Compare commits

...
Author SHA1 Message Date
Nikolay Edigaryev 75e6c33578 Produce macOS Golden Gate vanilla image 2026-08-12 10:57:51 +01:00
Fedor Kororkov c166ec1698 Merge pull request #364 from cirruslabs/dev/fkorotkov/tahoe-26-6-1-automation-permissions
Update Tahoe restore image and automation permissions
2026-08-07 10:38:00 -04:00
Fedor Korotkov 3d6445b446 Update Tahoe restore image and automation permissions 2026-08-07 10:24:00 -04:00
Fedor Kororkov f5a7e1e631 Merge pull request #363 from cirruslabs/dev/fkorotkov/fix-monthly-buildkite-tap-trust
Fix Homebrew 6 trust failure in monthly image builds
2026-08-06 12:20:10 -04:00
Fedor Korotkov 0a9ad1a419 Fix Buildkite formula trust in monthly builds 2026-08-06 08:36:12 -04:00
Fedor Korotkov cd2d1c6698 Decouple runner release builds from Xcode releases 2026-07-05 12:00:02 -04:00
Fedor Korotkov 65519d3874 Remove dependency on release-xcode for runner image 2026-07-05 11:57:09 -04:00
Fedor Korotkov 71b405bd0c Add Tahoe runner Xcode 26.6 and beta 2 (#356)
* Add Tahoe runner Xcode 26.6 and beta 2

* Add PR template validation workflow

* Install Ansible for template validation

* Build template images in PR workflow

* Authenticate Packer plugin downloads

* Prepare Xcode archives for PR builds

* Support authenticated Xcode archive downloads

* Use Xcode 27 beta 2 version token

* Increase Tahoe runner disk size

* Select Xcode apps by path during runner builds

* Update Homebrew before Tuist install

* Avoid Tuist cask validation during image builds

* Trust Tuist formula during image builds

* Add Tahoe iOS 27 beta runtime expectation
2026-07-04 22:21:50 -04:00
Fedor Kororkov 2be4479694 Update release.yml (#352) 2026-06-08 16:30:42 -07:00
Fedor Korotkov 206d99a672 Migrate CI to GitHub Actions (#351) 2026-06-03 06:37:04 -07:00
Fedor Korotkov 0ad265b76d macOS and Xcode 26.5 (#349)
* macOS and Xcode 26.5

* Updated expected tahoe runtimes
2026-05-25 19:14:54 -04:00
Nikolay Edigaryev 154a7604f9 vanilla-sequoia.pkr.hcl: click "Select Your Country or Region" (#335) 2026-05-16 10:36:46 -04:00
Fedor Korotkov 5a2d4fd8cc Xcode 26.4.1 (#348) 2026-05-02 19:53:10 -04:00
Diogo Araújo 70cb4395fe feat: boot command changes to tahoe 26.4 (#344)
* feat: boot command changes to tahoe 26.4

* add first time password to enable screen sharing
2026-04-05 12:38:36 -04:00
Fedor Korotkov 7360b62106 Adjusted disk sizes for macOS Tahoe configurations in CI setup. 2026-04-05 12:35:16 -04:00
Fedor Korotkov e46673151d Xcode 26.5-beta (#345)
* Xcode 26.5-beta

* Fixed syntax error in Xcode versions list for Tahoe configuration.

* Updated Tahoe runtimes to include Xcode 26.5 beta versions

* Updated Tahoe runtimes to include Xcode 26.5 beta versions
2026-04-04 20:30:07 -04:00
Jacob Rhoda 5e65e3e712 Update Android SDK tools version and dependencies (#343)
Updated Android SDK tools versions to reflect most up-to-date default versions used by the Android gradle plugin (9.1.0)

- Platform: 36
- Build Tools: 36.0.0
- NDK: 28.2.13676358
2026-03-26 15:40:01 -04:00
Fedor Korotkov 5cf26631b9 macOS & Xcode 26.4 (#340)
* macOS & Xcode 26.4

* No Sonoma runner image

* Updated Tahoe tvOS 26.4 runtime to release version 23L243
2026-03-24 21:26:24 -04:00
Fedor Korotkov 0d8fe3156a Xcode 26.4 RC (#337)
* Xcode 16.4 RC

* Updated disk size for Sonoma CI runner and Tahoe runtimes to final Xcode 26.4 release versions.
2026-03-21 08:07:50 -04:00
Fedor Korotkov 69866eb29b Xcode 26.4 Beta 3 (#332)
* Xcode 26.4 Beta 3

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Updated Tahoe runtimes and added iOS 26.2 builds to Cirrus configuration

* Removed iOS 26.2 from Tahoe runtimes list
2026-03-15 16:32:38 -04:00
Nikolay Edigaryev f2e700cda3 xcode.pkr.hcl: increase disk size from 120 to 140 GB (#333) 2026-03-15 13:08:44 -04:00
Nikolay Edigaryev 494e62f0b8 Disable SIP before running templates/base.pkr.hcl (#331)
* Disable SIP before running templates/base.pkr.hcl

* Don't forget to "packer init" before each "packer build"
2026-03-15 10:46:21 +01:00
Nikolay Edigaryev 27def7c5ce Prevent an array with empty element when XCODE_COMPONENTS is unset (#330) 2026-03-13 17:23:50 -04:00
Nikolay Edigaryev f9c2b3c122 base.pkr.hcl: update TCC.db and allow automation tools (#329) 2026-03-12 13:01:54 +01:00
Fedor Korotkov 7132d10945 Xcode 26.3 Release (#326) 2026-02-26 16:03:56 -05:00
Fedor Korotkov 33e373e65b Xcode 26.4 Beta 2 (#325)
* Xcode 26.4 Beta 2

* Updated Tahoe runtimes to latest Xcode 26.4 release versions
2026-02-23 19:52:43 -05:00
Fedor Korotkov cfa9e2361c Xcode 26.3 RC 2 (#324)
* Xcode 26.3 RC 2

* Increase DISK_SIZE from 230 to 240
2026-02-21 08:08:10 -05:00
Fedor Korotkov 09fce08792 Xcode 26.4 Beta (#323)
* Xcode 26.4 Beta

* Updated Tahoe runtimes to Xcode 26.4 Beta versions
2026-02-17 07:00:35 -05:00
Fedor Korotkov 01365193b9 Updated Tahoe template to use macOS 26.3 restore image. (#322)
Fixes #321
2026-02-13 16:20:18 +01:00
Fedor Korotkov 1414d3bf4b Added Buildkite agent installation to base Packer template. (#320) 2026-02-05 06:56:38 -05:00
Fedor Korotkov fbaec2adaa Xcode 26.3 RC (#319)
* Xcode 26.3 RC

* Removed unavailable runtimes from Tahoe list.
2026-02-04 10:13:22 -05:00
Fedor Korotkov f47f8bf08c Added rbenv 3.3.10 installation to address Fastlane compatibility in Xcode packer template. 2026-01-10 18:16:37 +01:00
Fedor Korotkov d56bd82e5d Refined Tuist installation steps in Xcode packer template. 2026-01-10 11:47:22 +01:00
Nikolay Edigaryev 4b95c2c93f Use the new <click 'Select Your Country or Region'> command (#317) 2025-12-16 21:02:14 +01:00
Fedor Korotkov 75924563a8 Updated macOS restore image comments for Sequoia 15.7.2 and Sonoma 14.8.2 2025-12-16 09:35:29 -05:00
Nikolay Edigaryev f3319b8eb8 Revert "Remove explicit FileVault step from Packer boot command for macOS 26.1 compatibility (#305)" (#316) 2025-12-15 19:07:52 -05:00
Fedor Korotkov 5ee829f2c8 macOS Tahoe 26.2 (#315) 2025-12-15 08:55:32 -05:00
Fedor Korotkov 64d9651dca Upgrade Node.js installation from version 20 to 24 (#314)
20 is retiring https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
2025-12-15 08:54:13 -05:00
Fedor Korotkov 0682bdb108 Xcode 26.2 (#313)
* Xcode 26.2

* Corrected Xcode version to 26.1.1 in Cirrus config.

* Updated Tahoe runtime build number for iOS 26.2.
2025-12-13 10:30:58 -05:00
Fedor Korotkov 3abe5ef330 Fixed syntax 2025-12-06 17:44:39 -05:00
Fedor Korotkov 36c1f1d9b7 Updated Tahoe runtimes to Xcode 26.2 release versions 2025-12-05 16:30:31 -05:00
Fedor Korotkov 413eb891fe Xcode 26.2 RC 2025-12-05 16:30:31 -05:00
Dominik Abilio de Jesus MoreiraandDominik Wunderlich be895f2507 Fix Gatekeeper disable step in boot command (#311)
Added the missing "tab" command in the "Disable GateKeeper (2/2)" section. Without this command, Gatekeeper was not fully disabled, causing the provisioner check to fail when verifying that Gatekeeper is disabled.

Co-authored-by: Dominik Wunderlich <dominik.wunderlich@teamviewer.com>
2025-12-05 14:42:22 +01:00
Fedor Korotkov 9115ef2553 Increase DISK_SIZE from 290 to 300 2025-11-22 11:36:44 -05:00
Fedor Korotkov 11b22ea0d0 Preinstall common AI agents (#308)
So it's possible to automate things within VMs.
2025-11-20 12:24:31 -05:00
Fedor Korotkov 062ecd3e0e Xcode 26.2 Beta 2 (#307)
* Xcode 26.2 Beta 2

Plus wait for simulators to become available.

* Update expected runtimes for Xcode 26.2 Beta 2

* Try to wait an hour

* Cleanup LLM generated script

* Add `exex-script.pkr.hcl` template and adjust simulator wait logic

* Finalize

* Fixed script name

* Fixed typo

* Use scrript option.
2025-11-20 10:16:45 -05:00
23 changed files with 1287 additions and 303 deletions
-26
View File
@@ -1,26 +0,0 @@
task:
name: "Update Base Images ($MACOS_VERSION)"
alias: update-base
matrix:
- env:
MACOS_VERSION: sonoma
DISABLE_SIP_TEMPLATE: disable-sip.pkr.hcl
- env:
MACOS_VERSION: sequoia
DISABLE_SIP_TEMPLATE: disable-sip-with-username.pkr.hcl
- env:
MACOS_VERSION: tahoe
DISABLE_SIP_TEMPLATE: disable-sip-with-username.pkr.hcl
<<: *defaults
pull_vanilla_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
build_base_script:
- packer init templates/base.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
disable_sip_script:
- packer build -var vm_name=$MACOS_VERSION-base "templates/${DISABLE_SIP_TEMPLATE}"
push_base_script:
- tart push $MACOS_VERSION-base ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
always:
cleanup_script:
- tart delete $MACOS_VERSION-base
-23
View File
@@ -1,23 +0,0 @@
task:
name: "Release Xcode $CIRRUS_TAG ($MACOS_VERSION)"
env:
XCODE_COMPONENTS: "MetalToolchain"
matrix:
- MACOS_VERSION: tahoe
- MACOS_VERSION: sequoia
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$CIRRUS_TAG\"]" -var xcode_components="[\"$XCODE_COMPONENTS\"]" templates/xcode.pkr.hcl
push_script: |
if [[ $CIRRUS_TAG == *"beta"* ]]
then
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG
else
tart push $MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$CIRRUS_TAG ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete $MACOS_VERSION-xcode:$CIRRUS_TAG || true
-41
View File
@@ -1,41 +0,0 @@
task:
name: "Update Runner Image ($MACOS_VERSION)"
env:
matrix:
- MACOS_VERSION: sonoma
XCODE_VERSIONS: "16.1,16"
DISK_SIZE: 230
- MACOS_VERSION: sequoia
XCODE_VERSIONS: "\"26.0.1\",16.4,16.3,16.2,16.1,16"
ADDITIONAL_IOS_BUILDS: "18.5,18.4,18.2,17.5"
ADDITIONAL_TVOS_BUILDS: "17.5"
XCODE_COMPONENTS: "\"MetalToolchain\""
DISK_SIZE: 400
- MACOS_VERSION: tahoe
XCODE_VERSIONS: "\"26.1.1\",\"26.0.1\",\"26.2-beta\""
XCODE_COMPONENTS: "\"MetalToolchain\""
ADDITIONAL_IOS_BUILDS: "18.6"
DISK_SIZE: 290
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
init_xcode_script: packer init templates/xcode.pkr.hcl
build_xcode_script: |
packer build -var tag=runner -var disk_size=$DISK_SIZE \
-var disk_free_mb=100000 \
-var macos_version="$MACOS_VERSION" \
-var xcode_version="[$XCODE_VERSIONS]" \
-var additional_ios_builds="[$ADDITIONAL_IOS_BUILDS]" \
-var additional_tvos_builds="[$ADDITIONAL_TVOS_BUILDS]" \
-var xcode_components="[$XCODE_COMPONENTS]" \
-var expected_runtimes_file="data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
push_script: |
if [[ -z "$CIRRUS_PR" ]]; then
tart push "$MACOS_VERSION-xcode:runner" ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION
else
echo "Skipping pushing for PR..."
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:runner"
-27
View File
@@ -1,27 +0,0 @@
env:
RESOLVE_VM_NAME: "resolve-macos-number-task-id-${CIRRUS_TASK_ID}"
RESOLVE_FILE: "${RESOLVE_VM_NAME}.txt"
task:
name: "Update Vanilla Image ($MACOS_VERSION)"
env:
matrix:
- MACOS_VERSION: tahoe
- MACOS_VERSION: sequoia
- MACOS_VERSION: sonoma
- MACOS_VERSION: monterey
only_if: $CIRRUS_BRANCH == $CIRRUS_DEFAULT_BRANCH && changesInclude("templates/vanilla-$MACOS_VERSION.pkr.hcl")
<<: *defaults
build_script:
- packer init templates/vanilla-$MACOS_VERSION.pkr.hcl
- packer build templates/vanilla-$MACOS_VERSION.pkr.hcl
resolve_macos_number_script:
- packer build -var vm_base_name=$MACOS_VERSION-vanilla -var vm_name=$RESOLVE_VM_NAME -var resolve_file=$RESOLVE_FILE templates/resolve-macos-number.pkr.hcl
- echo "MACOS_NUMBER=$(cat $RESOLVE_FILE)" >> $CIRRUS_ENV
- rm $RESOLVE_FILE
- tart delete $RESOLVE_VM_NAME
push_script:
- tart push $MACOS_VERSION-vanilla ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:$MACOS_NUMBER
always:
cleanup_script:
- tart delete $MACOS_VERSION-vanilla
-46
View File
@@ -1,46 +0,0 @@
task:
name: "Update Xcode Images ($MACOS_VERSION $XCODE_VERSION)"
depends_on: update-base
env:
matrix:
- MACOS_VERSION: tahoe
XCODE_VERSION: "26.1.1"
XCODE_COMPONENTS: "MetalToolchain"
LATEST: true
- MACOS_VERSION: tahoe
XCODE_VERSION: "26.0.1"
XCODE_COMPONENTS: "MetalToolchain"
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.4
LATEST: true
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.3
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.2
- MACOS_VERSION: sequoia
XCODE_VERSION: 16.1
- MACOS_VERSION: sequoia
XCODE_VERSION: 16
- MACOS_VERSION: sonoma
XCODE_VERSION: 16.1
LATEST: true
- MACOS_VERSION: sonoma
XCODE_VERSION: 16
- MACOS_VERSION: sonoma
XCODE_VERSION: 15.4
<<: *defaults
pull_base_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest
build_xcode_script:
- packer init templates/xcode.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" -var xcode_version="[\"$XCODE_VERSION\"]" -var xcode_components="[$XCODE_COMPONENTS]" templates/xcode.pkr.hcl
push_script: |
if [[ -z "$LATEST" ]]
then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest
fi
always:
cleanup_script:
- tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION"
-52
View File
@@ -1,52 +0,0 @@
load("cirrus", "env", "http", "fs", "changes_include")
load("github.com/cirrus-modules/graphql", "rerun_task_if_issue_in_logs")
def on_task_failed(ctx):
if ctx.payload.data.task.automaticReRun:
print("Task is already an automatic re-run! Won't even try to re-run it...")
return
rerun_task_if_issue_in_logs(ctx.payload.data.task.id, "The network connection was lost")
def on_build_failed(ctx):
# Only send Slack notifications for failed cron builds[1]
#
# [1]: https://cirrus-ci.org/guide/writing-tasks/#cron-builds
if "Cron" not in ctx.payload.data.build.changeMessageTitle:
return
resp = http.post(env.get("SLACK_WEBHOOK_URL"), headers={
"Content-Type": "application/json",
}, json_body={
"text": "Build {build_id} (\"{change_message_title}\") failed on branch \"{branch_name}\" in repository \"{repository_name}\".".format(
build_id=ctx.payload.data.build.id,
change_message_title=ctx.payload.data.build.changeMessageTitle,
branch_name=ctx.payload.data.build.branch,
repository_name=ctx.payload.data.repository.name,
),
"url": "https://cirrus-ci.com/build/{build_id}".format(
build_id=ctx.payload.data.build.id,
),
})
if resp.status_code != 200:
fail("failed to post message to Slack: got unexpected HTTP {}".format(resp.status_code))
resp_json = resp.json()
if resp_json["ok"] != True:
fail("got error when posting message to Slack: {}".format(resp_json["error"]))
def main(ctx):
result = fs.read(".ci/cirrus.vanilla.yml")
if env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.release.yml")
if env.get("CIRRUS_CRON") == "monthly":
result += fs.read(".ci/cirrus.base.yml")
result += fs.read(".ci/cirrus.xcode.yml")
prForRunners = env.get("CIRRUS_PR") and changes_include(".ci/cirrus.runner.yml")
if prForRunners or env.get("CIRRUS_TAG") != None:
result += fs.read(".ci/cirrus.runner.yml")
return result
-18
View File
@@ -1,18 +0,0 @@
persistent_worker:
labels:
name: dev-mini
resources:
tart-vms: 1
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: fkorotkov # GitHub supports only PATs
TART_REGISTRY_PASSWORD: ENCRYPTED[!82ed873afdf627284305afef4958c85a8f73127b09978a9786ac521559630ea6c9a5ab6e7f8315abf9ead09b6eff6eae!]
AWS_ACCESS_KEY_ID: ENCRYPTED[c187b670a17eead88c1698849376273991d09678efe37ae2f0c9738c27a2422741a71c501ef4b6a4df7bff3eca5213a9]
AWS_SECRET_ACCESS_KEY: ENCRYPTED[e456254a53b82e3167f2da23e24c389620cb3f7d47e4e5e7d993813bf9bb18c784d5cb8d88d19632073acc9e1f6096c9]
defaults: &defaults
timeout_in: 3h
info_script:
- tart --version
- packer --version
+203
View File
@@ -0,0 +1,203 @@
name: Monthly Images
on:
schedule:
- cron: "0 8 * * 6"
workflow_dispatch:
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
should-run:
name: Check Monthly Cadence
runs-on: [self-hosted, macOS, ARM64]
outputs:
build: ${{ steps.cadence.outputs.build }}
steps:
- name: Check first Saturday
id: cadence
env:
EVENT_NAME: ${{ github.event_name }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
build=true
else
day="$(date -u +%d)"
if (( 10#$day <= 7 )); then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
if [[ "$build" != "true" ]]; then
echo "Not the first Saturday of the month; skipping image rebuilds."
fi
update-base:
name: Update Base Images (${{ matrix.macos_version }})
needs: should-run
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
MACOS_VERSION: ${{ matrix.macos_version }}
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull vanilla image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Push base image
run: |
tart push "$MACOS_VERSION-base" "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-base" || true
update-xcode:
name: Update Xcode Images (${{ matrix.macos_version }} ${{ matrix.xcode_version }})
needs:
- should-run
- update-base
if: needs.should-run.outputs.build == 'true'
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_version: "26.2"
xcode_components: '"MetalToolchain"'
latest: true
- macos_version: tahoe
xcode_version: "26.1.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: tahoe
xcode_version: "26.0.1"
xcode_components: '"MetalToolchain"'
latest: false
- macos_version: sequoia
xcode_version: "16.4"
xcode_components: ""
latest: true
- macos_version: sequoia
xcode_version: "16.3"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.2"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16.1"
xcode_components: ""
latest: false
- macos_version: sequoia
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "16.1"
xcode_components: ""
latest: true
- macos_version: sonoma
xcode_version: "16"
xcode_components: ""
latest: false
- macos_version: sonoma
xcode_version: "15.4"
xcode_components: ""
latest: false
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSION: ${{ matrix.xcode_version }}
LATEST: ${{ matrix.latest }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build Xcode image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push Xcode image
run: |
if [[ "$LATEST" == "true" ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
else
tart push "$MACOS_VERSION-xcode:$XCODE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_VERSION"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_VERSION" || true
+167
View File
@@ -0,0 +1,167 @@
name: Release Images
on:
release:
types:
- published
workflow_dispatch:
inputs:
xcode_version:
description: "Xcode version/tag to release"
required: true
type: string
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
XCODE_RELEASE_VERSION: ${{ github.event.release.tag_name || inputs.xcode_version }}
jobs:
release-xcode:
name: Release Xcode ${{ github.event.release.tag_name || inputs.xcode_version }} (${{ matrix.macos_version }})
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- tahoe
- sequoia
env:
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: '"MetalToolchain"'
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Validate release version
run: |
set -euo pipefail
if [[ -z "$XCODE_RELEASE_VERSION" ]]; then
echo "XCODE_RELEASE_VERSION is required."
exit 1
fi
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build release image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[\"$XCODE_RELEASE_VERSION\"]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
templates/xcode.pkr.hcl
- name: Push release image
run: |
if [[ "$XCODE_RELEASE_VERSION" == *beta* ]]; then
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION"
else
tart push "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-xcode:latest"
fi
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:$XCODE_RELEASE_VERSION" || true
release-runner:
name: Update Runner Image (${{ matrix.macos_version }})
# Keep runner refreshes independent from the release-xcode matrix so one
# Xcode image failure does not skip the runner matrix.
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-2","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Tool versions
run: |
tart --version
packer --version
- name: Pull base image
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Build runner image
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Push runner image
run: |
tart push "$MACOS_VERSION-xcode:runner" "ghcr.io/cirruslabs/macos-runner:$MACOS_VERSION"
- name: Cleanup
if: always()
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true
+381
View File
@@ -0,0 +1,381 @@
name: Template Builds
on:
pull_request:
paths:
- ".github/workflows/monthly.yml"
- ".github/workflows/release.yml"
- ".github/workflows/template-validation.yml"
- "data/**"
- "scripts/**"
- "templates/**"
permissions:
contents: read
packages: read
concurrency:
group: template-builds-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
env:
FASTLANE_SESSION: ${{ secrets.FASTLANE_SESSION }}
FASTLANE_USER: ${{ secrets.FASTLANE_USER }}
HOMEBREW_NO_AUTO_UPDATE: 1
HOMEBREW_NO_INSTALL_CLEANUP: 1
PACKER_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
packer-validate:
name: Packer Validate
runs-on: macos-15
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Packer
uses: hashicorp/setup-packer@v3
- name: Install validation dependencies
run: |
brew install ansible
- name: Prepare validation inputs
run: |
mkdir -p "$HOME/XcodesCache"
touch "$HOME/XcodesCache/Xcode_26.6.xip"
- name: Validate templates
run: |
set -euo pipefail
validate() {
local template="$1"
shift
packer init "$template"
packer validate "$@" "$template"
}
for template in templates/vanilla-*.pkr.hcl; do
validate "$template"
done
validate templates/base.pkr.hcl \
-var vm_name=template-validation-base
validate templates/disable-sip.pkr.hcl \
-var vm_name=template-validation-disable-sip
validate templates/disable-sip-with-username.pkr.hcl \
-var vm_name=template-validation-disable-sip-user
validate templates/exex-script.pkr.hcl \
-var vm_name=template-validation-exec \
-var script_path=scripts/finalize-tahoe.sh
validate templates/resolve-macos-number.pkr.hcl \
-var vm_base_name=template-validation-base \
-var vm_name=template-validation-resolve \
-var resolve_file=macos-version.txt
validate templates/xcode.pkr.hcl \
-var macos_version=tahoe \
-var 'xcode_version=["26.6"]' \
-var expected_runtimes_file=data/expected.tahoe.runtimes.txt
build-vanilla:
name: Build Vanilla Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
build-base:
name: Build Base Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: sonoma
disable_sip_template: disable-sip.pkr.hcl
- macos_version: sequoia
disable_sip_template: disable-sip-with-username.pkr.hcl
- macos_version: tahoe
disable_sip_template: disable-sip-with-username.pkr.hcl
env:
DISABLE_SIP_TEMPLATE: ${{ matrix.disable_sip_template }}
MACOS_VERSION: ${{ matrix.macos_version }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Eq '^(templates/base\.pkr\.hcl|templates/disable-sip.*\.pkr\.hcl|data/(github_known_hosts|limit\.maxfiles\.plist|setup-info-template\.json|tart-guest-.*\.plist)|scripts/(install-actions-runner|update-tcc-database)\.sh|ansible/)' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest"
tart clone "ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" "$MACOS_VERSION-base"
- name: Disable SIP
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/$DISABLE_SIP_TEMPLATE"
packer build -var "vm_name=$MACOS_VERSION-base" "templates/$DISABLE_SIP_TEMPLATE"
- name: Build base image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/base.pkr.hcl
packer build -var "vm_name=$MACOS_VERSION-base" templates/base.pkr.hcl
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-base" || true
build-runner:
name: Build Runner Image (${{ matrix.macos_version }})
needs: packer-validate
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
- macos_version: tahoe
xcode_versions: '"26.6","27-beta-2","26.5","27-beta","26.4.1","26.3","26.2","26.1.1","26.0.1"'
additional_ios_builds: "18.6"
additional_tvos_builds: ""
xcode_components: '"MetalToolchain"'
disk_size: 520
- macos_version: sequoia
xcode_versions: '"26.0.1",16.4,16.3,16.2,16.1,16'
additional_ios_builds: "18.5,18.4,18.2,17.5"
additional_tvos_builds: "17.5"
xcode_components: '"MetalToolchain"'
disk_size: 380
env:
ADDITIONAL_IOS_BUILDS: ${{ matrix.additional_ios_builds }}
ADDITIONAL_TVOS_BUILDS: ${{ matrix.additional_tvos_builds }}
DISK_SIZE: ${{ matrix.disk_size }}
MACOS_VERSION: ${{ matrix.macos_version }}
XCODE_COMPONENTS: ${{ matrix.xcode_components }}
XCODE_VERSIONS: ${{ matrix.xcode_versions }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
git diff --name-only "$BASE_SHA" "$HEAD_SHA" > changed-files.txt
build=false
if grep -Fxq ".github/workflows/release.yml" changed-files.txt; then
build=true
elif grep -Fxq "data/expected.$MACOS_VERSION.runtimes.txt" changed-files.txt; then
build=true
elif grep -Fxq "scripts/finalize-$MACOS_VERSION.sh" changed-files.txt; then
build=true
elif grep -Eq '^(templates/xcode\.pkr\.hcl|data/setup-info-template\.json|scripts/install-actions-runner\.sh)$' changed-files.txt; then
build=true
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Pull base image
if: steps.select.outputs.build == 'true'
run: |
tart pull "ghcr.io/cirruslabs/macos-$MACOS_VERSION-base:latest"
- name: Prepare Xcode archives
if: steps.select.outputs.build == 'true'
run: |
set -euo pipefail
source ~/.zprofile || true
if ! command -v xcodes >/dev/null; then
brew install xcodes
fi
mkdir -p "$HOME/XcodesCache"
IFS=',' read -ra versions <<< "$XCODE_VERSIONS"
for raw_version in "${versions[@]}"; do
version="${raw_version//\"/}"
target="$HOME/XcodesCache/Xcode_${version}.xip"
if [[ -f "$target" ]]; then
echo "Using cached Xcode $version at $target"
continue
fi
echo "Downloading Xcode $version"
if [[ -z "${FASTLANE_SESSION:-}" ]]; then
echo "::error::Missing $target and FASTLANE_SESSION is not configured. Pre-cache the Xcode archive on the runner or add Apple Developer auth secrets."
exit 1
fi
download_args=(download "$version" --directory "$HOME/XcodesCache" --use-fastlane-auth)
if [[ -n "${FASTLANE_USER:-}" ]]; then
download_args+=(--fastlane-user "$FASTLANE_USER")
fi
xcodes "${download_args[@]}"
candidate=""
case "$version" in
27-beta-2)
candidate="$HOME/XcodesCache/Xcode_27_beta_2.xip"
;;
27-beta)
candidate="$HOME/XcodesCache/Xcode_27_beta.xip"
;;
*)
candidate="$(find "$HOME/XcodesCache" -maxdepth 1 -type f -name "Xcode_${version}*.xip" -print -quit)"
;;
esac
if [[ -n "$candidate" && -f "$candidate" && "$candidate" != "$target" ]]; then
mv "$candidate" "$target"
fi
test -f "$target"
done
- name: Build runner image
if: steps.select.outputs.build == 'true'
run: |
packer init templates/xcode.pkr.hcl
packer build \
-var tag=runner \
-var "disk_size=$DISK_SIZE" \
-var disk_free_mb=100000 \
-var "macos_version=$MACOS_VERSION" \
-var "xcode_version=[$XCODE_VERSIONS]" \
-var "additional_ios_builds=[$ADDITIONAL_IOS_BUILDS]" \
-var "additional_tvos_builds=[$ADDITIONAL_TVOS_BUILDS]" \
-var "xcode_components=[$XCODE_COMPONENTS]" \
-var "expected_runtimes_file=data/expected.$MACOS_VERSION.runtimes.txt" \
templates/xcode.pkr.hcl
- name: Finalize runner image
if: steps.select.outputs.build == 'true'
run: |
if [[ -f "scripts/finalize-$MACOS_VERSION.sh" ]]; then
packer build \
-var "vm_name=$MACOS_VERSION-xcode:runner" \
-var "script_path=scripts/finalize-$MACOS_VERSION.sh" \
templates/exex-script.pkr.hcl
else
echo "Skipping prepare script for $MACOS_VERSION"
fi
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-xcode:runner" || true
+129
View File
@@ -0,0 +1,129 @@
name: Vanilla Images
on:
push:
paths:
- "templates/vanilla-*.pkr.hcl"
workflow_dispatch:
inputs:
macos_version:
description: "macOS vanilla image to build"
required: true
default: all
type: choice
options:
- all
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
permissions:
contents: read
packages: write
concurrency:
group: tart-image-builds
cancel-in-progress: false
env:
TART_REGISTRY_HOSTNAME: ghcr.io
TART_REGISTRY_USERNAME: ${{ github.actor }}
TART_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
jobs:
update-vanilla:
name: Update Vanilla Image (${{ matrix.macos_version }})
if: >-
${{
github.event_name == 'workflow_dispatch' ||
github.ref == format('refs/heads/{0}', github.event.repository.default_branch)
}}
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 180
strategy:
fail-fast: false
max-parallel: 1
matrix:
macos_version:
- golden-gate
- tahoe
- sequoia
- sonoma
- monterey
env:
MACOS_VERSION: ${{ matrix.macos_version }}
RESOLVE_VM_NAME: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}
RESOLVE_FILE: resolve-macos-number-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.macos_version }}.txt
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Select image
id: select
env:
BEFORE_SHA: ${{ github.event.before }}
EVENT_NAME: ${{ github.event_name }}
INPUT_MACOS_VERSION: ${{ inputs.macos_version || 'all' }}
run: |
set -euo pipefail
build=false
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
if [[ "$INPUT_MACOS_VERSION" == "all" || "$INPUT_MACOS_VERSION" == "$MACOS_VERSION" ]]; then
build=true
fi
else
if [[ "$BEFORE_SHA" =~ ^0+$ ]]; then
git diff-tree --no-commit-id --name-only -r "$GITHUB_SHA" > changed-files.txt
else
git diff --name-only "$BEFORE_SHA" "$GITHUB_SHA" > changed-files.txt
fi
if grep -Fxq "templates/vanilla-$MACOS_VERSION.pkr.hcl" changed-files.txt; then
build=true
fi
fi
echo "build=$build" >> "$GITHUB_OUTPUT"
- name: Tool versions
if: steps.select.outputs.build == 'true'
run: |
tart --version
packer --version
- name: Build vanilla image
if: steps.select.outputs.build == 'true'
run: |
packer init "templates/vanilla-$MACOS_VERSION.pkr.hcl"
packer build "templates/vanilla-$MACOS_VERSION.pkr.hcl"
- name: Resolve macOS version
id: resolve
if: steps.select.outputs.build == 'true'
run: |
packer build \
-var "vm_base_name=$MACOS_VERSION-vanilla" \
-var "vm_name=$RESOLVE_VM_NAME" \
-var "resolve_file=$RESOLVE_FILE" \
templates/resolve-macos-number.pkr.hcl
echo "macos_number=$(cat "$RESOLVE_FILE")" >> "$GITHUB_OUTPUT"
rm -f "$RESOLVE_FILE"
- name: Push vanilla image
if: steps.select.outputs.build == 'true'
run: |
tart push "$MACOS_VERSION-vanilla" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest" \
"ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:${{ steps.resolve.outputs.macos_number }}"
- name: Cleanup
if: always() && steps.select.outputs.build == 'true'
run: |
tart delete "$MACOS_VERSION-vanilla" || true
tart delete "$RESOLVE_VM_NAME" || true
+1 -1
View File
@@ -15,7 +15,7 @@ packer build -var vm_name=sonoma-vanilla templates/disable-sip.pkr.hcl
## Building Base Image
```bash
packer build -var macos_version=sonoma templates/base.pkr.hcl
packer build -var vm_name=sonoma-vanilla templates/base.pkr.hcl
```
## Building Xcode Image
+4 -4
View File
@@ -1,11 +1,11 @@
## macOS Packer Templates for Tart
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with [Cirrus Runners](https://cirrus-runners.app/),
[Cirrus CI](https://cirrus-ci.org/guide/macOS/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
Repository with Packer templates to build macOS [Tart](https://tart.run/) virtual machines to use with self-hosted
GitHub Actions runners, [Cirrus Runners](https://cirrus-runners.app/) or [any other automation](https://tart.run/integrations/cirrus-cli/).
The following image variants are currently available:
* `macos-{tahoe,sequoia,sonoma}-vanilla` — a vanilla macOS installation with helpful tweaks such as auto-login, but no additional software preinstalled
* `macos-{golden-gate,tahoe,sequoia,sonoma}-vanilla` — a vanilla macOS installation with helpful tweaks such as auto-login, but no additional software preinstalled
* `macos-{tahoe,sequoia,sonoma}-base` — based on `macos-{tahoe,sequoia,sonoma}-vanilla` image, it comes with `brew` and [other useful software](https://github.com/cirruslabs/macos-image-templates/blob/main/templates/base.pkr.hcl) pre-installed, but without Xcode
* `macos-{tahoe,sequoia,sonoma}-xcode:N` — based on `macos-{tahoe,sequoia,sonoma}-base` image and has `Xcode N` with [`Flutter`](https://flutter.dev/) pre-installed
* `macos-runner:{tahoe,sequoia,sonoma}` — a variant of `xcode:N` with several versions of `Xcode` pre-installed and [`xcodes` tool](https://github.com/XcodesOrg/xcodes) to switch between them.
@@ -22,4 +22,4 @@ Please watch this repository releases to get notified about new images.
Some of the images are regularly getting rebuild in order to update the pre-installed packages.
[This configuration file](.ci/cirrus.release.yml) defines images that are getting rebuilt monthly on the first Saturday of the month.
[This workflow](.github/workflows/monthly.yml) defines images that are getting rebuilt monthly on the first Saturday of the month.
+11 -10
View File
@@ -2,13 +2,14 @@
iOS 18.6 (18.6 - 22G86) - com.apple.CoreSimulator.SimRuntime.iOS-18-6
iOS 26.0 (26.0.1 - 23A8464) - com.apple.CoreSimulator.SimRuntime.iOS-26-0
iOS 26.1 (26.1 - 23B86) - com.apple.CoreSimulator.SimRuntime.iOS-26-1
iOS 26.2 (26.2 - 23C5027f) - com.apple.CoreSimulator.SimRuntime.iOS-26-2
tvOS 26.0 (26.0 - 23J352) - com.apple.CoreSimulator.SimRuntime.tvOS-26-0
tvOS 26.1 (26.1 - 23J579) - com.apple.CoreSimulator.SimRuntime.tvOS-26-1
tvOS 26.2 (26.2 - 23K5029e) - com.apple.CoreSimulator.SimRuntime.tvOS-26-2
watchOS 26.0 (26.0 - 23R353) - com.apple.CoreSimulator.SimRuntime.watchOS-26-0
watchOS 26.1 (26.1 - 23S36) - com.apple.CoreSimulator.SimRuntime.watchOS-26-1
watchOS 26.2 (26.2 - 23S5280e) - com.apple.CoreSimulator.SimRuntime.watchOS-26-2
visionOS 26.0 (26.0 - 23M336) - com.apple.CoreSimulator.SimRuntime.xrOS-26-0
visionOS 26.1 (26.1 - 23N47) - com.apple.CoreSimulator.SimRuntime.xrOS-26-1
visionOS 26.2 (26.2 - 23N5279e) - com.apple.CoreSimulator.SimRuntime.xrOS-26-2
iOS 26.3 (26.3.1 - 23D8133) - com.apple.CoreSimulator.SimRuntime.iOS-26-3
iOS 26.4 (26.4.1 - 23E254a) - com.apple.CoreSimulator.SimRuntime.iOS-26-4
iOS 26.5 (26.5 - 23F77) - com.apple.CoreSimulator.SimRuntime.iOS-26-5
iOS 27.0 (27.0 - 24A5355p) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
iOS 27.0 (27.0 - 24A5370g) - com.apple.CoreSimulator.SimRuntime.iOS-27-0
tvOS 26.5 (26.5 - 23L470) - com.apple.CoreSimulator.SimRuntime.tvOS-26-5
tvOS 27.0 (27.0 - 24J5305f) - com.apple.CoreSimulator.SimRuntime.tvOS-27-0
watchOS 26.5 (26.5 - 23T570) - com.apple.CoreSimulator.SimRuntime.watchOS-26-5
watchOS 27.0 (27.0 - 24R5305f) - com.apple.CoreSimulator.SimRuntime.watchOS-27-0
visionOS 26.5 (26.5 - 23O470) - com.apple.CoreSimulator.SimRuntime.xrOS-26-5
visionOS 27.0 (27.0 - 24M5306g) - com.apple.CoreSimulator.SimRuntime.xrOS-27-0
+72
View File
@@ -0,0 +1,72 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
# Wait until `xcrun simctl list devices -v` no longer reports any devices as "unavailable".
#
# Exit codes:
# 0 - Success: no devices are marked as unavailable within the timeout window
# 1 - Failure: timed out waiting for devices to become available
# 2 - Failure: prerequisites missing (e.g., xcrun not found)
DEFAULT_TIMEOUT_MINUTES=60
TIMEOUT_MINUTES=${1:-$DEFAULT_TIMEOUT_MINUTES}
if ! [[ "$TIMEOUT_MINUTES" =~ ^[0-9]+$ ]]; then
echo "[wait-simulators] ERROR: TIMEOUT_MINUTES must be an integer number of minutes (got: '$TIMEOUT_MINUTES')." >&2
exit 2
fi
SECONDS_TOTAL=$(( TIMEOUT_MINUTES * 60 ))
DEADLINE=$(( $(date +%s) + SECONDS_TOTAL ))
SLEEP_SECONDS=15
# Print a one-line status snapshot of current unavailable devices (if any)
print_status() {
if xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] Still seeing 'unavailable' devices at $(date '+%Y-%m-%d %H:%M:%S')"
# Show a concise list of unavailable lines for debugging
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /'
else
echo "[wait-simulators] No 'unavailable' devices detected at $(date '+%Y-%m-%d %H:%M:%S')"
fi
}
trap 'echo "[wait-simulators] Interrupted" >&2; exit 130' INT TERM
echo "[wait-simulators] Waiting up to ${TIMEOUT_MINUTES} minute(s) for simulators to become available..."
while true; do
if ! xcrun simctl list devices -v | grep -qi "unavailable"; then
echo "[wait-simulators] All simulators are available."
exit 0
fi
NOW=$(date +%s)
if (( NOW >= DEADLINE )); then
echo "[wait-simulators] TIMEOUT after ${TIMEOUT_MINUTES} minute(s). Some simulators remain 'unavailable'." >&2
echo "[wait-simulators] Final snapshot of unavailable devices:" >&2
xcrun simctl list devices -v | grep -i "unavailable" | sed 's/^/[wait-simulators] /' >&2
exit 1
fi
print_status
REMAIN=$(( DEADLINE - NOW ))
# Sleep in chunks to allow quicker exit when they become available
SLEEP=$SLEEP_SECONDS
if (( REMAIN < SLEEP_SECONDS )); then SLEEP=$REMAIN; fi
sleep "$SLEEP"
# Loop and re-check
done
+55
View File
@@ -0,0 +1,55 @@
#!/bin/bash
source ~/.zprofile
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
update_tcc_database() {
sudo sqlite3 "$1" <<-'EOF'
INSERT OR REPLACE
INTO access (
service,
client_type,
client,
auth_value,
auth_reason,
auth_version,
indirect_object_identifier_type,
indirect_object_identifier
) VALUES
-- Indirect osascript invocation via SSH
('kTCCServiceAccessibility', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/libexec/sshd-keygen-wrapper', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct osascript invocation
('kTCCServiceAccessibility', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/usr/bin/osascript', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.systemevents'),
('kTCCServiceAppleEvents', 1, '/usr/bin/osascript', 2, 0, 1, 0, 'com.apple.Safari'),
-- Direct Python invocation
('kTCCServiceAccessibility', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 0, 'org.python.python', 2, 0, 1, NULL, 'UNUSED'),
-- Commands invoked through the Tart Guest Agent
('kTCCServiceAccessibility', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServiceScreenCapture', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED'),
('kTCCServicePostEvent', 1, '/opt/homebrew/bin/tart-guest-agent', 2, 0, 1, NULL, 'UNUSED');
EOF
}
# Update TCC.db for all users
update_tcc_database "/Library/Application Support/com.apple.TCC/TCC.db"
# Update TCC.db for the current user
update_tcc_database "${HOME}/Library/Application Support/com.apple.TCC/TCC.db"
+10 -5
View File
@@ -7,13 +7,12 @@ packer {
}
}
variable "macos_version" {
variable "vm_name" {
type = string
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-${var.macos_version}-vanilla:latest"
vm_name = "${var.macos_version}-base"
vm_name = "${var.vm_name}"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
@@ -65,6 +64,7 @@ build {
"brew --version",
"brew update",
"brew install wget unzip zip ca-certificates cmake gcc git-lfs jq yq gh gitlab-runner",
"brew install buildkite/buildkite/buildkite-agent@3",
"brew install equinix-labs/otel-cli/otel-cli",
"brew install curl || true", // doesn't work on Monterey
"brew install --cask git-credential-manager",
@@ -117,8 +117,8 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"brew install node@20",
"echo 'export PATH=\"/opt/homebrew/opt/node@20/bin:$PATH\"' >> ~/.zprofile",
"brew install node@24",
"echo 'export PATH=\"/opt/homebrew/opt/node@24/bin:$PATH\"' >> ~/.zprofile",
"source ~/.zprofile",
"node --version",
"npm install --global yarn",
@@ -177,4 +177,9 @@ build {
"sudo chmod 0644 /Library/LaunchAgents/org.cirruslabs.tart-guest-agent.plist",
]
}
# Update TCC.db and allow automation tools
provisioner "shell" {
script = "scripts/update-tcc-database.sh"
}
}
+39
View File
@@ -0,0 +1,39 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
source = "github.com/cirruslabs/tart"
}
}
}
variable "vm_name" {
type = string
}
variable "script_path" {
type = string
description = "Path to a local script that should be uploaded and executed inside the VM."
}
variable "pause_before" {
type = string
default = "60s"
description = "How long Packer should wait before running the uploaded script."
}
source "tart-cli" "tart" {
vm_name = "${var.vm_name}"
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "120s"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
script = var.script_path
pause_before = var.pause_before
}
}
+167
View File
@@ -0,0 +1,167 @@
packer {
required_plugins {
tart = {
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2026SummerSeed/fullrestores/140-55718/5809AFC6-1923-4590-AAFC-904A0283E659/UniversalMac_27.0_26A5388g_Restore.ipsw"
vm_name = "golden-gate-vanilla"
cpu_count = 4
memory_gb = 8
disk_size_gb = 50
ssh_password = "admin"
ssh_username = "admin"
ssh_timeout = "180s"
boot_command = [
# hello, hola, bonjour, etc.
"<wait60s><spacebar>",
# Language: most of the times we have a list of "English"[1], "English (UK)", etc. with
# "English" language already selected. If we type "english", it'll cause us to switch
# to the "English (UK)", which is not what we want. To solve this, we switch to some other
# language first, e.g. "Italiano" and then switch back to "English". We'll then jump to the
# first entry in a list of "english"-prefixed items, which will be "English".
#
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait30s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Accessibility
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Data & Privacy
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Create a Mac Account
"<wait10s><tab><tab><tab><tab><tab><tab>Managed via Tart<tab>admin<tab>admin<tab>admin<tab><tab><tab><spacebar>",
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In to Your Apple Account
#
# We choose "Other Sign-In Options" → "Sign in Later in Settings" here.
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar><up><spacebar>",
# Are you sure you want to skip signing in with an Apple Account?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Age Range -> Adult
"<wait10s><tab><tab><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
"<wait10s><tab><spacebar>",
# Select Your Time Zone
"<wait10s><tab><tab><tab>UTC<enter><leftShiftOn><tab><leftShiftOff><spacebar>",
# Analytics
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Screen Time
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Update Mac Automatically
"<wait10s><tab><tab><spacebar>",
# Liquid Glass
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Welcome to Mac
"<wait30s><spacebar>",
# Disable Voice Over
"<wait10s><leftAltOn><f5><leftAltOff>",
# Enable Keyboard navigation
# This is so that we can navigate the System Settings app using the keyboard
"<wait10s><leftAltOn><spacebar><leftAltOff>Terminal<wait10s><enter>",
"<wait10s><wait10s>defaults write NSGlobalDomain AppleKeyboardUIMode -int 3<enter>",
# Now that the installation is done, open "System Settings"
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait120s>",
# Navigate to "Sharing"
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><leftShiftOff><spacebar>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Type in the password to allow enabling Screen Sharing
"<wait10s>admin<enter>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
# Disable Gatekeeper (1/2)
"<wait10s>sudo spctl --global-disable<enter>",
"<wait10s>admin<enter>",
# Disable Gatekeeper (2/2)
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
# Quit System Settings
"<wait10s><leftAltOn>q<leftAltOff>",
]
// A (hopefully) temporary workaround for Virtualization.Framework's
// installation process not fully finishing in a timely manner
create_grace_time = "30s"
// Keep the recovery partition, otherwise it's not possible to "softwareupdate"
recovery_partition = "keep"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = [
// Enable passwordless sudo
"echo admin | sudo -S sh -c \"mkdir -p /etc/sudoers.d/; echo 'admin ALL=(ALL) NOPASSWD: ALL' | EDITOR=tee visudo /etc/sudoers.d/admin-nopasswd\"",
// Enable auto-login
//
// See https://github.com/xfreebird/kcpassword for details.
"echo '00000000: 1ced 3f4a bcbc ba2c caca 4e82' | sudo xxd -r - /etc/kcpassword",
"sudo defaults write /Library/Preferences/com.apple.loginwindow autoLoginUser admin",
// Disable screensaver at login screen
"sudo defaults write /Library/Preferences/com.apple.screensaver loginWindowIdleTime 0",
// Disable screensaver for admin user
"defaults -currentHost write com.apple.screensaver idleTime 0",
// Prevent the VM from sleeping
"sudo systemsetup -setsleep Off 2>/dev/null",
// Launch Safari to populate the defaults
"/Applications/Safari.app/Contents/MacOS/Safari &",
"SAFARI_PID=$!",
"disown",
"sleep 30",
"kill -9 $SAFARI_PID",
// Enable Safari's remote automation
"sudo safaridriver --enable",
// Disable screen lock
//
// Note that this only works if the user is logged-in,
// i.e. not on login screen.
"sysadminctl -screenLock off -password admin",
]
}
provisioner "shell" {
inline = [
# Ensure that Gatekeeper is disabled
"spctl --status | grep -q 'assessments disabled'"
]
}
}
+3 -3
View File
@@ -1,7 +1,7 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
@@ -12,7 +12,7 @@ packer {
}
source "tart-cli" "tart" {
// will be update to 15.7
// will be update to 15.7.2
from_ipsw = "https://updates.cdn-apple.com/2025SummerFCS/fullrestores/093-10809/CFD6DD38-DAF0-40DA-854F-31AAD1294C6F/UniversalMac_15.6.1_24G90_Restore.ipsw"
vm_name = "sequoia-vanilla"
cpu_count = 4
@@ -33,7 +33,7 @@ source "tart-cli" "tart" {
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait30s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait30s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
+1 -1
View File
@@ -12,7 +12,7 @@ packer {
}
source "tart-cli" "tart" {
// will be update to 14.8
// will be update to 14.8.2
from_ipsw = "https://updates.cdn-apple.com/2024SummerFCS/fullrestores/062-52859/932E0A8F-6644-4759-82DA-F8FA8DEA806A/UniversalMac_14.6.1_23G93_Restore.ipsw"
vm_name = "sonoma-vanilla"
cpu_count = 4
+15 -6
View File
@@ -1,18 +1,18 @@
packer {
required_plugins {
tart = {
version = ">= 1.12.0"
version = ">= 1.16.0"
source = "github.com/cirruslabs/tart"
}
ansible = {
version = "~> 1"
source = "github.com/hashicorp/ansible"
source = "github.com/hashicorp/ansible"
}
}
}
source "tart-cli" "tart" {
from_ipsw = "https://updates.cdn-apple.com/2025FallFCS/fullrestores/089-04148/791B6F00-A30B-4EB0-B2E3-257167F7715B/UniversalMac_26.1_25B78_Restore.ipsw"
from_ipsw = "https://updates.cdn-apple.com/2026SummerFCS/fullrestores/140-83079/25315EF6-AEAB-4588-9774-A3723774C47F/UniversalMac_26.6.1_25G76_Restore.ipsw"
vm_name = "tahoe-vanilla"
cpu_count = 4
memory_gb = 8
@@ -32,7 +32,7 @@ source "tart-cli" "tart" {
# [1]: should be named "English (US)", but oh well 🤷
"<wait30s>italiano<esc>english<enter>",
# Select Your Country or Region
"<wait60s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait60s><click 'Select Your Country or Region'><wait5s>united states<leftShiftOn><tab><leftShiftOff><spacebar>",
# Transfer Your Data to This Mac
"<wait10s><tab><tab><tab><spacebar><tab><tab><spacebar>",
# Written and Spoken Languages
@@ -46,13 +46,15 @@ source "tart-cli" "tart" {
# Enable Voice Over
"<wait120s><leftAltOn><f5><leftAltOff>",
# Sign In with Your Apple ID
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar><up><spacebar>",
# Are you sure you want to skip signing in with an Apple ID?
"<wait10s><tab><spacebar>",
# Terms and Conditions
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# I have read and agree to the macOS Software License Agreement
"<wait10s><tab><spacebar>",
# Age Range -> Adult
"<wait10s><tab><tab><tab><spacebar>",
# Enable Location Services
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Are you sure you don't want to use Location Services?
@@ -65,6 +67,10 @@ source "tart-cli" "tart" {
"<wait10s><tab><tab><spacebar>",
# Siri
"<wait10s><tab><spacebar><leftShiftOn><tab><leftShiftOff><spacebar>",
# You Mac is Ready for FileVault
"<wait10s><leftShiftOn><tab><tab><leftShiftOff><spacebar>",
# Mac Data Will Not Be Securely Encrypted
"<wait10s><tab><spacebar>",
# Choose Your Look
"<wait10s><leftShiftOn><tab><leftShiftOff><spacebar>",
# Update Mac Automatically
@@ -80,10 +86,13 @@ source "tart-cli" "tart" {
# Now that the installation is done, open "System Settings"
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait120s>",
# Navigate to "Sharing"
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Sharing<enter>",
# Navigate to "Screen Sharing" and enable it
"<wait10s><tab><tab><tab><tab><tab><spacebar>",
# Type in the password to allow enabling Screen Sharing
"<wait10s>admin<enter>",
# Navigate to "Remote Login" and enable it
"<wait10s><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><tab><spacebar>",
# Quit System Settings
@@ -95,7 +104,7 @@ source "tart-cli" "tart" {
# On Tahoe opening System Settings through Spotlight is not very reliable, sometimes opens System information
"<wait10s>open '/System/Applications/System Settings.app'<enter>",
"<wait10s><leftCtrlOn><f2><leftCtrlOff><right><right><right><down>Privacy & Security<enter>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><leftShiftOn><tab><tab><tab><tab><tab><tab><leftShiftOff>",
"<wait10s><down><wait1s><down><wait1s><enter>",
"<wait10s>admin<enter>",
"<wait10s><leftShiftOn><tab><leftShiftOff><wait1s><spacebar>",
+29 -40
View File
@@ -16,45 +16,45 @@ variable "xcode_version" {
}
variable "additional_ios_builds" {
type = list(string)
type = list(string)
default = []
}
variable "additional_tvos_builds" {
type = list(string)
type = list(string)
default = []
}
variable "xcode_components" {
type = list(string)
default = []
type = list(string)
default = []
description = "Additional Xcode components to download."
}
variable "expected_runtimes_file" {
type = string
default = ""
type = string
default = ""
description = "Path to file containing expected simulator runtimes. If empty, runtime verification is skipped."
}
variable "tag" {
type = string
type = string
default = ""
}
variable "disk_size" {
type = number
default = 120
type = number
default = 140
}
variable "disk_free_mb" {
type = number
type = number
default = 15000
}
variable "android_sdk_tools_version" {
type = string
default = "11076708" # https://developer.android.com/studio#command-line-tools-only
default = "14742923" # https://developer.android.com/studio#command-line-tools-only
}
source "tart-cli" "tart" {
@@ -100,6 +100,9 @@ build {
"brew --version",
"brew update",
"brew upgrade",
"brew install codex",
"brew install --cask claude-code",
"brew install --cask amazon-q"
]
}
@@ -130,7 +133,7 @@ build {
"rm android-sdk-tools.zip",
"mv $ANDROID_HOME/cmdline-tools/cmdline-tools $ANDROID_HOME/cmdline-tools/latest",
"yes | sdkmanager --licenses",
"yes | sdkmanager 'platform-tools' 'platforms;android-35' 'build-tools;35.0.0' 'ndk;27.2.12479018'"
"yes | sdkmanager 'platform-tools' 'platforms;android-36' 'build-tools;36.0.0' 'ndk;28.2.13676358'"
]
}
@@ -143,7 +146,7 @@ build {
}
provisioner "file" {
sources = [ for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
sources = [for version in var.xcode_version : pathexpand("~/XcodesCache/Xcode_${version}.xip")]
destination = "/Users/admin/Downloads/"
}
@@ -158,7 +161,7 @@ build {
// select the latest one as the default
dynamic "provisioner" {
for_each = local.xcode_install_provisioners
labels = ["shell"]
labels = ["shell"]
content {
inline = provisioner.value.inline
}
@@ -166,11 +169,11 @@ build {
dynamic "provisioner" {
for_each = length(var.xcode_version) > 2 ? [2] : []
labels = ["shell"]
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[2]}'",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[2]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
@@ -178,11 +181,11 @@ build {
dynamic "provisioner" {
for_each = length(var.xcode_version) > 1 ? [1] : []
labels = ["shell"]
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[1]}'",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[1]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
@@ -191,7 +194,7 @@ build {
provisioner "shell" {
inline = [
"source ~/.zprofile",
"sudo xcodes select '${var.xcode_version[0]}'",
"sudo xcode-select -s /Applications/Xcode_${var.xcode_version[0]}.app/Contents/Developer",
"xcodebuild -downloadAllPlatforms",
]
}
@@ -228,7 +231,11 @@ build {
"source ~/.zprofile",
"brew install libimobiledevice ideviceinstaller ios-deploy carthage",
"brew install xcbeautify swiftformat swiftlint swiftgen licenseplist",
"brew install mint tuist/tuist/tuist",
"brew install mint",
"git clone --depth 1 https://github.com/tuist/homebrew-tuist.git \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist\"",
"rm -rf \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Casks\"",
"tuist_version=$(ruby -ne 'if $_ =~ %r{/download/([^/]+)/}; puts $1; exit; end' \"$(brew --repository)/Library/Taps/tuist/homebrew-tuist/Aliases/tuist\") && brew trust --formula \"tuist/tuist/tuist@$tuist_version\" && brew install --formula \"tuist/tuist/tuist@$tuist_version\"",
"rbenv install 3.3.10",
"rbenv global 3.3.10", # fastlane conflicts with 3.4.0+ https://github.com/fastlane/fastlane/issues/29527
"gem update",
"gem install fastlane",
@@ -241,7 +248,7 @@ build {
// Copy expected runtimes file if provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["file"]
labels = ["file"]
content {
source = var.expected_runtimes_file
destination = "/Users/admin/runtimes.expected.txt"
@@ -251,7 +258,7 @@ build {
// Verify simulator runtimes match expected list if file was provided
dynamic "provisioner" {
for_each = var.expected_runtimes_file != "" ? [1] : []
labels = ["shell"]
labels = ["shell"]
content {
inline = [
"source ~/.zprofile",
@@ -341,30 +348,12 @@ build {
#
# [1]: https://apple.stackexchange.com/questions/412101/update-dyld-sim-shared-cache-is-taking-up-a-lot-of-memory
# [2]: https://stackoverflow.com/a/68394101/9316533
provisioner "shell" {
inline = [
"source ~/.zprofile",
"xcrun simctl runtime dyld_shared_cache update --all || sleep 180",
"xcrun simctl list -v",
]
}
// Restart the VM
provisioner "shell" {
inline = [
"sudo shutdown -r now"
]
expect_disconnect = true
}
// Wait for VM to come back up and run simctl commands again
provisioner "shell" {
inline = [
"source ~/.zprofile",
"xcrun simctl runtime dyld_shared_cache update --all || sleep 180",
"xcrun simctl list -v"
]
pause_before = "60s"
}
# Compatibility with GitHub Actions Runner Images, where