -05:00
fedor a63fb03f2e Ventura 13.6 2024-01-10 20:04:47 +04:00
Fedor Korotkov 8f93e8eae2 Removed chunking 2023-12-26 07:59:50 -05:00
Nikolay Edigaryev 8b9f6ce141 Tag vanilla image as 14.1 (#111)
Since we currently use UniversalMac_14.1_23B74_Restore.ipsw to build it.
2023-12-22 12:31:18 +04:00
Nikolay Edigaryev a9d8536f46 disable-sip.pkr.hcl: a better way to open Terminal (#110)
Without it, we open the "Share Disk..." menu option instead.

Also there's no more default language choice on Sonoma.
2023-12-21 21:03:02 +04:00
Nikolay Edigaryev 73dea7bcb0 Disable SIP in vanilla images (#109) 2023-12-20 19:14:56 +04:00
Nikolay Edigaryev e5f5edca05 .cirrus.yml: introduce "Update Vanilla Images" task (#108) 2023-12-20 15:11:26 +01:00
Nikolay Edigaryev 21522999bb Don't mistakenly select "English (UK)" language instead of "English" one (#107) 2023-12-19 12:12:17 +04:00
Nikolay Edigaryev 664d47260e Hide useless systemsetup errors and avoid scary Safari kill error (#106) 2023-12-15 11:14:20 +04:00
fedor 67a57c3064 Xcode 15.1 2023-12-12 21:56:50 +01:00
fedor fabd89cead Fixed tag 2023-12-12 21:56:10 +01:00
Fedor Korotkov b19d3fa66c Use alias for ECR pushes 2023-11-27 12:51:22 -05:00
Fedor Korotkov 3f1850ad07 ECR chunked push 2023-11-27 12:50:17 -05:00
Fedor Korotkov 4b7ac1f76f Increased timeout 2023-11-10 13:20:59 -05:00
Fedor Korotkov 98b522dbfa Push images to public ECR (#103)
* Push images to public ECR

Related to https://github.com/cirruslabs/tart/discussions/652

* Use the default alias until we get the custom one
2023-11-10 09:28:47 -05:00
fedor 41b20ab533 Revert "Pin version of activesupport (#101)"
This reverts commit 6555932569.
2023-11-06 11:22:57 -05:00
Fedor Korotkov b28936faa2 Xcode 15.0.1 2023-11-06 11:21:47 -05:00
fedor 3e3e6818f3 Sonoma 14.1 2023-10-25 16:10:45 -04:00
Fedor Korotkov 47695a9abd Runner 2.311.0 2023-10-23 16:30:43 -04:00
Fedor Korotkov 6555932569 Pin version of activesupport (#101)
* Pin version of `activesupport`

Fixes #100 while https://github.com/CocoaPods/CocoaPods/issues/12081 is not released.

* Fixed installation
2023-10-10 07:56:40 -04:00
Fedor Korotkov 4513f2adad GHA Runner 2.310.0 2023-10-09 09:51:05 -04:00
Fedor Korotkov 0a4f436302 Update README.md 2023-10-05 07:03:08 -04:00
Rui Marinho 277b13fb59 macOS 13.5.2 (#97) 2023-09-27 12:34:46 -04:00
Fedor Korotkov 19a8271935 Switch to Sonoma (#98)
Use RC and update all the scripts
2023-09-20 10:59:13 -04:00
fedor ba158f524c Removed quotes from Xcode version 2023-09-04 00:24:18 +02:00
fedor a34d6d3e51 macOS 13.5.1 2023-09-04 00:11:48 +02:00
Fedor Korotkov 59624221fe Update Xcode Image (#94)
During the monthly cron update. Fixes #93
2023-08-14 11:22:36 -04:00
Fedor Korotkov ac0d6efcf5 Update variables.pkrvars.hcl 2023-08-14 09:29:17 -04:00
Fedor Korotkov 4e75d95247 Update variables.pkrvars.hcl 2023-07-25 09:19:13 -04:00
fedor 7fcf10afd6 Build sonoma 2023-07-13 06:46:47 -04:00
fedor 0f7f741d45 Use latest 2023-07-13 06:46:17 -04:00
fedor f0e06a7c5e Bump the GHA runner 2023-07-13 06:46:09 -04:00
Melvin GundlachandMelvin Gundlach 21e5a3eb86 Update vanilla-sonoma to Beta 3 Update (#91)
Co-authored-by: Melvin Gundlach <mgundlach@it-economics.de>
2023-07-12 07:46:12 -04:00
Melvin GundlachandMelvin Gundlach a2d379b619 Update vanilla-sonoma to Beta 3 (#90)
Co-authored-by: Melvin Gundlach <mgundlach@it-economics.de>
2023-07-11 07:50:09 -04:00
Grigory Entin 5d00757016 Disabled screensaver for admin user. (#88) 2023-06-22 18:50:44 +04:00
32 changed files with 1469 additions and 211 deletions
+29
View File
@@ -0,0 +1,29 @@
task:
name: "Update Base Images ($MACOS_VERSION)"
alias: update-base
matrix:
- env:
MACOS_VERSION: ventura
DISABLE_SIP_TEMPLATE: disable-sip.pkr.hcl
- env:
MACOS_VERSION: sonoma
DISABLE_SIP_TEMPLATE: disable-sip.pkr.hcl
- env:
MACOS_VERSION: sequoia
DISABLE_SIP_TEMPLATE: disable-sip-with-username.pkr.hcl
- env:
MACOS_VERSION: tahoe
DISABLE_SIP_TEMPLATE: disable-sip-with-username.pkr.hcl
<<: *defaults
pull_vanilla_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
build_base_script:
- packer init templates/base.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
disable_sip_script:
- packer build -var vm_name=$MACOS_VERSION-base "templates/${DISABLE_SIP_TEMPLATE}"
push_base_script:
- tart push $MACOS_VERSION-base ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
always:
cleanup_script:
- tart delete $MACOS_VERSION-base
+21
View File
@@ -0,0 +1,21 @@
task:
name: "Release Xcode $CIRRUS_TAG ($MACOS_VERSION)"
matrix:
- env:
MACOS_VERSION: sequoia
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$CIRRUS_TAG\"]" templates/xcode.pkr.hcl
push_script: |
if [[ $CIRRUS_TAG == *"beta"* ]]
then
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG
else
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete $MACOS_VERSION-xcode:$CIRRUS_TAG || true
+34
View File
@@ -0,0 +1,34 @@
task:
name: "Update Runner Image ($MACOS_VERSION)"
execution_lock: runner-image-update
env:
matrix:
- MACOS_VERSION: sonoma
XCODE_VERSIONS: "16.1,16,15.4"
ADDITIONAL_IOS_BUILDS: "17.5"
DISK_SIZE: 275
- MACOS_VERSION: sequoia
XCODE_VERSIONS: "16.4,\"26-beta-7\",16.3,16.2,16.1,16"
ADDITIONAL_IOS_BUILDS: "18.5,18.4,18.2,17.5"
DISK_SIZE: 600
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
init_xcode_script: packer init templates/xcode.pkr.hcl
build_xcode_script: |
packer build -var tag=runner -var disk_size=$DISK_SIZE \
-var disk_free_mb=100000 \
-var macos_version="$MACOS_VERSION" \
-var xcode_version="[$XCODE_VERSIONS]" \
-var additional_ios_builds="[$ADDITIONAL_IOS_BUILDS]" \
-var expected_runtimes_file="data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
push_script: |
if [[ -z "$CIRRUS_PR" ]]; then
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
else
echo "Skipping pushing for PR..."
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:runner"
+28
View File
@@ -0,0 +1,28 @@
env:
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
task:
name: "Update Vanilla Image ($MACOS_VERSION)"
env:
matrix:
- MACOS_VERSION: tahoe
- MACOS_VERSION: sequoia
- MACOS_VERSION: sonoma
- MACOS_VERSION: ventura
- MACOS_VERSION: monterey
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
<<: *defaults
build_script:
- packer init templates/vanilla-$MACOS_VERSION.pkr.hcl
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
resolve_macos_number_script:
- packer build -var vm_base_name=$MACOS_VERSION-vanilla -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
- rm $RESOLVE_FILE
- tart delete $RESOLVE_VM_NAME
push_script:
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
always:
cleanup_script:
- tart delete $MACOS_VERSION-vanilla
+46
View File
@@ -0,0 +1,46 @@
task:
name: "Update Xcode Images ($MACOS_VERSION $XCODE_VERSION)"
depends_on: update-base
env:
matrix:
- MACOS_VERSION: tahoe
XCODE_VERSION: 26-beta-7
XCODE_COMPONENTS: "MetalToolchain"
LATEST: true
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.4
LATEST: true
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.3
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.2
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.1
- MACOS_VERSION: sequoia
XCODE_VERSION: 16
- MACOS_VERSION: sonoma
XCODE_VERSION: 16.1
LATEST: true
- MACOS_VERSION: sonoma
XCODE_VERSION: 16
- MACOS_VERSION: sonoma
XCODE_VERSION: 15.4
- MACOS_VERSION: ventura
XCODE_VERSION: 15.4
LATEST: true
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_xcode_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$XCODE_VERSION\"]" -var xcode_components="[\"$XCODE_COMPONENTS\"]" templates/xcode.pkr.hcl
push_script: |
if [[ -z "$LATEST" ]]
then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION"
+52
View File
@@ -0,0 +1,52 @@
load("cirrus", "env", "http", "fs", "changes_include")
load("github.com/cirrus-modules/graphql", "rerun_task_if_issue_in_logs")
def on_task_failed(ctx):
if ctx.payload.data.task.automaticReRun:
print("Task is already an automatic re-run! Won't even try to re-run it...")
return
rerun_task_if_issue_in_logs(ctx.payload.data.task.id, "The network connection was lost")
def on_build_failed(ctx):
# Only send Slack notifications for failed cron builds[1]
#
# [1]: https://cirrus-ci.org/guide/writing-tasks/#cron-builds
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
return
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
"Content-Type": "application/json",
}, json_body={
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
build_id=ctx.payload.data.build.id,
change_message_title=ctx.payload.data.build.changeMessageTitle,
branch_name=ctx.payload.data.build.branch,
repository_name=ctx.payload.data.repository.name,
),
"url": "https://cirrus-ci.com/build/{build_id}".format(
build_id=ctx.payload.data.build.id,
),
})
if resp.status_code != 200:
fail("failed to post message to Slack: got unexpected HTTP {}".format(resp.status_code))
resp_json = resp.json()
if resp_json["ok"] != True:
fail("got error when posting message to Slack: {}".format(resp_json["error"]))
def main(ctx):
result = fs.read(".ci/cirrus.vanilla.yml")
if env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.release.yml")
if env.get("CIRRUS_CRON") == "monthly":
result += fs.read(".ci/cirrus.base.yml")
result += fs.read(".ci/cirrus.xcode.yml")
prForRunners = env.get("CIRRUS_PR") and changes_include(".ci/cirrus.runner.yml")
if prForRunners or env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.runner.yml")
return result
+17 -48
View File
@@ -1,52 +1,21 @@
task:
name: "Update Base Image"
only_if: $CIRRUS_CRON != ""
persistent_worker:
labels:
name: dev-mini
env:
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
update_script: brew update && brew upgrade
info_script:
- tart --version
- packer --version
build_script:
- packer init templates/base.pkr.hcl
- packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
push_script:
- tart push ventura-base ghcr.io/cirruslabs/macos-ventura-base:latest
always:
cleanup_script:
- tart delete ventura-base
persistent_worker:
labels:
name: dev-mini
resources:
tart-vms: 1
task:
name: "Release Xcode $CIRRUS_TAG"
only_if: $CIRRUS_TAG != ""
persistent_worker:
labels:
name: dev-mini
env:
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
update_script: brew update && brew upgrade
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
AWS_ACCESS_KEY_ID: ENCRYPTED[c187b670a17eead88c1698849376273991d09678efe37ae2f0c9738c27a2422741a71c501ef4b6a4df7bff3eca5213a9]
AWS_SECRET_ACCESS_KEY: ENCRYPTED[e456254a53b82e3167f2da23e24c389620cb3f7d47e4e5e7d993813bf9bb18c784d5cb8d88d19632073acc9e1f6096c9]
defaults: &defaults
timeout_in: 3h
update_script:
- brew update || true
- brew upgrade || true
info_script:
- tart --version
- packer --version
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-ventura-base:latest
- tart clone ghcr.io/cirruslabs/macos-ventura-base:latest ventura-base
build_script:
- packer init templates/xcode.pkr.hcl
- packer build -var-file="variables.pkrvars.hcl" -var xcode_version="$CIRRUS_TAG" templates/xcode.pkr.hcl
push_script: |
if [[ $CIRRUS_TAG == *"beta"* ]]
then
tart push ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:$CIRRUS_TAG
else
tart push ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:latest
fi
always:
cleanup_script:
- tart delete ventura-base || true
- tart delete ventura-xcode:$CIRRUS_TAG || true
+25
View File
@@ -0,0 +1,25 @@
## Building Vanilla Image
To build `macos-sonoma-vanilla`:
```bash
packer build templates/vanilla-sonoma.pkr.hcl
```
Optionally, SIP can be disabled for each image by running the following commands:
```bash
packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
```
## Building Base Image
```bash
packer build -var macos_version=sonoma templates/base.pkr.hcl
```
## Building Xcode Image
```bash
packer build -var macos_version=sonoma -var xcode_version="[15.4]" templates/xcode.pkr.hcl
```
+15 -36
View File
@@ -1,45 +1,24 @@
## macOS Packer Templates for Cirrus CI
## macOS Packer Templates for Tart
Repository with Packer templates to build [Tart VMs](https://github.com/cirruslabs/tart) to use with [Cirrus CI](https://cirrus-ci.org/guide/macOS/).
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with [Cirrus Runners](https://cirrus-runners.app/),
[Cirrus CI](https://cirrus-ci.org/guide/macOS/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
* `macos-{monterey,ventura}-vanilla` image has nothing pre-installed
* `macos-{monterey,ventura}-base` image has only `brew` pre-installed
* `macos-{monterey,ventura}-xcode:N` image is based on `macos-{monterey,ventura}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
The following image variants are currently available:
See a full list of VMs available on Cirrus CI [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
* `macos-{sequoia,sonoma}-base` image has only `brew` pre-installed and the latest version of `macOS` available
* `macos-{sequoia,sonoma}-xcode:N` image is based on `macos-{sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
* `macos-runner:{sequoia,sonoma}` image is a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
## Building Vanilla Image
See a full list of VMs available [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
To build `macos-monterey-vanilla`:
## Release Cadence
```bash
packer build templates/vanilla-monterey.pkr.hcl
```
Once a new version of Xcode is released, we will initiate a GitHub release which will automatically build and push
a new version of the `macos-sequoia-xcode:N`. This generally happens the next weekend after a release.
Please watch this repository releases to get notified about new images.
To build `macos-ventura-vanilla`:
## Update Cadence
```bash
packer build templates/vanilla-ventura.pkr.hcl
```
Some of the images are regularly getting rebuild in order to update the pre-installed packages.
Optionally, SIP can be disabled for each image by running the following commands:
```bash
packer build -var vm_name=monterey-vanilla templates/disable-sip.pkr.hcl
```
```bash
packer build -var vm_name=ventura-vanilla templates/disable-sip.pkr.hcl
```
## Building Base Image
```bash
packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
```
## Building Xcode Image
```bash
packer build -var-file="variables.pkrvars.hcl" templates/xcode.pkr.hcl
```
[This configuration file](.ci/cirrus.release.yml) defines images that are getting rebuilt monthly on the first Saturday of the month.
+5
View File
@@ -0,0 +1,5 @@
- hosts: default
roles:
- system-updater
vars:
ansible_password: admin
@@ -0,0 +1,37 @@
- name: Perform first "softwareupdate" invocation
include_tasks: softwareupdate.yml
# Needed after a major macOS update, otherwise things like
# Command Line Tools won't be updated
- name: Perform second "softwareupdate" invocation
include_tasks: softwareupdate.yml
# This one looks weird, but unfortunately there's no other way around, because Homebrew
# is not designed to run as root (see https://gist.github.com/irazasyed/7732946
# for more details).
- name: fix up /usr/local permissions for Homebrew
file:
path: /usr/local/share/man
state: directory
owner: "{{ ansible_user_id }}"
recurse: yes
become: yes
- name: "ensure that there are no more software updates available: check for available updates"
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: "ensure that there are no more software updates available: parse available updates"
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: "ensure that there are no more software updates available: print available updates"
debug:
var: software_updates
- name: "ensure that there are no more software updates available: fail if some updates were not installed"
fail:
msg: "Found unapplied update: {{ item.label }}"
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
@@ -0,0 +1,43 @@
- name: check for available updates
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: parse available updates
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: print available updates
debug:
var: software_updates
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
- name: install available update
command:
cmd: "softwareupdate --install --agree-to-license --force --restart --user admin --stdinpass {{ stdinpass | default('') }} '{{ item.label }}'"
stdin: "{{ ansible_password }}"
register: update_result
# Work around the following:
# > Data could not be sent to remote host [...].
# > Make sure this host can be reached over ssh:
# > ssh: connect to host [...] port 22: Connection refused.
ignore_unreachable: yes
# Ignore SIGTERM/SIGKILL sent "softwareupdate" process
# when the system reboots due to --restart and any other errors,
# since we'll check whether the update was installed in main.yml
# anyway.
ignore_errors: yes
become: yes
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
# Wait for the connection since the previous command could restart the host
- name: wait for connection
wait_for_connection:
# We need to wait long enough for the "softwareupdate" to initiate the reboot,
# otherwise it's possible that we'll interrupt the process by running
# the commands below on a non-restarted system.
delay: 60
timeout: 1800
when: update_result is defined and not update_result.skipped | default(false)
+19
View File
@@ -0,0 +1,19 @@
== Runtimes ==
iOS 17.5 (17.5 - 21F79) - com.apple.CoreSimulator.SimRuntime.iOS-17-5
iOS 18.0 (18.0 - 22A3351) - com.apple.CoreSimulator.SimRuntime.iOS-18-0
iOS 18.1 (18.1 - 22B81) - com.apple.CoreSimulator.SimRuntime.iOS-18-1
iOS 18.2 (18.2 - 22C150) - com.apple.CoreSimulator.SimRuntime.iOS-18-2
iOS 18.3 (18.3.1 - 22D8075) - com.apple.CoreSimulator.SimRuntime.iOS-18-3
iOS 18.4 (18.4 - 22E238) - com.apple.CoreSimulator.SimRuntime.iOS-18-4
iOS 18.5 (18.5 - 22F77) - com.apple.CoreSimulator.SimRuntime.iOS-18-5
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0 - 23A5326a) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
tvOS 18.4 (18.4 - 22L254) - com.apple.CoreSimulator.SimRuntime.tvOS-18-4
tvOS 18.5 (18.5 - 22L572) - com.apple.CoreSimulator.SimRuntime.tvOS-18-5
tvOS 26.0 (26.0 - 23J5346a) - com.apple.CoreSimulator.SimRuntime.tvOS-26-0
watchOS 11.4 (11.4 - 22T250) - com.apple.CoreSimulator.SimRuntime.watchOS-11-4
watchOS 11.5 (11.5 - 22T572) - com.apple.CoreSimulator.SimRuntime.watchOS-11-5
watchOS 26.0 (26.0 - 23R5346a) - com.apple.CoreSimulator.SimRuntime.watchOS-26-0
visionOS 2.4 (2.4 - 22O237) - com.apple.CoreSimulator.SimRuntime.xrOS-2-4
visionOS 2.5 (2.5 - 22O473) - com.apple.CoreSimulator.SimRuntime.xrOS-2-5
visionOS 26.0 (26.0 - 23M5328a) - com.apple.CoreSimulator.SimRuntime.xrOS-26-0
+13
View File
@@ -0,0 +1,13 @@
== Runtimes ==
iOS 17.5 (17.5 - 21F79) - com.apple.CoreSimulator.SimRuntime.iOS-17-5
iOS 18.0 (18.0 - 22A3351) - com.apple.CoreSimulator.SimRuntime.iOS-18-0
iOS 18.1 (18.1 - 22B81) - com.apple.CoreSimulator.SimRuntime.iOS-18-1
tvOS 17.5 (17.5 - 21L569) - com.apple.CoreSimulator.SimRuntime.tvOS-17-5
tvOS 18.0 (18.0 - 22J356) - com.apple.CoreSimulator.SimRuntime.tvOS-18-0
tvOS 18.1 (18.1 - 22J578) - com.apple.CoreSimulator.SimRuntime.tvOS-18-1
watchOS 10.5 (10.5 - 21T575) - com.apple.CoreSimulator.SimRuntime.watchOS-10-5
watchOS 11.0 (11.0 - 22R349) - com.apple.CoreSimulator.SimRuntime.watchOS-11-0
watchOS 11.1 (11.1 - 22R581) - com.apple.CoreSimulator.SimRuntime.watchOS-11-1
visionOS 1.2 (1.2 - 21O5565d) - com.apple.CoreSimulator.SimRuntime.xrOS-1-2
visionOS 2.0 (2.0 - 22N318) - com.apple.CoreSimulator.SimRuntime.xrOS-2-0
visionOS 2.1 (2.1 - 22N580) - com.apple.CoreSimulator.SimRuntime.xrOS-2-1
+5
View File
@@ -0,0 +1,5 @@
== Runtimes ==
iOS 26.0 (26.0 - 23A5287g) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
tvOS 26.0 (26.0 - 23J5306f) - com.apple.CoreSimulator.SimRuntime.tvOS-26-0
watchOS 26.0 (26.0 - 23R5307g) - com.apple.CoreSimulator.SimRuntime.watchOS-26-0
visionOS 26.0 (26.0 - 23M5290f) - com.apple.CoreSimulator.SimRuntime.xrOS-26-0
+3
View File
@@ -0,0 +1,3 @@
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
+52
View File
@@ -0,0 +1,52 @@
[
{
"group": "Runner Detail",
"detail": [
{
"name": "OS Information",
"script": "echo \"macOS $(sw_vers -productVersion) ($(sw_vers -buildVersion))\""
},
{
"name": "Build Date",
"script": "date +\"%Y-%m-%d\""
}
]
},
{
"group": "Software Detail",
"detail": [
{
"name": "Xcode Versions",
"script": "xcodes installed --no-color || echo \"Xcode not installed\""
},
{
"name": "Python Version",
"script": "python3 --version"
},
{
"name": "Node Version",
"script": "node --version"
},
{
"name": "Ruby Version",
"script": "ruby --version"
},
{
"name": "Bundler Version",
"script": "bundler --version"
},
{
"name": "CocoaPods Version",
"script": "pod --version"
},
{
"name": "Fastlane Version",
"script": "fastlane --version"
},
{
"name": "SwiftLint Version",
"script": "swiftlint --version"
}
]
}
]
+30
View File
@@ -0,0 +1,30 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>org.cirruslabs.tart-guest-agent</string>
<key>ProgramArguments</key>
<array>
<string>/opt/homebrew/bin/tart-guest-agent</string>
<string>--run-agent</string>
</array>
<key>EnvironmentVariables</key>
<dict>
<key>PATH</key>
<string>/bin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/homebrew/bin</string>
<key>TERM</key>
<string>xterm-256color</string>
</dict>
<key>WorkingDirectory</key>
<string>/Users/admin</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<true/>
<key>StandardOutPath</key>
<string>/tmp/tart-guest-agent.log</string>
<key>StandardErrorPath</key>
<string>/tmp/tart-guest-agent.log</string>
</dict>
</plist>
+28
View File
@@ -0,0 +1,28 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>org.cirruslabs.tart-guest-daemon</string>
<key>ProgramArguments</key>
<array>
<string>/opt/homebrew/bin/tart-guest-agent</string>
<string>--run-daemon</string>
</array>
<key>EnvironmentVariables</key>
<dict>
<key>PATH</key>
<string>/bin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/homebrew/bin</string>
</dict>
<key>WorkingDirectory</key>
<string>/var/empty</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<true/>
<key>StandardOutPath</key>
<string>/tmp/tart-guest-daemon.log</string>
<key>StandardErrorPath</key>
<string>/tmp/tart-guest-daemon.log</string>
</dict>
</plist>
+6
View File
@@ -0,0 +1,6 @@
#!/usr/bin/expect -f
spawn automationmodetool enable-automationmode-without-authentication
expect "Enter the password for user 'admin':"
send "admin\n"
expect "Setting up machine to allow Automation Mode without requiring user authentication... succeeded."
+20
View File
@@ -0,0 +1,20 @@
#!/bin/bash
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
source ~/.zprofile
brew install jq
DOWNLOAD_URL=$(curl -sS 'https://api.github.com/repos/actions/runner/releases/latest' | jq --raw-output '.assets[] | select(.name | test("actions-runner-osx-arm64-[0-9.]+.tar.gz")) | .browser_download_url')
rm -rf actions-runner && mkdir actions-runner && cd actions-runner
wget -O - "${DOWNLOAD_URL}" | tar xz
+84 -18
View File
@@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 1.2.0"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
@@ -11,12 +11,8 @@ variable "macos_version" {
type = string
}
variable "gha_version" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:13.4"
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:latest"
vm_name = "${var.macos_version}-base"
cpu_count = 4
memory_gb = 8
@@ -53,15 +49,6 @@ build {
]
}
provisioner "shell" {
inline = [
"cd $HOME",
"mkdir actions-runner && cd actions-runner",
"curl -O -L https://github.com/actions/runner/releases/download/v${var.gha_version}/actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"tar xzf ./actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"rm actions-runner-osx-arm64-${var.gha_version}.tar.gz",
]
}
provisioner "shell" {
inline = [
"/bin/bash -c \"$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\"",
@@ -69,13 +56,49 @@ build {
"echo 'eval \"$(/opt/homebrew/bin/brew shellenv)\"' >> ~/.zprofile",
"echo \"export HOMEBREW_NO_AUTO_UPDATE=1\" >> ~/.zprofile",
"echo \"export HOMEBREW_NO_INSTALL_CLEANUP=1\" >> ~/.zprofile",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew --version",
"brew update",
"brew install wget cmake gcc git-lfs jq gh gitlab-runner",
"brew install wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
"brew install curl || true", // doesn't work on Monterey
"brew install --cask git-credential-manager",
"git lfs install",
"sudo softwareupdate --install-rosetta --agree-to-license"
]
}
// Add GitHub to known hosts
// Similar to https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/configure-ssh.sh
provisioner "shell" {
inline = [
"mkdir -p ~/.ssh"
]
}
provisioner "file" {
source = "data/github_known_hosts"
destination = "~/.ssh/known_hosts"
}
// Install the GitHub Actions runner
provisioner "shell" {
script = "scripts/install-actions-runner.sh"
}
// Create a /Users/runner → /Users/admin symlink to support certain GitHub Actions
// like ruby/setup-ruby that hard-code the "/Users/runner/hostedtoolcache" path[1]
//
// [1]: https://github.com/ruby/setup-ruby/blob/6bd3d993c602f6b675728ebaecb2b569ff86e99b/common.js#L268
provisioner "shell" {
inline = [
"sudo ln -s /Users/admin /Users/runner"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
@@ -84,7 +107,7 @@ build {
"echo 'if which rbenv > /dev/null; then eval \"$(rbenv init -)\"; fi' >> ~/.zprofile",
"source ~/.zprofile",
"rbenv install 2.7.8", // latest 2.x.x before EOL
"rbenv install $(rbenv install -l | grep -v - | tail -1)",
"rbenv install -l | grep -v - | tail -2 | xargs -L1 rbenv install",
"rbenv global $(rbenv install -l | grep -v - | tail -1)",
"gem install bundler",
]
@@ -92,7 +115,9 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install node",
"brew install node@20",
"echo 'export PATH=\"/opt/homebrew/opt/node@20/bin:$PATH\"' >> ~/.zprofile",
"source ~/.zprofile",
"node --version",
"npm install --global yarn",
"yarn --version",
@@ -109,4 +134,45 @@ build {
"brew install awscli"
]
}
# Enable UI automation, see https://github.com/cirruslabs/macos-image-templates/issues/136
provisioner "shell" {
script = "scripts/automationmodetool.expect"
}
// some other health checks
provisioner "shell" {
inline = [
"source ~/.zprofile",
"test -d /Users/runner",
"test -f ~/.ssh/known_hosts"
]
}
// Guest agent for Tart VMs
provisioner "file" {
source = "data/tart-guest-daemon.plist"
destination = "~/tart-guest-daemon.plist"
}
provisioner "file" {
source = "data/tart-guest-agent.plist"
destination = "~/tart-guest-agent.plist"
}
provisioner "shell" {
inline = [
# Install Tart Guest Agent
"source ~/.zprofile",
"brew install cirruslabs/cli/tart-guest-agent",
# Install daemon variant of the Tart Guest Agent
"sudo mv ~/tart-guest-daemon.plist /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
"sudo chown root:wheel /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
"sudo chmod 0644 /Library/LaunchDaemons/org.cirruslabs.tart-guest-daemon.plist",
# Install agent variant of the Tart Guest Agent
"sudo mv ~/tart-guest-agent.plist /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
"sudo chown root:wheel /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
"sudo chmod 0644 /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
]
}
}
@@ -0,0 +1,39 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_name" {
type = string
}
source "tart-cli" "tart" {
vm_name = "${var.vm_name}"
recovery = true
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
communicator = "none"
boot_command = [
# Skip over "Macintosh" and select "Options"
# to boot into macOS Recovery
"<wait60s><right><right><enter>",
# Open Terminal
"<wait10s><leftAltOn>T<leftAltOff>",
# Disable SIP
"<wait10s>csrutil disable<enter>",
"<wait10s>y<enter>",
"<wait10s>admin<enter>",
"<wait10s>admin<enter>",
# Shutdown
"<wait10s>halt<enter>"
]
}
build {
sources = ["source.tart-cli.tart"]
}
+2 -5
View File
@@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 1.2.0"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
@@ -22,11 +22,8 @@ source "tart-cli" "tart" {
# Skip over "Macintosh" and select "Options"
# to boot into macOS Recovery
"<wait60s><right><right><enter>",
# Select default language
"<wait10s><enter>",
# Open Terminal
"<wait10s><leftCtrlOn><f2><leftCtrlOff>",
"<right><right><right><right><down><down><down><enter>",
"<wait10s><leftAltOn>T<leftAltOff>",
# Disable SIP
"<wait10s>csrutil disable<enter>",
"<wait10s>y<enter>",
+48
View File
@@ -0,0 +1,48 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_base_name" {
type = string
}
variable "vm_name" {
type = string
}
variable "resolve_file" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "${var.vm_base_name}"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
# Use "-productVersion" instead of "--productVersion"
# to support old-style syntax used on macOS Monterey
"sw_vers -productVersion > /tmp/sw-vers-product-version.txt",
]
}
provisioner "file" {
source = "/tmp/sw-vers-product-version.txt"
destination = "${var.resolve_file}"
direction = "download"
}
}
+49 -13
View File
@@ -4,25 +4,34 @@ packer {
version = ">= 1.2.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
# and https://www.theiphonewiki.com/wiki/Beta_Firmware/Mac/13.x
from_ipsw = "https://updates.cdn-apple.com/2022FallFCS/fullrestores/012-40537/0EC7C669-13E9-49FB-BD64-9EECC1D174B2/UniversalMac_12.6_21G115_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2022FallFCS/fullrestores/012-66032/8D8D90C6-A876-4FFF-BBF4-D158939B3841/UniversalMac_12.6.1_21G217_Restore.ipsw"
vm_name = "monterey-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language
"<wait30s><enter>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
@@ -74,6 +83,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -90,18 +102,20 @@ build {
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off",
"sudo systemsetup -setsleep Off",
"sudo systemsetup -setcomputersleep Off",
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"sleep 3",
"kill -9 %1",
// Enable Safari's remote automation and "Develop" menu
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
"defaults write com.apple.Safari IncludeDevelopMenu -bool true",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
@@ -109,4 +123,26 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
"--extra-vars", "stdinpass=admin",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+176
View File
@@ -0,0 +1,176 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2025SummerFCS/fullrestores/093-10809/CFD6DD38-DAF0-40DA-854F-31AAD1294C6F/UniversalMac_15.6.1_24G90_Restore.ipsw"
vm_name = "sequoia-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab>UTC<enter><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><spacebar>",
# Welcome to Mac
"<wait10s><spacebar>",
# Disable Voice Over
"<leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Now that the installation is done, open "System Settings"
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (2/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+49 -24
View File
@@ -1,31 +1,36 @@
packer {
required_plugins {
tart = {
version = ">= 1.2.0"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
# Currently macOS 14 (Sonoma) can only be obtained via the following links:
# unauthenticated[1] and authenticated[2].
#
# [1]: https://updates.cdn-apple.com/2023SummerSeed/fullrestores/032-95861/67600C59-8516-4A46-B9D7-4007D395CEF5/UniversalMac_14.0_23A5276g_Restore.ipsw
# [2]: https://download.developer.apple.com/WWDC_2023/macOS_14_Beta_Restore_Images/UniversalMac_14.0_23A5257q_Restore.ipsw
from_ipsw = "https://updates.cdn-apple.com/2023SummerSeed/fullrestores/032-95861/67600C59-8516-4A46-B9D7-4007D395CEF5/UniversalMac_14.0_23A5276g_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2024SummerFCS/fullrestores/062-52859/932E0A8F-6644-4759-82DA-F8FA8DEA806A/UniversalMac_14.6.1_23G93_Restore.ipsw"
vm_name = "sonoma-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language
"<wait30s>english<enter>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
@@ -70,12 +75,6 @@ source "tart-cli" "tart" {
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Open "Remote Login" details
"<wait10s><tab><spacebar>",
# Enable "Full Disk Access"
"<wait10s><tab><spacebar>",
# Click "Done"
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><spacebar>",
# Disable Voice Over
"<leftAltOn><f5><leftAltOff>",
]
@@ -83,6 +82,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -99,18 +101,20 @@ build {
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off",
"sudo systemsetup -setsleep Off",
"sudo systemsetup -setcomputersleep Off",
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 %1",
// Enable Safari's remote automation and "Develop" menu
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
"defaults write com.apple.Safari IncludeDevelopMenu -bool true",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
@@ -118,4 +122,25 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+180
View File
@@ -0,0 +1,180 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2025SummerSeed/fullrestores/093-26148/FDF54F82-98DF-4285-A0DB-CB30F4F93C71/UniversalMac_26.0_25A5349a_Restore.ipsw"
vm_name = "tahoe-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s><tab><tab><tab><tab><tab><tab>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><tab><spacebar>",
# Welcome to Mac
"<wait30s><spacebar>",
# Disable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Now that the installation is done, open "System Settings"
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<wait10s><enter>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (2/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools .*\\)/\\1/p' | tr '\\n' '\\0' | xargs -0 -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+49 -12
View File
@@ -1,28 +1,38 @@
packer {
required_plugins {
tart = {
version = ">= 1.2.0"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
# and https://www.theiphonewiki.com/wiki/Beta_Firmware/Mac/13.x
from_ipsw = "https://updates.cdn-apple.com/2023SpringFCS/fullrestores/032-84884/F97A22EE-9B5E-4FD5-94C1-B39DCEE8D80F/UniversalMac_13.4_22F66_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2023FallFCS/fullrestores/042-55833/C0830847-A2F8-458F-B680-967991820931/UniversalMac_13.6_22G120_Restore.ipsw"
vm_name = "ventura-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language
"<wait30s>english<enter>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Written and Spoken Languages
@@ -80,6 +90,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -96,23 +109,47 @@ build {
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setdisplaysleep Off",
"sudo systemsetup -setsleep Off",
"sudo systemsetup -setcomputersleep Off",
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
"sudo systemsetup -setsleep Off 2>/dev/null",
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 %1",
// Enable Safari's remote automation and "Develop" menu
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
"defaults write com.apple.Safari IncludeDevelopMenu -bool true",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
"defaults -currentHost write com.apple.screensaver idleTime 0"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+265 -52
View File
@@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 1.2.0"
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
@@ -12,60 +12,109 @@ variable "macos_version" {
}
variable "xcode_version" {
type = string
type = list(string)
}
variable "gha_version" {
variable "additional_ios_builds" {
type = list(string)
default = []
}
variable "xcode_components" {
type = list(string)
default = []
description = "Additional Xcode components to download."
}
variable "expected_runtimes_file" {
type = string
default = ""
description = "Path to file containing expected simulator runtimes. If empty, runtime verification is skipped."
}
variable "tag" {
type = string
default = ""
}
variable "disk_size" {
type = number
default = 120
}
variable "disk_free_mb" {
type = number
default = 15000
}
variable "android_sdk_tools_version" {
type = string
default = "9477386" # https://developer.android.com/studio/#command-tools
default = "11076708" # https://developer.android.com/studio#command-line-tools-only
}
source "tart-cli" "tart" {
vm_base_name = "${var.macos_version}-base"
vm_name = "${var.macos_version}-xcode:${var.xcode_version}"
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-base:latest"
// use tag or the last element of the xcode_version list
vm_name = "${var.macos_version}-xcode:${var.tag != "" ? var.tag : var.xcode_version[0]}"
cpu_count = 4
memory_gb = 8
disk_size_gb = 90
disk_size_gb = var.disk_size
headless = true
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
locals {
xcode_install_provisioners = [
for version in reverse(sort(var.xcode_version)) : {
type = "shell"
inline = [
"source ~/.zprofile",
"sudo xcodes install ${version} --experimental-unxip --path /Users/admin/Downloads/Xcode_${version}.xip --select --empty-trash",
// get selected xcode path, strip /Contents/Developer and move to GitHub compatible locations
"INSTALLED_PATH=$(xcodes select -p)",
"CONTENTS_DIR=$(dirname $INSTALLED_PATH)",
"APP_DIR=$(dirname $CONTENTS_DIR)",
"sudo mv $APP_DIR /Applications/Xcode_${version}.app",
"sudo xcode-select -s /Applications/Xcode_${version}.app",
"xcodebuild -downloadPlatform iOS",
"xcodebuild -runFirstLaunch",
"df -h",
]
}
]
}
build {
sources = ["source.tart-cli.tart"]
// re-install the actions runner
provisioner "shell" {
inline = [
"cd $HOME",
"rm -rf actions-runner",
"mkdir actions-runner && cd actions-runner",
"curl -O -L https://github.com/actions/runner/releases/download/v${var.gha_version}/actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"tar xzf ./actions-runner-osx-arm64-${var.gha_version}.tar.gz",
"rm actions-runner-osx-arm64-${var.gha_version}.tar.gz",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew --version",
"brew update",
"brew upgrade",
"brew install curl wget unzip zip ca-certificates",
"sudo softwareupdate --install-rosetta --agree-to-license"
]
}
// Re-install the GitHub Actions runner
provisioner "shell" {
script = "scripts/install-actions-runner.sh"
}
// make sure our workaround from base is still valid
provisioner "shell" {
inline = [
"sudo ln -s /Users/admin /Users/runner || true"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install homebrew/cask-versions/temurin17",
"brew install openjdk@17",
"echo 'export PATH=\"/opt/homebrew/opt/openjdk@17/bin:$PATH\"' >> ~/.zprofile",
"echo 'export ANDROID_HOME=$HOME/android-sdk' >> ~/.zprofile",
"echo 'export ANDROID_SDK_ROOT=$ANDROID_HOME' >> ~/.zprofile",
"echo 'export PATH=$PATH:$ANDROID_HOME/cmdline-tools/latest/bin:$ANDROID_HOME/platform-tools:$ANDROID_HOME/emulator' >> ~/.zprofile",
@@ -76,28 +125,129 @@ build {
"rm android-sdk-tools.zip",
"mv $ANDROID_HOME/cmdline-tools/cmdline-tools $ANDROID_HOME/cmdline-tools/latest",
"yes | sdkmanager --licenses",
"yes | sdkmanager 'platform-tools' 'platforms;android-33' 'build-tools;34.0.0' 'ndk;25.2.9519653'"
"yes | sdkmanager 'platform-tools' 'platforms;android-35' 'build-tools;35.0.0' 'ndk;27.2.12479018'"
]
}
provisioner "shell" {
inline = [
"echo 'export PATH=/usr/local/bin/:$PATH' >> ~/.zprofile",
"source ~/.zprofile",
"wget --quiet https://github.com/RobotsAndPencils/xcodes/releases/latest/download/xcodes.zip",
"unzip xcodes.zip",
"rm xcodes.zip",
"chmod +x xcodes",
"sudo mkdir -p /usr/local/bin/",
"sudo mv xcodes /usr/local/bin/xcodes",
"brew install xcodesorg/made/xcodes",
"xcodes version",
"wget --quiet https://storage.googleapis.com/xcodes-cache/Xcode_${var.xcode_version}.xip",
"xcodes install ${var.xcode_version} --experimental-unxip --path $PWD/Xcode_${var.xcode_version}.xip",
"sudo rm -rf ~/.Trash/*",
"xcodes select ${var.xcode_version}",
"xcodebuild -downloadAllPlatforms",
"xcodebuild -runFirstLaunch",
]
}
provisioner "file" {
sources = [ for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
destination = "/Users/admin/Downloads/"
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"df -h",
]
}
// iterate over all Xcode versions and install them
// select the latest one as the default
dynamic "provisioner" {
for_each = local.xcode_install_provisioners
labels = ["shell"]
content {
inline = provisioner.value.inline
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 2 ? [2] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[2]}'",
"xcodebuild -downloadAllPlatforms",
]
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 1 ? [1] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[1]}'",
"xcodebuild -downloadAllPlatforms",
]
}
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[0]}'",
"xcodebuild -downloadAllPlatforms",
]
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for runtime in var.additional_ios_builds : "xcodebuild -downloadPlatform iOS -buildVersion ${runtime}"
]
)
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for component in var.xcode_components : "xcodebuild -downloadComponent ${component}"
]
)
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy carthage",
"brew install xcbeautify swiftformat swiftlint swiftgen licenseplist",
"brew install mint tuist/tuist/tuist",
"rbenv global 3.3.9", # fastlane conflicts with 3.4.0+ https://github.com/fastlane/fastlane/issues/29527
"gem update",
"gem install fastlane",
"gem install cocoapods",
"gem install xcpretty",
"gem uninstall --ignore-dependencies ffi && gem install ffi -- --enable-libffi-alloc"
]
}
// Copy expected runtimes file if provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["file"]
content {
source = var.expected_runtimes_file
destination = "/Users/admin/runtimes.expected.txt"
}
}
// Verify simulator runtimes match expected list if file was provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"xcrun simctl list runtimes > /Users/admin/runtimes.actual.txt",
"diff -q /Users/admin/runtimes.actual.txt /Users/admin/runtimes.expected.txt || (echo 'Simulator runtimes do not match expected list' && cat /Users/admin/runtimes.actual.txt && exit 1)",
"rm /Users/admin/runtimes.actual.txt /Users/admin/runtimes.expected.txt"
]
}
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
@@ -112,22 +262,14 @@ build {
"flutter precache",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy fastlane carthage",
"sudo gem update",
"sudo gem install cocoapods",
"sudo gem uninstall --ignore-dependencies ffi && sudo gem install ffi -- --enable-libffi-alloc"
]
}
# useful utils for mobile development
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install graphicsmagick imagemagick",
"brew install wix/brew/applesimutils"
"brew install wix/brew/applesimutils",
"brew install gnupg"
]
}
@@ -135,14 +277,12 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo security delete-certificate -Z FF6797793A3CD798DC5B2ABEF56F73EDC9F83A64 /Library/Keychains/System.keychain",
"curl -o add-certificate.swift https://raw.githubusercontent.com/actions/runner-images/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/add-certificate.swift",
"swiftc add-certificate.swift",
"sudo mv ./add-certificate /usr/local/bin/add-certificate",
"curl -o AppleWWDRCAG3.cer https://www.apple.com/certificateauthority/AppleWWDRCAG3.cer",
"curl -o DeveloperIDG2CA.cer https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer",
"sudo add-certificate AppleWWDRCAG3.cer",
"sudo add-certificate DeveloperIDG2CA.cer",
"curl -o add-certificate.swift https://raw.githubusercontent.com/actions/runner-images/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/add-certificate.swift",
"swiftc -suppress-warnings add-certificate.swift",
"sudo ./add-certificate AppleWWDRCAG3.cer",
"sudo ./add-certificate DeveloperIDG2CA.cer",
"rm add-certificate* *.cer"
]
}
@@ -153,4 +293,77 @@ build {
"flutter doctor"
]
}
// check there is at least 15GB of free space and fail if not
provisioner "shell" {
inline = [
"source ~/.zprofile",
"df -h",
"export FREE_MB=$(df -m | awk '{print $4}' | head -n 2 | tail -n 1)",
"[[ $FREE_MB -gt ${var.disk_free_mb} ]] && echo OK || exit 1"
]
}
// some other health checks
provisioner "shell" {
inline = [
"source ~/.zprofile",
"test -d /Users/runner"
]
}
# Disable apsd[1][2] daemon as it causes high CPU usage after boot
#
# [1]: https://iboysoft.com/wiki/apsd-mac.html
# [2]: https://discussions.apple.com/thread/4459153
provisioner "shell" {
inline = [
"sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.apsd.plist"
]
}
# Compatibility with GitHub Actions Runner Images, where
# /usr/local/bin belongs to the default user. Also see [2].
#
# [1]: https://github.com/actions/runner-images/blob/6bbddd20d76d61606bea5a0133c950cc44c370d3/images/macos/scripts/build/configure-machine.sh#L96
# [2]: https://github.com/actions/runner-images/discussions/7607
provisioner "shell" {
inline = [
"sudo chown admin /usr/local/bin"
]
}
# Wait for the "update_dyld_sim_shared_cache" process[1][2] to finish
# to avoid wasting CPU cycles after boot
#
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
# [2]: https://stackoverflow.com/a/68394101/9316533
provisioner "shell" {
inline = [
"sleep 1800"
]
}
// Install setup-info-generator
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install cirruslabs/cli/setup-info-generator"
]
}
// Copy setup info template
provisioner "file" {
source = "data/setup-info-template.json"
destination = "~/setup-info-template.json"
}
// Generate setup info
provisioner "shell" {
inline = [
"source ~/.zprofile",
"cat ~/setup-info-template.json | setup-info-generator > ~/actions-runner/.setup_info",
"rm ~/setup-info-template.json"
]
}
}
-3
View File
@@ -1,3 +0,0 @@
macos_version = "ventura"
gha_version = "2.304.0"
xcode_version = "14.3.1"