mirror of
https://github.com/cirruslabs/macos-image-templates.git
synced 2026-09-30 03:42:04 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a63fb03f2e | ||
|
|
8f93e8eae2 | ||
|
|
8b9f6ce141 | ||
|
|
a9d8536f46 | ||
|
|
73dea7bcb0 | ||
|
|
e5f5edca05 | ||
|
|
21522999bb | ||
|
|
664d47260e | ||
|
|
67a57c3064 | ||
|
|
fabd89cead | ||
|
|
b19d3fa66c | ||
|
|
3f1850ad07 | ||
|
|
4b7ac1f76f | ||
|
|
98b522dbfa | ||
|
|
41b20ab533 | ||
|
|
b28936faa2 | ||
|
|
3e3e6818f3 | ||
|
|
47695a9abd | ||
|
|
6555932569 | ||
|
|
4513f2adad | ||
|
|
0a4f436302 | ||
|
|
277b13fb59 | ||
|
|
19a8271935 | ||
|
|
ba158f524c | ||
|
|
a34d6d3e51 | ||
|
|
59624221fe | ||
|
|
ac0d6efcf5 | ||
|
|
4e75d95247 | ||
|
|
7fcf10afd6 | ||
|
|
0f7f741d45 | ||
|
|
f0e06a7c5e | ||
|
|
21e5a3eb86 | ||
|
|
a2d379b619 | ||
|
|
5d00757016 | ||
|
|
04eaf0415f | ||
|
|
fc12391db4 | ||
|
|
62bb71fc2c |
+63
-24
@@ -1,52 +1,91 @@
|
||||
persistent_worker:
|
||||
labels:
|
||||
name: dev-mini
|
||||
|
||||
env:
|
||||
TART_REGISTRY_HOSTNAME: ghcr.io
|
||||
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
|
||||
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
|
||||
AWS_ACCESS_KEY_ID: ENCRYPTED[c187b670a17eead88c1698849376273991d09678efe37ae2f0c9738c27a2422741a71c501ef4b6a4df7bff3eca5213a9]
|
||||
AWS_SECRET_ACCESS_KEY: ENCRYPTED[e456254a53b82e3167f2da23e24c389620cb3f7d47e4e5e7d993813bf9bb18c784d5cb8d88d19632073acc9e1f6096c9]
|
||||
|
||||
task:
|
||||
name: "Update Base Image"
|
||||
only_if: $CIRRUS_CRON != ""
|
||||
persistent_worker:
|
||||
labels:
|
||||
name: dev-mini
|
||||
env:
|
||||
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
|
||||
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
|
||||
name: "Update Vanilla Images"
|
||||
only_if: false
|
||||
timeout_in: 3h
|
||||
update_script: brew update && brew upgrade
|
||||
info_script:
|
||||
- tart --version
|
||||
- packer --version
|
||||
build_script:
|
||||
- packer init templates/base.pkr.hcl
|
||||
- packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
|
||||
- packer init templates/vanilla-sonoma.pkr.hcl
|
||||
- packer build templates/vanilla-sonoma.pkr.hcl
|
||||
disable_sip_script:
|
||||
- packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
|
||||
push_script:
|
||||
- tart push ventura-base ghcr.io/cirruslabs/macos-ventura-base:latest
|
||||
- tart push sonoma-vanilla ghcr.io/cirruslabs/macos-sonoma-vanilla:latest ghcr.io/cirruslabs/macos-sonoma-vanilla:14.1
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete ventura-base
|
||||
- tart delete sonoma-vanilla || true
|
||||
|
||||
task:
|
||||
name: "Update Non-Vanilla Images"
|
||||
only_if: $CIRRUS_CRON != ""
|
||||
timeout_in: 3h
|
||||
update_script: brew update && brew upgrade
|
||||
info_script:
|
||||
- tart --version
|
||||
- packer --version
|
||||
env_script:
|
||||
- echo "XCODE_VERSION=$(cat variables.pkrvars.hcl | grep xcode_version | awk '{print $(NF)}' | tr -d '\"')" >> $CIRRUS_ENV
|
||||
build_base_script:
|
||||
- packer init templates/base.pkr.hcl
|
||||
- packer build -var-file="variables.pkrvars.hcl" templates/base.pkr.hcl
|
||||
build_xcode_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var-file="variables.pkrvars.hcl" templates/xcode.pkr.hcl
|
||||
push_base_script:
|
||||
- tart push sonoma-base ghcr.io/cirruslabs/macos-sonoma-base:latest
|
||||
push_xcode_script:
|
||||
- tart push sonoma-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-sonoma-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-sonoma-xcode:latest
|
||||
push_base_ecr_script:
|
||||
- tart push sonoma-base public.ecr.aws/cirruslabs/macos:sonoma-base
|
||||
push_xcode_ecr_script:
|
||||
- tart push sonoma-xcode:$XCODE_VERSION public.ecr.aws/cirruslabs/macos:sonoma-xcode-$XCODE_VERSION public.ecr.aws/cirruslabs/macos:sonoma-xcode
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete sonoma-base || true
|
||||
- tart delete sonoma-xcode:$XCODE_VERSION || true
|
||||
|
||||
task:
|
||||
name: "Release Xcode $CIRRUS_TAG"
|
||||
only_if: $CIRRUS_TAG != ""
|
||||
persistent_worker:
|
||||
labels:
|
||||
name: dev-mini
|
||||
env:
|
||||
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
|
||||
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
|
||||
timeout_in: 3h
|
||||
update_script: brew update && brew upgrade
|
||||
info_script:
|
||||
- tart --version
|
||||
- packer --version
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-ventura-base:latest
|
||||
- tart clone ghcr.io/cirruslabs/macos-ventura-base:latest ventura-base
|
||||
- tart pull ghcr.io/cirruslabs/macos-sonoma-base:latest
|
||||
- tart clone ghcr.io/cirruslabs/macos-sonoma-base:latest sonoma-base
|
||||
build_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var-file="variables.pkrvars.hcl" -var xcode_version="$CIRRUS_TAG" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
if [[ $CIRRUS_TAG == *"beta"* ]]
|
||||
then
|
||||
tart push ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:$CIRRUS_TAG
|
||||
tart push sonoma-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-sonoma-xcode:$CIRRUS_TAG
|
||||
else
|
||||
tart push ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-ventura-xcode:latest
|
||||
tart push sonoma-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-sonoma-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-sonoma-xcode:latest
|
||||
fi
|
||||
push_ecr_script: |
|
||||
if [[ $CIRRUS_TAG == *"beta"* ]]
|
||||
then
|
||||
tart push sonoma-xcode:$CIRRUS_TAG public.ecr.aws/cirruslabs/macos:sonoma-xcode-$CIRRUS_TAG
|
||||
else
|
||||
tart push sonoma-xcode:$CIRRUS_TAG public.ecr.aws/cirruslabs/macos:sonoma-xcode-$CIRRUS_TAG public.ecr.aws/cirruslabs/macos:sonoma-xcode
|
||||
fi
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete ventura-base || true
|
||||
- tart delete ventura-xcode:$CIRRUS_TAG || true
|
||||
- tart delete sonoma-base || true
|
||||
- tart delete sonoma-xcode:$CIRRUS_TAG || true
|
||||
|
||||
@@ -1,35 +1,25 @@
|
||||
## macOS Packer Templates for Cirrus CI
|
||||
## macOS Packer Templates for Tart
|
||||
|
||||
Repository with Packer templates to build [Tart VMs](https://github.com/cirruslabs/tart) to use with [Cirrus CI](https://cirrus-ci.org/guide/macOS/).
|
||||
Repository with Packer templates to build [Tart VMs](https://github.com/cirruslabs/tart) to use with [Cirrus Runners](https://tart.run/integrations/github-actions/) and [Cirrus CI](https://cirrus-ci.org/guide/macOS/).
|
||||
|
||||
* `macos-{monterey,ventura}-vanilla` image has nothing pre-installed
|
||||
* `macos-{monterey,ventura}-base` image has only `brew` pre-installed
|
||||
* `macos-{monterey,ventura}-xcode:N` image is based on `macos-{monterey,ventura}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
|
||||
* `macos-{monterey,ventura,sonoma}-vanilla` image has nothing pre-installed
|
||||
* `macos-{monterey,ventura,sonoma}-base` image has only `brew` pre-installed
|
||||
* `macos-{monterey,ventura,sonoma}-xcode:N` image is based on `macos-{monterey,ventura}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
|
||||
|
||||
See a full list of VMs available on Cirrus CI [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
|
||||
See a full list of VMs available [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
|
||||
|
||||
## Building Vanilla Image
|
||||
|
||||
To build `macos-monterey-vanilla`:
|
||||
To build `macos-sonoma-vanilla`:
|
||||
|
||||
```bash
|
||||
packer build templates/vanilla-monterey.pkr.hcl
|
||||
```
|
||||
|
||||
To build `macos-ventura-vanilla`:
|
||||
|
||||
```bash
|
||||
packer build templates/vanilla-ventura.pkr.hcl
|
||||
packer build templates/vanilla-sonoma.pkr.hcl
|
||||
```
|
||||
|
||||
Optionally, SIP can be disabled for each image by running the following commands:
|
||||
|
||||
```bash
|
||||
packer build -var vm_name=monterey-vanilla templates/disable-sip.pkr.hcl
|
||||
```
|
||||
|
||||
```bash
|
||||
packer build -var vm_name=ventura-vanilla templates/disable-sip.pkr.hcl
|
||||
packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
|
||||
```
|
||||
|
||||
## Building Base Image
|
||||
|
||||
@@ -16,7 +16,7 @@ variable "gha_version" {
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:13.4"
|
||||
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:latest"
|
||||
vm_name = "${var.macos_version}-base"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
@@ -45,13 +45,6 @@ build {
|
||||
]
|
||||
}
|
||||
|
||||
# setup DNS
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"networksetup -setdnsservers Ethernet 8.8.8.8 8.8.4.4 1.1.1.1",
|
||||
]
|
||||
}
|
||||
|
||||
# Create a symlink for bash compatibility
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
|
||||
@@ -22,11 +22,8 @@ source "tart-cli" "tart" {
|
||||
# Skip over "Macintosh" and select "Options"
|
||||
# to boot into macOS Recovery
|
||||
"<wait60s><right><right><enter>",
|
||||
# Select default language
|
||||
"<wait10s><enter>",
|
||||
# Open Terminal
|
||||
"<wait10s><leftCtrlOn><f2><leftCtrlOff>",
|
||||
"<right><right><right><right><down><down><down><enter>",
|
||||
"<wait10s><leftAltOn>T<leftAltOff>",
|
||||
# Disable SIP
|
||||
"<wait10s>csrutil disable<enter>",
|
||||
"<wait10s>y<enter>",
|
||||
|
||||
@@ -90,14 +90,18 @@ build {
|
||||
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
|
||||
// Disable screensaver at login screen
|
||||
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
|
||||
// Disable screensaver for admin user
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0",
|
||||
// Prevent the VM from sleeping
|
||||
"sudo systemsetup -setdisplaysleep Off",
|
||||
"sudo systemsetup -setsleep Off",
|
||||
"sudo systemsetup -setcomputersleep Off",
|
||||
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setsleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
|
||||
// Launch Safari to populate the defaults
|
||||
"/Applications/Safari.app/Contents/MacOS/Safari &",
|
||||
"sleep 3",
|
||||
"kill -9 %1",
|
||||
"SAFARI_PID=$!",
|
||||
"disown",
|
||||
"sleep 30",
|
||||
"kill -9 $SAFARI_PID",
|
||||
// Enable Safari's remote automation and "Develop" menu
|
||||
"sudo safaridriver --enable",
|
||||
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
|
||||
|
||||
@@ -8,12 +8,7 @@ packer {
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
# Currently macOS 14 (Sonoma) can only be obtained via the following links:
|
||||
# unauthenticated[1] and authenticated[2].
|
||||
#
|
||||
# [1]: https://updates.cdn-apple.com/2023SummerSeed/fullrestores/032-94355/CBE8CBE1-750D-487E-A393-B90FEF60CEBA/UniversalMac_14.0_23A5257q_Restore.ipsw
|
||||
# [2]: https://download.developer.apple.com/WWDC_2023/macOS_14_Beta_Restore_Images/UniversalMac_14.0_23A5257q_Restore.ipsw
|
||||
from_ipsw = "https://updates.cdn-apple.com/2023SummerSeed/fullrestores/032-94355/CBE8CBE1-750D-487E-A393-B90FEF60CEBA/UniversalMac_14.0_23A5257q_Restore.ipsw"
|
||||
from_ipsw = "https://updates.cdn-apple.com/2023FallFCS/fullrestores/042-86430/DBE44960-58A6-4715-948B-D64F33F769BD/UniversalMac_14.1_23B74_Restore.ipsw"
|
||||
vm_name = "sonoma-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
@@ -24,8 +19,14 @@ source "tart-cli" "tart" {
|
||||
boot_command = [
|
||||
# hello, hola, bonjour, etc.
|
||||
"<wait60s><spacebar>",
|
||||
# Language
|
||||
"<wait30s>english<enter>",
|
||||
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
|
||||
# "English" language already selected. If we type "english", it'll cause us to switch
|
||||
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
|
||||
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
|
||||
# first entry in a list of "english"-prefixed items, which will be "English".
|
||||
#
|
||||
# [1]: should be named "English (US)", but oh well 🤷
|
||||
"<wait30s>italiano<esc>english<enter>",
|
||||
# Select Your Country and Region
|
||||
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Written and Spoken Languages
|
||||
@@ -99,14 +100,18 @@ build {
|
||||
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
|
||||
// Disable screensaver at login screen
|
||||
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
|
||||
// Disable screensaver for admin user
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0",
|
||||
// Prevent the VM from sleeping
|
||||
"sudo systemsetup -setdisplaysleep Off",
|
||||
"sudo systemsetup -setsleep Off",
|
||||
"sudo systemsetup -setcomputersleep Off",
|
||||
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setsleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
|
||||
// Launch Safari to populate the defaults
|
||||
"/Applications/Safari.app/Contents/MacOS/Safari &",
|
||||
"SAFARI_PID=$!",
|
||||
"disown",
|
||||
"sleep 30",
|
||||
"kill -9 %1",
|
||||
"kill -9 $SAFARI_PID",
|
||||
// Enable Safari's remote automation and "Develop" menu
|
||||
"sudo safaridriver --enable",
|
||||
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
|
||||
|
||||
@@ -10,7 +10,7 @@ packer {
|
||||
source "tart-cli" "tart" {
|
||||
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
|
||||
# and https://www.theiphonewiki.com/wiki/Beta_Firmware/Mac/13.x
|
||||
from_ipsw = "https://updates.cdn-apple.com/2023SpringFCS/fullrestores/032-84884/F97A22EE-9B5E-4FD5-94C1-B39DCEE8D80F/UniversalMac_13.4_22F66_Restore.ipsw"
|
||||
from_ipsw = "https://updates.cdn-apple.com/2023FallFCS/fullrestores/042-55833/C0830847-A2F8-458F-B680-967991820931/UniversalMac_13.6_22G120_Restore.ipsw"
|
||||
vm_name = "ventura-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
@@ -96,14 +96,18 @@ build {
|
||||
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
|
||||
// Disable screensaver at login screen
|
||||
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
|
||||
// Disable screensaver for admin user
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0",
|
||||
// Prevent the VM from sleeping
|
||||
"sudo systemsetup -setdisplaysleep Off",
|
||||
"sudo systemsetup -setsleep Off",
|
||||
"sudo systemsetup -setcomputersleep Off",
|
||||
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setsleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
|
||||
// Launch Safari to populate the defaults
|
||||
"/Applications/Safari.app/Contents/MacOS/Safari &",
|
||||
"SAFARI_PID=$!",
|
||||
"disown",
|
||||
"sleep 30",
|
||||
"kill -9 %1",
|
||||
"kill -9 $SAFARI_PID",
|
||||
// Enable Safari's remote automation and "Develop" menu
|
||||
"sudo safaridriver --enable",
|
||||
"defaults write com.apple.Safari.SandboxBroker ShowDevelopMenu -bool true",
|
||||
@@ -113,6 +117,7 @@ build {
|
||||
// Note that this only works if the user is logged-in,
|
||||
// i.e. not on login screen.
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -8,19 +8,19 @@ packer {
|
||||
}
|
||||
|
||||
variable "macos_version" {
|
||||
type = string
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "xcode_version" {
|
||||
type = string
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "gha_version" {
|
||||
type = string
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "android_sdk_tools_version" {
|
||||
type = string
|
||||
type = string
|
||||
default = "9477386" # https://developer.android.com/studio/#command-tools
|
||||
}
|
||||
|
||||
@@ -138,13 +138,15 @@ build {
|
||||
"sudo security delete-certificate -Z FF6797793A3CD798DC5B2ABEF56F73EDC9F83A64 /Library/Keychains/System.keychain",
|
||||
"curl -o add-certificate.swift https://raw.githubusercontent.com/actions/runner-images/fb3b6fd69957772c1596848e2daaec69eabca1bb/images/macos/provision/configuration/add-certificate.swift",
|
||||
"swiftc add-certificate.swift",
|
||||
"sudo mv ./add-certificate /usr/local/bin/add-certificate",
|
||||
"curl -o AppleWWDRCAG3.cer https://www.apple.com/certificateauthority/AppleWWDRCAG3.cer",
|
||||
"curl -o DeveloperIDG2CA.cer https://www.apple.com/certificateauthority/DeveloperIDG2CA.cer",
|
||||
"sudo ./add-certificate AppleWWDRCAG3.cer",
|
||||
"sudo ./add-certificate DeveloperIDG2CA.cer",
|
||||
"sudo add-certificate AppleWWDRCAG3.cer",
|
||||
"sudo add-certificate DeveloperIDG2CA.cer",
|
||||
"rm add-certificate* *.cer"
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
macos_version = "ventura"
|
||||
gha_version = "2.304.0"
|
||||
xcode_version = "14.3.1"
|
||||
macos_version = "sonoma"
|
||||
gha_version = "2.311.0"
|
||||
xcode_version = "15.1"
|
||||
|
||||
Reference in New Issue
Block a user