mirror of
https://github.com/cirruslabs/macos-image-templates.git
synced 2026-09-30 03:42:04 +02:00
Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c453ee2350 | ||
|
|
64b1190f65 | ||
|
|
4df29efc66 | ||
|
|
b205e70322 | ||
|
|
c18ef9c553 | ||
|
|
cec270adb3 | ||
|
|
6d14eaee8c | ||
|
|
f1a9e22ed2 | ||
|
|
2545826772 |
@@ -9,6 +9,8 @@ task:
|
||||
<<: *defaults
|
||||
pull_vanilla_script:
|
||||
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
|
||||
install_sshpass_script:
|
||||
- brew install sshpass
|
||||
build_base_script:
|
||||
- packer init templates/base.pkr.hcl
|
||||
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
|
||||
|
||||
+11
-5
@@ -1,15 +1,16 @@
|
||||
env:
|
||||
RESOLVE_VM_BASE_NAME: "ghcr.io/cirruslabs/macos-${MACOS_VERSION}-vanilla:latest"
|
||||
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
|
||||
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
|
||||
|
||||
task:
|
||||
name: "Update Vanilla Image ($MACOS_VERSION $MACOS_NUMBER)"
|
||||
name: "Update Vanilla Image ($MACOS_VERSION)"
|
||||
env:
|
||||
matrix:
|
||||
- MACOS_VERSION: sequoia
|
||||
MACOS_NUMBER: 15.2
|
||||
- MACOS_VERSION: sonoma
|
||||
MACOS_NUMBER: 14.6
|
||||
- MACOS_VERSION: ventura
|
||||
MACOS_NUMBER: 13.6
|
||||
- MACOS_VERSION: monterey
|
||||
MACOS_NUMBER: 12.6.1
|
||||
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
|
||||
<<: *defaults
|
||||
build_script:
|
||||
@@ -17,6 +18,11 @@ task:
|
||||
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
|
||||
disable_sip_script:
|
||||
- packer build -var vm_name=$MACOS_VERSION-vanilla templates/disable-sip.pkr.hcl
|
||||
resolve_macos_number_script:
|
||||
- packer build -var vm_base_name=$RESOLVE_VM_BASE_NAME -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
|
||||
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
|
||||
- rm $RESOLVE_FILE
|
||||
- tart delete $RESOLVE_VM_NAME
|
||||
push_script:
|
||||
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
|
||||
always:
|
||||
|
||||
+10
-6
@@ -16,14 +16,18 @@ def on_build_failed(ctx):
|
||||
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
|
||||
return
|
||||
|
||||
resp = http.post("https://slack.com/api/chat.postMessage", headers={
|
||||
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
|
||||
"Content-Type": "application/json",
|
||||
"Authorization": "Bearer " + env.get("SLACK_TOKEN"),
|
||||
}, json_body={
|
||||
"channel": "#image-updates",
|
||||
"text": "Build <https://cirrus-ci.com/build/{build_id}|{build_id} (\"{change_message_title}\")> failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
|
||||
build_id=ctx.payload.data.build.id, change_message_title=ctx.payload.data.build.changeMessageTitle,
|
||||
branch_name=ctx.payload.data.build.branch, repository_name=ctx.payload.data.repository.name),
|
||||
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
|
||||
build_id=ctx.payload.data.build.id,
|
||||
change_message_title=ctx.payload.data.build.changeMessageTitle,
|
||||
branch_name=ctx.payload.data.build.branch,
|
||||
repository_name=ctx.payload.data.repository.name,
|
||||
),
|
||||
"url": "https://cirrus-ci.com/build/{build_id}".format(
|
||||
build_id=ctx.payload.data.build.id,
|
||||
),
|
||||
})
|
||||
|
||||
if resp.status_code != 200:
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
- hosts: default
|
||||
roles:
|
||||
- system-updater
|
||||
vars:
|
||||
ansible_password: admin
|
||||
@@ -0,0 +1,27 @@
|
||||
- name: Perform first "softwareupdate" invocation
|
||||
include_tasks: softwareupdate.yml
|
||||
|
||||
# Needed after a major macOS update, otherwise things like
|
||||
# Command Line Tools won't be updated
|
||||
- name: Perform second "softwareupdate" invocation
|
||||
include_tasks: softwareupdate.yml
|
||||
|
||||
# This one looks weird, but unfortunately there's no other way around, because Homebrew
|
||||
# is not designed to run as root (see https://gist.github.com/irazasyed/7732946
|
||||
# for more details).
|
||||
- name: fix up /usr/local permissions for Homebrew
|
||||
file:
|
||||
path: /usr/local/share/man
|
||||
state: directory
|
||||
owner: "{{ ansible_user_id }}"
|
||||
recurse: yes
|
||||
become: yes
|
||||
|
||||
- name: Ensure that there are no more software updates available (1/2)
|
||||
command: "softwareupdate --all --list"
|
||||
register: check_updates_result
|
||||
|
||||
- name: Ensure that there are no more software updates available (2/2)
|
||||
assert:
|
||||
that:
|
||||
- "'No new software available' in check_updates_result.stderr"
|
||||
@@ -0,0 +1,26 @@
|
||||
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
|
||||
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
|
||||
- name: install all macOS updates
|
||||
command:
|
||||
cmd: "softwareupdate --all --install --agree-to-license --force --restart --user admin --stdinpass"
|
||||
stdin: "{{ ansible_password }}"
|
||||
register: update_result
|
||||
# Work around the following:
|
||||
# > Data could not be sent to remote host [...].
|
||||
# > Make sure this host can be reached over ssh:
|
||||
# > ssh: connect to host [...] port 22: Connection refused.
|
||||
ignore_unreachable: yes
|
||||
# Ignore SIGTERM/SIGKILL sent "softwareupdate" process
|
||||
# when the system reboots due to --restart
|
||||
failed_when: update_result.rc not in [0, 9, -9, 15, -15]
|
||||
become: yes
|
||||
|
||||
# Wait for the connection since the previous command could restart the host
|
||||
- name: wait for connection
|
||||
wait_for_connection:
|
||||
# We need to wait long enough for the "softwareupdate" to initiate the reboot,
|
||||
# otherwise it's possible that we'll interrupt the process by running
|
||||
# the commands below on a non-restarted system.
|
||||
delay: 60
|
||||
timeout: 1800
|
||||
when: "'No updates are available' not in (update_result.stderr_lines | join('\n'))"
|
||||
@@ -0,0 +1,3 @@
|
||||
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
|
||||
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
|
||||
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
|
||||
+20
-1
@@ -56,6 +56,11 @@ build {
|
||||
"echo 'eval \"$(/opt/homebrew/bin/brew shellenv)\"' >> ~/.zprofile",
|
||||
"echo \"export HOMEBREW_NO_AUTO_UPDATE=1\" >> ~/.zprofile",
|
||||
"echo \"export HOMEBREW_NO_INSTALL_CLEANUP=1\" >> ~/.zprofile",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"brew --version",
|
||||
"brew update",
|
||||
@@ -67,6 +72,18 @@ build {
|
||||
]
|
||||
}
|
||||
|
||||
// Add GitHub to known hosts
|
||||
// Similar to https://github.com/actions/runner-images/blob/main/images/macos/scripts/build/configure-ssh.sh
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"mkdir -p ~/.ssh"
|
||||
]
|
||||
}
|
||||
provisioner "file" {
|
||||
source = "data/github_known_hosts"
|
||||
destination = "~/.ssh/known_hosts"
|
||||
}
|
||||
|
||||
// Install the GitHub Actions runner
|
||||
provisioner "shell" {
|
||||
script = "scripts/install-actions-runner.sh"
|
||||
@@ -127,7 +144,9 @@ build {
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"source ~/.zprofile",
|
||||
"test -d /Users/runner"
|
||||
"test -d /Users/runner",
|
||||
"test -f ~/.ssh/known_hosts",
|
||||
"brew doctor"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
packer {
|
||||
required_plugins {
|
||||
tart = {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
variable "vm_base_name" {
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "vm_name" {
|
||||
type = string
|
||||
}
|
||||
|
||||
variable "resolve_file" {
|
||||
type = string
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
vm_base_name = "${var.vm_base_name}"
|
||||
vm_name = "${var.vm_name}"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
ssh_password = "admin"
|
||||
ssh_username = "admin"
|
||||
ssh_timeout = "120s"
|
||||
}
|
||||
|
||||
build {
|
||||
sources = ["source.tart-cli.tart"]
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
"sw_vers --productVersion > /tmp/sw-vers-product-version.txt",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "file" {
|
||||
source = "/tmp/sw-vers-product-version.txt"
|
||||
destination = "${var.resolve_file}"
|
||||
direction = "download"
|
||||
}
|
||||
}
|
||||
@@ -4,6 +4,10 @@ packer {
|
||||
version = ">= 1.2.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -79,6 +83,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -116,4 +123,17 @@ build {
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,11 +4,15 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
source "tart-cli" "tart" {
|
||||
from_ipsw = "https://updates.cdn-apple.com/2024FallFCS/fullrestores/072-44245/E811A1B0-28A9-4FCD-AE32-322E796F0EB8/UniversalMac_15.2_24C101_Restore.ipsw"
|
||||
from_ipsw = "https://updates.cdn-apple.com/2025WinterFCS/fullrestores/072-08269/7CAAB9F7-E970-428D-8764-4CD7BCD105CD/UniversalMac_15.3_24D60_Restore.ipsw"
|
||||
vm_name = "sequoia-vanilla"
|
||||
cpu_count = 4
|
||||
memory_gb = 8
|
||||
@@ -83,6 +87,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -118,4 +125,17 @@ build {
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,10 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -78,6 +82,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -115,4 +122,17 @@ build {
|
||||
"sysadminctl -screenLock off -password admin",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,10 @@ packer {
|
||||
version = ">= 1.12.0"
|
||||
source = "github.com/cirruslabs/tart"
|
||||
}
|
||||
ansible = {
|
||||
version = "~> 1"
|
||||
source = "github.com/hashicorp/ansible"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -86,6 +90,9 @@ source "tart-cli" "tart" {
|
||||
// A (hopefully) temporary workaround for Virtualization.Framework's
|
||||
// installation process not fully finishing in a timely manner
|
||||
create_grace_time = "30s"
|
||||
|
||||
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
|
||||
recovery_partition = "keep"
|
||||
}
|
||||
|
||||
build {
|
||||
@@ -124,4 +131,17 @@ build {
|
||||
"defaults -currentHost write com.apple.screensaver idleTime 0"
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "shell" {
|
||||
inline = [
|
||||
# Install command-line tools
|
||||
"touch /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
"softwareupdate --list | sed -n 's/.*Label: \\(Command Line Tools for Xcode-.*\\)/\\1/p' | xargs -I {} softwareupdate --install '{}'",
|
||||
"rm /tmp/.com.apple.dt.CommandLineTools.installondemand.in-progress",
|
||||
]
|
||||
}
|
||||
|
||||
provisioner "ansible" {
|
||||
playbook_file = "ansible/playbook-system-updater.yml"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user