Compare commits

...
Author SHA1 Message Date
Nikolay Edigaryev 75e6c33578 Produce macOS Golden Gate vanilla image 2026-08-12 10:57:51 +01:00
Fedor Kororkov c166ec1698 Merge pull request #364 from cirruslabs/dev/fkorotkov/tahoe-26-6-1-automation-permissions
Update Tahoe restore image and automation permissions
2026-08-07 10:38:00 -04:00
Fedor Korotkov 3d6445b446 Update Tahoe restore image and automation permissions 2026-08-07 10:24:00 -04:00
Fedor Kororkov f5a7e1e631 Merge pull request #363 from cirruslabs/dev/fkorotkov/fix-monthly-buildkite-tap-trust
Fix Homebrew 6 trust failure in monthly image builds
2026-08-06 12:20:10 -04:00
Fedor Korotkov 0a9ad1a419 Fix Buildkite formula trust in monthly builds 2026-08-06 08:36:12 -04:00
Fedor Korotkov cd2d1c6698 Decouple runner release builds from Xcode releases 2026-07-05 12:00:02 -04:00
Fedor Korotkov 65519d3874 Remove dependency on release-xcode for runner image 2026-07-05 11:57:09 -04:00
Fedor Korotkov 71b405bd0c Add Tahoe runner Xcode 26.6 and beta 2 (#356)
* Add Tahoe runner Xcode 26.6 and beta 2

* Add PR template validation workflow

* Install Ansible for template validation

* Build template images in PR workflow

* Authenticate Packer plugin downloads

* Prepare Xcode archives for PR builds

* Support authenticated Xcode archive downloads

* Use Xcode 27 beta 2 version token

* Increase Tahoe runner disk size

* Select Xcode apps by path during runner builds

* Update Homebrew before Tuist install

* Avoid Tuist cask validation during image builds

* Trust Tuist formula during image builds

* Add Tahoe iOS 27 beta runtime expectation
2026-07-04 22:21:50 -04:00
Fedor Kororkov 2be4479694 Update release.yml (#352) 2026-06-08 16:30:42 -07:00
Fedor Korotkov 206d99a672 Migrate CI to GitHub Actions (#351) 2026-06-03 06:37:04 -07:00
Fedor Korotkov 0ad265b76d macOS and Xcode 26.5 (#349)
* macOS and Xcode 26.5

* Updated expected tahoe runtimes
2026-05-25 19:14:54 -04:00
Nikolay Edigaryev 154a7604f9 vanilla-sequoia.pkr.hcl: click "Select Your Country or Region" (#335) 2026-05-16 10:36:46 -04:00
Fedor Korotkov 5a2d4fd8cc Xcode 26.4.1 (#348) 2026-05-02 19:53:10 -04:00
Diogo Araújo 70cb4395fe feat: boot command changes to tahoe 26.4 (#344)
* feat: boot command changes to tahoe 26.4

* add first time password to enable screen sharing
2026-04-05 12:38:36 -04:00
Fedor Korotkov 7360b62106 Adjusted disk sizes for macOS Tahoe configurations in CI setup. 2026-04-05 12:35:16 -04:00
Fedor Korotkov e46673151d Xcode 26.5-beta (#345)
* Xcode 26.5-beta

* Fixed syntax error in Xcode versions list for Tahoe configuration.

* Updated Tahoe runtimes to include Xcode 26.5 beta versions

* Updated Tahoe runtimes to include Xcode 26.5 beta versions
2026-04-04 20:30:07 -04:00
Jacob Rhoda 5e65e3e712 Update Android SDK tools version and dependencies (#343)
Updated Android SDK tools versions to reflect most up-to-date default versions used by the Android gradle plugin (9.1.0)

- Platform: 36
- Build Tools: 36.0.0
- NDK: 28.2.13676358
2026-03-26 15:40:01 -04:00
Fedor Korotkov 5cf26631b9 macOS & Xcode 26.4 (#340)
* macOS & Xcode 26.4

* No Sonoma runner image

* Updated Tahoe tvOS 26.4 runtime to release version 23L243
2026-03-24 21:26:24 -04:00
Fedor Korotkov 0d8fe3156a Xcode 26.4 RC (#337)
* Xcode 16.4 RC

* Updated disk size for Sonoma CI runner and Tahoe runtimes to final Xcode 26.4 release versions.
2026-03-21 08:07:50 -04:00
Fedor Korotkov 69866eb29b Xcode 26.4 Beta 3 (#332)
* Xcode 26.4 Beta 3

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Removed iOS 26.2 from Tahoe runtimes list
2026-03-15 16:32:38 -04:00
Nikolay Edigaryev f2e700cda3 xcode.pkr.hcl: increase disk size from 120 to 140 GB (#333) 2026-03-15 13:08:44 -04:00
Nikolay Edigaryev 494e62f0b8 Disable SIP before running templates/base.pkr.hcl (#331)
* Disable SIP before running templates/base.pkr.hcl

* Don't forget to "packer init" before each "packer build"
2026-03-15 10:46:21 +01:00
Nikolay Edigaryev 27def7c5ce Prevent an array with empty element when XCODE_COMPONENTS is unset (#330) 2026-03-13 17:23:50 -04:00
Nikolay Edigaryev f9c2b3c122 base.pkr.hcl: update TCC.db and allow automation tools (#329) 2026-03-12 13:01:54 +01:00
Fedor Korotkov 7132d10945 Xcode 26.3 Release (#326) 2026-02-26 16:03:56 -05:00
Fedor Korotkov 33e373e65b Xcode 26.4 Beta 2 (#325)
* Xcode 26.4 Beta 2

* Updated Tahoe runtimes to latest Xcode 26.4 release versions
2026-02-23 19:52:43 -05:00
Fedor Korotkov cfa9e2361c Xcode 26.3 RC 2 (#324)
* Xcode 26.3 RC 2

* Increase DISK_SIZE from 230 to 240
2026-02-21 08:08:10 -05:00
Fedor Korotkov 09fce08792 Xcode 26.4 Beta (#323)
* Xcode 26.4 Beta

* Updated Tahoe runtimes to Xcode 26.4 Beta versions
2026-02-17 07:00:35 -05:00
Fedor Korotkov 01365193b9 Updated Tahoe template to use macOS 26.3 restore image. (#322)
Fixes #321
2026-02-13 16:20:18 +01:00
Fedor Korotkov 1414d3bf4b Added Buildkite agent installation to base Packer template. (#320) 2026-02-05 06:56:38 -05:00
Fedor Korotkov fbaec2adaa Xcode 26.3 RC (#319)
* Xcode 26.3 RC

* Removed unavailable runtimes from Tahoe list.
2026-02-04 10:13:22 -05:00
Fedor Korotkov f47f8bf08c Added rbenv 3.3.10 installation to address Fastlane compatibility in Xcode packer template. 2026-01-10 18:16:37 +01:00
Fedor Korotkov d56bd82e5d Refined Tuist installation steps in Xcode packer template. 2026-01-10 11:47:22 +01:00
Nikolay Edigaryev 4b95c2c93f Use the new <click 'Select Your Country or Region'> command (#317) 2025-12-16 21:02:14 +01:00
Fedor Korotkov 75924563a8 Updated macOS restore image comments for Sequoia 15.7.2 and Sonoma 14.8.2 2025-12-16 09:35:29 -05:00
Nikolay Edigaryev f3319b8eb8 Revert "Remove explicit FileVault step from Packer boot command for macOS 26.1 compatibility (#305)" (#316) 2025-12-15 19:07:52 -05:00
Fedor Korotkov 5ee829f2c8 macOS Tahoe 26.2 (#315) 2025-12-15 08:55:32 -05:00
Fedor Korotkov 64d9651dca Upgrade Node.js installation from version 20 to 24 (#314)
20 is retiring https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
2025-12-15 08:54:13 -05:00
Fedor Korotkov 0682bdb108 Xcode 26.2 (#313)
* Xcode 26.2

* Corrected Xcode version to 26.1.1 in Cirrus config.

* Updated Tahoe runtime build number for iOS 26.2.
2025-12-13 10:30:58 -05:00
Fedor Korotkov 3abe5ef330 Fixed syntax 2025-12-06 17:44:39 -05:00
Fedor Korotkov 36c1f1d9b7 Updated Tahoe runtimes to Xcode 26.2 release versions 2025-12-05 16:30:31 -05:00
Fedor Korotkov 413eb891fe Xcode 26.2 RC 2025-12-05 16:30:31 -05:00
Dominik Abilio de Jesus MoreiraandDominik Wunderlich be895f2507 Fix Gatekeeper disable step in boot command (#311)
Added the missing "tab" command in the "Disable GateKeeper (2/2)" section. Without this command, Gatekeeper was not fully disabled, causing the provisioner check to fail when verifying that Gatekeeper is disabled.

Co-authored-by: Dominik Wunderlich <dominik.wunderlich@teamviewer.com>
2025-12-05 14:42:22 +01:00
Fedor Korotkov 9115ef2553 Increase DISK_SIZE from 290 to 300 2025-11-22 11:36:44 -05:00
Fedor Korotkov 11b22ea0d0 Preinstall common AI agents (#308)
So it's possible to automate things within VMs.
2025-11-20 12:24:31 -05:00
Fedor Korotkov 062ecd3e0e Xcode 26.2 Beta 2 (#307)
* Xcode 26.2 Beta 2

Plus wait for simulators to become available.

* Update expected runtimes for Xcode 26.2 Beta 2

* Try to wait an hour

* Cleanup LLM generated script

* Add `exex-script.pkr.hcl` template and adjust simulator wait logic

* Finalize

* Fixed script name

* Fixed typo

* Use scrript option.
2025-11-20 10:16:45 -05:00
Fedor Korotkov 329c3e137e Add iOS 18.6 runtime to Tahoe (#306)
* Add iOS 18.7.2 runtime to Tahoe

* 18.6

* Updated expected runtimes

* Bump disk
2025-11-14 11:35:52 -05:00
Dominik Wunderlich e681fe0983 Remove explicit FileVault step from Packer boot command for macOS 26.1 compatibility (#305)
Remove the explicit FileVault step from the Packer boot command sequence used during macOS setup.
In macOS 26.1, the FileVault setup screen no longer appears consistently during initial setup because FileVault encryption is now automatically handled via system defaults, Apple ID, or MDM profiles.
This change prevents script failure or waiting on a missing UI prompt.
2025-11-13 19:57:38 +04:00
Fedor Korotkov 2e6e2dfb6e Removed redundant xcodes version command in provisioner 2025-11-12 20:23:10 -05:00
Fedor Korotkov 0652373c8c Updated simulator 2025-11-12 20:21:25 -05:00
Fedor Korotkov 082799eb6f Fixed Xcodes installation (#304)
* Fixed Xcodes installation

* Removed redundant execution lock from Cirrus runner configuration
2025-11-12 19:14:44 -05:00
Fedor Korotkov 3b47c8dfc6 Revert GitHub Actions Runner compatibility provisioner changes 2025-11-12 19:00:34 -05:00
Fedor Korotkov 69ed3fe0fa Xcode 26.1.1 (#302)
* Xcode 26.1.1

* Proper literal

* Install prebuilt binary for xcodes

* split

* Revert "split"

This reverts commit 8a0363fe31.

* Fix xcodes installation and update file ownership logic

* echo path

* Use full path

* revert chmod
2025-11-12 18:18:51 -05:00
Fedor Korotkov 256b8cc1c8 Restart VM while building Xcode variant (#301)
* Restart VM while building Xcode variant

In an attempt to make https://github.com/actions/runner-images/issues/12948 less flaky. Xcode Release Notes at some point mentioend a first boot for another issue so let's make the VM boot twoce and do caching population just to be extra cautios.

* just `xcrun simctl list -v`

* support sonoma
2025-11-11 18:10:42 -05:00
Fedor KorotkovandChristoph Aldrian d7752dd971 Xcode 26.1 Release and 26.2 Beta (#298)
* Xcode 26.1 Release and 26.2 Beta

Plus installed tvOS 17.5 on Sequoia runner

* Update .ci/cirrus.runner.yml

Co-authored-by: Christoph Aldrian <caldrian@users.noreply.github.com>

* Updated expected runtimes

* Bump disk for Tahoe

* install `otel-cli`

---------

Co-authored-by: Christoph Aldrian <caldrian@users.noreply.github.com>
2025-11-08 09:26:25 -05:00
Fedor Korotkov 64b8b7407b macOS Tahoe 26.1 2025-11-04 08:44:11 -05:00
Fedor Korotkov 91c8fbf624 Do not auto-update Ventura 2025-11-01 12:01:55 -04:00
Fedor Korotkov aec76f172d Ruby 3.3.10 2025-11-01 12:00:49 -04:00
Fedor Korotkov a2b4e1ebfe Xcode 26.1-rc (#297)
* Xcode 26.1-rc

* Updated simulators
2025-11-01 10:41:03 -04:00
Fedor Korotkov 1f481f72c7 Xcode 26 Beta 3 (#296)
* Xcode 26 Beta 3

* Updated expected runtimes

* Removed iOS 26 due to

> iOS 26 is not available for download.

Seems only 26.0.1 is available.
2025-10-25 10:57:45 -04:00
Fedor Korotkov 463004bc84 Xcode 26 Beta 2 (#291)
* Xcode 26 Beta 2

* Updated expected runtimes

* new line
2025-10-10 12:27:20 -04:00
Fedor Korotkov 6755f3d245 Removed update (#293) 2025-10-10 20:25:46 +04:00
Nikolay Edigaryev aa8af495d1 README.md: update image descriptions (#289)
* README.md: update image descriptions

* Proper Xcode spelling
2025-09-29 15:57:11 +04:00
Fedor Korotkov 4232c64336 Remove asdf installation from base image (#290) 2025-09-29 07:44:04 -04:00
Fedor Korotkov f4565a71c7 Xcode 26.1 Beta (#286)
* Xcode 26.1 Beta

* Updated runtimes

* Bump disk
2025-09-26 10:33:06 -04:00
Fedor Korotkov 971a78c341 Xcode 16 on Sonoma (#287)
* Xcode 16 on Sonoma

* Updated runtimes

* Bump disk
2025-09-26 08:00:13 -04:00
Jakub Olejník 4f13a88f28 Use Terminal to open System settings on Tahoe (#283) 2025-09-25 21:04:19 +04:00
Fedor KorotkovandNikolay Edigaryev ba783a5bc7 Xcode 26.0.1 (#285)
* Xcode 26.0.1

* Update .ci/cirrus.runner.yml

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>

* Fixed build

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2025-09-25 09:10:25 -04:00
Fedor Korotkov db71c44bc1 Fixed syntax 2025-09-20 09:45:23 +02:00
Fedor Korotkov 5ed6926ec7 Fixed syntax 2025-09-20 09:40:41 +02:00
Fedor Korotkov 95ee5a5656 Pre-install asdf and mise (#284)
* Pre-install asdf

* Install mise
2025-09-19 06:30:06 -04:00
ea02816fa7 Xcode 26 Release (#281)
* Xcode 26 Release

Make it default for Sequoia runner.

* Update .ci/cirrus.runner.yml

Co-authored-by: Matouš Skála <skala.matous@gmail.com>

* Updated 23R353

* Update .ci/cirrus.runner.yml

Co-authored-by: Aleš Hanžlík <hanzlikale@gmail.com>

---------

Co-authored-by: Matouš Skála <skala.matous@gmail.com>
Co-authored-by: Aleš Hanžlík <hanzlikale@gmail.com>
2025-09-16 15:21:27 -04:00
Tony Arnold e6a57fc713 iOS Simulator Runtime 23A343 (#280) 2025-09-16 08:00:35 -04:00
Fedor Korotkov 17dc1dab05 Bumped all vanillas (#279) 2025-09-16 07:26:04 -04:00
Fedor Korotkov b86acf6821 No need to update Tahoe 2025-09-12 16:56:43 -04:00
Fedor Korotkov 537b590859 Tahoe runner (#278) 2025-09-11 22:10:21 -04:00
Fedor Korotkov 45c214692c Xcode 26 RC (#276)
* Xcode 26 RC

* Updated expected list
2025-09-09 17:33:00 -04:00
Fedor Korotkov b94738812f Fixed components 2025-09-07 14:32:40 -04:00
Fedor Korotkov 2d4e5b9968 macOS 26.0 beta 9 2025-09-02 15:07:24 -04:00
Fedor Korotkov 24607711dc Include XCODE_COMPONENTS on release cuts (#272)
* Include XCODE_COMPONENTS on release cuts

Fixes https://github.com/cirruslabs/macos-image-templates/issues/264#issuecomment-3242673167

* -var xcode_components
2025-09-01 12:01:22 -04:00
Nikolay Edigaryev 081c8ac4e3 vanilla-tahoe.pkr.hcl: adapt "boot_command" to recent installer changes (#271) 2025-08-29 11:15:40 -04:00
Fedor Korotkov d0f94cc4c8 Xcode 26 Beta 7 and macOS 26.0 beta 8 (#270)
* Xcode 26 Beta 7 and macOS 26.0 beta 8

* fixed syntax
2025-08-29 10:47:35 -04:00
fe19dc9f17 Install Metal toolchain for Xcode 26 and newer (#268)
* Install Metal toolchain when Xcode version is 26 or newer

* Define a variable rather than using a regex

* Provide the Xcode components as a list

* Use “shell” rather than “provisioner”

* Update .ci/cirrus.xcode.yml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-08-26 08:05:50 -04:00
Nikolay Edigaryev 6f8ae07451 Disable SIP on "-base" and "-xcode" images only (#269)
* Disable SIP on "-base" and "-xcode" images only

* Ventura needs DISABLE_SIP_TEMPLATE too
2025-08-26 00:17:00 +04:00
Fedor Korotkov 16a5100187 macOS Sequoia 15.6.1 (#267) 2025-08-20 15:45:07 -04:00
Fedor Korotkov 7058092d82 Xcode 26 Beta 6 and other updates (#266)
Related to #265
2025-08-20 14:08:27 -04:00
Fedor Korotkov 0d3b4f4efd Update latest betas (#259)
* Latest betas

* Ruby 3.3.9

* Updated simulators

* New line
2025-08-09 07:17:50 -04:00
Nikolay Edigaryev aad3ba254d vanilla-sequoia.pkr.hcl: upgrade IPSW from 15.5 to 15.6 (#261) 2025-08-07 06:32:08 -04:00
Nikolay Edigaryev 0c0a90071d vanilla-sonoma.pkr.hcl: use macOS Sonoma IPSW instead of Sequoia IPSW (#260) 2025-08-07 05:38:29 -04:00
Fedor Korotkov 276b6dde65 Include SwiftLint version in .setup_info (#258) 2025-08-04 12:27:24 -04:00
Fedor Korotkov 5e8c823ef0 Install all iOS packages after Xcode installation 2025-08-02 05:05:49 -04:00
Fedor Korotkov b6445b9d3a Xcode 26 Beta 4 (#256)
* Xcode 26 Beta 4

* Updated simulators

* Updated simulators

* Fixes after CI

* New line

* bring back 18.5

* bump disk
2025-08-02 04:48:25 -04:00
Fedor Korotkov ad9ce34d12 Install additional common packages (#257) 2025-08-01 15:14:46 -04:00
Fedor Korotkov 9746337eeb Sonoma 15.6 2025-07-29 17:08:48 -04:00
Fedor Korotkov f7880705ec All simulators for the last 3 versions of Xcode (#254) 2025-07-23 16:44:14 -04:00
Fedor Korotkov bc67673068 Update cirrus.runner.yml 2025-07-14 16:17:41 -04:00
Fedor Korotkov 393d7c615b Sonoma Xcode 15.4 (#253)
* Sonoma Xcode 15.4

* More disk

* watchOS 10.5 on sonoma

* Removed watchOS
2025-07-14 15:38:02 -04:00
Fedor Korotkov f292033e59 Fixed index out of bound 2025-07-14 14:43:21 -04:00
Fedor Korotkov e3cf995511 Xcode 26 Beta 3 (#251)
* Xcode 26 Beta 3

* Print disk sizes between Xcodes

* Tweak sizes

* Strip some simulators

* 17.5 for sonoma

* fixed expected runtimes

* Tweaked disk sizes
2025-07-11 15:01:42 -04:00
James Smith 3c3581a46f Update image to macOS 26 beta 3 (#250) 2025-07-08 00:45:56 -04:00
Fedor Korotkov 2fbdfd6186 Beta 1 runtimes 2025-07-07 08:14:11 +04:00
Fedor Korotkov a806b2d4ef Reverted to 26-beta 2025-07-07 08:09:46 +04:00
Fedor Korotkov c48cab887b Reverted to 26-beta-1 2025-07-07 08:06:34 +04:00
Fedor Korotkov d5d126deaa Revert "Updated runtimes"
This reverts commit ac6cbef9a6.
2025-07-07 08:06:28 +04:00
fedor ac6cbef9a6 Updated runtimes 2025-06-29 06:54:08 -07:00
Fedor Korotkov 9736671744 Xcode 26 Beta 2 (#249)
* Xcode 26 Beta 2

* Updated runtimes
2025-06-28 16:25:56 -07:00
Fedor Korotkov 2ec40d16cb macOS Tahoe Beta 2 (#248) 2025-06-24 10:39:45 -04:00
Nikolay Edigaryev ce496aa3ad Increase timeouts before "Select Your Country or Region" (#247)
...and "Welcome to Mac" screens.
2025-06-16 09:34:15 -04:00
fedor 660eac6ae0 Removed brew doctor
Because of Tahoe
2025-06-12 21:45:23 -07:00
fedor 530036c1bc Trigger vanilla 2025-06-12 18:05:15 -07:00
Fedor Korotkov 69ca3f729a Build base/xcode/runner variants for Tahoe (#245) 2025-06-12 16:23:41 -07:00
Nikolay Edigaryev e70eea50c4 Automated macOS 26 (Tahoe) installation (#244)
* Automated macOS 26 (Tahoe) installation

* Support "Command Line Tools beta  for Xcode-26.0" label

* account for "beta"
* preserve multiple spaces

* .ci/cirrus.vanilla.yml: add "MACOS_VERSION: tahoe"

* Disable SIP for Tahoe
2025-06-12 10:16:46 -07:00
Nikolay Edigaryev 3ac0f46b3e tart-guest-agent: specify TERM and set working directory to HOME (#243) 2025-06-12 00:08:06 +04:00
Fedor Korotkov 63e44895a7 New line 2025-06-09 16:27:39 -07:00
Fedor Korotkov c1d543be58 Xcode 26 beta (#241)
* Xcode 26 beta

* Updated Runtimes
2025-06-09 14:52:00 -07:00
27 changed files with 1548 additions and 310 deletions
-19
View File
@@ -1,19 +0,0 @@
task:
name: "Update Base Images ($MACOS_VERSION)"
alias: update-base
matrix:
- env:
MACOS_VERSION: sonoma
- env:
MACOS_VERSION: sequoia
<<: *defaults
pull_vanilla_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
build_base_script:
- packer init templates/base.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
push_base_script:
- tart push $MACOS_VERSION-base ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
always:
cleanup_script:
- tart delete $MACOS_VERSION-base
-21
View File
@@ -1,21 +0,0 @@
task:
name: "Release Xcode $CIRRUS_TAG ($MACOS_VERSION)"
matrix:
- env:
MACOS_VERSION: sequoia
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$CIRRUS_TAG\"]" templates/xcode.pkr.hcl
push_script: |
if [[ $CIRRUS_TAG == *"beta"* ]]
then
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG
else
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete $MACOS_VERSION-xcode:$CIRRUS_TAG || true
-33
View File
@@ -1,33 +0,0 @@
task:
name: "Update Runner Image ($MACOS_VERSION)"
execution_lock: runner-image-update
env:
matrix:
- MACOS_VERSION: sonoma
XCODE_VERSIONS: "16.1,16,15.4,15.3,15.2,15.1,\"15.0.1\""
DISK_SIZE: 400
- MACOS_VERSION: sequoia
XCODE_VERSIONS: "16.4,16.3,16.2,16.1,16"
ADDITIONAL_IOS_BUILDS: "18.4,18.2,17.5"
DISK_SIZE: 400
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
init_xcode_script: packer init templates/xcode.pkr.hcl
build_xcode_script: |
packer build -var tag=runner -var disk_size=$DISK_SIZE \
-var disk_free_mb=100000 \
-var macos_version="$MACOS_VERSION" \
-var xcode_version="[$XCODE_VERSIONS]" \
-var additional_ios_builds="[$ADDITIONAL_IOS_BUILDS]" \
-var expected_runtimes_file="data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
push_script: |
if [[ -z "$CIRRUS_PR" ]]; then
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
else
echo "Skipping pushing for PR..."
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:runner"
-31
View File
@@ -1,31 +0,0 @@
env:
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
DISABLE_SIP_TEMPLATE: disable-sip.pkr.hcl
task:
name: "Update Vanilla Image ($MACOS_VERSION)"
env:
matrix:
- MACOS_VERSION: sequoia
DISABLE_SIP_TEMPLATE: disable-sip-with-username.pkr.hcl
- MACOS_VERSION: sonoma
- MACOS_VERSION: ventura
- MACOS_VERSION: monterey
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
<<: *defaults
build_script:
- packer init templates/vanilla-$MACOS_VERSION.pkr.hcl
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
disable_sip_script:
- packer build -var vm_name=$MACOS_VERSION-vanilla "templates/${DISABLE_SIP_TEMPLATE}"
resolve_macos_number_script:
- packer build -var vm_base_name=$MACOS_VERSION-vanilla -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
- rm $RESOLVE_FILE
- tart delete $RESOLVE_VM_NAME
push_script:
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
always:
cleanup_script:
- tart delete $MACOS_VERSION-vanilla
-37
View File
@@ -1,37 +0,0 @@
task:
name: "Update Xcode Images ($MACOS_VERSION $XCODE_VERSION)"
depends_on: update-base
env:
matrix:
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.4
LATEST: true
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.3
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.2
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.1
- MACOS_VERSION: sequoia
XCODE_VERSION: 16
- MACOS_VERSION: sonoma
XCODE_VERSION: 16.1
LATEST: true
- MACOS_VERSION: sonoma
XCODE_VERSION: 16
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_xcode_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$XCODE_VERSION\"]" templates/xcode.pkr.hcl
push_script: |
if [[ -z "$LATEST" ]]
then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION"
-52
View File
@@ -1,52 +0,0 @@
load("cirrus", "env", "http", "fs", "changes_include")
load("github.com/cirrus-modules/graphql", "rerun_task_if_issue_in_logs")
def on_task_failed(ctx):
if ctx.payload.data.task.automaticReRun:
print("Task is already an automatic re-run! Won't even try to re-run it...")
return
rerun_task_if_issue_in_logs(ctx.payload.data.task.id, "The network connection was lost")
def on_build_failed(ctx):
# Only send Slack notifications for failed cron builds[1]
#
# [1]: https://cirrus-ci.org/guide/writing-tasks/#cron-builds
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
return
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
"Content-Type": "application/json",
}, json_body={
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
build_id=ctx.payload.data.build.id,
change_message_title=ctx.payload.data.build.changeMessageTitle,
branch_name=ctx.payload.data.build.branch,
repository_name=ctx.payload.data.repository.name,
),
"url": "https://cirrus-ci.com/build/{build_id}".format(
build_id=ctx.payload.data.build.id,
),
})
if resp.status_code != 200:
fail("failed to post message to Slack: got unexpected HTTP {}".format(resp.status_code))
resp_json = resp.json()
if resp_json["ok"] != True:
fail("got error when posting message to Slack: {}".format(resp_json["error"]))
def main(ctx):
result = fs.read(".ci/cirrus.vanilla.yml")
if env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.release.yml")
if env.get("CIRRUS_CRON") == "monthly":
result += fs.read(".ci/cirrus.base.yml")
result += fs.read(".ci/cirrus.xcode.yml")
prForRunners = env.get("CIRRUS_PR") and changes_include(".ci/cirrus.runner.yml")
if prForRunners or env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.runner.yml")
return result
-21
View File
@@ -1,21 +0,0 @@
persistent_worker:
labels:
name: dev-mini
resources:
tart-vms: 1
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
AWS_ACCESS_KEY_ID: ENCRYPTED[c187b670a17eead88c1698849376273991d09678efe37ae2f0c9738c27a2422741a71c501ef4b6a4df7bff3eca5213a9]
AWS_SECRET_ACCESS_KEY: ENCRYPTED[e456254a53b82e3167f2da23e24c389620cb3f7d47e4e5e7d993813bf9bb18c784d5cb8d88d19632073acc9e1f6096c9]
defaults: &defaults
timeout_in: 3h
update_script:
- brew update || true
- brew upgrade || true
info_script:
- tart --version
- packer --version
+203
View File
@@ -0,0 +1,203 @@
name: Monthly Images
on:
schedule:
- cron: "0 8 * * 6"
workflow_dispatch:
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
should-run:
name: Check Monthly Cadence
runs-on: [self-hosted, macOS, ARM64]
outputs:
build: ${{ steps.cadence.outputs.build }}
steps:
- name: Check first Saturday
id: cadence
env:
EVENT_NAME: ${{ github.event_name }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
build=true
else
day="$(date -u +%d)"
if (( 10#$day <= 7 )); then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
if [[ "$build" != "true" ]]; then
echo "Not the first Saturday of the month; skipping image rebuilds."
fi
update-base:
name: Update Base Images (${{ matrix.macos_version }})
needs: should-run
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
MACOS_VERSION: ${{ matrix.macos_version }}
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull vanilla image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Push base image
run: |
tart push "$MACOS_VERSION-base" "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-base" || true
update-xcode:
name: Update Xcode Images (${{ matrix.macos_version }} ${{ matrix.xcode_version }})
needs:
- should-run
- update-base
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_version: "26.2"
xcode_components: '"MetalToolchain"'
latest: true
- macos_version: tahoe
xcode_version: "26.1.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: tahoe
xcode_version: "26.0.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: sequoia
xcode_version: "16.4"
xcode_components: ""
latest: true
- macos_version: sequoia
xcode_version: "16.3"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.2"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.1"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "16.1"
xcode_components: ""
latest: true
- macos_version: sonoma
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "15.4"
xcode_components: ""
latest: false
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSION: ${{ matrix.xcode_version }}
LATEST: ${{ matrix.latest }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build Xcode image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push Xcode image
run: |
if [[ "$LATEST" == "true" ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION" || true
+167
View File
@@ -0,0 +1,167 @@
name: Release Images
on:
release:
types:
- published
workflow_dispatch:
inputs:
xcode_version:
description: "Xcode version/tag to release"
required: true
type: string
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
XCODE_RELEASE_VERSION: ${{ github.event.release.tag_name || inputs.xcode_version }}
jobs:
release-xcode:
name: Release Xcode ${{ github.event.release.tag_name || inputs.xcode_version }} (${{ matrix.macos_version }})
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- tahoe
- sequoia
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: '"MetalToolchain"'
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Validate release version
run: |
set -euo pipefail
if [[ -z "$XCODE_RELEASE_VERSION" ]]; then
echo "XCODE_RELEASE_VERSION is required."
exit 1
fi
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build release image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_RELEASE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push release image
run: |
if [[ "$XCODE_RELEASE_VERSION" == *beta* ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION"
else
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" || true
release-runner:
name: Update Runner Image (${{ matrix.macos_version }})
# Keep runner refreshes independent from the release-xcode matrix so one
# Xcode image failure does not skip the runner matrix.
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-2","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build runner image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Push runner image
run: |
tart push "$MACOS_VERSION-xcode:runner" "ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true
+381
View File
@@ -0,0 +1,381 @@
name: Template Builds
on:
pull_request:
paths:
- ".github/workflows/monthly.yml"
- ".github/workflows/release.yml"
- ".github/workflows/template-validation.yml"
- "data/**"
- "scripts/**"
- "templates/**"
permissions:
contents: read
packages: read
concurrency:
group: template-builds-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
env:
FASTLANE_SESSION: ${{ secrets.FASTLANE_SESSION }}
FASTLANE_USER: ${{ secrets.FASTLANE_USER }}
HOMEBREW_NO_AUTO_UPDATE: 1
HOMEBREW_NO_INSTALL_CLEANUP: 1
PACKER_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
packer-validate:
name: Packer Validate
runs-on: macos-15
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Packer
uses: hashicorp/setup-packer@v3
- name: Install validation dependencies
run: |
brew install ansible
- name: Prepare validation inputs
run: |
mkdir -p "$HOME/XcodesCache"
touch "$HOME/XcodesCache/Xcode_26.6.xip"
- name: Validate templates
run: |
set -euo pipefail
validate() {
local template="$1"
shift
packer init "$template"
packer validate "$@" "$template"
}
for template in templates/vanilla-*.pkr.hcl; do
validate "$template"
done
validate templates/base.pkr.hcl \
-var vm_name=template-validation-base
validate templates/disable-sip.pkr.hcl \
-var vm_name=template-validation-disable-sip
validate templates/disable-sip-with-username.pkr.hcl \
-var vm_name=template-validation-disable-sip-user
validate templates/exex-script.pkr.hcl \
-var vm_name=template-validation-exec \
-var script_path=scripts/finalize-tahoe.sh
validate templates/resolve-macos-number.pkr.hcl \
-var vm_base_name=template-validation-base \
-var vm_name=template-validation-resolve \
-var resolve_file=macos-version.txt
validate templates/xcode.pkr.hcl \
-var macos_version=tahoe \
-var 'xcode_version=["26.6"]' \
-var expected_runtimes_file=data/expected.tahoe.runtimes.txt
build-vanilla:
name: Build Vanilla Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
build-base:
name: Build Base Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Eq '^(templates/base\.pkr\.hcl|templates/disable-sip.*\.pkr\.hcl|data/(github_known_hosts|limit\.maxfiles\.plist|setup-info-template\.json|tart-guest-.*\.plist)|scripts/(install-actions-runner|update-tcc-database)\.sh|ansible/)' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-base" || true
build-runner:
name: Build Runner Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-2","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq ".github/workflows/release.yml" changed-files.txt; then
build=true
elif grep -Fxq "data/expected.$MACOS_VERSION.runtimes.txt" changed-files.txt; then
build=true
elif grep -Fxq "scripts/finalize-$MACOS_VERSION.sh" changed-files.txt; then
build=true
elif grep -Eq '^(templates/xcode\.pkr\.hcl|data/setup-info-template\.json|scripts/install-actions-runner\.sh)$' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull base image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Prepare Xcode archives
if: steps.select.outputs.build == 'true'
run: |
set -euo pipefail
source ~/.zprofile || true
if ! command -v xcodes >/dev/null; then
brew install xcodes
fi
mkdir -p "$HOME/XcodesCache"
IFS=',' read -ra versions <<< "$XCODE_VERSIONS"
for raw_version in "${versions[@]}"; do
version="${raw_version//\"/}"
target="$HOME/XcodesCache/Xcode_${version}.xip"
if [[ -f "$target" ]]; then
echo "Using cached Xcode $version at $target"
continue
fi
echo "Downloading Xcode $version"
if [[ -z "${FASTLANE_SESSION:-}" ]]; then
echo "::error::Missing $target and FASTLANE_SESSION is not configured. Pre-cache the Xcode archive on the runner or add Apple Developer auth secrets."
exit 1
fi
download_args=(download "$version" --directory "$HOME/XcodesCache" --use-fastlane-auth)
if [[ -n "${FASTLANE_USER:-}" ]]; then
download_args+=(--fastlane-user "$FASTLANE_USER")
fi
xcodes "${download_args[@]}"
candidate=""
case "$version" in
27-beta-2)
candidate="$HOME/XcodesCache/Xcode_27_beta_2.xip"
;;
27-beta)
candidate="$HOME/XcodesCache/Xcode_27_beta.xip"
;;
*)
candidate="$(find "$HOME/XcodesCache" -maxdepth 1 -type f -name "Xcode_${version}*.xip" -print -quit)"
;;
esac
if [[ -n "$candidate" && -f "$candidate" && "$candidate" != "$target" ]]; then
mv "$candidate" "$target"
fi
test -f "$target"
done
- name: Build runner image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
if: steps.select.outputs.build == 'true'
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true
+129
View File
@@ -0,0 +1,129 @@
name: Vanilla Images
on:
push:
paths:
- "templates/vanilla-*.pkr.hcl"
workflow_dispatch:
inputs:
macos_version:
description: "macOS vanilla image to build"
required: true
default: all
type: choice
options:
- all
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
update-vanilla:
name: Update Vanilla Image (${{ matrix.macos_version }})
if: >-
${{
github.event_name == 'workflow_dispatch' ||
github.ref == format('refs/heads/{0}', github.event.repository.default_branch)
}}
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
RESOLVE_VM_NAME: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}
RESOLVE_FILE: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}.txt
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BEFORE_SHA: ${{ github.event.before }}
EVENT_NAME: ${{ github.event_name }}
INPUT_MACOS_VERSION: ${{ inputs.macos_version || 'all' }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
if [[ "$INPUT_MACOS_VERSION" == "all" || "$INPUT_MACOS_VERSION" == "$MACOS_VERSION" ]]; then
build=true
fi
else
if [[ "$BEFORE_SHA" =~ ^0+$ ]]; then
git diff-tree --no-commit-id --name-only -r "$GITHUB_SHA" > changed-files.txt
else
git diff --name-only "$BEFORE_SHA" "$GITHUB_SHA" > changed-files.txt
fi
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Resolve macOS version
id: resolve
if: steps.select.outputs.build == 'true'
run: |
packer build \
-var "vm_base_name=$MACOS_VERSION-vanilla" \
-var "vm_name=$RESOLVE_VM_NAME" \
-var "resolve_file=$RESOLVE_FILE" \
templates/resolve-macos-number.pkr.hcl
echo "macos_number=$(cat "$RESOLVE_FILE")" >> "$GITHUB_OUTPUT"
rm -f "$RESOLVE_FILE"
- name: Push vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart push "$MACOS_VERSION-vanilla" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:${{ steps.resolve.outputs.macos_number }}"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
tart delete "$RESOLVE_VM_NAME" || true
+1 -1
View File
@@ -15,7 +15,7 @@ packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
## Building Base Image
```bash
packer build -var macos_version=sonoma templates/base.pkr.hcl
packer build -var vm_name=sonoma-vanilla templates/base.pkr.hcl
```
## Building Xcode Image
+9 -16
View File
@@ -1,32 +1,25 @@
## macOS Packer Templates for Tart
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with [Cirrus Runners](https://cirrus-runners.app/),
[Cirrus CI](https://cirrus-ci.org/guide/macOS/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with self-hosted
GitHub Actions runners, [Cirrus Runners](https://cirrus-runners.app/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
The following image variants are currently available:
* `macos-{sequoia,sonoma}-base` image has only `brew` pre-installed and the latest version of `macOS` available
* `macos-{sequoia,sonoma}-xcode:N` image is based on `macos-{sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
* `macos-runner:{sequoia,sonoma}` image is a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
* `macos-{golden-gate,tahoe,sequoia,sonoma}-vanilla` — a vanilla macOS installation with helpful tweaks such as auto-login, but no additional software preinstalled
* `macos-{tahoe,sequoia,sonoma}-base` — based on `macos-{tahoe,sequoia,sonoma}-vanilla` image, it comes with `brew` and [other useful software](https://github.com/cirruslabs/macos-image-templates/blob/main/templates/base.pkr.hcl) pre-installed, but without Xcode
* `macos-{tahoe,sequoia,sonoma}-xcode:N` — based on `macos-{tahoe,sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
* `macos-runner:{tahoe,sequoia,sonoma}` — a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
See a full list of VMs available [here](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos-).
## Release Cadence
Once a new version of Xcode is released, we will initiate a GitHub release which will automatically build and push
a new version of the `macos-sequoia-xcode:N`. This generally happens within 24 hours of a release.
a new version of the `macos-{tahoe,sequoia}-xcode:N`. This generally happens the next weekend after a release.
Please watch this repository releases to get notified about new images.
For an Xcode release which is non beta and not an RC `ghcr.io/cirruslabs/macos-runner:sequoia` image will also be updated.
## Update Cadence
Some of the images are regularly getting rebuild in order to update the pre-installed packages. The following images are updated
monthly on the first Saturday of the month:
Some of the images are regularly getting rebuild in order to update the pre-installed packages.
* `ghcr.io/cirruslabs/macos-{sequoia,sonoma}-base`
* `ghcr.io/cirruslabs/macos-runner:sonoma` which is a superset of `ghcr.io/cirruslabs/macos-sonoma-xcode:{latest,16.1,16,15.4,15.3,15.2,15.1,15.0.1}`
* `ghcr.io/cirruslabs/macos-runner:sequoia` which is a superset of `ghcr.io/cirruslabs/macos-sequoia-xcode:{latest,16.3,16.2,16.1,16,15.4}`
Note that `ghcr.io/cirruslabs/macos-runner:{sequoia,sonoma}` are updated every Sunday and these images are [optimised for startup](https://cirrus-runners.app/blog/2024/04/11/optimizing-startup-time-of-cirrus-runners/)
on Cirrus Runners and Cirrus CI services.
[This workflow](.github/workflows/monthly.yml) defines images that are getting rebuilt monthly on the first Saturday of the month.
+6 -9
View File
@@ -6,18 +6,15 @@ iOS 18.2 (18.2 - 22C150) - com.apple.CoreSimulator.SimRuntime.iOS-18-2
iOS 18.3 (18.3.1 - 22D8075) - com.apple.CoreSimulator.SimRuntime.iOS-18-3
iOS 18.4 (18.4 - 22E238) - com.apple.CoreSimulator.SimRuntime.iOS-18-4
iOS 18.5 (18.5 - 22F77) - com.apple.CoreSimulator.SimRuntime.iOS-18-5
tvOS 18.0 (18.0 - 22J356) - com.apple.CoreSimulator.SimRuntime.tvOS-18-0
tvOS 18.1 (18.1 - 22J578) - com.apple.CoreSimulator.SimRuntime.tvOS-18-1
tvOS 18.2 (18.2 - 22K154) - com.apple.CoreSimulator.SimRuntime.tvOS-18-2
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0.1 - 23A8464) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
tvOS 17.5 (17.5 - 21L569) - com.apple.CoreSimulator.SimRuntime.tvOS-17-5
tvOS 18.4 (18.4 - 22L254) - com.apple.CoreSimulator.SimRuntime.tvOS-18-4
tvOS 18.5 (18.5 - 22L572) - com.apple.CoreSimulator.SimRuntime.tvOS-18-5
watchOS 11.0 (11.0 - 22R349) - com.apple.CoreSimulator.SimRuntime.watchOS-11-0
watchOS 11.1 (11.1 - 22R581) - com.apple.CoreSimulator.SimRuntime.watchOS-11-1
watchOS 11.2 (11.2 - 22S99) - com.apple.CoreSimulator.SimRuntime.watchOS-11-2
tvOS 26.0 (26.0 - 23J352) - com.apple.CoreSimulator.SimRuntime.tvOS-26-0
watchOS 11.4 (11.4 - 22T250) - com.apple.CoreSimulator.SimRuntime.watchOS-11-4
watchOS 11.5 (11.5 - 22T572) - com.apple.CoreSimulator.SimRuntime.watchOS-11-5
visionOS 2.0 (2.0 - 22N318) - com.apple.CoreSimulator.SimRuntime.xrOS-2-0
visionOS 2.1 (2.1 - 22N580) - com.apple.CoreSimulator.SimRuntime.xrOS-2-1
visionOS 2.3 (2.3 - 22N895) - com.apple.CoreSimulator.SimRuntime.xrOS-2-3
watchOS 26.0 (26.0 - 23R353) - com.apple.CoreSimulator.SimRuntime.watchOS-26-0
visionOS 2.4 (2.4 - 22O237) - com.apple.CoreSimulator.SimRuntime.xrOS-2-4
visionOS 2.5 (2.5 - 22O473) - com.apple.CoreSimulator.SimRuntime.xrOS-2-5
visionOS 26.0 (26.0 - 23M336) - com.apple.CoreSimulator.SimRuntime.xrOS-26-0
-15
View File
@@ -1,24 +1,9 @@
== Runtimes ==
iOS 17.0 (17.0.1 - 21A342) - com.apple.CoreSimulator.SimRuntime.iOS-17-0
iOS 17.2 (17.2 - 21C62) - com.apple.CoreSimulator.SimRuntime.iOS-17-2
iOS 17.4 (17.4 - 21E213) - com.apple.CoreSimulator.SimRuntime.iOS-17-4
iOS 17.5 (17.5 - 21F79) - com.apple.CoreSimulator.SimRuntime.iOS-17-5
iOS 18.0 (18.0 - 22A3351) - com.apple.CoreSimulator.SimRuntime.iOS-18-0
iOS 18.1 (18.1 - 22B81) - com.apple.CoreSimulator.SimRuntime.iOS-18-1
tvOS 17.0 (17.0 - 21J353) - com.apple.CoreSimulator.SimRuntime.tvOS-17-0
tvOS 17.2 (17.2 - 21K364) - com.apple.CoreSimulator.SimRuntime.tvOS-17-2
tvOS 17.4 (17.4 - 21L224) - com.apple.CoreSimulator.SimRuntime.tvOS-17-4
tvOS 17.5 (17.5 - 21L569) - com.apple.CoreSimulator.SimRuntime.tvOS-17-5
tvOS 18.0 (18.0 - 22J356) - com.apple.CoreSimulator.SimRuntime.tvOS-18-0
tvOS 18.1 (18.1 - 22J578) - com.apple.CoreSimulator.SimRuntime.tvOS-18-1
watchOS 10.0 (10.0 - 21R355) - com.apple.CoreSimulator.SimRuntime.watchOS-10-0
watchOS 10.2 (10.2 - 21S364) - com.apple.CoreSimulator.SimRuntime.watchOS-10-2
watchOS 10.4 (10.4 - 21T214) - com.apple.CoreSimulator.SimRuntime.watchOS-10-4
watchOS 10.5 (10.5 - 21T575) - com.apple.CoreSimulator.SimRuntime.watchOS-10-5
watchOS 11.0 (11.0 - 22R349) - com.apple.CoreSimulator.SimRuntime.watchOS-11-0
watchOS 11.1 (11.1 - 22R581) - com.apple.CoreSimulator.SimRuntime.watchOS-11-1
visionOS 1.0 (1.0 - 21N305) - com.apple.CoreSimulator.SimRuntime.xrOS-1-0
visionOS 1.1 (1.1 - 21O209) - com.apple.CoreSimulator.SimRuntime.xrOS-1-1
visionOS 1.2 (1.2 - 21O5565d) - com.apple.CoreSimulator.SimRuntime.xrOS-1-2
visionOS 2.0 (2.0 - 22N318) - com.apple.CoreSimulator.SimRuntime.xrOS-2-0
visionOS 2.1 (2.1 - 22N580) - com.apple.CoreSimulator.SimRuntime.xrOS-2-1
+15
View File
@@ -0,0 +1,15 @@
== Runtimes ==
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0.1 - 23A8464) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
iOS 26.1 (26.1 - 23B86) - com.apple.CoreSimulator.SimRuntime.iOS-26-1
iOS 26.3 (26.3.1 - 23D8133) - com.apple.CoreSimulator.SimRuntime.iOS-26-3
iOS 26.4 (26.4.1 - 23E254a) - com.apple.CoreSimulator.SimRuntime.iOS-26-4
iOS 26.5 (26.5 - 23F77) - com.apple.CoreSimulator.SimRuntime.iOS-26-5
iOS 27.0 (27.0 - 24A5355p) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
iOS 27.0 (27.0 - 24A5370g) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
tvOS 26.5 (26.5 - 23L470) - com.apple.CoreSimulator.SimRuntime.tvOS-26-5
tvOS 27.0 (27.0 - 24J5305f) - com.apple.CoreSimulator.SimRuntime.tvOS-27-0
watchOS 26.5 (26.5 - 23T570) - com.apple.CoreSimulator.SimRuntime.watchOS-26-5
watchOS 27.0 (27.0 - 24R5305f) - com.apple.CoreSimulator.SimRuntime.watchOS-27-0
visionOS 26.5 (26.5 - 23O470) - com.apple.CoreSimulator.SimRuntime.xrOS-26-5
visionOS 27.0 (27.0 - 24M5306g) - com.apple.CoreSimulator.SimRuntime.xrOS-27-0
+4
View File
@@ -42,6 +42,10 @@
{
"name": "Fastlane Version",
"script": "fastlane --version"
},
{
"name": "SwiftLint Version",
"script": "swiftlint --version"
}
]
}
+3 -1
View File
@@ -13,9 +13,11 @@
<dict>
<key>PATH</key>
<string>/bin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/homebrew/bin</string>
<key>TERM</key>
<string>xterm-256color</string>
</dict>
<key>WorkingDirectory</key>
<string>/var/empty</string>
<string>/Users/admin</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
+72
View File
@@ -0,0 +1,72 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
# Wait until `xcrun simctl list devices -v` no longer reports any devices as "unavailable".
#
# Exit codes:
# 0 - Success: no devices are marked as unavailable within the timeout window
# 1 - Failure: timed out waiting for devices to become available
# 2 - Failure: prerequisites missing (e.g., xcrun not found)
DEFAULT_TIMEOUT_MINUTES=60
TIMEOUT_MINUTES=${1:-$DEFAULT_TIMEOUT_MINUTES}
if ! [[ "$TIMEOUT_MINUTES" =~ ^[0-9]+$ ]]; then
echo "[wait-simulators] ERROR: TIMEOUT_MINUTES must be an integer number of minutes (got: '$TIMEOUT_MINUTES')." >&2
exit 2
fi
SECONDS_TOTAL=$(( TIMEOUT_MINUTES * 60 ))
DEADLINE=$(( $(date +%s) + SECONDS_TOTAL ))
SLEEP_SECONDS=15
# Print a one-line status snapshot of current unavailable devices (if any)
print_status() {
if xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] Still seeing 'unavailable' devices at $(date '+%Y-%m-%d %H:%M:%S')"
# Show a concise list of unavailable lines for debugging
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /'
else
echo "[wait-simulators] No 'unavailable' devices detected at $(date '+%Y-%m-%d %H:%M:%S')"
fi
}
trap 'echo "[wait-simulators] Interrupted" >&2; exit 130' INT TERM
echo "[wait-simulators] Waiting up to ${TIMEOUT_MINUTES} minute(s) for simulators to become available..."
while true; do
if ! xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] All simulators are available."
exit 0
fi
NOW=$(date +%s)
if (( NOW >= DEADLINE )); then
echo "[wait-simulators] TIMEOUT after ${TIMEOUT_MINUTES} minute(s). Some simulators remain 'unavailable'." >&2
echo "[wait-simulators] Final snapshot of unavailable devices:" >&2
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /' >&2
exit 1
fi
print_status
REMAIN=$(( DEADLINE - NOW ))
# Sleep in chunks to allow quicker exit when they become available
SLEEP=$SLEEP_SECONDS
if (( REMAIN < SLEEP_SECONDS )); then SLEEP=$REMAIN; fi
sleep "$SLEEP"
# Loop and re-check
done
+55
View File
@@ -0,0 +1,55 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
update_tcc_database() {
sudo sqlite3 "$1" <<-'EOF'
INSERT OR REPLACE
INTO access (
service,
client_type,
client,
auth_value,
auth_reason,
auth_version,
indirect_object_identifier_type,
indirect_object_identifier
) VALUES
-- Indirect osascript invocation via SSH
('kTCCServiceAccessibility', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct osascript invocation
('kTCCServiceAccessibility', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct Python invocation
('kTCCServiceAccessibility', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
-- Commands invoked through the Tart Guest Agent
('kTCCServiceAccessibility', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED');
EOF
}
# Update TCC.db for all users
update_tcc_database "/Library/Application Support/com.apple.TCC/TCC.db"
# Update TCC.db for the current user
update_tcc_database "${HOME}/Library/Application Support/com.apple.TCC/TCC.db"
+13 -7
View File
@@ -7,13 +7,12 @@ packer {
}
}
variable "macos_version" {
variable "vm_name" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:latest"
vm_name = "${var.macos_version}-base"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
@@ -65,6 +64,8 @@ build {
"brew --version",
"brew update",
"brew install wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
"brew install buildkite/buildkite/buildkite-agent@3",
"brew install equinix-labs/otel-cli/otel-cli",
"brew install curl || true", // doesn't work on Monterey
"brew install --cask git-credential-manager",
"git lfs install",
@@ -105,6 +106,7 @@ build {
"brew install libyaml", # https://github.com/rbenv/ruby-build/discussions/2118
"brew install rbenv",
"echo 'if which rbenv > /dev/null; then eval \"$(rbenv init -)\"; fi' >> ~/.zprofile",
"brew install mise",
"source ~/.zprofile",
"rbenv install 2.7.8", // latest 2.x.x before EOL
"rbenv install -l | grep -v - | tail -2 | xargs -L1 rbenv install",
@@ -115,8 +117,8 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install node@20",
"echo 'export PATH=\"/opt/homebrew/opt/node@20/bin:$PATH\"' >> ~/.zprofile",
"brew install node@24",
"echo 'export PATH=\"/opt/homebrew/opt/node@24/bin:$PATH\"' >> ~/.zprofile",
"source ~/.zprofile",
"node --version",
"npm install --global yarn",
@@ -145,8 +147,7 @@ build {
inline = [
"source ~/.zprofile",
"test -d /Users/runner",
"test -f ~/.ssh/known_hosts",
"brew doctor"
"test -f ~/.ssh/known_hosts"
]
}
@@ -176,4 +177,9 @@ build {
"sudo chmod 0644 /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
]
}
# Update TCC.db and allow automation tools
provisioner "shell" {
script = "scripts/update-tcc-database.sh"
}
}
+39
View File
@@ -0,0 +1,39 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_name" {
type = string
}
variable "script_path" {
type = string
description = "Path to a local script that should be uploaded and executed inside the VM."
}
variable "pause_before" {
type = string
default = "60s"
description = "How long Packer should wait before running the uploaded script."
}
source "tart-cli" "tart" {
vm_name = "${var.vm_name}"
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
script = var.script_path
pause_before = var.pause_before
}
}
+167
View File
@@ -0,0 +1,167 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2026SummerSeed/fullrestores/140-55718/5809AFC6-1923-4590-AAFC-904A0283E659/UniversalMac_27.0_26A5388g_Restore.ipsw"
vm_name = "golden-gate-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait30s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s><tab><tab><tab><tab><tab><tab>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In to Your Apple Account
#
# We choose "Other Sign-In Options" → "Sign in Later in Settings" here.
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar><up><spacebar>",
# Are you sure you want to skip signing in with an Apple Account?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Age Range -> Adult
"<wait10s><tab><tab><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Update Mac Automatically
"<wait10s><tab><tab><spacebar>",
# Liquid Glass
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Welcome to Mac
"<wait30s><spacebar>",
# Disable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
# Now that the installation is done, open "System Settings"
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait120s>",
# Navigate to "Sharing"
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><leftShiftOff><spacebar>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Type in the password to allow enabling Screen Sharing
"<wait10s>admin<enter>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
# Disable Gatekeeper (2/2)
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
}
+5 -4
View File
@@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
@@ -12,14 +12,15 @@ packer {
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2025SpringFCS/fullrestores/082-44534/CE6C1054-99A3-4F67-A823-3EE9E6510CDE/UniversalMac_15.5_24F74_Restore.ipsw"
// will be update to 15.7.2
from_ipsw = "https://updates.cdn-apple.com/2025SummerFCS/fullrestores/093-10809/CFD6DD38-DAF0-40DA-854F-31AAD1294C6F/UniversalMac_15.6.1_24G90_Restore.ipsw"
vm_name = "sequoia-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "300s"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
@@ -32,7 +33,7 @@ source "tart-cli" "tart" {
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait30s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
+3 -2
View File
@@ -12,14 +12,15 @@ packer {
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2024SummerFCS/fullrestores/052-69922/F5DA2B64-25EB-4370-9E89-FA5689859796/UniversalMac_14.6_23G80_Restore.ipsw"
// will be update to 14.8.2
from_ipsw = "https://updates.cdn-apple.com/2024SummerFCS/fullrestores/062-52859/932E0A8F-6644-4759-82DA-F8FA8DEA806A/UniversalMac_14.6.1_23G93_Restore.ipsw"
vm_name = "sonoma-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
+163
View File
@@ -0,0 +1,163 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2026SummerFCS/fullrestores/140-83079/25315EF6-AEAB-4588-9774-A3723774C47F/UniversalMac_26.6.1_25G76_Restore.ipsw"
vm_name = "tahoe-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s><tab><tab><tab><tab><tab><tab>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><spacebar><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar><up><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Age Range -> Adult
"<wait10s><tab><tab><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
"<wait10s><tab><tab><spacebar>",
# Welcome to Mac
"<wait30s><spacebar>",
# Disable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
# Now that the installation is done, open "System Settings"
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait120s>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Type in the password to allow enabling Screen Sharing
"<wait10s>admin<enter>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
# Disable Gatekeeper (2/2)
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
}
+113 -41
View File
@@ -16,34 +16,45 @@ variable "xcode_version" {
}
variable "additional_ios_builds" {
type = list(string)
type = list(string)
default = []
}
variable "additional_tvos_builds" {
type = list(string)
default = []
}
variable "xcode_components" {
type = list(string)
default = []
description = "Additional Xcode components to download."
}
variable "expected_runtimes_file" {
type = string
default = ""
type = string
default = ""
description = "Path to file containing expected simulator runtimes. If empty, runtime verification is skipped."
}
variable "tag" {
type = string
type = string
default = ""
}
variable "disk_size" {
type = number
default = 120
type = number
default = 140
}
variable "disk_free_mb" {
type = number
type = number
default = 15000
}
variable "android_sdk_tools_version" {
type = string
default = "11076708" # https://developer.android.com/studio#command-line-tools-only
default = "14742923" # https://developer.android.com/studio#command-line-tools-only
}
source "tart-cli" "tart" {
@@ -72,8 +83,9 @@ locals {
"APP_DIR=$(dirname $CONTENTS_DIR)",
"sudo mv $APP_DIR /Applications/Xcode_${version}.app",
"sudo xcode-select -s /Applications/Xcode_${version}.app",
"xcodebuild -downloadAllPlatforms",
"xcodebuild -downloadPlatform iOS",
"xcodebuild -runFirstLaunch",
"df -h",
]
}
]
@@ -88,6 +100,9 @@ build {
"brew --version",
"brew update",
"brew upgrade",
"brew install codex",
"brew install --cask claude-code",
"brew install --cask amazon-q"
]
}
@@ -118,51 +133,69 @@ build {
"rm android-sdk-tools.zip",
"mv $ANDROID_HOME/cmdline-tools/cmdline-tools $ANDROID_HOME/cmdline-tools/latest",
"yes | sdkmanager --licenses",
"yes | sdkmanager 'platform-tools' 'platforms;android-35' 'build-tools;35.0.0' 'ndk;27.2.12479018'"
"yes | sdkmanager 'platform-tools' 'platforms;android-36' 'build-tools;36.0.0' 'ndk;28.2.13676358'"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy carthage",
"brew install xcbeautify swiftformat",
"rbenv global 3.3.8", # fastlane conflicts with 3.4.0+ https://github.com/fastlane/fastlane/issues/29527
"gem update",
"gem install fastlane",
"gem install cocoapods",
"gem install xcpretty",
"gem uninstall --ignore-dependencies ffi && gem install ffi -- --enable-libffi-alloc"
]
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install xcodesorg/made/xcodes",
"brew install xcodes",
"xcodes version",
]
}
provisioner "file" {
sources = [ for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
sources = [for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
destination = "/Users/admin/Downloads/"
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"df -h",
]
}
// iterate over all Xcode versions and install them
// select the latest one as the default
dynamic "provisioner" {
for_each = local.xcode_install_provisioners
labels = ["shell"]
labels = ["shell"]
content {
inline = provisioner.value.inline
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 2 ? [2] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[2]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
}
dynamic "provisioner" {
for_each = length(var.xcode_version) > 1 ? [1] : []
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[1]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[0]}'",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[0]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
@@ -175,10 +208,47 @@ build {
)
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for runtime in var.additional_tvos_builds : "xcodebuild -downloadPlatform tvOS -buildVersion ${runtime}"
]
)
}
provisioner "shell" {
inline = concat(
["source ~/.zprofile"],
[
for component in var.xcode_components : "xcodebuild -downloadComponent ${component}"
]
)
}
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy carthage",
"brew install xcbeautify swiftformat swiftlint swiftgen licenseplist",
"brew install mint",
"git clone --depth 1 https://github.com/tuist/homebrew-tuist.git \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist\"",
"rm -rf \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Casks\"",
"tuist_version=$(ruby -ne 'if $_ =~ %r{/download/([^/]+)/}; puts $1; exit; end' \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Aliases/tuist\") && brew trust --formula \"tuist/tuist/tuist@$tuist_version\" && brew install --formula \"tuist/tuist/tuist@$tuist_version\"",
"rbenv install 3.3.10",
"rbenv global 3.3.10", # fastlane conflicts with 3.4.0+ https://github.com/fastlane/fastlane/issues/29527
"gem update",
"gem install fastlane",
"gem install cocoapods",
"gem install xcpretty",
"gem uninstall --ignore-dependencies ffi && gem install ffi -- --enable-libffi-alloc"
]
}
// Copy expected runtimes file if provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["file"]
labels = ["file"]
content {
source = var.expected_runtimes_file
destination = "/Users/admin/runtimes.expected.txt"
@@ -188,7 +258,7 @@ build {
// Verify simulator runtimes match expected list if file was provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["shell"]
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
@@ -273,6 +343,19 @@ build {
]
}
# Wait for the "update_dyld_sim_shared_cache" process[1][2] to finish
# to avoid wasting CPU cycles after boot
#
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
# [2]: https://stackoverflow.com/a/68394101/9316533
provisioner "shell" {
inline = [
"source ~/.zprofile",
"xcrun simctl runtime dyld_shared_cache update --all || sleep 180",
"xcrun simctl list -v"
]
}
# Compatibility with GitHub Actions Runner Images, where
# /usr/local/bin belongs to the default user. Also see [2].
#
@@ -284,17 +367,6 @@ build {
]
}
# Wait for the "update_dyld_sim_shared_cache" process[1][2] to finish
# to avoid wasting CPU cycles after boot
#
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
# [2]: https://stackoverflow.com/a/68394101/9316533
provisioner "shell" {
inline = [
"sleep 1800"
]
}
// Install setup-info-generator
provisioner "shell" {
inline = [