mirror of
https://github.com/cirruslabs/macos-image-templates.git
synced 2026-09-30 03:42:04 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ec6a446fc1 | ||
|
|
4206908127 | ||
|
|
d42ba4a1e1 | ||
|
|
005b272792 | ||
|
|
ec0c478a02 | ||
|
|
ad419122b2 | ||
|
|
2335029721 | ||
|
|
c3819d6d35 | ||
|
|
1f9fdd5630 | ||
|
|
447a46c522 | ||
|
|
345b223e76 | ||
|
|
5f66cb1ca2 | ||
|
|
0542253d49 | ||
|
|
cdc53f0a12 | ||
|
|
99e619e634 | ||
|
|
946adbfc95 | ||
|
|
e134909aa8 | ||
|
|
998bbf8ca8 | ||
|
|
5a55351c81 | ||
|
|
64b1190f65 | ||
|
|
4df29efc66 | ||
|
|
b205e70322 | ||
|
|
c18ef9c553 | ||
|
|
cec270adb3 | ||
|
|
6d14eaee8c | ||
|
|
f1a9e22ed2 | ||
|
|
2545826772 | ||
|
|
0b49ba6651 | ||
|
|
e5474440fc | ||
|
|
0c165a93d2 | ||
|
|
d3ad77c873 | ||
|
|
40128d40e2 | ||
|
|
7920f0cda2 | ||
|
|
b3b4dafc83 | ||
|
|
ae70c6052d | ||
|
|
1ea5f77e35 | ||
|
|
8392fd1b30 | ||
|
|
fdff7d8daf | ||
|
|
6a01707630 | ||
|
|
49718082b2 | ||
|
|
5b17f4e264 | ||
|
|
14fb85f5b3 | ||
|
|
c8a1e808b6 | ||
|
|
8c1f0c213f | ||
|
|
9875d24c4b | ||
|
|
8425f62a71 | ||
|
|
7ebaf88c48 | ||
|
|
639b46cb2f | ||
|
|
77cc104d6d | ||
|
|
159d4c1c36 | ||
|
|
2a0a476e3b | ||
|
|
74040f6870 | ||
|
|
9f061dacb4 | ||
|
|
f8fd129df6 | ||
|
|
80bedb81db | ||
|
|
7692f27396 | ||
|
|
2bd3a78831 | ||
|
|
39e0ccf2e4 | ||
|
|
e3cad7e8c2 | ||
|
|
47f36a33f8 | ||
|
|
c198ef9957 | ||
|
|
d038ed85d2 | ||
|
|
da102cc5e6 | ||
|
|
b0520dfd1d | ||
|
|
37c77845c8 | ||
|
|
9a16028831 | ||
|
|
cd817762c5 | ||
|
|
32c59db145 | ||
|
|
8dcd824d76 | ||
|
|
200bc65efb | ||
|
|
74aca70ef6 | ||
|
|
1e710b24b9 | ||
|
|
26c6575d1c | ||
|
|
63e491fbf8 | ||
|
|
600cb89e35 | ||
|
|
dbde34c6a8 | ||
|
|
ef6d97a77e | ||
|
|
760e04e340 | ||
|
|
b863116992 | ||
|
|
444b21aba2 | ||
|
|
525f51a54e | ||
|
|
5c7259d9a9 | ||
|
|
24ff639c4d | ||
|
|
0be36e7056 | ||
|
|
ed0b1e4c15 | ||
|
|
489255bec4 |
@@ -0,0 +1,19 @@
|
||||
task:
|
||||
name: "Update Base Images ($MACOS_VERSION)"
|
||||
alias: update-base
|
||||
matrix:
|
||||
- env:
|
||||
MACOS_VERSION: sonoma
|
||||
- env:
|
||||
MACOS_VERSION: sequoia
|
||||
<<: *defaults
|
||||
pull_vanilla_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
|
||||
build_base_script:
|
||||
- packer init templates/base.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
|
||||
push_base_script:
|
||||
- tart push $MACOS_VERSION-base ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete $MACOS_VERSION-base
|
||||
@@ -0,0 +1,21 @@
|
||||
task:
|
||||
name: "Release Xcode $CIRRUS_TAG ($MACOS_VERSION)"
|
||||
matrix:
|
||||
- env:
|
||||
MACOS_VERSION: sequoia
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
build_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$CIRRUS_TAG\"]" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
if [[ $CIRRUS_TAG == *"beta"* ]]
|
||||
then
|
||||
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG
|
||||
else
|
||||
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
|
||||
fi
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete $MACOS_VERSION-xcode:$CIRRUS_TAG || true
|
||||
@@ -0,0 +1,28 @@
|
||||
task:
|
||||
name: "Update Runner Image ($MACOS_VERSION)"
|
||||
execution_lock: runner-image-update
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSIONS: "16.1,16,15.4,15.3,15.2,15.1,\"15.0.1\""
|
||||
DISK_SIZE: 375
|
||||
- MACOS_VERSION: sequoia
|
||||
XCODE_VERSIONS: "16.2,\"16.3-beta-2\",16.1,16,15.4"
|
||||
ADDITIONAL_IOS_BUILDS: "18.2"
|
||||
DISK_SIZE: 375
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
init_xcode_script: packer init templates/xcode.pkr.hcl
|
||||
build_xcode_script: |
|
||||
packer build -var tag=runner -var disk_size=$DISK_SIZE \
|
||||
-var disk_free_mb=100000 \
|
||||
-var macos_version="$MACOS_VERSION" \
|
||||
-var xcode_version="[$XCODE_VERSIONS]" \
|
||||
-var additional_ios_builds="[$ADDITIONAL_IOS_BUILDS]" \
|
||||
templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete "$MACOS_VERSION-xcode:runner"
|
||||
@@ -0,0 +1,29 @@
|
||||
env:
|
||||
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
|
||||
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
|
||||
|
||||
task:
|
||||
name: "Update Vanilla Image ($MACOS_VERSION)"
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sequoia
|
||||
- MACOS_VERSION: sonoma
|
||||
- MACOS_VERSION: ventura
|
||||
- MACOS_VERSION: monterey
|
||||
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
|
||||
<<: *defaults
|
||||
build_script:
|
||||
- packer init templates/vanilla-$MACOS_VERSION.pkr.hcl
|
||||
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
|
||||
disable_sip_script:
|
||||
- packer build -var vm_name=$MACOS_VERSION-vanilla templates/disable-sip.pkr.hcl
|
||||
resolve_macos_number_script:
|
||||
- packer build -var vm_base_name=$MACOS_VERSION-vanilla -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
|
||||
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
|
||||
- rm $RESOLVE_FILE
|
||||
- tart delete $RESOLVE_VM_NAME
|
||||
push_script:
|
||||
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete $MACOS_VERSION-vanilla
|
||||
@@ -0,0 +1,45 @@
|
||||
task:
|
||||
name: "Update Xcode Images ($MACOS_VERSION $XCODE_VERSION)"
|
||||
depends_on: update-base
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sequoia
|
||||
XCODE_VERSION: 16.2
|
||||
LATEST: true
|
||||
- MACOS_VERSION: sequoia
|
||||
XCODE_VERSION: 16.1
|
||||
- MACOS_VERSION: sequoia
|
||||
XCODE_VERSION: 16
|
||||
- MACOS_VERSION: sequoia
|
||||
XCODE_VERSION: 15.4
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 16.1
|
||||
LATEST: true
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 16
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.4
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.3
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.2
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.1
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.0.1
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
build_xcode_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$XCODE_VERSION\"]" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
if [[ -z "$LATEST" ]]
|
||||
then
|
||||
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION
|
||||
else
|
||||
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
|
||||
fi
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION"
|
||||
+48
-4
@@ -1,7 +1,51 @@
|
||||
load("cirrus", "env", "http", "fs")
|
||||
load("github.com/cirrus-modules/graphql", "rerun_task_if_issue_in_logs")
|
||||
|
||||
|
||||
def on_task_failed(ctx):
|
||||
if ctx.payload.data.task.automaticReRun:
|
||||
print("Task is already an automatic re-run! Won't even try to re-run it...")
|
||||
return
|
||||
rerun_task_if_issue_in_logs(ctx.payload.data.task.id, "The network connection was lost")
|
||||
if ctx.payload.data.task.automaticReRun:
|
||||
print("Task is already an automatic re-run! Won't even try to re-run it...")
|
||||
return
|
||||
rerun_task_if_issue_in_logs(ctx.payload.data.task.id, "The network connection was lost")
|
||||
|
||||
|
||||
def on_build_failed(ctx):
|
||||
# Only send Slack notifications for failed cron builds[1]
|
||||
#
|
||||
# [1]: https://cirrus-ci.org/guide/writing-tasks/#cron-builds
|
||||
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
|
||||
return
|
||||
|
||||
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
|
||||
"Content-Type": "application/json",
|
||||
}, json_body={
|
||||
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
|
||||
build_id=ctx.payload.data.build.id,
|
||||
change_message_title=ctx.payload.data.build.changeMessageTitle,
|
||||
branch_name=ctx.payload.data.build.branch,
|
||||
repository_name=ctx.payload.data.repository.name,
|
||||
),
|
||||
"url": "https://cirrus-ci.com/build/{build_id}".format(
|
||||
build_id=ctx.payload.data.build.id,
|
||||
),
|
||||
})
|
||||
|
||||
if resp.status_code != 200:
|
||||
fail("failed to post message to Slack: got unexpected HTTP {}".format(resp.status_code))
|
||||
|
||||
resp_json = resp.json()
|
||||
|
||||
if resp_json["ok"] != True:
|
||||
fail("got error when posting message to Slack: {}".format(resp_json["error"]))
|
||||
|
||||
|
||||
def main(ctx):
|
||||
result = fs.read(".ci/cirrus.vanilla.yml")
|
||||
if env.get("CIRRUS_TAG") != None:
|
||||
result += fs.read(".ci/cirrus.release.yml")
|
||||
if env.get("CIRRUS_CRON") == "monthly":
|
||||
result += fs.read(".ci/cirrus.base.yml")
|
||||
result += fs.read(".ci/cirrus.xcode.yml")
|
||||
if env.get("CIRRUS_CRON") == "weekly":
|
||||
result += fs.read(".ci/cirrus.runner.yml")
|
||||
return result
|
||||
|
||||
-124
@@ -19,127 +19,3 @@ defaults: &defaults
|
||||
info_script:
|
||||
- tart --version
|
||||
- packer --version
|
||||
|
||||
task:
|
||||
name: "Update Vanilla Sonoma Image"
|
||||
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-sonoma.pkr.hcl")
|
||||
<<: *defaults
|
||||
build_script:
|
||||
- packer init templates/vanilla-sonoma.pkr.hcl
|
||||
- packer build templates/vanilla-sonoma.pkr.hcl
|
||||
disable_sip_script:
|
||||
- packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
|
||||
push_script:
|
||||
- tart push sonoma-vanilla ghcr.io/cirruslabs/macos-sonoma-vanilla:latest ghcr.io/cirruslabs/macos-sonoma-vanilla:14.6
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete sonoma-vanilla
|
||||
|
||||
task:
|
||||
name: "Update Vanilla Sequoia Image"
|
||||
persistent_worker:
|
||||
labels:
|
||||
name: dev-mini-experimental
|
||||
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-sequoia.pkr.hcl")
|
||||
<<: *defaults
|
||||
build_script:
|
||||
- packer init templates/vanilla-sequoia.pkr.hcl
|
||||
- packer build templates/vanilla-sequoia.pkr.hcl
|
||||
disable_sip_script:
|
||||
- packer build -var vm_name=sequoia-vanilla templates/disable-sip.pkr.hcl
|
||||
push_script:
|
||||
- tart push sequoia-vanilla ghcr.io/cirruslabs/macos-sequoia-vanilla:latest ghcr.io/cirruslabs/macos-sequoia-vanilla:15.1 ghcr.io/cirruslabs/macos-sequoia-vanilla:15.1-beta-1
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete sequoia-vanilla
|
||||
|
||||
task:
|
||||
name: "Update Base Images ($MACOS_VERSION)"
|
||||
alias: update-base
|
||||
matrix:
|
||||
- env:
|
||||
MACOS_VERSION: sonoma
|
||||
only_if: $CIRRUS_CRON == "monthly"
|
||||
<<: *defaults
|
||||
pull_vanilla_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
|
||||
build_base_script:
|
||||
- packer init templates/base.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
|
||||
push_base_script:
|
||||
- tart push $MACOS_VERSION-base ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete $MACOS_VERSION-base
|
||||
|
||||
task:
|
||||
name: "Update Xcode Images ($MACOS_VERSION $XCODE_VERSION)"
|
||||
depends_on: update-base
|
||||
only_if: $CIRRUS_CRON == "monthly" # Every first Saturday of a month at 14 UTC
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.4
|
||||
LATEST: true
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.3
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSION: 15.2
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
build_xcode_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$XCODE_VERSION\"]" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
if [[ -z "$LATEST" ]]
|
||||
then
|
||||
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION
|
||||
else
|
||||
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
|
||||
fi
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION"
|
||||
|
||||
task:
|
||||
name: "Update Runner Image ($MACOS_VERSION)"
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sonoma
|
||||
XCODE_VERSIONS: 15.2,15.3,15.4
|
||||
only_if: $CIRRUS_TAG != "" || $CIRRUS_CRON == "weekly" # Every Sunday at 14 UTC
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
build_xcode_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var tag=runner -var disk_size=250 -var disk_free_mb=100000 -var macos_version="$MACOS_VERSION" -var xcode_version="[$XCODE_VERSIONS]" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete "$MACOS_VERSION-xcode:runner"
|
||||
|
||||
task:
|
||||
name: "Release Xcode $CIRRUS_TAG ($MACOS_VERSION)"
|
||||
only_if: $CIRRUS_TAG != ""
|
||||
matrix:
|
||||
- env:
|
||||
MACOS_VERSION: sonoma
|
||||
<<: *defaults
|
||||
pull_base_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
|
||||
build_script:
|
||||
- packer init templates/xcode.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$CIRRUS_TAG\"]" templates/xcode.pkr.hcl
|
||||
push_script: |
|
||||
if [[ $CIRRUS_TAG == *"beta"* ]]
|
||||
then
|
||||
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG
|
||||
else
|
||||
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
|
||||
fi
|
||||
always:
|
||||
cleanup_script:
|
||||
- tart delete $MACOS_VERSION-xcode:$CIRRUS_TAG || true
|
||||
|
||||
@@ -7,15 +7,17 @@ The following image variants are currently available:
|
||||
|
||||
* `macos-{sequoia,sonoma}-base` image has only `brew` pre-installed and the latest version of `macOS` available
|
||||
* `macos-{sequoia,sonoma}-xcode:N` image is based on `macos-{sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
|
||||
* `macos-runner:sonoma` image is a variant of `xcode:N` with 3 latest versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
|
||||
* `macos-runner:{sequoia,sonoma}` image is a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
|
||||
|
||||
See a full list of VMs available [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
|
||||
|
||||
## Release Cadence
|
||||
|
||||
Once a new version of Xcode is released, we will initiate a GitHub release which will automatically build and push
|
||||
a new version of the `macos-{sequoia,sonoma}-xcode:N` image as well as `macos-runner:sonoma`. This generally happens within 24 hours
|
||||
of a release. Please watch this repository releases to get notified about new images.
|
||||
a new version of the `macos-sequoia-xcode:N`. This generally happens within 24 hours of a release.
|
||||
Please watch this repository releases to get notified about new images.
|
||||
|
||||
For an Xcode release which is non beta and not an RC `ghcr.io/cirruslabs/macos-runner:sequoia` image will also be updated.
|
||||
|
||||
## Update Cadence
|
||||
|
||||
@@ -23,8 +25,8 @@ Some of the images are regularly getting rebuild in order to update the pre-inst
|
||||
monthly on the first Saturday of the month:
|
||||
|
||||
* `ghcr.io/cirruslabs/macos-{sequoia,sonoma}-base`
|
||||
* `ghcr.io/cirruslabs/macos-sonoma-xcode:{16-beta,latest,15.4,15.3,15.2}`
|
||||
* `ghcr.io/cirruslabs/macos-sequoia-xcode:{16-beta}`
|
||||
* `ghcr.io/cirruslabs/macos-runner:sonoma` which is a superset of `ghcr.io/cirruslabs/macos-sonoma-xcode:{latest,16.1,16,15.4,15.3,15.2,15.1,15.0.1}`
|
||||
* `ghcr.io/cirruslabs/macos-runner:sequoia` which is a superset of `ghcr.io/cirruslabs/macos-sequoia-xcode:{latest,16.2,16.3-beta-2,16.1,16,15.4}`
|
||||
|
||||
Note that `ghcr.io/cirruslabs/macos-runner:sonoma` is updated every Sunday and this image is [optimised for startup](https://cirrus-runners.app/blog/2024/04/11/optimizing-startup-time-of-cirrus-runners/)
|
||||
Note that `ghcr.io/cirruslabs/macos-runner:{sequoia,sonoma}` are updated every Sunday and these images are [optimised for startup](https://cirrus-runners.app/blog/2024/04/11/optimizing-startup-time-of-cirrus-runners/)
|
||||
on Cirrus Runners and Cirrus CI services.
|
||||
@@ -0,0 +1,5 @@
|
||||
- hosts: default
|
||||
roles:
|
||||
- system-updater
|
||||
vars:
|
||||
ansible_password: admin
|
||||
@@ -0,0 +1,37 @@
|
||||
- name: Perform first "softwareupdate" invocation
|
||||
include_tasks: softwareupdate.yml
|
||||
|
||||
# Needed after a major macOS update, otherwise things like
|
||||
# Command Line Tools won't be updated
|
||||
- name: Perform second "softwareupdate" invocation
|
||||
include_tasks: softwareupdate.yml
|
||||
|
||||
# This one looks weird, but unfortunately there's no other way around, because Homebrew
|
||||
# is not designed to run as root (see https://gist.github.com/irazasyed/7732946
|
||||
# for more details).
|
||||
- name: fix up /usr/local permissions for Homebrew
|
||||
file:
|
||||
path: /usr/local/share/man
|
||||
state: directory
|
||||
owner: "{{ ansible_user_id }}"
|
||||
recurse: yes
|
||||
become: yes
|
||||
|
||||
- name: "ensure that there are no more software updates available: check for available updates"
|
||||
command:
|
||||
cmd: "softwareupdate --all --list"
|
||||
register: software_updates_result
|
||||
|
||||
- name: "ensure that there are no more software updates available: parse available updates"
|
||||
set_fact:
|
||||
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
|
||||
|
||||
- name: "ensure that there are no more software updates available: print available updates"
|
||||
debug:
|
||||
var: software_updates
|
||||
|
||||
- name: "ensure that there are no more software updates available: fail if some updates were not installed"
|
||||
fail:
|
||||
msg: "Found unapplied update: {{ item.label }}"
|
||||
loop: "{{ software_updates }}"
|
||||
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
|
||||
@@ -0,0 +1,43 @@
|
||||
- name: check for available updates
|
||||
command:
|
||||
cmd: "softwareupdate --all --list"
|
||||
register: software_updates_result
|
||||
|
||||
- name: parse available updates
|
||||
set_fact:
|
||||
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
|
||||
|
||||
- name: print available updates
|
||||
debug:
|
||||
var: software_updates
|
||||
|
||||
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
|
||||
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
|
||||
- name: install available update
|
||||
command:
|
||||
cmd: "softwareupdate --install --agree-to-license --force --restart --user admin --stdinpass {{ stdinpass | default('') }} '{{ item.label }}'"
|
||||
stdin: "{{ ansible_password }}"
|
||||
register: update_result
|
||||
# Work around the following:
|
||||
# > Data could not be sent to remote host [...].
|
||||
# > Make sure this host can be reached over ssh:
|
||||
# > ssh: connect to host [...] port 22: Connection refused.
|
||||
ignore_unreachable: yes
|
||||
# Ignore SIGTERM/SIGKILL sent "softwareupdate" process
|
||||
# when the system reboots due to --restart and any other errors,
|
||||
# since we'll check whether the update was installed in main.yml
|
||||
# anyway.
|
||||
ignore_errors: yes
|
||||
become: yes
|
||||
loop: "{{ software_updates }}"
|
||||
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
|
||||
|
||||
# Wait for the connection since the previous command could restart the host
|
||||
- name: wait for connection
|
||||
wait_for_connection:
|
||||
# We need to wait long enough for the "softwareupdate" to initiate the reboot,
|
||||
# otherwise it's possible that we'll interrupt the process by running
|
||||
# the commands below on a non-restarted system.
|
||||
delay: 60
|
||||
timeout: 1800
|
||||
when: update_result is defined and not update_result.skipped | default(false)
|
||||
@@ -0,0 +1,3 @@
|
||||
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
|
||||
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
|
||||
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
|
||||
@@ -0,0 +1,40 @@
|
||||
[
|
||||
{
|
||||
"group": "Runner Detail",
|
||||
"detail": [
|
||||
{
|
||||
"name": "OS Information",
|
||||
"script": "echo \"macOS $(sw_vers -productVersion) ($(sw_vers -buildVersion))\""
|
||||
},
|
||||
{
|
||||
"name": "Build Date",
|
||||
"script": "date +\"%Y-%m-%d\""
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"group": "Software Detail",
|
||||
"detail": [
|
||||
{
|
||||
"name": "Python Version",
|
||||
"script": "python3 --version"
|
||||
},
|
||||
{
|
||||
"name": "Node Version",
|
||||
"script": "node --version"
|
||||
},
|
||||
{
|
||||
"name": "Ruby Version",
|
||||
"script": "ruby --version"
|
||||
},
|
||||
{
|
||||
"name": "CocoaPods Version",
|
||||
"script": "pod --version"
|
||||
},
|
||||
{
|
||||
"name": "Fastlane Version",
|
||||
"script": "fastlane --version"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
+22
-2
@@ -56,16 +56,34 @@ build {
|
||||
"echo 'eval \"$(/opt/homebrew/bin/brew shellenv)\"' >> ~/.zprofile",
|
||||
"echo \"export HOMEBREW_NO_AUTO_UPDATE=1\" >> ~/.zprofile",
|
||||
"echo \"export HOMEBREW_NO_INSTALL_CLEANUP=1\" >> ~/.zprofile",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"brew --version",
|
||||
"brew update",
|
||||
"brew install curl wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
|
||||
"brew install wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
|
||||
"brew install curl || true", // doesn't work on Monterey
|
||||
"brew install --cask git-credential-manager",
|
||||
"git lfs install",
|
||||
"sudo softwareupdate --install-rosetta --agree-to-license"
|
||||
]
|
||||
}
|
||||
|
||||
// Add GitHub to known hosts
|
||||
// Similar to https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/configure-ssh.sh
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"mkdir -p ~/.ssh"
|
||||
]
|
||||
}
|
||||
provisioner "file" {
|
||||
source = "data/github_known_hosts"
|
||||
destination = "~/.ssh/known_hosts"
|
||||
}
|
||||
|
||||
// Install the GitHub Actions runner
|
||||
provisioner "shell" {
|
||||
script = "scripts/install-actions-runner.sh"
|
||||
@@ -126,7 +144,9 @@ build {
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"test -d /Users/runner"
|
||||
"test -d /Users/runner",
|
||||
"test -f ~/.ssh/known_hosts",
|
||||
"brew doctor"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
packer {
|
||||
required_plugins {
|
||||
tart = {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
variable "vm_base_name" {
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "vm_name" {
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "resolve_file" {
|
||||
type = string
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
vm_base_name = "${var.vm_base_name}"
|
||||
vm_name = "${var.vm_name}"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "120s"
|
||||
}
|
||||
|
||||
build {
|
||||
sources = ["source.tart-cli.tart"]
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Use "-productVersion" instead of "--productVersion"
|
||||
# to support old-style syntax used on macOS Monterey
|
||||
"sw_vers -productVersion > /tmp/sw-vers-product-version.txt",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "file" {
|
||||
source = "/tmp/sw-vers-product-version.txt"
|
||||
destination = "${var.resolve_file}"
|
||||
direction = "download"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,148 @@
|
||||
packer {
|
||||
required_plugins {
|
||||
tart = {
|
||||
version = ">= 1.2.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
# You can find macOS IPSW URLs on various websites like https://ipsw.me/
|
||||
from_ipsw = "https://updates.cdn-apple.com/2022FallFCS/fullrestores/012-66032/8D8D90C6-A876-4FFF-BBF4-D158939B3841/UniversalMac_12.6.1_21G217_Restore.ipsw"
|
||||
vm_name = "monterey-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
disk_size_gb = 50
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "120s"
|
||||
boot_command = [
|
||||
# hello, hola, bonjour, etc.
|
||||
"<wait60s><spacebar>",
|
||||
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
|
||||
# "English" language already selected. If we type "english", it'll cause us to switch
|
||||
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
|
||||
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
|
||||
# first entry in a list of "english"-prefixed items, which will be "English".
|
||||
#
|
||||
# [1]: should be named "English (US)", but oh well 🤷
|
||||
"<wait30s>italiano<esc>english<enter>",
|
||||
# Select Your Country and Region
|
||||
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Written and Spoken Languages
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Accessibility
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Data & Privacy
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Migration Assistant
|
||||
"<wait10s><tab><tab><tab><spacebar>",
|
||||
# Sign In with Your Apple ID
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Are you sure you want to skip signing in with an Apple ID?
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Terms and Conditions
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# I have read and agree to the macOS Software License Agreement
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Create a Computer Account
|
||||
"<wait10s>admin<tab><tab>admin<tab>admin<tab><tab><tab><spacebar>",
|
||||
# Enable Location Services
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Are you sure you don't want to use Location Services?
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Select Your Time Zone
|
||||
"<wait10s><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Analytics
|
||||
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Screen Time
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Siri
|
||||
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Choose Your Look
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Enable Voice Over
|
||||
"<wait10s><leftAltOn><f5><leftAltOff><wait5s>v",
|
||||
# Now that the installation is done, open "System Preferences"
|
||||
"<wait10s><leftAltOn><spacebar><leftAltOff>System Preferences<enter>",
|
||||
# Navigate to "Sharing"
|
||||
"<wait10s>sharing<enter>",
|
||||
# Enable Screen Sharing
|
||||
"<wait10s><tab><tab><tab><tab><spacebar>",
|
||||
# Enable Remote Login
|
||||
"<wait10s><down><down><down><down><spacebar><tab><tab><spacebar>",
|
||||
# Disable Voice Over
|
||||
"<leftAltOn><f5><leftAltOff>",
|
||||
]
|
||||
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
sources = ["source.tart-cli.tart"]
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
// Enable passwordless sudo
|
||||
"echo admin | sudo -S sh -c \"echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
|
||||
// Enable auto-login
|
||||
//
|
||||
// See https://github.com/xfreebird/kcpassword for details.
|
||||
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
|
||||
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
|
||||
// Disable screensaver at login screen
|
||||
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
|
||||
// Disable screensaver for admin user
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0",
|
||||
// Prevent the VM from sleeping
|
||||
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setsleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
|
||||
// Launch Safari to populate the defaults
|
||||
"/Applications/Safari.app/Contents/MacOS/Safari &",
|
||||
"SAFARI_PID=$!",
|
||||
"disown",
|
||||
"sleep 30",
|
||||
"kill -9 $SAFARI_PID",
|
||||
// Enable Safari's remote automation
|
||||
"sudo safaridriver --enable",
|
||||
// Disable screen lock
|
||||
//
|
||||
// Note that this only works if the user is logged-in,
|
||||
// i.e. not on login screen.
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
extra_arguments = [
|
||||
"-vvv",
|
||||
"--extra-vars", "stdinpass=admin",
|
||||
]
|
||||
ansible_env_vars = [
|
||||
"ANSIBLE_TRANSPORT=paramiko",
|
||||
"ANSIBLE_HOST_KEY_CHECKING=False",
|
||||
]
|
||||
use_proxy = false
|
||||
}
|
||||
}
|
||||
@@ -4,15 +4,19 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
from_ipsw = "https://updates.cdn-apple.com/2024SummerSeed/fullrestores/062-47125/381F8D56-0EB1-4EB6-AEF4-04D9BC5D2426/UniversalMac_15.1_24B5009l_Restore.ipsw"
|
||||
from_ipsw = "https://updates.cdn-apple.com/2025SpringFCS/fullrestores/082-16517/AACDDC33-9683-4431-98AF-F04EF7C15EE3/UniversalMac_15.4_24E248_Restore.ipsw"
|
||||
vm_name = "sequoia-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
disk_size_gb = 40
|
||||
disk_size_gb = 50
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "300s"
|
||||
@@ -27,32 +31,34 @@ source "tart-cli" "tart" {
|
||||
#
|
||||
# [1]: should be named "English (US)", but oh well 🤷
|
||||
"<wait30s>italiano<esc>english<enter>",
|
||||
# Select Your Country and Region
|
||||
# Select Your Country or Region
|
||||
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Transfer Your Data to This Mac
|
||||
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
|
||||
# Written and Spoken Languages
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Accessibility
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Data & Privacy
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Migration Assistant
|
||||
"<wait10s><tab><tab><tab><spacebar>",
|
||||
# Create a Mac Account
|
||||
"<wait10s>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
|
||||
# Enable Voice Over
|
||||
"<wait120s><leftAltOn><f5><leftAltOff>",
|
||||
# Sign In with Your Apple ID
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Are you sure you want to skip signing in with an Apple ID?
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Terms and Conditions
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# I have read and agree to the macOS Software License Agreement
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Create a Computer Account
|
||||
"<wait10s>admin<tab><tab>admin<tab>admin<tab><tab><tab><spacebar>",
|
||||
# Enable Location Services
|
||||
"<wait120s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Are you sure you don't want to use Location Services?
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Select Your Time Zone
|
||||
"<wait10s><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
"<wait10s><tab><tab>UTC<enter><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
|
||||
# Analytics
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Screen Time
|
||||
@@ -61,25 +67,49 @@ source "tart-cli" "tart" {
|
||||
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Choose Your Look
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
|
||||
# Welcome to Mac
|
||||
# Update Mac Automatically
|
||||
"<wait10s><tab><spacebar>",
|
||||
# Enable Voice Over
|
||||
"<wait10s><leftAltOn><f5><leftAltOff><wait5s>v",
|
||||
# Welcome to Mac
|
||||
"<wait10s><spacebar>",
|
||||
# Disable Voice Over
|
||||
"<leftAltOn><f5><leftAltOff>",
|
||||
# Enable Keyboard navigation
|
||||
# This is so that we can navigate the System Settings app using the keyboard
|
||||
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
|
||||
"<wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
|
||||
"<wait10s><leftAltOn>q<leftAltOff>",
|
||||
# Now that the installation is done, open "System Settings"
|
||||
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
|
||||
# Navigate to "Sharing"
|
||||
"<wait10s><leftAltOn>f<leftAltOff>sharing<enter>",
|
||||
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
|
||||
# Navigate to "Screen Sharing" and enable it
|
||||
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
|
||||
"<wait10s><tab><tab><tab><tab><tab><tab><tab><spacebar>",
|
||||
# Navigate to "Remote Login" and enable it
|
||||
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
|
||||
# Disable Voice Over
|
||||
"<leftAltOn><f5><leftAltOff>",
|
||||
# Quit System Settings
|
||||
"<wait10s><leftAltOn>q<leftAltOff>",
|
||||
# Disable Gatekeeper (1/2)
|
||||
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
|
||||
"<wait10s>sudo spctl --global-disable<enter>",
|
||||
"<wait10s>admin<enter>",
|
||||
"<wait10s><leftAltOn>q<leftAltOff>",
|
||||
# Disable Gatekeeper (2/2)
|
||||
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
|
||||
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff>",
|
||||
"<wait10s><down><wait1s><down><wait1s><enter>",
|
||||
"<wait10s>admin<enter>",
|
||||
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
|
||||
# Quit System Settings
|
||||
"<wait10s><leftAltOn>q<leftAltOff>",
|
||||
]
|
||||
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -99,9 +129,7 @@ build {
|
||||
// Disable screensaver for admin user
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0",
|
||||
// Prevent the VM from sleeping
|
||||
"sudo systemsetup -setdisplaysleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setsleep Off 2>/dev/null",
|
||||
"sudo systemsetup -setcomputersleep Off 2>/dev/null",
|
||||
// Launch Safari to populate the defaults
|
||||
"/Applications/Safari.app/Contents/MacOS/Safari &",
|
||||
"SAFARI_PID=$!",
|
||||
@@ -117,4 +145,32 @@ build {
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Ensure that Gatekeeper is disabled
|
||||
"spctl --status | grep -q 'assessments disabled'"
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
extra_arguments = [
|
||||
"-vvv",
|
||||
]
|
||||
ansible_env_vars = [
|
||||
"ANSIBLE_TRANSPORT=paramiko",
|
||||
"ANSIBLE_HOST_KEY_CHECKING=False",
|
||||
]
|
||||
use_proxy = false
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,10 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -12,7 +16,7 @@ source "tart-cli" "tart" {
|
||||
vm_name = "sonoma-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
disk_size_gb = 40
|
||||
disk_size_gb = 50
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "120s"
|
||||
@@ -78,6 +82,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -115,4 +122,25 @@ build {
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
extra_arguments = [
|
||||
"-vvv",
|
||||
]
|
||||
ansible_env_vars = [
|
||||
"ANSIBLE_TRANSPORT=paramiko",
|
||||
"ANSIBLE_HOST_KEY_CHECKING=False",
|
||||
]
|
||||
use_proxy = false
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,10 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -14,7 +18,7 @@ source "tart-cli" "tart" {
|
||||
vm_name = "ventura-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
disk_size_gb = 40
|
||||
disk_size_gb = 50
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "120s"
|
||||
@@ -86,6 +90,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -124,4 +131,25 @@ build {
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0"
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
extra_arguments = [
|
||||
"-vvv",
|
||||
]
|
||||
ansible_env_vars = [
|
||||
"ANSIBLE_TRANSPORT=paramiko",
|
||||
"ANSIBLE_HOST_KEY_CHECKING=False",
|
||||
]
|
||||
use_proxy = false
|
||||
}
|
||||
}
|
||||
|
||||
+82
-5
@@ -15,6 +15,11 @@ variable "xcode_version" {
|
||||
type = list(string)
|
||||
}
|
||||
|
||||
variable "additional_ios_builds" {
|
||||
type = list(string)
|
||||
default = []
|
||||
}
|
||||
|
||||
variable "tag" {
|
||||
type = string
|
||||
default = ""
|
||||
@@ -32,13 +37,13 @@ variable "disk_free_mb" {
|
||||
|
||||
variable "android_sdk_tools_version" {
|
||||
type = string
|
||||
default = "11076708" # https://developer.android.com/studio/#command-tools
|
||||
default = "11076708" # https://developer.android.com/studio#command-line-tools-only
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-base:latest"
|
||||
// use tag or the last element of the xcode_version list
|
||||
vm_name = "${var.macos_version}-xcode:${var.tag != "" ? var.tag : var.xcode_version[length(var.xcode_version) - 1]}"
|
||||
vm_name = "${var.macos_version}-xcode:${var.tag != "" ? var.tag : var.xcode_version[0]}"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
disk_size_gb = var.disk_size
|
||||
@@ -50,7 +55,7 @@ source "tart-cli" "tart" {
|
||||
|
||||
locals {
|
||||
xcode_install_provisioners = [
|
||||
for version in var.xcode_version : {
|
||||
for version in reverse(sort(var.xcode_version)) : {
|
||||
type = "shell"
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
@@ -107,7 +112,7 @@ build {
|
||||
"rm android-sdk-tools.zip",
|
||||
"mv $ANDROID_HOME/cmdline-tools/cmdline-tools $ANDROID_HOME/cmdline-tools/latest",
|
||||
"yes | sdkmanager --licenses",
|
||||
"yes | sdkmanager 'platform-tools' 'platforms;android-33' 'build-tools;34.0.0' 'ndk;25.2.9519653'"
|
||||
"yes | sdkmanager 'platform-tools' 'platforms;android-35' 'build-tools;35.0.0' 'ndk;27.2.12479018'"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -134,6 +139,22 @@ build {
|
||||
}
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"sudo xcodes select '${var.xcode_version[0]}'",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = concat(
|
||||
["source ~/.zprofile"],
|
||||
[
|
||||
for runtime in var.additional_ios_builds : "xcodebuild -downloadPlatform iOS -buildVersion ${runtime}"
|
||||
]
|
||||
)
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
@@ -165,7 +186,8 @@ build {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"brew install graphicsmagick imagemagick",
|
||||
"brew install wix/brew/applesimutils"
|
||||
"brew install wix/brew/applesimutils",
|
||||
"brew install gnupg"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -207,4 +229,59 @@ build {
|
||||
"test -d /Users/runner"
|
||||
]
|
||||
}
|
||||
|
||||
# Disable apsd[1][2] daemon as it causes high CPU usage after boot
|
||||
#
|
||||
# [1]: https://iboysoft.com/wiki/apsd-mac.html
|
||||
# [2]: https://discussions.apple.com/thread/4459153
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.apsd.plist"
|
||||
]
|
||||
}
|
||||
|
||||
# Compatibility with GitHub Actions Runner Images, where
|
||||
# /usr/local/bin belongs to the default user. Also see [2].
|
||||
#
|
||||
# [1]: https://github.com/actions/runner-images/blob/6bbddd20d76d61606bea5a0133c950cc44c370d3/images/macos/scripts/build/configure-machine.sh#L96
|
||||
# [2]: https://github.com/actions/runner-images/discussions/7607
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"sudo chown admin /usr/local/bin"
|
||||
]
|
||||
}
|
||||
|
||||
# Wait for the "update_dyld_sim_shared_cache" process[1][2] to finish
|
||||
# to avoid wasting CPU cycles after boot
|
||||
#
|
||||
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
|
||||
# [2]: https://stackoverflow.com/a/68394101/9316533
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"sleep 1800"
|
||||
]
|
||||
}
|
||||
|
||||
// Install setup-info-generator
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"brew install cirruslabs/cli/setup-info-generator"
|
||||
]
|
||||
}
|
||||
|
||||
// Copy setup info template
|
||||
provisioner "file" {
|
||||
source = "data/setup-info-template.json"
|
||||
destination = "~/setup-info-template.json"
|
||||
}
|
||||
|
||||
// Generate setup info
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"cat ~/setup-info-template.json | setup-info-generator > ~/actions-runner/.setup_info",
|
||||
"rm ~/setup-info-template.json"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user