Compare commits

..
27 Commits
Author SHA1 Message Date
ec6a446fc1 Support macOS Sequoia 15.4 (#224)
* Support macOS Sequoia 15.4

* Navigate to "Sharing" and "Privacy & Security" through menu bar

System Settings's search box does not always work as intended.

* Choose "Only Download Automatically"

* Use "Managed via Tart" full user name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* Use "Managed via Tart" user full name

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>

* macOS 15.4 RC 2

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

* Use macOS 15.4 release IPSW

Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor@cirruslabs.org>
Co-authored-by: Brett Best <6104381+Brett-Best@users.noreply.github.com>
2025-03-31 22:34:07 +04:00
Nikolay Edigaryev 4206908127 vanilla-sequoia.pkr.hcl: disable Gatekeeper (#220)
* vanilla-sequoia.pkr.hcl: disable Gatekeeper

* Don't forget to enter sudo password

Since passwordless sudo is not yet enabled at this point.
2025-03-21 22:54:15 +04:00
fedor d42ba4a1e1 Additional iOS builds 2025-03-11 03:01:50 +04:00
fedor 005b272792 Additional iOS 18.2 runtime
Related https://github.com/cirruslabs/macos-image-templates/issues/219#issuecomment-2709774915
2025-03-10 19:51:22 +04:00
fedor ec0c478a02 Escape runtime 2025-03-10 14:07:10 +04:00
Fedor Korotkov ad419122b2 Bump disk size 2025-03-09 12:35:45 +04:00
fedor 2335029721 Xcode 16.3-beta-2 2025-03-08 14:41:16 +04:00
Sergio Pinheiro c3819d6d35 Fix syntax issue (#218) 2025-03-03 22:16:25 +04:00
Fedor Korotkov 1f9fdd5630 Xcode 16.3-beta-1 2025-02-21 15:15:56 -08:00
Fedor Korotkov 447a46c522 Integrate .setup_info tool (#216)
I generate the tool from the specs a few weeks ago using AI. This PR also is generated fully using AI.
2025-02-17 08:42:28 -08:00
Nikolay Edigaryev 345b223e76 Resolve the version of the VM image just built, not the one in the OCI (#217) 2025-02-16 20:28:00 +04:00
Nikolay Edigaryev 5f66cb1ca2 Use "-productVersion" instead of "--productVersion" to support Monterey (#215)
* Use "-productVersion" instead of "--productVersion" to support Monterey

* No need to relocate anything as we're starting from scratch (IPSW)
2025-02-16 01:03:05 +04:00
Nikolay Edigaryev 0542253d49 Ignore errors for "install available update" Ansible task (#213)
* Ignore errors for "install available update" Ansible task

* Do not fail when update_result is not defined
2025-02-13 17:07:58 -05:00
Nikolay Edigaryev cdc53f0a12 vanilla-monterey.pkr.hcl: remove duplicate extra_arguments (#212) 2025-02-12 18:39:37 +04:00
Nikolay Edigaryev 99e619e634 Increase vanilla VM images disk size from 40 to 50 GB and use "relocate" (#211) 2025-02-12 18:09:39 +04:00
Nikolay Edigaryev 946adbfc95 Use single instead of double quotes to avoid YAML syntax error (#210) 2025-02-12 03:39:32 +04:00
Nikolay Edigaryev e134909aa8 Provide a default when stdinpass variable is not set (#209) 2025-02-12 02:12:06 +04:00
Nikolay Edigaryev 998bbf8ca8 Parse available updates to avoid upgrading to the next macOS version (#208)
* Parse available updates to avoid upgrading to the next macOS version

* Do not override ANSIBLE_CONFIG with our ansible.cfg

Otherwise Packer + Ansible integration goes haywire.

Instead, only modify the required variables through ansible_env_vars.

* Support Monterey
2025-02-12 01:45:40 +04:00
Nikolay Edigaryev 5a55351c81 Use xargs fix for all vanilla images, not just Sequoia (#207) 2025-02-06 18:55:36 +04:00
Nikolay Edigaryev 64b1190f65 Only pass a single item to "softwareupdate --install" each time (#206) 2025-02-06 17:39:40 +04:00
Nikolay Edigaryev 4df29efc66 Run "softwareupdate" on vanilla images (#204)
* Run "softwareupdate" on vanilla images

* Install Command Line Tools for Xcode

* Run Ansible after password-less sudo is configured

* Don't use SFTP

* Fix Ansible playbook path

* No updates are available → No new software available

* stderr_lines → stderr

* Dynamically resolve MACOS_NUMBER
2025-02-01 01:23:11 +04:00
Fedor Korotkov b205e70322 macOS Sequoia 15.3 (#205) 2025-01-27 14:38:08 -05:00
Nikolay Edigaryev c18ef9c553 Use Slack workflows (#201)
* Use Slack workflows

* Use SLACK_WEBHOOK_URL
2025-01-14 23:47:30 +04:00
fedor cec270adb3 No software updates 2025-01-06 17:54:53 -05:00
fedor 6d14eaee8c Install recommended updates 2025-01-06 17:36:50 -05:00
Fedor Korotkov f1a9e22ed2 Fixed known host creation (#202)
`~/.ssh` should exist for `file` provisioner.
2025-01-06 14:35:10 -05:00
Fedor Korotkov 2545826772 Add github.com keys to ~/.ssh/known_hosts (#200)
* Add github.com keys to `~/.ssh/known_hosts`

* Static known hosts

* Fixed path
2025-01-06 09:54:14 -05:00
16 changed files with 400 additions and 32 deletions
+4 -3
View File
@@ -7,8 +7,9 @@ task:
XCODE_VERSIONS: "16.1,16,15.4,15.3,15.2,15.1,\"15.0.1\""
DISK_SIZE: 375
- MACOS_VERSION: sequoia
XCODE_VERSIONS: "16.2,16.1,16,15.4"
DISK_SIZE: 320
XCODE_VERSIONS: "16.2,\"16.3-beta-2\",16.1,16,15.4"
ADDITIONAL_IOS_BUILDS: "18.2"
DISK_SIZE: 375
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
@@ -18,7 +19,7 @@ task:
-var disk_free_mb=100000 \
-var macos_version="$MACOS_VERSION" \
-var xcode_version="[$XCODE_VERSIONS]" \
-var additional_runtimes="[$ADDITIONAL_RUNTIMES]" \
-var additional_ios_builds="[$ADDITIONAL_IOS_BUILDS]" \
templates/xcode.pkr.hcl
push_script: |
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
+10 -5
View File
@@ -1,15 +1,15 @@
env:
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
task:
name: "Update Vanilla Image ($MACOS_VERSION $MACOS_NUMBER)"
name: "Update Vanilla Image ($MACOS_VERSION)"
env:
matrix:
- MACOS_VERSION: sequoia
MACOS_NUMBER: 15.2
- MACOS_VERSION: sonoma
MACOS_NUMBER: 14.6
- MACOS_VERSION: ventura
MACOS_NUMBER: 13.6
- MACOS_VERSION: monterey
MACOS_NUMBER: 12.6.1
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
<<: *defaults
build_script:
@@ -17,6 +17,11 @@ task:
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
disable_sip_script:
- packer build -var vm_name=$MACOS_VERSION-vanilla templates/disable-sip.pkr.hcl
resolve_macos_number_script:
- packer build -var vm_base_name=$MACOS_VERSION-vanilla -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
- rm $RESOLVE_FILE
- tart delete $RESOLVE_VM_NAME
push_script:
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
always:
+10 -6
View File
@@ -16,14 +16,18 @@ def on_build_failed(ctx):
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
return
resp = http.post("https://slack.com/api/chat.postMessage", headers={
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
"Content-Type": "application/json",
"Authorization": "Bearer " + env.get("SLACK_TOKEN"),
}, json_body={
"channel": "#image-updates",
"text": "Build <https://cirrus-ci.com/build/{build_id}|{build_id} (\"{change_message_title}\")> failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
build_id=ctx.payload.data.build.id, change_message_title=ctx.payload.data.build.changeMessageTitle,
branch_name=ctx.payload.data.build.branch, repository_name=ctx.payload.data.repository.name),
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
build_id=ctx.payload.data.build.id,
change_message_title=ctx.payload.data.build.changeMessageTitle,
branch_name=ctx.payload.data.build.branch,
repository_name=ctx.payload.data.repository.name,
),
"url": "https://cirrus-ci.com/build/{build_id}".format(
build_id=ctx.payload.data.build.id,
),
})
if resp.status_code != 200:
+1 -1
View File
@@ -26,7 +26,7 @@ monthly on the first Saturday of the month:
* `ghcr.io/cirruslabs/macos-{sequoia,sonoma}-base`
* `ghcr.io/cirruslabs/macos-runner:sonoma` which is a superset of `ghcr.io/cirruslabs/macos-sonoma-xcode:{latest,16.1,16,15.4,15.3,15.2,15.1,15.0.1}`
* `ghcr.io/cirruslabs/macos-runner:sequoia` which is a superset of `ghcr.io/cirruslabs/macos-sequoia-xcode:{latest,16.2,16.1,16,15.4}`
* `ghcr.io/cirruslabs/macos-runner:sequoia` which is a superset of `ghcr.io/cirruslabs/macos-sequoia-xcode:{latest,16.2,16.3-beta-2,16.1,16,15.4}`
Note that `ghcr.io/cirruslabs/macos-runner:{sequoia,sonoma}` are updated every Sunday and these images are [optimised for startup](https://cirrus-runners.app/blog/2024/04/11/optimizing-startup-time-of-cirrus-runners/)
on Cirrus Runners and Cirrus CI services.
+5
View File
@@ -0,0 +1,5 @@
- hosts: default
roles:
- system-updater
vars:
ansible_password: admin
@@ -0,0 +1,37 @@
- name: Perform first "softwareupdate" invocation
include_tasks: softwareupdate.yml
# Needed after a major macOS update, otherwise things like
# Command Line Tools won't be updated
- name: Perform second "softwareupdate" invocation
include_tasks: softwareupdate.yml
# This one looks weird, but unfortunately there's no other way around, because Homebrew
# is not designed to run as root (see https://gist.github.com/irazasyed/7732946
# for more details).
- name: fix up /usr/local permissions for Homebrew
file:
path: /usr/local/share/man
state: directory
owner: "{{ ansible_user_id }}"
recurse: yes
become: yes
- name: "ensure that there are no more software updates available: check for available updates"
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: "ensure that there are no more software updates available: parse available updates"
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: "ensure that there are no more software updates available: print available updates"
debug:
var: software_updates
- name: "ensure that there are no more software updates available: fail if some updates were not installed"
fail:
msg: "Found unapplied update: {{ item.label }}"
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
@@ -0,0 +1,43 @@
- name: check for available updates
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: parse available updates
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: print available updates
debug:
var: software_updates
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
- name: install available update
command:
cmd: "softwareupdate --install --agree-to-license --force --restart --user admin --stdinpass {{ stdinpass | default('') }} '{{ item.label }}'"
stdin: "{{ ansible_password }}"
register: update_result
# Work around the following:
# > Data could not be sent to remote host [...].
# > Make sure this host can be reached over ssh:
# > ssh: connect to host [...] port 22: Connection refused.
ignore_unreachable: yes
# Ignore SIGTERM/SIGKILL sent "softwareupdate" process
# when the system reboots due to --restart and any other errors,
# since we'll check whether the update was installed in main.yml
# anyway.
ignore_errors: yes
become: yes
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
# Wait for the connection since the previous command could restart the host
- name: wait for connection
wait_for_connection:
# We need to wait long enough for the "softwareupdate" to initiate the reboot,
# otherwise it's possible that we'll interrupt the process by running
# the commands below on a non-restarted system.
delay: 60
timeout: 1800
when: update_result is defined and not update_result.skipped | default(false)
+3
View File
@@ -0,0 +1,3 @@
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
+40
View File
@@ -0,0 +1,40 @@
[
{
"group": "Runner Detail",
"detail": [
{
"name": "OS Information",
"script": "echo \"macOS $(sw_vers -productVersion) ($(sw_vers -buildVersion))\""
},
{
"name": "Build Date",
"script": "date +\"%Y-%m-%d\""
}
]
},
{
"group": "Software Detail",
"detail": [
{
"name": "Python Version",
"script": "python3 --version"
},
{
"name": "Node Version",
"script": "node --version"
},
{
"name": "Ruby Version",
"script": "ruby --version"
},
{
"name": "CocoaPods Version",
"script": "pod --version"
},
{
"name": "Fastlane Version",
"script": "fastlane --version"
}
]
}
]
+20 -1
View File
@@ -56,6 +56,11 @@ build {
"echo 'eval \"$(/opt/homebrew/bin/brew shellenv)\"' >> ~/.zprofile",
"echo \"export HOMEBREW_NO_AUTO_UPDATE=1\" >> ~/.zprofile",
"echo \"export HOMEBREW_NO_INSTALL_CLEANUP=1\" >> ~/.zprofile",
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew --version",
"brew update",
@@ -67,6 +72,18 @@ build {
]
}
// Add GitHub to known hosts
// Similar to https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/configure-ssh.sh
provisioner "shell" {
inline = [
"mkdir -p ~/.ssh"
]
}
provisioner "file" {
source = "data/github_known_hosts"
destination = "~/.ssh/known_hosts"
}
// Install the GitHub Actions runner
provisioner "shell" {
script = "scripts/install-actions-runner.sh"
@@ -127,7 +144,9 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"test -d /Users/runner"
"test -d /Users/runner",
"test -f ~/.ssh/known_hosts",
"brew doctor"
]
}
}
+48
View File
@@ -0,0 +1,48 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_base_name" {
type = string
}
variable "vm_name" {
type = string
}
variable "resolve_file" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "${var.vm_base_name}"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
# Use "-productVersion" instead of "--productVersion"
# to support old-style syntax used on macOS Monterey
"sw_vers -productVersion > /tmp/sw-vers-product-version.txt",
]
}
provisioner "file" {
source = "/tmp/sw-vers-product-version.txt"
destination = "${var.resolve_file}"
direction = "download"
}
}
+30 -1
View File
@@ -4,6 +4,10 @@ packer {
version = ">= 1.2.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
@@ -13,7 +17,7 @@ source "tart-cli" "tart" {
vm_name = "monterey-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
@@ -79,6 +83,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -116,4 +123,26 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
"--extra-vars", "stdinpass=admin",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+66 -11
View File
@@ -4,15 +4,19 @@ packer {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2024FallFCS/fullrestores/072-44245/E811A1B0-28A9-4FCD-AE32-322E796F0EB8/UniversalMac_15.2_24C101_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2025SpringFCS/fullrestores/082-16517/AACDDC33-9683-4431-98AF-F04EF7C15EE3/UniversalMac_15.4_24E248_Restore.ipsw"
vm_name = "sequoia-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "300s"
@@ -27,28 +31,30 @@ source "tart-cli" "tart" {
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country and Region
# Select Your Country or Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Migration Assistant
"<wait10s><tab><tab><tab><spacebar>",
# Create a Mac Account
"<wait10s>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Create a Computer Account
"<wait10s>admin<tab><tab>admin<tab>admin<tab><tab><tab><spacebar>",
# Enable Location Services
"<wait120s><leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
@@ -61,8 +67,12 @@ source "tart-cli" "tart" {
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><spacebar>",
# Welcome to Mac
"<wait10s><spacebar>",
# Disable Voice Over
"<leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
@@ -71,18 +81,35 @@ source "tart-cli" "tart" {
# Now that the installation is done, open "System Settings"
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
# Navigate to "Sharing"
"<wait10s><leftAltOn>f<leftAltOff>sharing<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
"<wait10s><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<enter>",
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (2/2)
"<wait10s><leftAltOn><spacebar><leftAltOff>System Settings<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff><leftShiftOn><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -118,4 +145,32 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+29 -1
View File
@@ -4,6 +4,10 @@ packer {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
@@ -12,7 +16,7 @@ source "tart-cli" "tart" {
vm_name = "sonoma-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
@@ -78,6 +82,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -115,4 +122,25 @@ build {
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+29 -1
View File
@@ -4,6 +4,10 @@ packer {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
@@ -14,7 +18,7 @@ source "tart-cli" "tart" {
vm_name = "ventura-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 40
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
@@ -86,6 +90,9 @@ source "tart-cli" "tart" {
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
@@ -124,4 +131,25 @@ build {
"defaults -currentHost write com.apple.screensaver idleTime 0"
]
}
provisioner "shell" {
inline = [
# Install command-line tools
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
]
}
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"-vvv",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+25 -2
View File
@@ -15,7 +15,7 @@ variable "xcode_version" {
type = list(string)
}
variable "additional_runtimes" {
variable "additional_ios_builds" {
type = list(string)
default = []
}
@@ -150,7 +150,7 @@ build {
inline = concat(
["source ~/.zprofile"],
[
for runtime in var.additional_runtimes : "sudo xcodes runtimes install ${runtime}"
for runtime in var.additional_ios_builds : "xcodebuild -downloadPlatform iOS -buildVersion ${runtime}"
]
)
}
@@ -261,4 +261,27 @@ build {
"sleep 1800"
]
}
// Install setup-info-generator
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install cirruslabs/cli/setup-info-generator"
]
}
// Copy setup info template
provisioner "file" {
source = "data/setup-info-template.json"
destination = "~/setup-info-template.json"
}
// Generate setup info
provisioner "shell" {
inline = [
"source ~/.zprofile",
"cat ~/setup-info-template.json | setup-info-generator > ~/actions-runner/.setup_info",
"rm ~/setup-info-template.json"
]
}
}