Compare commits

..
Author SHA1 Message Date
Nikolay Edigaryev a9f16e07e6 Provide a default when stdinpass variable is not set 2025-02-11 23:03:01 +01:00
Nikolay Edigaryev 998bbf8ca8 Parse available updates to avoid upgrading to the next macOS version (#208)
* Parse available updates to avoid upgrading to the next macOS version

* Do not override ANSIBLE_CONFIG with our ansible.cfg

Otherwise Packer + Ansible integration goes haywire.

Instead, only modify the required variables through ansible_env_vars.

* Support Monterey
2025-02-12 01:45:40 +04:00
Nikolay Edigaryev 5a55351c81 Use xargs fix for all vanilla images, not just Sequoia (#207) 2025-02-06 18:55:36 +04:00
7 changed files with 60 additions and 12 deletions
-2
View File
@@ -9,8 +9,6 @@ task:
<<: *defaults
pull_vanilla_script:
- tart pull ghcr.io/cirruslabs/macos-$MACOS_VERSION-vanilla:latest
install_sshpass_script:
- brew install sshpass
build_base_script:
- packer init templates/base.pkr.hcl
- packer build -var macos_version="$MACOS_VERSION" templates/base.pkr.hcl
+17 -7
View File
@@ -17,11 +17,21 @@
recurse: yes
become: yes
- name: Ensure that there are no more software updates available (1/2)
command: "softwareupdate --all --list"
register: check_updates_result
- name: "ensure that there are no more software updates available: check for available updates"
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: Ensure that there are no more software updates available (2/2)
assert:
that:
- "'No new software available' in check_updates_result.stderr"
- name: "ensure that there are no more software updates available: parse available updates"
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: "ensure that there are no more software updates available: print available updates"
debug:
var: software_updates
- name: "ensure that there are no more software updates available: fail if some updates were not installed"
fail:
msg: "Found unapplied update: {{ item.label }}"
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
@@ -1,8 +1,21 @@
- name: check for available updates
command:
cmd: "softwareupdate --all --list"
register: software_updates_result
- name: parse available updates
set_fact:
software_updates: "{{ software_updates_result.stdout | regex_findall('\\* Label: (.*)\\n\\tTitle: (.*), Version: (.*), Size: (.*), Recommended: (.*), Action: (.*), .*') | map('zip', ['label', 'title', 'version', 'size', 'recommended', 'action']) | map('map', 'reverse') | map('community.general.dict') }}"
- name: print available updates
debug:
var: software_updates
# It seems that we must always pass "--restart" command-line argument to "softwareupdate",
# otherwise on the OS update the "softwareupdate" will be stuck at "Downloaded: macOS [...]"
- name: install all macOS updates
- name: install available update
command:
cmd: "softwareupdate --all --install --agree-to-license --force --restart --user admin --stdinpass"
cmd: "softwareupdate --install --agree-to-license --force --restart --user admin --stdinpass {{ stdinpass | default("") }} '{{ item.label }}'"
stdin: "{{ ansible_password }}"
register: update_result
# Work around the following:
@@ -14,6 +27,8 @@
# when the system reboots due to --restart
failed_when: update_result.rc not in [0, 9, -9, 15, -15]
become: yes
loop: "{{ software_updates }}"
when: "not item.label.startswith('macOS') or item.version.split('.')[0] == ansible_facts['distribution_version'].split('.')[0]"
# Wait for the connection since the previous command could restart the host
- name: wait for connection
@@ -23,4 +38,6 @@
# the commands below on a non-restarted system.
delay: 60
timeout: 1800
when: "'No updates are available' not in (update_result.stderr_lines | join('\n'))"
when:
- update_result is defined
- not update_result.skipped
+8
View File
@@ -135,5 +135,13 @@ build {
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
extra_arguments = [
"--extra-vars", "stdinpass=admin",
]
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+5
View File
@@ -137,5 +137,10 @@ build {
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+5
View File
@@ -134,5 +134,10 @@ build {
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}
+5
View File
@@ -143,5 +143,10 @@ build {
provisioner "ansible" {
playbook_file = "ansible/playbook-system-updater.yml"
ansible_env_vars = [
"ANSIBLE_TRANSPORT=paramiko",
"ANSIBLE_HOST_KEY_CHECKING=False",
]
use_proxy = false
}
}